Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

removed vulnerability with axios dependency update #132

Merged
merged 1 commit into from
Dec 19, 2023

Conversation

ps73
Copy link
Contributor

@ps73 ps73 commented Nov 22, 2023

axios 0.8.1 - 1.5.1
Severity: moderate
Axios Cross-Site Request Forgery Vulnerability - GHSA-wf5p-g6vw-rhxx

@ps73
Copy link
Contributor Author

ps73 commented Nov 22, 2023

This PR fixes this by updating axios to newest version.

@headlessme
Copy link

headlessme commented Dec 19, 2023

@yakovkhalinsky could you merge this PR to resolve the axios vulnerability? Or @odensc?

@yakovkhalinsky yakovkhalinsky merged commit 3443721 into yakovkhalinsky:master Dec 19, 2023
@headlessme
Copy link

@yakovkhalinsky thanks for the quick resolution here! Could you also publish the latest to NPM?

@yakovkhalinsky
Copy link
Owner

@headlessme might take me a few days, I'm on holday at the moment :)

I'll have to set everything up to help with publishing to npm, it's a been a while since I've been involved directly with this repo, regardless I promise to get this done soon 👍

@headlessme
Copy link

Thanks! Have a nice holiday 🏝️

@jracabado
Copy link

@yakovkhalinsky sorry I had not seen this thread, I opened an issue related to this CVE: #133

@ps73
Copy link
Contributor Author

ps73 commented Jan 5, 2024

@yakovkhalinsky Is there any eta when this will be released to npm?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants