Skip to content

Bumped axios to ^1.8.4 #82

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Mar 24, 2025
Merged

Bumped axios to ^1.8.4 #82

merged 1 commit into from
Mar 24, 2025

Conversation

toonvandenbos
Copy link
Member

A concerned user performed a penetration test, raising the issue of a vulnerability found in one of the package's JS dependencies, axios.

This PR just bumps axios to its latest release.

For more information about the fixed vulnerability in the previous Axios version, see CVE:
https://nvd.nist.gov/vuln/detail/CVE-2024-39338

@toonvandenbos toonvandenbos merged commit 262fe80 into main Mar 24, 2025
18 checks passed
@toonvandenbos toonvandenbos deleted the bump-axios branch March 24, 2025 18:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant