-
Notifications
You must be signed in to change notification settings - Fork 0
chore(deps): update dependency axios to v0.28.0 [security] #110
base: master
Are you sure you want to change the base?
Conversation
Kudos, SonarCloud Quality Gate passed! 0 Bugs No Coverage information |
02cc33e
to
fc8563d
Compare
fc8563d
to
80b0fa1
Compare
Kudos, SonarCloud Quality Gate passed! 0 Bugs No Coverage information |
80b0fa1
to
7393a03
Compare
7393a03
to
f01d5f9
Compare
f01d5f9
to
2fd14ef
Compare
Kudos, SonarCloud Quality Gate passed! 0 Bugs No Coverage information |
2fd14ef
to
5ebeb20
Compare
5ebeb20
to
b74f6fc
Compare
b74f6fc
to
3264a69
Compare
Kudos, SonarCloud Quality Gate passed! 0 Bugs No Coverage information |
3264a69
to
749b83a
Compare
b0e983c
to
fd4ad4a
Compare
Kudos, SonarCloud Quality Gate passed! 0 Bugs No Coverage information |
fd4ad4a
to
e5313fc
Compare
e5313fc
to
bcb2947
Compare
bcb2947
to
0c8daad
Compare
Kudos, SonarCloud Quality Gate passed! 0 Bugs No Coverage information |
0c8daad
to
adf23d8
Compare
New and removed dependencies detected. Learn more about Socket for GitHub ↗︎
🚮 Removed packages: npm/axios@0.21.0 |
adf23d8
to
7ecc6ee
Compare
7ecc6ee
to
1164c94
Compare
Kudos, SonarCloud Quality Gate passed! 0 Bugs No Coverage information |
1164c94
to
e911d0c
Compare
Kudos, SonarCloud Quality Gate passed! 0 Bugs No Coverage information |
e911d0c
to
d6b4c2a
Compare
d6b4c2a
to
c733314
Compare
Quality Gate passedIssues Measures |
This PR contains the following updates:
0.21.0
->0.28.0
GitHub Vulnerability Alerts
CVE-2020-28168
Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.
CVE-2021-3749
axios before v0.21.2 is vulnerable to Inefficient Regular Expression Complexity.
CVE-2023-45857
An issue discovered in Axios 0.8.1 through 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.
Release Notes
axios/axios (axios)
v0.28.0
Compare Source
Release notes:
Bug Fixes
withXSRFToken
option to v0.x (#6091)Backports from v1.x:
axios.formToJSON
method (#4735)url-encoded-form
serializer to respect theformSerializer
config (#4721)string[]
toAxiosRequestHeaders
type (#4322)AxiosError
stack capturing; (#4718)AxiosError
status code type; (#4717)blob
to the list of protocols supported by the browser (#4678)v0.27.2
Compare Source
Fixes and Functionality:
v0.27.1
Compare Source
Fixes and Functionality:
v0.27.0
Compare Source
Breaking changes:
Content-Type
request header when passing FormData (#3785)transformRequest
andtoFormData
(#4470)QOL and DevX improvements:
Fixes and Functionality:
Internal and Tests:
Documentation:
Notes:
v0.26.1
Compare Source
Fixes and Functionality:
v0.26.0
Compare Source
Fixes and Functionality:
v0.25.0
Compare Source
Breaking changes:
Fixes and Functionality:
boolean
andnumber
types (#4144)undefined
(#3153)Internal and Tests:
Documentation:
Huge thanks to everyone who contributed to this release via code (authors listed below) or via reviews and triaging on GitHub:
v0.24.0
Compare Source
Breaking changes:
Huge thanks to everyone who contributed to this release via code (authors listed below) or via reviews and triaging on GitHub:
v0.23.0
Compare Source
Breaking changes:
Fixes and Functionality:
Internal and Tests:
Documentation:
Huge thanks to everyone who contributed to this release via code (authors listed below) or via reviews and triaging on GitHub:
v0.22.0
Compare Source
Fixes and Functionality:
Huge thanks to everyone who contributed to this release via code (authors listed below) or via reviews and triaging on GitHub:
v0.21.4
Compare Source
Fixes and Functionality:
Huge thanks to everyone who contributed to this release via code (authors listed below) or via reviews and triaging on GitHub:
v0.21.3
Compare Source
Fixes and Functionality:
Huge thanks to everyone who contributed to this release via code (authors listed below) or via reviews and triaging on GitHub:
v0.21.2
Compare Source
Fixes and Functionality:
Internal and Tests:
Documentation:
AUTH_TOKEN
with multiple domain endpoints (#3539)Huge thanks to everyone who contributed to this release via code (authors listed below) or via reviews and triaging on GitHub:
v0.21.1
Compare Source
Fixes and Functionality:
AxiosError
(#2949)Internal and Tests:
socket
http test (#3364)Huge thanks to everyone who contributed to this release via code (authors listed below) or via reviews and triaging on GitHub:
Configuration
📅 Schedule: Branch creation - "" in timezone Europe/Paris, Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate. View repository job log here.