Skip to content

Commit e2891b5

Browse files
antonisclaudelucas-zimerman
authored
chore(deps): bump axios to ^1.13.5 (#5708)
* chore(deps): bump axios to ^1.13.5 Adds a yarn resolution to force axios to >=1.13.5, patching three vulnerabilities: SSRF and credential leakage via absolute URL (< 1.8.2), DoS via no data size check (< 1.12.0), and DoS via __proto__ key in mergeConfig (<= 1.13.4). Consolidates multiple axios versions onto 1.13.5. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * chore(deps): bump form-data resolution from 4.0.4 to 4.0.5 Bumps form-data to satisfy axios 1.13.5's dependency on ^4.0.5. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> Co-authored-by: LucasZF <lucas-zimerman1@hotmail.com>
1 parent 35b66e7 commit e2891b5

File tree

2 files changed

+16
-70
lines changed

2 files changed

+16
-70
lines changed

package.json

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -60,8 +60,9 @@
6060
],
6161
"resolutions": {
6262
"appium-chromedriver@npm:5.6.73/@xmldom/xmldom": "0.8.10",
63+
"axios": "^1.13.5",
6364
"fast-xml-parser": "^5.3.6",
64-
"form-data": "4.0.4",
65+
"form-data": "4.0.5",
6566
"qs": "^6.14.2",
6667
"lodash": "^4.17.23",
6768
"tar-fs": "^3.1.1",

yarn.lock

Lines changed: 14 additions & 69 deletions
Original file line numberDiff line numberDiff line change
@@ -14633,69 +14633,14 @@ __metadata:
1463314633
languageName: node
1463414634
linkType: hard
1463514635

14636-
"axios@npm:1.12.0":
14637-
version: 1.12.0
14638-
resolution: "axios@npm:1.12.0"
14636+
"axios@npm:^1.13.5":
14637+
version: 1.13.5
14638+
resolution: "axios@npm:1.13.5"
1463914639
dependencies:
14640-
follow-redirects: ^1.15.6
14641-
form-data: ^4.0.4
14640+
follow-redirects: ^1.15.11
14641+
form-data: ^4.0.5
1464214642
proxy-from-env: ^1.1.0
14643-
checksum: f2a109efea16711907ae86acc46434d52da28e889bf1d2fc2b66844e82c9908f6d96d988ad9043b37d4146abc182e67d61abd87367152bbbc1cd73afa3c5de71
14644-
languageName: node
14645-
linkType: hard
14646-
14647-
"axios@npm:1.6.3":
14648-
version: 1.6.3
14649-
resolution: "axios@npm:1.6.3"
14650-
dependencies:
14651-
follow-redirects: ^1.15.0
14652-
form-data: ^4.0.0
14653-
proxy-from-env: ^1.1.0
14654-
checksum: 07ef3bb83fc2dacc1ae2c97f2bbd04ef7701f5655f9037789d79ee78b698ffa50eaa8465c2017d4d3e9ce7d94cb779f730acaab32ce9036d0a4933c1e89df4da
14655-
languageName: node
14656-
linkType: hard
14657-
14658-
"axios@npm:1.7.2":
14659-
version: 1.7.2
14660-
resolution: "axios@npm:1.7.2"
14661-
dependencies:
14662-
follow-redirects: ^1.15.6
14663-
form-data: ^4.0.0
14664-
proxy-from-env: ^1.1.0
14665-
checksum: e457e2b0ab748504621f6fa6609074ac08c824bf0881592209dfa15098ece7e88495300e02cd22ba50b3468fd712fe687e629dcb03d6a3f6a51989727405aedf
14666-
languageName: node
14667-
linkType: hard
14668-
14669-
"axios@npm:1.7.3":
14670-
version: 1.7.3
14671-
resolution: "axios@npm:1.7.3"
14672-
dependencies:
14673-
follow-redirects: ^1.15.6
14674-
form-data: ^4.0.0
14675-
proxy-from-env: ^1.1.0
14676-
checksum: bc304d6da974922342aed7c33155934354429cdc7e1ba9d399ab9ff3ac76103f3697eeedf042a634d43cdae682182bcffd942291db42d2be45b750597cdd5eef
14677-
languageName: node
14678-
linkType: hard
14679-
14680-
"axios@npm:1.9.0":
14681-
version: 1.9.0
14682-
resolution: "axios@npm:1.9.0"
14683-
dependencies:
14684-
follow-redirects: ^1.15.6
14685-
form-data: ^4.0.0
14686-
proxy-from-env: ^1.1.0
14687-
checksum: 631f02c9c279f2ae90637a4989cc9d75c1c27aefd16b6e8eb90f98a4d0bddaccfd1cb1387be12101d1ab0f9bbf0c47e2451b4de0cf2870462a7d9ed3de8da3f2
14688-
languageName: node
14689-
linkType: hard
14690-
14691-
"axios@npm:^1.4.0, axios@npm:^1.6.5, axios@npm:^1.6.7, axios@npm:^1.7.4, axios@npm:^1.x":
14692-
version: 1.8.4
14693-
resolution: "axios@npm:1.8.4"
14694-
dependencies:
14695-
follow-redirects: ^1.15.6
14696-
form-data: ^4.0.0
14697-
proxy-from-env: ^1.1.0
14698-
checksum: e901dc1730bdcd769839b3d93ae6d6457a53d79b19a0eb623ebfea333441259ab51e63ca118baa47a5156567401466ac739f31087b4ee5e6770ab2e227484538
14643+
checksum: 985024c4a32f837053f198f02a308fd6f8bfb4053a2f21e39e37992bc6d06917f008679c36b3e7f0f0c9060c85ffe37c61e58d2ac662595d68dc1b89cef78de8
1469914644
languageName: node
1470014645
linkType: hard
1470114646

@@ -20479,13 +20424,13 @@ __metadata:
2047920424
languageName: node
2048020425
linkType: hard
2048120426

20482-
"follow-redirects@npm:^1.15.0, follow-redirects@npm:^1.15.6":
20483-
version: 1.15.6
20484-
resolution: "follow-redirects@npm:1.15.6"
20427+
"follow-redirects@npm:^1.15.11":
20428+
version: 1.15.11
20429+
resolution: "follow-redirects@npm:1.15.11"
2048520430
peerDependenciesMeta:
2048620431
debug:
2048720432
optional: true
20488-
checksum: a62c378dfc8c00f60b9c80cab158ba54e99ba0239a5dd7c81245e5a5b39d10f0c35e249c3379eae719ff0285fff88c365dd446fab19dee771f1d76252df1bbf5
20433+
checksum: 20bf55e9504f59e6cc3743ba27edb2ebf41edea1baab34799408f2c050f73f0c612728db21c691276296d2795ea8a812dc532a98e8793619fcab91abe06d017f
2048920434
languageName: node
2049020435
linkType: hard
2049120436

@@ -20531,16 +20476,16 @@ __metadata:
2053120476
languageName: node
2053220477
linkType: hard
2053320478

20534-
"form-data@npm:4.0.4":
20535-
version: 4.0.4
20536-
resolution: "form-data@npm:4.0.4"
20479+
"form-data@npm:4.0.5":
20480+
version: 4.0.5
20481+
resolution: "form-data@npm:4.0.5"
2053720482
dependencies:
2053820483
asynckit: ^0.4.0
2053920484
combined-stream: ^1.0.8
2054020485
es-set-tostringtag: ^2.1.0
2054120486
hasown: ^2.0.2
2054220487
mime-types: ^2.1.12
20543-
checksum: 9b7788836df9fa5a6999e0c02515b001946b2a868cfe53f026c69e2c537a2ff9fbfb8e9d2b678744628f3dc7a2d6e14e4e45dfaf68aa6239727f0bdb8ce0abf2
20488+
checksum: af8328413c16d0cded5fccc975a44d227c5120fd46a9e81de8acf619d43ed838414cc6d7792195b30b248f76a65246949a129a4dadd148721948f90cd6d4fb69
2054420489
languageName: node
2054520490
linkType: hard
2054620491

0 commit comments

Comments
 (0)