Skip to content

SDK-405 Bump version to 2.2.2 and pin axios to v1.14.0#554

Merged
joaodordio merged 2 commits intomainfrom
SDK-405
Mar 31, 2026
Merged

SDK-405 Bump version to 2.2.2 and pin axios to v1.14.0#554
joaodordio merged 2 commits intomainfrom
SDK-405

Conversation

@joaodordio
Copy link
Copy Markdown
Member

@joaodordio joaodordio commented Mar 31, 2026

JIRA Ticket

Description

axios 1.14.1 was published via a hijacked npm account and included a RAT. Versions <=1.13.4 are vulnerable to a DoS via prototype pollution in mergeConfig. This pins all three package.json files to the safe 1.14.0 release and adds a yarn resolutions block as an additional safeguard.

Test Steps

@joaodordio joaodordio self-assigned this Mar 31, 2026
@joaodordio joaodordio requested a review from mprew97 as a code owner March 31, 2026 17:29
@codecov-commenter
Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 74.45%. Comparing base (e38d2dc) to head (bd0baeb).

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #554   +/-   ##
=======================================
  Coverage   74.45%   74.45%           
=======================================
  Files          57       57           
  Lines        2736     2736           
  Branches      815      798   -17     
=======================================
  Hits         2037     2037           
- Misses        658      698   +40     
+ Partials       41        1   -40     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@joaodordio joaodordio enabled auto-merge (squash) March 31, 2026 17:39
@joaodordio joaodordio merged commit 65b07d2 into main Mar 31, 2026
6 checks passed
@joaodordio joaodordio deleted the SDK-405 branch March 31, 2026 17:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants