Skip to content

Update axios to 1.15.0 to solve vulnerability#3216

Merged
EmilyRagan merged 1 commit intomainfrom
update-axios
Apr 14, 2026
Merged

Update axios to 1.15.0 to solve vulnerability#3216
EmilyRagan merged 1 commit intomainfrom
update-axios

Conversation

@EmilyRagan
Copy link
Copy Markdown
Contributor

@EmilyRagan EmilyRagan self-assigned this Apr 13, 2026
@codecov
Copy link
Copy Markdown

codecov Bot commented Apr 13, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 78.39%. Comparing base (40b8191) to head (e755dad).
⚠️ Report is 6 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #3216      +/-   ##
==========================================
+ Coverage   78.35%   78.39%   +0.03%     
==========================================
  Files         674      674              
  Lines       55466    55466              
  Branches      728      728              
==========================================
+ Hits        43462    43482      +20     
+ Misses      11926    11906      -20     
  Partials       78       78              
Flag Coverage Δ
python 79.63% <ø> (-0.01%) ⬇️
ruby-api 83.40% <ø> (+0.49%) ⬆️
ruby-backend 81.54% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@sonarqubecloud
Copy link
Copy Markdown

@socket-security
Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Added@​types/​jasmine@​5.1.15771007686100

View full report

@socket-security
Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm entities is 91.0% likely obfuscated

Confidence: 0.91

Location: Package overview

From: ?npm/@angular-devkit/build-angular@18.2.21npm/entities@4.5.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/entities@4.5.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm esbuild-wasm is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ?npm/@angular-devkit/build-angular@18.2.21npm/esbuild-wasm@0.23.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/esbuild-wasm@0.23.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@EmilyRagan EmilyRagan added maintenance Dependencies or other issues not bugs or features dependencies Pull requests that update a dependency file labels Apr 13, 2026
@EmilyRagan EmilyRagan merged commit af4dcb7 into main Apr 14, 2026
54 of 55 checks passed
@EmilyRagan EmilyRagan deleted the update-axios branch April 14, 2026 17:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file maintenance Dependencies or other issues not bugs or features

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants