Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency axios to v1 [SECURITY] #3343

Merged
merged 4 commits into from Nov 15, 2023

Conversation

openverse-bot
Copy link
Collaborator

@openverse-bot openverse-bot commented Nov 13, 2023

Closes #2299

This PR contains the following updates:

Package Type Update Change
axios (source) dependencies major ^0.27.0 -> ^1.0.0

GitHub Vulnerability Alerts

CVE-2023-45857

An issue discovered in Axios 0.8.1 through 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.


Release Notes

axios/axios (axios)

v1.6.0

Compare Source

Bug Fixes
PRs

⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459
Contributors to this release

1.5.1 (2023-09-26)

Bug Fixes
  • adapters: improved adapters loading logic to have clear error messages; (#​5919) (e410779)
  • formdata: fixed automatic addition of the Content-Type header for FormData in non-browser environments; (#​5917) (bc9af51)
  • headers: allow content-encoding header to handle case-insensitive values (#​5890) (#​5892) (4c89f25)
  • types: removed duplicated code (9e62056)
Contributors to this release
PRs

⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459

v1.5.1

Compare Source

Bug Fixes
  • adapters: improved adapters loading logic to have clear error messages; (#​5919) (e410779)
  • formdata: fixed automatic addition of the Content-Type header for FormData in non-browser environments; (#​5917) (bc9af51)
  • headers: allow content-encoding header to handle case-insensitive values (#​5890) (#​5892) (4c89f25)
  • types: removed duplicated code (9e62056)
Contributors to this release
PRs

⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459

v1.5.0

Compare Source

Bug Fixes
  • adapter: make adapter loading error more clear by using platform-specific adapters explicitly (#​5837) (9a414bb)
  • dns: fixed cacheable-lookup integration; (#​5836) (b3e327d)
  • headers: added support for setting header names that overlap with class methods; (#​5831) (d8b4ca0)
  • headers: fixed common Content-Type header merging; (#​5832) (8fda276)
Features
Contributors to this release
PRs

⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459

v1.4.0

Compare Source

Bug Fixes
  • formdata: add multipart/form-data content type for FormData payload on custom client environments; (#​5678) (bbb61e7)
  • package: export package internals with unsafe path prefix; (#​5677) (df38c94)
Features
Performance Improvements
  • merge-config: optimize mergeConfig performance by avoiding duplicate key visits; (#​5679) (e6f7053)
Contributors to this release
PRs

⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459

1.3.6 (2023-04-19)

Bug Fixes
  • types: added transport to RawAxiosRequestConfig (#​5445) (6f360a2)
  • utils: make isFormData detection logic stricter to avoid unnecessary calling of the toString method on the target; (#​5661) (aa372f7)
Contributors to this release
PRs

⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459

1.3.5 (2023-04-05)

Bug Fixes
  • headers: fixed isValidHeaderName to support full list of allowed characters; (#​5584) (e7decef)
  • params: re-added the ability to set the function as paramsSerializer config; (#​5633) (a56c866)
Contributors to this release
PRs

⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459

1.3.4 (2023-02-22)

Bug Fixes
  • blob: added a check to make sure the Blob class is available in the browser's global scope; (#​5548) (3772c8f)
  • http: fixed regression bug when handling synchronous errors inside the adapter; (#​5564) (a3b246c)
Contributors to this release
PRs

⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459

1.3.3 (2023-02-13)

Bug Fixes
  • formdata: added a check to make sure the FormData class is available in the browser's global scope; (#​5545) (a6dfa72)
  • formdata: fixed setting NaN as Content-Length for form payload in some cases; (#​5535) (c19f7bf)
  • headers: fixed the filtering logic of the clear method; (#​5542) (ea87ebf)
Contributors to this release
PRs

⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459

1.3.2 (2023-02-03)

Bug Fixes
Contributors to this release
PRs

⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459

1.3.1 (2023-02-01)

Bug Fixes
  • formdata: add hotfix to use the asynchronous API to compute the content-length header value; (#​5521) (96d336f)
  • serializer: fixed serialization of array-like objects; (#​5518) (08104c0)
Contributors to this release
PRs

⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459

v1.3.6

Compare Source

Bug Fixes
  • types: added transport to RawAxiosRequestConfig (#​5445) (6f360a2)
  • utils: make isFormData detection logic stricter to avoid unnecessary calling of the toString method on the target; (#​5661) (aa372f7)
Contributors to this release
PRs

⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459

v1.3.5

Compare Source

Bug Fixes
  • headers: fixed isValidHeaderName to support full list of allowed characters; (#​5584) (e7decef)
  • params: re-added the ability to set the function as paramsSerializer config; (#​5633) (a56c866)
Contributors to this release
PRs

⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459

v1.3.4

Compare Source

Bug Fixes
  • blob: added a check to make sure the Blob class is available in the browser's global scope; (#​5548) (3772c8f)
  • http: fixed regression bug when handling synchronous errors inside the adapter; (#​5564) (a3b246c)
Contributors to this release
PRs

⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459

v1.3.3

Compare Source

Bug Fixes
  • formdata: added a check to make sure the FormData class is available in the browser's global scope; (#​5545) (a6dfa72)
  • formdata: fixed setting NaN as Content-Length for form payload in some cases; (#​5535) (c19f7bf)
  • headers: fixed the filtering logic of the clear method; (#​5542) (ea87ebf)
Contributors to this release
PRs

⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459

v1.3.2

Compare Source

Bug Fixes
Contributors to this release
PRs

⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459

v1.3.1

Compare Source

Bug Fixes
  • formdata: add hotfix to use the asynchronous API to compute the content-length header value; (#​5521) (96d336f)
  • serializer: fixed serialization of array-like objects; (#​5518) (08104c0)
Contributors to this release
PRs

⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459

v1.3.0

Compare Source

Bug Fixes
Features
  • fomdata: added support for spec-compliant FormData & Blob types; (#​5316) (6ac574e)
Contributors to this release
PRs

⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459

1.2.6 (2023-01-28)

Bug Fixes
  • headers: added missed Authorization accessor; (#​5502) (342c0ba)
  • types: fixed CommonRequestHeadersList & CommonResponseHeadersList types to be private in commonJS; (#​5503) (5a3d0a3)
Contributors to this release
PRs

⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459

1.2.5 (2023-01-26)

Bug Fixes
  • types: fixed AxiosHeaders to handle spread syntax by making all methods non-enumerable; (#​5499) (580f1e8)
Contributors to this release
PRs

⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459

1.2.4 (2023-01-22)

Bug Fixes
Contributors to this release
PRs

⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459

1.2.3 (2023-01-10)

Bug Fixes
  • types: fixed AxiosRequestConfig header interface by refactoring it to RawAxiosRequestConfig; (#​5420) (0811963)
Contributors to this release
PRs

⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459

[1.2.2] - 2022-12-29

Fixed
Chores
  • chore(ci): set conventional-changelog header config #​5406
  • chore(ci): fix automatic contributors resolving #​5403
  • chore(ci): improved logging for the contributors list generator #​5398
  • chore(ci): fix release action #​5397
  • chore(ci): fix version bump script by adding bump argument for target version #​5393
  • chore(deps): bump decode-uri-component from 0.2.0 to 0.2.2 #​5342
  • chore(ci): GitHub Actions Release script #​5384
  • chore(ci): release scripts #​5364
Contributors to this release

[1.2.1] - 2022-12-05

Changed
  • feat(exports): export mergeConfig #​5151
Fixed
  • fix(CancelledError): include config #​4922
  • fix(general): removing multiple/trailing/leading whitespace #​5022
  • fix(headers): decompression for responses without Content-Length header #​5306
  • fix(webWorker): exception to sending form data in web worker #​5139
Refactors
  • refactor(types): AxiosProgressEvent.event type to any #​5308
  • refactor(types): add missing types for static AxiosError.from method #​4956
Chores
  • chore(docs): remove README link to non-existent upgrade guide #​5307
  • chore(docs): typo in issue template name #​5159
Contributors to this release
PRs

⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459

[1.2.0] - 2022-11-10

Changed
  • changed: refactored module exports #​5162
  • change: re-added support for loading Axios with require('axios').default #​5225
Fixed
  • fix: improve AxiosHeaders class #​5224
  • fix: TypeScript type definitions for commonjs #​5196
  • fix: type definition of use method on AxiosInterceptorManager to match the the README #​5071
  • fix: __dirname is not defined in the sandbox #​5269
  • fix: AxiosError.toJSON method to avoid circular references #​5247
  • fix: Z_BUF_ERROR when content-encoding is set but the response body is empty #​5250
Refactors
  • refactor: allowing adapters to be loaded by name #​5277
Chores
  • chore: force CI restart #​5243
  • chore: update ECOSYSTEM.md #​5077
  • chore: update get/index.html #​5116
  • chore: update Sandbox UI/UX #​5205
  • chore:(actions): remove git credentials after checkout #​5235
  • chore(actions): bump actions/dependency-review-action from 2 to 3 #​5266
  • chore(packages): bump loader-utils from 1.4.1 to 1.4.2 #​5295
  • chore(packages): bump engine.io from 6.2.0 to 6.2.1 #​5294
  • chore(packages): bump socket.io-parser from 4.0.4 to 4.0.5 #​5241
  • chore(packages): bump loader-utils from 1.4.0 to 1.4.1 #​5245
  • chore(docs): update Resources links in README #​5119
  • chore(docs): update the link for JSON url #​5265
  • chore(docs): fix broken links #​5218
  • chore(docs): update and rename UPGRADE_GUIDE.md to MIGRATION_GUIDE.md #​5170
  • chore(docs): typo fix line #​856 and #​920 #​5194
  • chore(docs): typo fix #​800 #​5193
  • chore(docs): fix typos #​5184
  • chore(docs): fix punctuation in README.md #​5197
  • chore(docs): update readme in the Handling Errors section - issue reference #​5260 #​5261
  • chore: remove \b from filename #​5207
  • chore(docs): update CHANGELOG.md #​5137
  • chore: add sideEffects false to package.json #​5025
Contributors to this release
PRs

⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459

[1.1.3] - 2022-10-15

Added
  • Added custom params serializer support #​5113
Fixed
  • Fixed top-level export to keep them in-line with static properties #​5109
  • Stopped including null values to query string. #​5108
  • Restored proxy config backwards compatibility with 0.x #​5097
  • Added back AxiosHeaders in AxiosHeaderValue #​5103
  • Pin CDN install instructions to a specific version #​5060
  • Handling of array values fixed for AxiosHeaders #​5085
Chores
  • docs: match badge style, add link to them #​5046
  • chore: fixing comments typo #​5054
  • chore: update issue template #​5061
  • chore: added progress capturing section to the docs; #​5084
Contributors to this release
PRs

⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459

[1.1.2] - 2022-10-07

Fixed
  • Fixed broken exports for UMD builds.
Contributors to this release
PRs

⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459

[1.1.1] - 2022-10-07

Fixed
  • Fixed broken exports for common js. This fix breaks a prior fix, I will fix both issues ASAP but the commonJS use is more impactful.
Contributors to this release
PRs

⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459

[1.1.0] - 2022-10-06

Fixed
  • Fixed missing exports in type definition index.d.ts #​5003
  • Fixed query params composing #​5018
  • Fixed GenericAbortSignal interface by making it more generic #​5021
  • Fixed adding "clear" to AxiosInterceptorManager #​5010
  • Fixed commonjs & umd exports #​5030
  • Fixed inability to access response headers when using axios 1.x with Jest #​5036
Contributors to this release
PRs

⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459

[1.0.0] - 2022-10-04

Added
  • Added stack trace to AxiosError #​4624
  • Add AxiosError to AxiosStatic #​4654
  • Replaced Rollup as our build runner #​4596
  • Added generic TS types for the exposed toFormData helper #​4668
  • Added listen callback function #​4096
  • Added instructions for installing using PNPM #​4207
  • Added generic AxiosAbortSignal TS interface to avoid importing AbortController polyfill #​4229
  • Added axios-url-template in ECOSYSTEM.md #​4238
  • Added a clear() function to the request and response interceptors object so a user can ensure that all interceptors have been removed from an axios instance #​4248
  • Added react hook plugin #​4319
  • Adding HTTP status code for transformResponse #​4580
  • Added blob to the list of protocols supported by the browser #​4678
  • Resolving proxy from env on redirect #​4436
  • Added enhanced toFormData implementation with additional options 4704
  • Adding Canceler parameters config and request #​4711
  • Added automatic payload serialization to application/x-www-form-urlencoded #​4714
  • Added the ability for webpack users to overwrite built-ins #​4715
  • Added string[] to AxiosRequestHeaders type #​4322
  • Added the ability for the url-encoded-form serializer to respect the formSerializer config #​4721
  • Added isCancel type assert #​4293
  • Added data URL support for node.js #​4725
  • Adding types for progress event callbacks #​4675
  • URL params serializer #​4734
  • Added axios.formToJSON method #​4735
  • Bower platform add data protocol #​4804
  • Use WHATWG URL API instead of url.parse() #​4852
  • Add ENUM containing Http Status Codes to typings #​4903
  • Improve typing of timeout in index.d.ts #​4934
Changed
  • Updated AxiosError.config to be optional in the type definition #​4665
  • Updated README emphasizing the URLSearchParam built-in interface over other solutions #​4590
  • Include request and config when creating a CanceledError instance #​4659
  • Changed func-names eslint rule to as-needed #​4492
  • Replacing deprecated substr() with slice() as substr() is deprecated #​4468
  • Updating HTTP links in README.md to use HTTPS #​4387
  • Updated to a better trim() polyfill #​4072
  • Updated types to allow specifying partial default headers on instance create #​4185
  • Expanded isAxiosError types #​4344
  • Updated type definition for axios instance methods #​4224
  • Updated eslint config #​4722
  • Updated Docs #​4742
  • Refactored Axios to use ES2017 #​4787
Deprecated
  • There are multiple deprecations, refactors and fixes provided in this release. Please read through the full release notes to see how this may impact your project and use case.
Removed
  • Removed incorrect argument for NetworkError constructor #​4656
  • Removed Webpack #​4596
  • Removed function that transform arguments to array #​4544
Fixed
  • Fixed grammar in README #​4649
  • Fixed code error in README #​4599
  • Optimized the code that checks cancellation #​4587
  • Fix url pointing to defaults.js in README #​4532
  • Use type alias instead of interface for AxiosPromise #​4505
  • Fix some word spelling and lint style in code comments #​4500
  • Edited readme with 3 updated browser icons of Chrome, FireFox and Safari #​4414
  • Bump follow-redirects from 1.14.9 to 1.15.0 #​4673
  • Fixing http tests to avoid hanging when assertions fail #​4435
  • Fix TS definition for AxiosRequestTransformer #​4201
  • Fix grammatical issues in README #​4232
  • Fixing instance.defaults.headers type #​4557
  • Fixed race condition on immediate requests cancellation #​4261
  • Fixing Z_BUF_ERROR when no content #​4701
  • Fixing proxy beforeRedirect regression #​4708
  • Fixed AxiosError status code type #​4717
  • Fixed AxiosError stack capturing #​4718
  • Fixing AxiosRequestHeaders typings #​4334
  • Fixed max body length defaults #​4731
  • Fixed toFormData Blob issue on node>v17 #​4728
  • Bump grunt from 1.5.2 to 1.5.3 #​4743
  • Fixing content-type header repeated #​4745
  • Fixed timeout error message for http 4738
  • Request ignores false, 0 and empty string as body values #​4785
  • Added back missing minified builds #​4805
  • Fixed a type error #​4815
  • Fixed a regression bug with unsubscribing from cancel token; #​4819
  • Remove repeated compression algorithm #​4820
  • The error of calling extend to pass parameters #​4857
  • SerializerOptions.indexes allows boolean | null | undefined #​4862
  • Require interceptors to return values #​4874
  • Removed unused imports #​4949
  • Allow null indexes on formSerializer and paramsSerializer #​4960
Chores
  • Set permissions for GitHub actions #​4765
  • Included githubactions in the dependabot config #​4770
  • Included dependency review #​4771
  • Update security.md #​4784
  • Remove unnecessary spaces #​4854
  • Simplify the import path of AxiosError #​4875
  • Fix Gitpod dead link #​4941
  • Enable syntax highlighting for a code block #​4970
  • Using Logo Axios in Readme.md #​4993
  • Fix markup for note in README #​4825
  • Fix typo and formatting, add colons #​4853
  • Fix typo in readme #​4942
Security
Contributors to this release

v1.2.6

Compare Source

Bug Fixes
  • headers: added missed Authorization accessor; (#​5502) (342c0ba)
  • types: fixed CommonRequestHeadersList & CommonResponseHeadersList types to be private in commonJS; (#​5503) (5a3d0a3)
Contributors to this release
PRs

⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459

v1.2.5

Compare Source

Bug Fixes
  • types: fixed AxiosHeaders to handle

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@openverse-bot openverse-bot requested review from a team as code owners November 13, 2023 02:39
@openverse-bot openverse-bot added dependencies Pull requests that update a dependency file 💻 aspect: code Concerns the software code in the repository 🟨 tech: javascript Involves JavaScript 🟩 priority: low Low priority and doesn't need to be rushed 🧰 goal: internal improvement Improvement that benefits maintainers, not users 🧱 stack: frontend Related to the Nuxt frontend labels Nov 13, 2023
@github-actions github-actions bot added the 🧱 stack: mgmt Related to repo management and automations label Nov 13, 2023
Copy link
Contributor

@sarayourfriend sarayourfriend left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM 👍

Really glad to have dependency checks for the frontend now!

Copy link

github-actions bot commented Nov 13, 2023

Size Change: +16.8 kB (+2%)

Total Size: 973 kB

Filename Size Change
./frontend/.nuxt/dist/client/app.js 132 kB +57 B (0%)
./frontend/.nuxt/dist/client/commons/app.js 105 kB +11.6 kB (+13%) ⚠️
./frontend/.nuxt/dist/client/commons/app.modern.js 87.5 kB +4.5 kB (+5%) 🔍
./frontend/.nuxt/dist/client/pages/audio/_id/index.js 17.5 kB +51 B (0%)
./frontend/.nuxt/dist/client/pages/audio/_id/index.modern.js 16.4 kB +19 B (0%)
./frontend/.nuxt/dist/client/pages/image/_id/index.js 16.2 kB +349 B (+2%)
./frontend/.nuxt/dist/client/pages/image/_id/index.modern.js 14.8 kB +10 B (0%)
./frontend/.nuxt/dist/client/pages/index.js 6.41 kB +28 B (0%)
./frontend/.nuxt/dist/client/pages/search.js 5.82 kB +33 B (+1%)
./frontend/.nuxt/dist/client/vendors/app.js 68.5 kB +60 B (0%)
./frontend/.nuxt/dist/client/vendors/app.modern.js 68 kB -37 B (0%)
ℹ️ View Unchanged
Filename Size Change
./frontend/.nuxt/dist/client/242.js 343 B +2 B (+1%)
./frontend/.nuxt/dist/client/242.modern.js 346 B 0 B
./frontend/.nuxt/dist/client/243.js 1.85 kB +1 B (0%)
./frontend/.nuxt/dist/client/app.modern.js 123 kB +5 B (0%)
./frontend/.nuxt/dist/client/commons/components/v-error-section/components/v-external-search-form/components/v-external-source-li/4e2d09e1.js 5.18 kB 0 B
./frontend/.nuxt/dist/client/commons/components/v-error-section/components/v-external-search-form/components/v-external-source-li/4e2d09e1.modern.js 5.62 kB 0 B
./frontend/.nuxt/dist/client/components/loading-icon.js 732 B -1 B (0%)
./frontend/.nuxt/dist/client/components/loading-icon.modern.js 736 B +1 B (0%)
./frontend/.nuxt/dist/client/components/table-sort-icon.js 514 B -1 B (0%)
./frontend/.nuxt/dist/client/components/table-sort-icon.modern.js 518 B -1 B (0%)
./frontend/.nuxt/dist/client/components/v-all-results-grid.js 6.85 kB -5 B (0%)
./frontend/.nuxt/dist/client/components/v-all-results-grid.modern.js 6.68 kB +4 B (0%)
./frontend/.nuxt/dist/client/components/v-audio-collection.js 4.5 kB -5 B (0%)
./frontend/.nuxt/dist/client/components/v-audio-collection.modern.js 4.37 kB +3 B (0%)
./frontend/.nuxt/dist/client/components/v-audio-list.js 1.43 kB -1 B (0%)
./frontend/.nuxt/dist/client/components/v-audio-list.modern.js 1.4 kB 0 B
./frontend/.nuxt/dist/client/components/v-audio-result.js 1.12 kB -1 B (0%)
./frontend/.nuxt/dist/client/components/v-audio-result.modern.js 1.1 kB +1 B (0%)
./frontend/.nuxt/dist/client/components/v-audio-track-skeleton.js 956 B -1 B (0%)
./frontend/.nuxt/dist/client/components/v-audio-track-skeleton.modern.js 960 B -1 B (0%)
./frontend/.nuxt/dist/client/components/v-audio-track.js 5.99 kB +2 B (0%)
./frontend/.nuxt/dist/client/components/v-audio-track.modern.js 5.96 kB +1 B (0%)
./frontend/.nuxt/dist/client/components/v-back-to-search-results-link.js 634 B -1 B (0%)
./frontend/.nuxt/dist/client/components/v-back-to-search-results-link.modern.js 641 B 0 B
./frontend/.nuxt/dist/client/components/v-bone.js 632 B +1 B (0%)
./frontend/.nuxt/dist/client/components/v-bone.modern.js 636 B 0 B
./frontend/.nuxt/dist/client/components/v-box-layout.js 1.15 kB -2 B (0%)
./frontend/.nuxt/dist/client/components/v-box-layout.modern.js 1.16 kB +2 B (0%)
./frontend/.nuxt/dist/client/components/v-collection-header.js 1.3 kB -1 B (0%)
./frontend/.nuxt/dist/client/components/v-collection-header.modern.js 1.31 kB -3 B (0%)
./frontend/.nuxt/dist/client/components/v-content-link.js 1.06 kB -1 B (0%)
./frontend/.nuxt/dist/client/components/v-content-link.modern.js 1.05 kB -1 B (0%)
./frontend/.nuxt/dist/client/components/v-content-page.js 530 B 0 B
./frontend/.nuxt/dist/client/components/v-content-page.modern.js 536 B +2 B (0%)
./frontend/.nuxt/dist/client/components/v-content-report-button.js 493 B 0 B
./frontend/.nuxt/dist/client/components/v-content-report-button.modern.js 497 B 0 B
./frontend/.nuxt/dist/client/components/v-content-report-form.js 3.35 kB 0 B
./frontend/.nuxt/dist/client/components/v-content-report-form.modern.js 3.23 kB +2 B (0%)
./frontend/.nuxt/dist/client/components/v-content-report-popover.js 3.82 kB +4 B (0%)
./frontend/.nuxt/dist/client/components/v-content-report-popover.modern.js 3.7 kB +4 B (0%)
./frontend/.nuxt/dist/client/components/v-copy-button.js 3.8 kB +3 B (0%)
./frontend/.nuxt/dist/client/components/v-copy-button.modern.js 3.81 kB 0 B
./frontend/.nuxt/dist/client/components/v-copy-license.js 2.34 kB 0 B
./frontend/.nuxt/dist/client/components/v-copy-license.modern.js 2.31 kB 0 B
./frontend/.nuxt/dist/client/components/v-dmca-notice.js 795 B 0 B
./frontend/.nuxt/dist/client/components/v-dmca-notice.modern.js 801 B +1 B (0%)
./frontend/.nuxt/dist/client/components/v-error-image.js 2.51 kB +3 B (0%)
./frontend/.nuxt/dist/client/components/v-error-image.modern.js 2.47 kB +1 B (0%)
./frontend/.nuxt/dist/client/components/v-error-section.js 5.22 kB +1 B (0%)
./frontend/.nuxt/dist/client/components/v-error-section.modern.js 4.58 kB +1 B (0%)
./frontend/.nuxt/dist/client/components/v-external-search-form.js 4.1 kB 0 B
./frontend/.nuxt/dist/client/components/v-external-search-form.modern.js 3.44 kB -3 B (0%)
./frontend/.nuxt/dist/client/components/v-external-source-list.js 2.63 kB +1 B (0%)
./frontend/.nuxt/dist/client/components/v-external-source-list.modern.js 1.99 kB -3 B (0%)
./frontend/.nuxt/dist/client/components/v-full-layout.js 1.66 kB +1 B (0%)
./frontend/.nuxt/dist/client/components/v-full-layout.modern.js 1.66 kB +1 B (0%)
./frontend/.nuxt/dist/client/components/v-get-media-button.js 622 B +1 B (0%)
./frontend/.nuxt/dist/client/components/v-get-media-button.modern.js 628 B 0 B
./frontend/.nuxt/dist/client/components/v-grid-skeleton.js 1.55 kB -1 B (0%)
./frontend/.nuxt/dist/client/components/v-grid-skeleton.modern.js 1.55 kB +2 B (0%)
./frontend/.nuxt/dist/client/components/v-hide-button.js 594 B +1 B (0%)
./frontend/.nuxt/dist/client/components/v-hide-button.modern.js 592 B 0 B
./frontend/.nuxt/dist/client/components/v-home-gallery.js 4.28 kB -1 B (0%)
./frontend/.nuxt/dist/client/components/v-home-gallery.modern.js 4.26 kB 0 B
./frontend/.nuxt/dist/client/components/v-homepage-content.js 1.82 kB -1 B (0%)
./frontend/.nuxt/dist/client/components/v-homepage-content.modern.js 1.79 kB -1 B (0%)
./frontend/.nuxt/dist/client/components/v-image-cell.js 2.24 kB +3 B (0%)
./frontend/.nuxt/dist/client/components/v-image-cell.modern.js 2.23 kB +2 B (0%)
./frontend/.nuxt/dist/client/components/v-image-grid.js 4.52 kB -4 B (0%)
./frontend/.nuxt/dist/client/components/v-image-grid.modern.js 4.4 kB +5 B (0%)
./frontend/.nuxt/dist/client/components/v-license-tab-panel.js 641 B +1 B (0%)
./frontend/.nuxt/dist/client/components/v-license-tab-panel.modern.js 649 B -1 B (0%)
./frontend/.nuxt/dist/client/components/v-load-more.js 1.18 kB +1 B (0%)
./frontend/.nuxt/dist/client/components/v-load-more.modern.js 1.07 kB 0 B
./frontend/.nuxt/dist/client/components/v-media-details.js 5.84 kB +4 B (0%)
./frontend/.nuxt/dist/client/components/v-media-details.modern.js 5.69 kB +3 B (0%)
./frontend/.nuxt/dist/client/components/v-media-license.js 930 B -1 B (0%)
./frontend/.nuxt/dist/client/components/v-media-license.modern.js 938 B -2 B (0%)
./frontend/.nuxt/dist/client/components/v-media-reuse.js 3 kB +4 B (0%)
./frontend/.nuxt/dist/client/components/v-media-reuse.modern.js 2.97 kB -1 B (0%)
./frontend/.nuxt/dist/client/components/v-media-tag.js 416 B +1 B (0%)
./frontend/.nuxt/dist/client/components/v-media-tag.modern.js 419 B -2 B (0%)
./frontend/.nuxt/dist/client/components/v-media-tags.js 830 B -1 B (0%)
./frontend/.nuxt/dist/client/components/v-media-tags.modern.js 824 B -2 B (0%)
./frontend/.nuxt/dist/client/components/v-metadata-value.js 604 B +1 B (0%)
./frontend/.nuxt/dist/client/components/v-metadata-value.modern.js 609 B 0 B
./frontend/.nuxt/dist/client/components/v-metadata.js 1.32 kB +4 B (0%)
./frontend/.nuxt/dist/client/components/v-metadata.modern.js 1.32 kB 0 B
./frontend/.nuxt/dist/client/components/v-modal.js 981 B 0 B
./frontend/.nuxt/dist/client/components/v-modal.modern.js 973 B 0 B
./frontend/.nuxt/dist/client/components/v-no-results.js 2.67 kB +1 B (0%)
./frontend/.nuxt/dist/client/components/v-no-results.modern.js 2.03 kB -3 B (0%)
./frontend/.nuxt/dist/client/components/v-old-icon-button.js 853 B +1 B (0%)
./frontend/.nuxt/dist/client/components/v-old-icon-button.modern.js 847 B +1 B (0%)
./frontend/.nuxt/dist/client/components/v-radio.js 1.02 kB +1 B (0%)
./frontend/.nuxt/dist/client/components/v-radio.modern.js 1.02 kB +1 B (0%)
./frontend/.nuxt/dist/client/components/v-related-audio.js 823 B -1 B (0%)
./frontend/.nuxt/dist/client/components/v-related-audio.modern.js 743 B +1 B (0%)
./frontend/.nuxt/dist/client/components/v-related-audio/pages/search/audio.js 4.49 kB -5 B (0%)
./frontend/.nuxt/dist/client/components/v-related-audio/pages/search/audio.modern.js 4.36 kB +4 B (0%)
./frontend/.nuxt/dist/client/components/v-related-images.js 803 B +2 B (0%)
./frontend/.nuxt/dist/client/components/v-related-images.modern.js 719 B 0 B
./frontend/.nuxt/dist/client/components/v-report-desc-form.js 996 B +1 B (0%)
./frontend/.nuxt/dist/client/components/v-report-desc-form.modern.js 999 B +1 B (0%)
./frontend/.nuxt/dist/client/components/v-row-layout.js 2.04 kB 0 B
./frontend/.nuxt/dist/client/components/v-row-layout.modern.js 2.05 kB +4 B (0%)
./frontend/.nuxt/dist/client/components/v-safety-wall.js 1.46 kB +2 B (0%)
./frontend/.nuxt/dist/client/components/v-safety-wall.modern.js 1.46 kB -1 B (0%)
./frontend/.nuxt/dist/client/components/v-scroll-button.js 891 B 0 B
./frontend/.nuxt/dist/client/components/v-scroll-button.modern.js 892 B +1 B (0%)
./frontend/.nuxt/dist/client/components/v-search-results-title.js 616 B -1 B (0%)
./frontend/.nuxt/dist/client/components/v-search-results-title.modern.js 621 B -1 B (0%)
./frontend/.nuxt/dist/client/components/v-single-result-controls.js 1.18 kB -1 B (0%)
./frontend/.nuxt/dist/client/components/v-single-result-controls.modern.js 1.18 kB +3 B (0%)
./frontend/.nuxt/dist/client/components/v-sketch-fab-viewer.js 1.02 kB +1 B (0%)
./frontend/.nuxt/dist/client/components/v-sketch-fab-viewer.modern.js 916 B +1 B (0%)
./frontend/.nuxt/dist/client/components/v-snackbar.js 1.06 kB 0 B
./frontend/.nuxt/dist/client/components/v-snackbar.modern.js 1.07 kB -2 B (0%)
./frontend/.nuxt/dist/client/components/v-sources-table.js 15.1 kB 0 B
./frontend/.nuxt/dist/client/components/v-sources-table.modern.js 15.1 kB +2 B (0%)
./frontend/.nuxt/dist/client/components/v-tag.js 411 B 0 B
./frontend/.nuxt/dist/client/components/v-tag.modern.js 415 B 0 B
./frontend/.nuxt/dist/client/components/v-warning-suppressor.js 306 B 0 B
./frontend/.nuxt/dist/client/components/v-warning-suppressor.modern.js 311 B 0 B
./frontend/.nuxt/dist/client/pages/about.js 1.42 kB -1 B (0%)
./frontend/.nuxt/dist/client/pages/about.modern.js 1.42 kB +2 B (0%)
./frontend/.nuxt/dist/client/pages/feedback.js 1.36 kB 0 B
./frontend/.nuxt/dist/client/pages/feedback.modern.js 1.36 kB +3 B (0%)
./frontend/.nuxt/dist/client/pages/image/_id/report.js 5 kB -1 B (0%)
./frontend/.nuxt/dist/client/pages/image/_id/report.modern.js 4.75 kB +6 B (0%)
./frontend/.nuxt/dist/client/pages/index.modern.js 6.35 kB -1 B (0%)
./frontend/.nuxt/dist/client/pages/preferences.js 1.46 kB -1 B (0%)
./frontend/.nuxt/dist/client/pages/preferences.modern.js 1.46 kB -1 B (0%)
./frontend/.nuxt/dist/client/pages/privacy.js 1.26 kB +1 B (0%)
./frontend/.nuxt/dist/client/pages/privacy.modern.js 1.26 kB +2 B (0%)
./frontend/.nuxt/dist/client/pages/search-help.js 1.64 kB +3 B (0%)
./frontend/.nuxt/dist/client/pages/search-help.modern.js 1.62 kB +3 B (0%)
./frontend/.nuxt/dist/client/pages/search.modern.js 8.14 kB +4 B (0%)
./frontend/.nuxt/dist/client/pages/search/audio.js 498 B -1 B (0%)
./frontend/.nuxt/dist/client/pages/search/audio.modern.js 501 B -2 B (0%)
./frontend/.nuxt/dist/client/pages/search/image.js 453 B +1 B (0%)
./frontend/.nuxt/dist/client/pages/search/image.modern.js 454 B 0 B
./frontend/.nuxt/dist/client/pages/search/index.js 316 B +1 B (0%)
./frontend/.nuxt/dist/client/pages/search/index.modern.js 320 B -1 B (0%)
./frontend/.nuxt/dist/client/pages/search/model-3d.js 243 B +1 B (0%)
./frontend/.nuxt/dist/client/pages/search/model-3d.modern.js 246 B 0 B
./frontend/.nuxt/dist/client/pages/search/video.js 240 B 0 B
./frontend/.nuxt/dist/client/pages/search/video.modern.js 244 B 0 B
./frontend/.nuxt/dist/client/pages/sensitive-content.js 1.52 kB +1 B (0%)
./frontend/.nuxt/dist/client/pages/sensitive-content.modern.js 1.53 kB +2 B (0%)
./frontend/.nuxt/dist/client/pages/sources.js 1.53 kB 0 B
./frontend/.nuxt/dist/client/pages/sources.modern.js 1.54 kB +2 B (0%)
./frontend/.nuxt/dist/client/runtime.js 2.8 kB 0 B
./frontend/.nuxt/dist/client/runtime.modern.js 2.81 kB 0 B

compressed-size-action

@obulat obulat self-requested a review November 13, 2023 04:43
@sarayourfriend
Copy link
Contributor

Ah, thank goodness for CI. There's a build failure. Looking at it now.

@sarayourfriend
Copy link
Contributor

I've got a fix for the runtime error coming as well, just testing it fully locally.

@sarayourfriend
Copy link
Contributor

This should work... 🤞

@github-actions github-actions bot added the 🧱 stack: documentation Related to Sphinx documentation label Nov 13, 2023
@openverse-bot
Copy link
Collaborator Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

Warning: custom changes will be lost.

Copy link

Full-stack documentation: https://docs.openverse.org/_preview/3343

Please note that GitHub pages takes a little time to deploy newly pushed code, if the links above don't work or you see old versions, wait 5 minutes and try again.

You can check the GitHub pages deployment action list to see the current status of the deployments.

@sarayourfriend
Copy link
Contributor

The first request in the API token test cases is always with undefined URL. I cannot figure out why that is happening, and can't figure out if it's somehow related to axios-mock-adapter (there are no issues I can find on axios or there). @obulat maybe you'd have better luck than me finding the source of the undefined URL in the first request for each test case?

@obulat
Copy link
Contributor

obulat commented Nov 14, 2023

The first request in the API token test cases is always with undefined URL. I cannot figure out why that is happening, and can't figure out if it's somehow related to axios-mock-adapter (there are no issues I can find on axios or there). @obulat maybe you'd have better luck than me finding the source of the undefined URL in the first request for each test case?

new MockAdapter returns a Promise instead of the adapter, which causes the onPost is not a function error.

There's a fix involving transformIgnorePatterns on SO, but it didn't fix the problem when I tried it.

A similar issue in the axios-mock-adapter repository doesn't seem to have a fix yet: ctimmerm/axios-mock-adapter#377

We could consider moving from axios-mock-adapter to https://github.com/knee-cola/jest-mock-axios, which seems to be more frequently updated.

@sarayourfriend
Copy link
Contributor

sarayourfriend commented Nov 14, 2023

Oh! We can just await the mock adapter function then?

The fixes you're mentioning are for getting jest to not complain about the axios compilation errors, right? I came across similar ones. The only one that worked is the one I applied in 78c84c3

Good find about the promise though... let me see what I can do there.

Edit: Never mind, I see the linked SO answer is different. It got me digging into Axios mock adapter and I found out the issue has to do with the import of Axios mock adapter accidentally being axios itself due to too-loose a setting in jest.config.js in the commit I mentioned above!

The latest commit should fix everything 🤞

@sarayourfriend sarayourfriend force-pushed the gha-renovatenpm-axios-vulnerability branch from 41b6c30 to a03462f Compare November 14, 2023 23:38
@@ -22,7 +23,7 @@ module.exports = {
"^.+\\.svg$": "<rootDir>/test/unit/svg-transform.js",
},
testPathIgnorePatterns: ["/playwright/", "/storybook/", ".remake"],
collectCoverage: true,
collectCoverage: false,
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm setting this to false because (a) it's profoundly annoying to deal with locally when running a single test, your console gets flooded with coverage information and (b) we literally do not use this coverage information anywhere at the moment.

#2299

@sarayourfriend
Copy link
Contributor

@obulat Ready for review here.

@@ -12,7 +12,7 @@ module.exports = {
"^~~/(.*)$": "<rootDir>/$1",
"^vue$": "vue/dist/vue.common.js",
"(.*svg)(\\?inline)$": "<rootDir>/test/unit/test-utils/svgTransform.js",
axios: "axios/dist/node/axios.cjs",
"^axios$": "axios/dist/node/axios.cjs",
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Oh, this is so....unexpected! I spent a lot of time trying to figure out the fix, but I would never think of looking into this import! Thank you for finding the fix, @sarayourfriend!

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It all came down to attaching a debugger and noticing that new AxiosMockAdapter raised an error in the debug console and then inspecting the imported object and realising "oh... that's Axios!" and then I noticed that the keys here are regexes. I actually did a 🤦 when I realised what a mistake I'd made 😅

@obulat obulat merged commit 671f0f2 into main Nov 15, 2023
41 checks passed
@obulat obulat deleted the gha-renovatenpm-axios-vulnerability branch November 15, 2023 10:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
💻 aspect: code Concerns the software code in the repository dependencies Pull requests that update a dependency file 🧰 goal: internal improvement Improvement that benefits maintainers, not users 🟩 priority: low Low priority and doesn't need to be rushed 🧱 stack: documentation Related to Sphinx documentation 🧱 stack: frontend Related to the Nuxt frontend 🧱 stack: mgmt Related to repo management and automations 🟨 tech: javascript Involves JavaScript
Projects
Archived in project
Development

Successfully merging this pull request may close these issues.

Disable coverage by default when running unit tests locally
3 participants