Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency axios to v0.21.1 [SECURITY] - abandoned #15

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Jun 1, 2019

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
axios (source) 0.18.0 -> 0.21.1 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2019-10742

Versions of axios prior to 0.18.1 are vulnerable to Denial of Service. If a request exceeds the maxContentLength property, the package prints an error but does not stop the request. This may cause high CPU usage and lead to Denial of Service.

Recommendation

Upgrade to 0.18.1 or later.

CVE-2020-28168

Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.


Release Notes

axios/axios

v0.21.1

Compare Source

Fixes and Functionality:
  • Hotfix: Prevent SSRF (#​3410)
  • Protocol not parsed when setting proxy config from env vars (#​3070)
  • Updating axios in types to be lower case (#​2797)
  • Adding a type guard for AxiosError (#​2949)
Internal and Tests:
  • Remove the skipping of the socket http test (#​3364)
  • Use different socket for Win32 test (#​3375)

Huge thanks to everyone who contributed to this release via code (authors listed below) or via reviews and triaging on GitHub:

v0.21.0

Compare Source

Fixes and Functionality:
  • Fixing requestHeaders.Authorization (#​3287)
  • Fixing node types (#​3237)
  • Fixing axios.delete ignores config.data (#​3282)
  • Revert "Fixing overwrite Blob/File type as Content-Type in browser. (#​1773)" (#​3289)
  • Fixing an issue that type 'null' and 'undefined' is not assignable to validateStatus when typescript strict option is enabled (#​3200)
Internal and Tests:
  • Lock travis to not use node v15 (#​3361)
Documentation:

Huge thanks to everyone who contributed to this release via code (authors listed below) or via reviews and triaging on GitHub:

v0.20.0

Compare Source

Release of 0.20.0-pre as a full release with no other changes.

v0.19.2

Compare Source

v0.19.1

Compare Source

Fixes and Functionality:
  • Fixing invalid agent issue (#​1904)
  • Fix ignore set withCredentials false (#​2582)
  • Delete useless default to hash (#​2458)
  • Fix HTTP/HTTPs agents passing to follow-redirect (#​1904)
  • Fix ignore set withCredentials false (#​2582)
  • Fix CI build failure (#​2570)
  • Remove dependency on is-buffer from package.json (#​1816)
  • Adding options typings (#​2341)
  • Adding Typescript HTTP method definition for LINK and UNLINK. (#​2444)
  • Update dist with newest changes, fixes Custom Attributes issue
  • Change syntax to see if build passes (#​2488)
  • Update Webpack + deps, remove now unnecessary polyfills (#​2410)
  • Fix to prevent XSS, throw an error when the URL contains a JS script (#​2464)
  • Add custom timeout error copy in config (#​2275)
  • Add error toJSON example (#​2466)
  • Fixing Vulnerability A Fortify Scan finds a critical Cross-Site Scrip… (#​2451)
  • Fixing subdomain handling on no_proxy (#​2442)
  • Make redirection from HTTP to HTTPS work ([#​2426][https://github.com/axios/axios/pull/2426](https://togithub.com/axios/axios/pull/2426)6] and (#​2547)
  • Add toJSON property to AxiosError type (#​2427)
  • Fixing socket hang up error on node side for slow response. (#​1752)
  • Alternative syntax to send data into the body (#​2317)
  • Fixing custom config options (#​2207)
  • Fixing set config.method after mergeConfig for Axios.prototype.request (#​2383)
  • Axios create url bug (#​2290)
  • Do not modify config.url when using a relative baseURL (resolves #​1628) (#​2391)
  • Add typescript HTTP method definition for LINK and UNLINK (#​2444)
Internal:
Documentation:
  • Fixing typo in CHANGELOG.md: s/Functionallity/Functionality (#​2639)
  • Fix badge, use master branch (#​2538)
  • Fix typo in changelog #​2193
  • Document fix (#​2514)
  • Update docs with no_proxy change, issue #​2484 (#​2513)
  • Fixing missing words in docs template (#​2259)
  • 🐛Fix request finally documentation in README (#​2189)
  • updating spelling and adding link to docs (#​2212)
  • docs: minor tweak (#​2404)
  • Update response interceptor docs (#​2399)
  • Update README.md (#​2504)
  • Fix word 'sintaxe' to 'syntax' in README.md (#​2432)
  • upadating README: notes on CommonJS autocomplete (#​2256)
  • Fix grammar in README.md (#​2271)
  • Doc fixes, minor examples cleanup (#​2198)

v0.19.0

Compare Source

Fixes and Functionality:
  • Unzip response body only for statuses != 204 (#​1129) - drawski
  • Destroy stream on exceeding maxContentLength (fixes #​1098) (#​1485) - Gadzhi Gadzhiev
  • Makes Axios error generic to use AxiosResponse (#​1738) - Suman Lama
  • Fixing Mocha tests by locking follow-redirects version to 1.5.10 (#​1993) - grumblerchester
  • Allow uppercase methods in typings. (#​1781) - Ken Powers
  • Fixing .eslintrc without extension (#​1789) - Manoel
  • Consistent coding style (#​1787) - Ali Servet Donmez
  • Fixing building url with hash mark (#​1771) - Anatoly Ryabov
  • This commit fix building url with hash map (fragment identifier) when parameters are present: they must not be added after #, because client cut everything after #
  • Preserve HTTP method when following redirect (#​1758) - Rikki Gibson
  • Add getUri signature to TypeScript definition. (#​1736) - Alexander Trauzzi
  • Adding isAxiosError flag to errors thrown by axios (#​1419) - Ayush Gupta
  • Fix failing SauceLabs tests by updating configuration - Emily Morehouse
Documentation:
  • Add information about auth parameter to README (#​2166) - xlaguna
  • Add DELETE to list of methods that allow data as a config option (#​2169) - Daniela Borges Matos de Carvalho
  • Update ECOSYSTEM.md - Add Axios Endpoints (#​2176) - Renan
  • Add r2curl in ECOSYSTEM (#​2141) - 유용우 / CX
  • Update README.md - Add instructions for installing with yarn (#​2036) - Victor Hermes
  • Fixing spacing for README.md (#​2066) - Josh McCarty
  • Update README.md. - Change .then to .finally in example code (#​2090) - Omar Cai
  • Clarify what values responseType can have in Node (#​2121) - Tyler Breisacher
  • docs(ECOSYSTEM): add axios-api-versioning (#​2020) - Weffe
  • It seems that responseType: 'blob' doesn't actually work in Node (when I tried using it, response.data was a string, not a Blob, since Node doesn't have Blobs), so this clarifies that this option should only be used in the browser
  • Add issue templates - Emily Morehouse
  • Update README.md. - Add Querystring library note (#​1896) - Dmitriy Eroshenko
  • Add react-hooks-axios to Libraries section of ECOSYSTEM.md (#​1925) - Cody Chan
  • Clarify in README that default timeout is 0 (no timeout) (#​1750) - Ben Standefer

v0.18.1

Compare Source

Security Fix:
  • Destroy stream on exceeding maxContentLength (fixes #​1098) (#​1485) - Gadzhi Gadzhiev

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@codecov
Copy link

codecov bot commented Jun 1, 2019

Codecov Report

Merging #15 into master will not change coverage.
The diff coverage is n/a.

Impacted file tree graph

@@           Coverage Diff           @@
##           master      #15   +/-   ##
=======================================
  Coverage   97.72%   97.72%           
=======================================
  Files           3        3           
  Lines          44       44           
=======================================
  Hits           43       43           
  Misses          1        1

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 0e926bd...f3d875f. Read the comment docs.

@codecov
Copy link

codecov bot commented Jun 1, 2019

Codecov Report

❗ No coverage uploaded for pull request base (master@0e926bd). Click here to learn what that means.
The diff coverage is n/a.

❗ Current head 84fe60a differs from pull request most recent head 8d85d57. Consider uploading reports for the commit 8d85d57 to get more accurate results

@@          Coverage Diff           @@
##             master   #15   +/-   ##
======================================
  Coverage          ?     0           
======================================
  Files             ?     0           
  Lines             ?     0           
  Branches          ?     0           
======================================
  Hits              ?     0           
  Misses            ?     0           
  Partials          ?     0           

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 0e926bd...8d85d57. Read the comment docs.

@renovate renovate bot force-pushed the renovate/npm-axios-vulnerability branch from f3d875f to aff4bfc Compare June 19, 2019 13:55
@renovate renovate bot changed the title Update dependency axios to v0.19.0 [SECURITY] Update dependency axios to v0.18.1 [SECURITY] Jun 19, 2019
@renovate renovate bot force-pushed the renovate/npm-axios-vulnerability branch from aff4bfc to 84fe60a Compare January 5, 2021 15:58
@renovate renovate bot changed the title Update dependency axios to v0.18.1 [SECURITY] Update dependency axios to v0.21.1 [SECURITY] Jan 5, 2021
@renovate renovate bot force-pushed the renovate/npm-axios-vulnerability branch from 84fe60a to b0094b8 Compare October 18, 2021 15:15
@renovate renovate bot changed the title Update dependency axios to v0.21.1 [SECURITY] Update dependency axios to v0.21.2 [SECURITY] Oct 18, 2021
@renovate renovate bot changed the title Update dependency axios to v0.21.2 [SECURITY] Update dependency axios to v0.21.1 [SECURITY] Apr 25, 2022
@renovate renovate bot force-pushed the renovate/npm-axios-vulnerability branch from b0094b8 to 8d85d57 Compare April 25, 2022 02:07
@renovate
Copy link
Contributor Author

renovate bot commented Mar 24, 2023

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

Copy link
Contributor Author

renovate bot commented Jan 5, 2024

Autoclosing Skipped

This PR has been flagged for autoclosing. However, it is being skipped due to the branch being already modified. Please close/delete it manually or report a bug if you think this is in error.

@renovate renovate bot changed the title Update dependency axios to v0.21.1 [SECURITY] Update dependency axios to v0.21.1 [SECURITY] - abandoned Jan 5, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant