Skip to content

branch-4.1: [fix](build) Bump UI axios to patched release #63185#63983

Merged
yiguolei merged 1 commit into
branch-4.1from
auto-pick-63185-branch-4.1
Jun 2, 2026
Merged

branch-4.1: [fix](build) Bump UI axios to patched release #63185#63983
yiguolei merged 1 commit into
branch-4.1from
auto-pick-63185-branch-4.1

Conversation

@github-actions
Copy link
Copy Markdown
Contributor

@github-actions github-actions Bot commented Jun 2, 2026

Cherry-picked from #63185

### What problem does this PR solve?

Problem Summary:
The legacy UI package depends on `axios` `^0.19.2`, which is affected by
known security advisories. This updates the dependency to a patched
release line (`^1.16.0`) to reduce exposure from vulnerable transitive
HTTP client behavior.

Signed-off-by: Arpit Jain <arpitjain099@gmail.com>
@github-actions github-actions Bot requested a review from yiguolei as a code owner June 2, 2026 02:53
@hello-stephen
Copy link
Copy Markdown
Contributor

Thank you for your contribution to Apache Doris.
Don't know what should be done next? See How to process your PR.

Please clearly describe your PR:

  1. What problem was fixed (it's best to include specific error reporting information). How it was fixed.
  2. Which behaviors were modified. What was the previous behavior, what is it now, why was it modified, and what possible impacts might there be.
  3. What features were added. Why was this function added?
  4. Which code was refactored and why was this part of the code refactored?
  5. Which functions were optimized and what is the difference before and after the optimization?

@hello-stephen
Copy link
Copy Markdown
Contributor

run buildall

@yiguolei yiguolei merged commit 10c3d1a into branch-4.1 Jun 2, 2026
29 of 32 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants