Skip to content

chore: update cidrs.json#270

Merged
github-actions[bot] merged 1 commit into
mainfrom
ci/update-cidrs
Mar 20, 2024
Merged

chore: update cidrs.json#270
github-actions[bot] merged 1 commit into
mainfrom
ci/update-cidrs

Conversation

@github-actions
Copy link
Copy Markdown
Contributor

  • Update cidrs.json

@github-actions github-actions Bot merged commit 1508244 into main Mar 20, 2024
@github-actions github-actions Bot deleted the ci/update-cidrs branch March 20, 2024 00:01
github-actions Bot added a commit that referenced this pull request Jun 2, 2026
Add npm overrides to pin axios to ^1.16.0 to resolve four high/medium
severity Dependabot alerts (GHSA-3g43-6gmg-66jw, GHSA-35jp-ww65-95wh,
GHSA-pjwm-pj3p-43mv, GHSA-898c-q2cr-xwhg).

axios is a transitive dependency pulled in via lerna -> nx -> axios.
The direct dependency (lerna@^9.0.7) depends on nx >=21.5.3 <23.0.0
and the currently resolved nx@22.6.5 pins axios@1.15.0. Since lerna
has not yet shipped a release that bumps nx to a version with axios
>=1.16.0, an overrides entry is the appropriate remediation.

The lockfile now resolves axios to 1.16.1.

Fixes alerts: #268, #269, #270, #271

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant