Skip to content

Update axios to latest and fix npm audit vulnerabilities#730

Merged
pipedrive-public-gha-bot[bot] merged 4 commits into
masterfrom
fix-npm-audit-vulnerabilities
May 13, 2026
Merged

Update axios to latest and fix npm audit vulnerabilities#730
pipedrive-public-gha-bot[bot] merged 4 commits into
masterfrom
fix-npm-audit-vulnerabilities

Conversation

@ziimk
Copy link
Copy Markdown
Contributor

@ziimk ziimk commented May 13, 2026

Related Tickets & Documents

Description

  • Updated lodash dependency from 4.17.21 to 4.18.1
  • Updated axios dependency from 1.13.6 to 1.16.0
  • Updated transitive dependencies via npm audit fix: ajv, brace-expansion, diff, follow-redirects, js-yaml, minimatch, picomatch, yaml

Type of PR?

  • 🚧 Maintenance

Manual testing

Automated tests added?

  • 👍 Unit tests
  • 👍 Functional tests
  • 👍 E2E tests
  • 🙅 N/A

ziimk and others added 2 commits May 11, 2026 13:02
Bump lodash 4.17.21 -> 4.18.1, axios 1.13.6 -> 1.16.0, and other
transitive deps via npm audit fix (brace-expansion, diff,
follow-redirects, js-yaml, minimatch, picomatch, yaml, ajv).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@ziimk ziimk added the npm-version-patch used for deployment label May 13, 2026
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
>=3.4.0 is unbounded and could pull in a breaking major version.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@ziimk ziimk added the npm-ready-for-publish used for deployment label May 13, 2026
pipedrive-public-gha-bot Bot pushed a commit that referenced this pull request May 13, 2026
@pipedrive-public-gha-bot pipedrive-public-gha-bot Bot merged commit 240f20f into master May 13, 2026
7 checks passed
@pipedrive-public-gha-bot pipedrive-public-gha-bot Bot deleted the fix-npm-audit-vulnerabilities branch May 13, 2026 12:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

npm-ready-for-publish used for deployment npm-version-patch used for deployment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants