Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Axios dependency has vulnerability #380

Closed
bj00rn opened this issue Nov 16, 2023 · 8 comments
Closed

Axios dependency has vulnerability #380

bj00rn opened this issue Nov 16, 2023 · 8 comments

Comments

@bj00rn
Copy link

bj00rn commented Nov 16, 2023

Do you want to request a feature or report a bug?

BUG

What is the current behavior?

image

If the current behavior is a bug, please provide the steps to reproduce.

What is the expected behavior?

If this is a feature request, what is motivation or use case for changing the behavior?

Please mention other relevant information.

  • node version: 10x
  • Operating system
  • bundlesize version: 0.18.1
@siddharthkp
Copy link
Owner

PR welcome!

@bj00rn
Copy link
Author

bj00rn commented Nov 16, 2023

@siddharthkp lot's of open PRs here though, is this being maintained?

also dependencybot will do a good job at keeping up with these things, maybe enable it?

@siddharthkp
Copy link
Owner

lot's of open PRs here though, is this being maintained?

sometimes, for moments like these

@bj00rn
Copy link
Author

bj00rn commented Nov 16, 2023

did #381

tests are failing locally though, no idea why, does not seem related to axios

also I noticed github-builder is in dependencies and depends on axios. Needs fixing or move to devDependencies if not used

@bj00rn bj00rn changed the title Aixos dependency has vulnerability Axios dependency has vulnerability Nov 17, 2023
@siddharthkp
Copy link
Owner

github-build is definitely used :)

@poojagunturu96
Copy link
Contributor

poojagunturu96 commented Dec 20, 2023

I submitted a PR for this as well #382, based off of @bj00rn's PR. I also updated github-build as it was also dependent on axios. Local tests were passing.

@ruZZintl
Copy link

lot's of open PRs here though, is this being maintained?

sometimes, for moments like these

Please update these dependencies due to vulnerabilities. Thanks.

@palashmon
Copy link
Collaborator

Fixed in PR #382

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants