Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade axios, github-build dependencies #382

Merged
merged 1 commit into from Mar 15, 2024

Conversation

poojagunturu96
Copy link
Contributor

Description

Upgraded axios dependency as the current version has a security vulnerability. Upgraded github-build as well, as github-build depended on the vulnerable version of axios.

Motivation and Context

Fix for #380.

Types of changes

  • Dependency upgrade (non-breaking change which fixes an issue)

Checklist:

  • My code follows the code style of this project.
  • If my change requires a change to the documentation I have updated the documentation accordingly.
  • I have read the CONTRIBUTING document.
  • I created an issue for the Pull Request

@ruZZintl
Copy link

@siddharthkp please merge this and create a new release. It addresses GHSA-wf5p-g6vw-rhxx

@ruZZintl
Copy link

ruZZintl commented Jan 2, 2024

ETA? Any reason to not merge this? If not, please merge and release. Thanks.

@ruZZintl
Copy link

@siddharthkp is this repo being maintained?

@loftshed
Copy link

@siddharthkp just want to add myself to the crowd requesting this lil dependency bump, if you ever get the time it would be very appreciated 🥺

@Kamariw95
Copy link

Adding myself to this crowd as well. Can one of us be given write access to merge and update? 👀 @siddharthkp

@siddharthkp siddharthkp merged commit 79e296b into siddharthkp:master Mar 15, 2024
@siddharthkp
Copy link
Owner

Released as bundlesize@0.18.2

@loftshed
Copy link

@siddharthkp Thank you!! :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

5 participants