Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade axios from 0.24.0 to 0.27.2 #278

Merged
merged 2 commits into from
Jan 13, 2024

Conversation

Loonz206
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade axios from 0.24.0 to 0.27.2.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 6 versions ahead of your current version.
  • The recommended version was released 2 years ago, on 2022-04-27.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Incomplete List of Disallowed Inputs
SNYK-JS-BABELTRAVERSE-5962462
465/1000
Why? CVSS 9.3
No Known Exploit
Remote Code Execution (RCE)
SNYK-JS-SHELLQUOTE-1766506
465/1000
Why? CVSS 9.3
No Known Exploit
Prototype Pollution
SNYK-JS-MONGOOSE-2961688
465/1000
Why? CVSS 9.3
Proof of Concept
Prototype Pollution
SNYK-JS-MONGOOSE-5777721
465/1000
Why? CVSS 9.3
Proof of Concept
Prototype Poisoning
SNYK-JS-QS-3153490
465/1000
Why? CVSS 9.3
Proof of Concept
Denial of Service (DoS)
SNYK-JS-TRIMNEWLINES-1298042
465/1000
Why? CVSS 9.3
No Known Exploit
Sandbox Bypass
SNYK-JS-WEBPACK-3358798
465/1000
Why? CVSS 9.3
Proof of Concept
Prototype Pollution
SNYK-JS-LOADERUTILS-3043105
465/1000
Why? CVSS 9.3
No Known Exploit
Prototype Pollution
SNYK-JS-LOADERUTILS-3043105
465/1000
Why? CVSS 9.3
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-CONVENTIONALCOMMITSPARSER-1766960
465/1000
Why? CVSS 9.3
No Known Exploit
Information Exposure
SNYK-JS-FOLLOWREDIRECTS-2332181
465/1000
Why? CVSS 9.3
Proof of Concept
Information Exposure
SNYK-JS-NANOID-2332193
465/1000
Why? CVSS 9.3
Proof of Concept
Session Fixation
SNYK-JS-PASSPORT-2840631
465/1000
Why? CVSS 9.3
No Known Exploit
Improper Input Validation
SNYK-JS-POSTCSS-5926692
465/1000
Why? CVSS 9.3
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-TERSER-2806366
465/1000
Why? CVSS 9.3
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-TRIMOFFNEWLINES-1296850
465/1000
Why? CVSS 9.3
Proof of Concept
Open Redirect
SNYK-JS-GOT-2932019
465/1000
Why? CVSS 9.3
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-HTTPCACHESEMANTICS-3248783
465/1000
Why? CVSS 9.3
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-LOADERUTILS-3042992
465/1000
Why? CVSS 9.3
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-LOADERUTILS-3105943
465/1000
Why? CVSS 9.3
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-LOADERUTILS-3042992
465/1000
Why? CVSS 9.3
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-LOADERUTILS-3105943
465/1000
Why? CVSS 9.3
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-3050818
465/1000
Why? CVSS 9.3
No Known Exploit
Prototype Pollution
SNYK-JS-MINIMIST-2429795
465/1000
Why? CVSS 9.3
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-WORDWRAP-3149973
465/1000
Why? CVSS 9.3
Proof of Concept
Information Exposure
SNYK-JS-FOLLOWREDIRECTS-2396346
465/1000
Why? CVSS 9.3
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: axios
  • 0.27.2 - 2022-04-27

    Fixes and Functionality:

    • Fixed FormData posting in browser environment by reverting #3785 (#4640)
    • Enhanced protocol parsing implementation (#4639)
    • Fixed bundle size
  • 0.27.1 - 2022-04-26

    Fixes and Functionality:

    • Removed import of url module in browser build due to huge size overhead and builds being broken (#4594)
    • Bumped follow-redirects to ^1.14.9 (#4615)
  • 0.27.0 - 2022-04-25

    Breaking changes:

    • New toFormData helper function that allows the implementor to pass an object and allow axios to convert it to FormData (#3757)
    • Removed functionality that removed the the Content-Type request header when passing FormData (#3785)
    • (*) Refactored error handling implementing AxiosError as a constructor, this is a large change to error handling on the whole (#3645)
    • Separated responsibility for FormData instantiation between transformRequest and toFormData (#4470)
    • (*) Improved and fixed multiple issues with FormData support (#4448)

    QOL and DevX improvements:

    • Added a multipart/form-data testing playground allowing contributors to debug changes easily (#4465)

    Fixes and Functionality:

    • Refactored project file structure to avoid circular imports (#4515) & (#4516)
    • Bumped follow-redirects to ^1.14.9 (#4562)

    Internal and Tests:

    • Updated dev dependencies to latest version

    Documentation:

    • Fixing incorrect link in changelog (#4551)

    Notes:

    • (*) Please read these pull requests before updating, these changes are very impactful and far reaching.
  • 0.26.1 - 2022-03-09

    Fixes and Functionality:

    • Refactored project file structure to avoid circular imports (#4220)
  • 0.26.0 - 2022-02-13

    Fixes and Functionality:

    • Fixed The timeoutErrorMessage property in config not work with Node.js (#3581)
    • Added errors to be displayed when the query parsing process itself fails (#3961)
    • Fix/remove url required (#4426)
    • Update follow-redirects dependency due to Vulnerability (#4462)
    • Bump karma from 6.3.11 to 6.3.14 (#4461)
    • Bump follow-redirects from 1.14.7 to 1.14.8 (#4473)
  • 0.25.0 - 2022-01-18

    Breaking changes:

    • Fixing maxBodyLength enforcement (#3786)
    • Don't rely on strict mode behaviour for arguments (#3470)
    • Adding error handling when missing url (#3791)
    • Update isAbsoluteURL.js removing escaping of non-special characters (#3809)
    • Use native Array.isArray() in utils.js (#3836)
    • Adding error handling inside stream end callback (#3967)

    Fixes and Functionality:

    • Added aborted even handler (#3916)
    • Header types expanded allowing boolean and number types (#4144)
    • Fix cancel signature allowing cancel message to be undefined (#3153)
    • Updated type checks to be formulated better (#3342)
    • Avoid unnecessary buffer allocations (#3321)
    • Adding a socket handler to keep TCP connection live when processing long living requests (#3422)
    • Added toFormData helper function (#3757)
    • Adding responseEncoding prop type in AxiosRequestConfig (#3918)

    Internal and Tests:

    • Adding axios-test-instance to ecosystem (#3786)
    • Optimize the logic of isAxiosError (#3546)
    • Add tests and documentation to display how multiple inceptors work (#3564)
    • Updating follow-redirects to version 1.14.7 (#4379)

    Documentation:

    • Fixing changelog to show corrext pull request (#4219)
    • Update upgrade guide for https proxy setting (#3604)

    Huge thanks to everyone who contributed to this release via code (authors listed below) or via reviews and triaging on GitHub:

  • 0.24.0 - 2021-10-25

    Breaking changes:

    • Revert: change type of AxiosResponse to any, please read lengthy discussion here: (#4141) pull request: (#4186)

    Huge thanks to everyone who contributed to this release via code (authors listed below) or via reviews and triaging on GitHub:

from axios GitHub release notes

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Copy link

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
0.0% 0.0% Duplication

@Loonz206 Loonz206 enabled auto-merge (squash) January 13, 2024 06:33
Copy link

Quality Gate Passed Quality Gate passed

Kudos, no new issues were introduced!

0 New issues
0 Security Hotspots
No data about Coverage
No data about Duplication

See analysis details on SonarCloud

@Loonz206 Loonz206 disabled auto-merge January 13, 2024 06:36
@Loonz206 Loonz206 merged commit 77444d1 into main Jan 13, 2024
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants