Conversation
Member
|
@Kolahzary Thank you for your support. We handled the security issue on here: #344 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #342
Summary
Bumps the exact
axiospin from0.33.0to0.34.0to resolve GHSA-x97p-jq2g-jp4f (high severity, a prototype-pollution gadget in axiostoFormData). The fix is in 0.34.0, on the same 0.x line, so this stays on 0.x and does not move to axios 1.x.Because the dependency is pinned exactly, users of
@craftgate/craftgatecan't pick up the fix until the pin changes. Security scanners (npm audit, Dependabot, Snyk) currently flag every project that installs this package.Changes
package.json:"axios": "0.33.0"→"axios": "0.34.0". It is still an exact pin, and no other dependencies changed.Impact
axios is the only runtime dependency. It is used in one place,
src/lib/HttpClient.ts(axios.create({ baseURL })). The client never builds FormData or multipart bodies, so the bump doesn't change behaviour.Testing
npm run build: passesnpm test: 77 passed, 0 failednpm run lint:check: passesnpm ls axios: resolves onlyaxios@0.34.0, including the copy thataxios-mock-adapteruses