Skip to content

chore: Bump axios from 1.16.0 to 1.18.1 - #274

Open
ernst-dev wants to merge 2 commits into
mainfrom
dependabot/npm_and_yarn/axios-1.18.1
Open

chore: Bump axios from 1.16.0 to 1.18.1#274
ernst-dev wants to merge 2 commits into
mainfrom
dependabot/npm_and_yarn/axios-1.18.1

Conversation

@ernst-dev

Copy link
Copy Markdown
Member

Bumps axios from 1.16.0 to 1.18.1 to address multiple security vulnerabilities.

This is a lockfile-only change (transitive dependency; package-lock.json only).

Vulnerabilities addressed

Severity Advisory Summary
High GHSA-gcfj-64vw-6mp9 Node HTTP adapter can use an inherited proxy after interceptor config cloning
Medium GHSA-7q8q-rj6j-mhjq Nested axios option objects can consume polluted prototype values
Medium GHSA-mmx7-hfxf-jppx Prototype pollution gadgets can alter axios request construction
Medium GHSA-f4gw-2p7v-4548 NO_PROXY bypass for 0.0.0.0 local addresses
Medium GHSA-xj6q-8x83-jv6g Prototype pollution auth subfields can inject Basic auth
  • Vulnerable versions: < 1.18.0
  • Patched version: 1.18.0 (bumped to 1.18.1)

Lockfile regenerated with the repo's scripts/clean-package-lock.js post-processing so only the axios subtree changes.

Opened by roko-dependabot-handler on behalf of @ernst-dev to remediate a Dependabot alert that had no auto-generated fix.

@ernst-dev
ernst-dev requested a review from a team as a code owner July 23, 2026 11:19
@ernst-dev
ernst-dev requested review from SpyZzey and removed request for a team July 23, 2026 11:19
@ernst-dev ernst-dev added the dependencies Pull requests that update a dependency file label Jul 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants