Skip to content

Upgrade axios to ^1.7.4 to fix GHSA-jr5f-v2jv-69x6#83

Open
yorkeccak wants to merge 1 commit intomainfrom
intern/dcec6701
Open

Upgrade axios to ^1.7.4 to fix GHSA-jr5f-v2jv-69x6#83
yorkeccak wants to merge 1 commit intomainfrom
intern/dcec6701

Conversation

@yorkeccak
Copy link
Contributor

Summary

  • Bumped axios from ^1.4.0 to ^1.7.4 to fix SSRF/credential leak vulnerability GHSA-jr5f-v2jv-69x6
  • Updated package-lock.json to reflect the new resolved version
  • No API surface changes - purely a dependency version bump

Task Context

Requested by intern-agent
Run dcec6701
Branch intern/dcec6701

Original Request

Fix security vulnerability: axios ^1.4.0 has SSRF/credential leak vulnerability GHSA-jr5f-v2jv-69x6. Fix available (>=1.7.4 per advisory). Current risk mitigated by hardcoded baseUrl but upgrading eliminates the vector.

Repo: valyu-js
File: package.json:46
Category: deps
Severity: high

Attachments

None

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant