Geocodio / geocodio-library-node

geocod.io Node library
MIT License
15 stars 6 forks source link

Axios Security Vulnerability #9

Closed joshmossas closed 3 years ago

joshmossas commented 3 years ago

There is a server-side request forgery vulnerability in versions of Axios before 0.21.1 (related NPM advisory).

The Axios dependency should be updated to latest version to resolve this.

Screenshot from npm audit

image

atolchinsky commented 3 years ago

Same issue here. Looks like there is an open PR (#8) to address this as of 9 days ago, but its yet to be merged.

MiniCodeMonkey commented 3 years ago

Thanks for letting us know!

The axios dependency has been updated now, and pushed with release v1.3.1