appirio-tech / tc-core-library-js

6 stars 9 forks source link

[Snyk] Upgrade axios from 0.19.2 to 0.22.0 #34

Open snyk-bot opened 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to upgrade axios from 0.19.2 to 0.22.0.

merge advice :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Server-Side Request Forgery (SSRF)
SNYK-JS-AXIOS-1038255
616/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.9
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: axios from axios GitHub release notes
Commit messages
Package name: axios
  • 72f14ce Updated date
  • 3e01600 Prepping v0.22.0 for release
  • 6100f69 Fixed default transitional config for custom Axios instance; (#4052)
  • ac10a25 Updating CI to run on release branches
  • 9bcff10 Fixed cancelToken leakage; Added AbortController support; (#3305)
  • fffa02c Feat/export package version constant (#4065)
  • 66d188d fix/Avoid package.json import; (#4041)
  • f3ca637 Caseless header comparing in HTTP adapter. (#2880)
  • 4091b07 Release/0.21.4 (#4025)
  • 90205f8 Change headers type to string record (#3021)
  • 92b29d2 Make the default type of response data never (#3002)
  • 4eeb3b1 Improved type-safety for AxiosRequestConfig (#2995)
  • cd7ff04 Adding HTTP status code to error.toJSON (#2956)
  • b5a1a67 Adding nodejs http.request option: insecureHTTPParser (#2930)
  • 4f25380 Exposing the Axios constructor in index.d.ts (#2872)
  • c26762f Adding types entry in package.json (#2831)
  • 69d3cc4 Allow create() to be used recursively (#2795)
  • e367be5 [Releasing] 0.21.3
  • 83ae383 Correctly add response interceptors to interceptor chain (#4013)
  • c0c8761 [Updating] changelog to include links to issues and contributors
  • 619bb46 [Releasing] v0.21.2
  • 82c9455 Create SECURITY.md (#3981)
  • 5b45711 Security fix for ReDoS (#3980)
  • 5bc9ea2 Update ECOSYSTEM.md (#3817)
Compare

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs