twilio / twilio-node

Node.js helper library
MIT License
1.37k stars 495 forks source link

chore: Update axios to 1.6 to pull in fix for CVE 2023 45857 #971

Closed kitu-apietila closed 8 months ago

kitu-apietila commented 8 months ago

Fixes

Checklist

If you have questions, please file a support ticket, or create a GitHub Issue in this repository.

yangsu-ab commented 8 months ago

any progress on this? i see another PR opened a week ago addressing this vulnerability.

yangsu-ab commented 8 months ago

@kitu-apietila seems like it got approved, rebase/pull main to get it tested and merged?

kitu-apietila commented 8 months ago

@kitu-apietila seems like it got approved, rebase/pull main to get it tested and merged?

According to Github:

Review required At least 1 approving review is required by reviewers with write access

I've gone ahead and rebased.

yangsu-ab commented 8 months ago

@kitu-apietila seems like it got approved, rebase/pull main to get it tested and merged?

According to Github:

Review required At least 1 approving review is required by reviewers with write access

I've gone ahead and rebased.

i thought deepakverdethos had write access to approve :rofl:

ghost commented 8 months ago

@kitu-apietila seems like it got approved, rebase/pull main to get it tested and merged?

According to Github: Review required At least 1 approving review is required by reviewers with write access I've gone ahead and rebased.

i thought deepakverdethos had write access to approve 🤣

We want this fix so bad, I thought I would give it a try by approving it. Well it didn't work 🤣

tiwarishubham635 commented 8 months ago

Hi! We are working on fixing this pipeline. Should be able to merge it by today. Thanks!

Afellman commented 7 months ago

I see the fix has been merged in. Any ETA on a new version published to NPM?

tiwarishubham635 commented 7 months ago

The new changes will be published this Thursday