ymcatwincities / openy_activity_finder

Activity Finder for Open Y
https://github.com/YCloudYUSA/yusaopeny_activity_finder
GNU General Public License v3.0
3 stars 24 forks source link

[Snyk] Upgrade axios from 0.24.0 to 0.26.0 #159

Closed snyk-bot closed 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to upgrade axios from 0.24.0 to 0.26.0.

merge advice :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Information Exposure
SNYK-JS-FOLLOWREDIRECTS-2332181
372/1000
Why? Proof of Concept exploit, CVSS 5.3
Proof of Concept
Information Exposure
SNYK-JS-FOLLOWREDIRECTS-2396346
372/1000
Why? Proof of Concept exploit, CVSS 5.3
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: axios
  • 0.26.0 - 2022-02-13

    0.26.0 (February 13, 2022)

    Fixes and Functionality:

    • Fixed The timeoutErrorMessage property in config not work with Node.js (#3581)
    • Added errors to be displayed when the query parsing process itself fails (#3961)
    • Fix/remove url required (#4426)
    • Update follow-redirects dependency due to Vulnerability (#4462)
    • Bump karma from 6.3.11 to 6.3.14 (#4461)
    • Bump follow-redirects from 1.14.7 to 1.14.8 (#4473)
  • 0.25.0 - 2022-01-18

    0.25.0 (January 18, 2022)

    Breaking changes:

    • Fixing maxBodyLength enforcement (#3786)
    • Don't rely on strict mode behaviour for arguments (#3470)
    • Adding error handling when missing url (#3791)
    • Update isAbsoluteURL.js removing escaping of non-special characters (#3809)
    • Use native Array.isArray() in utils.js (#3836)
    • Adding error handling inside stream end callback (#3967)

    Fixes and Functionality:

    • Added aborted even handler (#3916)
    • Header types expanded allowing boolean and number types (#4144)
    • Fix cancel signature allowing cancel message to be undefined (#3153)
    • Updated type checks to be formulated better (#3342)
    • Avoid unnecessary buffer allocations (#3321)
    • Adding a socket handler to keep TCP connection live when processing long living requests (#3422)
    • Added toFormData helper function (#3757)
    • Adding responseEncoding prop type in AxiosRequestConfig (#3918)

    Internal and Tests:

    • Adding axios-test-instance to ecosystem (#3786)
    • Optimize the logic of isAxiosError (#3546)
    • Add tests and documentation to display how multiple inceptors work (#3564)
    • Updating follow-redirects to version 1.14.7 (#4379)

    Documentation:

    • Fixing changelog to show corrext pull request (#4219)
    • Update upgrade guide for https proxy setting (#3604)

    Huge thanks to everyone who contributed to this release via code (authors listed below) or via reviews and triaging on GitHub:

  • 0.24.0 - 2021-10-25

    0.24.0 (October 25, 2021)

    Breaking changes:

    • Revert: change type of AxiosResponse to any, please read lengthy discussion here: (#4141) pull request: (#4186)

    Huge thanks to everyone who contributed to this release via code (authors listed below) or via reviews and triaging on GitHub:

from axios GitHub release notes
Commit messages
Package name: axios
  • c9aca75 Releasing v0.26.0
  • 3f842e0 Merge branch 'master' of github.com:axios/axios
  • 2f1e818 Merge branch 'cookieMr-master'
  • 95295f6 Fixed conflict in package lock
  • b3aa79e Bump follow-redirects from 1.14.7 to 1.14.8 (#4473)
  • d660e29 Revert "Fixed isFormData predicate; (#4413)" (#4472)
  • 447a24d Bump karma from 6.3.11 to 6.3.14 (#4461)
  • c5bdbd4 Update follow-redirects dependency due to Vurnerbility
  • 73e3bdb Fixed isFormData predicate; (#4413)
  • cc86c6c Fix/remove url required (#4426)
  • 1163588 Added errors to be displayed when the query parsing process itself fails. (#3961)
  • 4461761 Fixed The timeoutErrorMessage property in config not work with Node.js (fixes #3580) (#3581)
  • 5c5cbdf Removed cancel token request test till debugging on FireFox can be done
  • 63dfce8 Releasing v0.25
  • dccaeb1 Updated changelog for release
  • 51f3ccb Updating follow-redirects with security updates (#4379)
  • ccc9516 Fixing removing package-lock from gitignore (#4346)
  • ea0d9c6 Adding error handling inside stream end callback (#3967)
  • 4fbf61d Adding responseEncoding prop type in AxiosRequestConfig (#3918)
  • a76571a Use native `Array.isArray()` in `utils.js` (#3836)
  • a8cd75a Update isAbsoluteURL.js (#3809)
  • 9579290 Adding error handling when missing url (#3791)
  • 9964815 toFormData helper function (#3757)
  • c00c4dd Fixing maxBodyLength enforcement (#3786)
Compare

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs