Skip to content

Bump axios + override follow-redirects#24

Merged
scsmith merged 1 commit intomainfrom
bump-axios
Apr 29, 2026
Merged

Bump axios + override follow-redirects#24
scsmith merged 1 commit intomainfrom
bump-axios

Conversation

@scsmith
Copy link
Copy Markdown
Contributor

@scsmith scsmith commented Apr 28, 2026

Closes Dependabot alerts #63, #64, #65.

axios's semver range still resolves follow-redirects to 1.15.11, so an override is the minimum-blast-radius fix to pull in the 1.16.0 patch. npm audit reports 0 vulnerabilities after this change.

Version bump + npm publish to follow as a separate commit.

Closes Dependabot alerts #63, #64, #65:
- GHSA-3p68-rc4w-qgx5: axios NO_PROXY hostname normalization SSRF
- GHSA-jr5f-v2jv-69x6: axios cloud metadata exfiltration via headers
- GHSA-r4q5-vmmm-2653: follow-redirects auth header leak on redirect

axios's semver range still resolves follow-redirects to 1.15.11, so an
override is needed to pull in 1.16.0. npm audit now reports 0 vulns.
@scsmith scsmith merged commit c7d2b92 into main Apr 29, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant