Skip to content

Commit ebf51ef

Browse files
junweid62Junwei Dai
and
Junwei Dai
authored
fix(security): Upgrade axios to 1.8.2 to fix SSRF (opensearch-project#991)
* fix(security): Upgrade axios to 1.8.2 to fix SSRF & credential leakage vulnerability Signed-off-by: Junwei Dai <junweid@amazon.com> * fix(security): Upgrade axios to 1.8.2 to fix SSRF & credential leakage vulnerability, add yarn.lock change Signed-off-by: Junwei Dai <junweid@amazon.com> * Revert "fix(security): Upgrade axios to 1.8.2 to fix SSRF & credential leakage vulnerability, add yarn.lock change" This reverts commit 1546cbc. Signed-off-by: Junwei Dai <junweid@amazon.com> * fix(security): Upgrade axios to 1.8.2 to fix SSRF & credential leakage vulnerability, add yarn.lock change Signed-off-by: Junwei Dai <junweid@amazon.com> --------- Signed-off-by: Junwei Dai <junweid@amazon.com> Co-authored-by: Junwei Dai <junweid@amazon.com>
1 parent db278de commit ebf51ef

File tree

2 files changed

+5
-5
lines changed

2 files changed

+5
-5
lines changed

package.json

+1-1
Original file line numberDiff line numberDiff line change
@@ -54,7 +54,7 @@
5454
"@sideway/formula": "^3.0.1",
5555
"semver": "^5.7.2",
5656
"browserify-sign": "^4.2.2",
57-
"axios": "^1.6.1",
57+
"axios": "^1.8.2",
5858
"braces": "^3.0.3",
5959
"micromatch": "^4.0.8"
6060
}

yarn.lock

+4-4
Original file line numberDiff line numberDiff line change
@@ -186,10 +186,10 @@ asynckit@^0.4.0:
186186
resolved "https://registry.yarnpkg.com/asynckit/-/asynckit-0.4.0.tgz#c79ed97f7f34cb8f2ba1bc9790bcc366474b4b79"
187187
integrity sha512-Oei9OH4tRh0YqU3GxhX79dM/mwVgvbZJaSNaRk+bshkj0S5cfHcgYakreBjrHwatXKbz+IoIdYLxrKim2MjW0Q==
188188

189-
axios@^1.6.1:
190-
version "1.7.7"
191-
resolved "https://registry.yarnpkg.com/axios/-/axios-1.7.7.tgz#2f554296f9892a72ac8d8e4c5b79c14a91d0a47f"
192-
integrity sha512-S4kL7XrjgBmvdGut0sN3yJxqYzrDOnivkBiN0OFs6hLiUam3UPvswUo0kqGyhqUZGEOytHyumEdXsAkgCOUf3Q==
189+
axios@^1.8.2:
190+
version "1.8.2"
191+
resolved "https://registry.yarnpkg.com/axios/-/axios-1.8.2.tgz#fabe06e241dfe83071d4edfbcaa7b1c3a40f7979"
192+
integrity sha512-ls4GYBm5aig9vWx8AWDSGLpnpDQRtWAfrjU+EuytuODrFBkqesN2RkOQCBzrA1RQNHw1SmRMSDDDSwzNAYQ6Rg==
193193
dependencies:
194194
follow-redirects "^1.15.6"
195195
form-data "^4.0.0"

0 commit comments

Comments
 (0)