Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Aug 13, 2024

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
axios (source) 1.7.2 -> 1.7.4 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2024-39338

axios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative URLs.


Release Notes

axios/axios (axios)

v1.7.4

Compare Source

Bug Fixes
Contributors to this release

v1.7.3

Compare Source

Bug Fixes
Contributors to this release

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot force-pushed the renovate/npm-axios-vulnerability branch 7 times, most recently from c05241d to de01a6c Compare August 24, 2024 07:34
@renovate renovate bot force-pushed the renovate/npm-axios-vulnerability branch 7 times, most recently from 7dd9fbb to cc8d775 Compare September 1, 2024 08:52
@renovate renovate bot force-pushed the renovate/npm-axios-vulnerability branch 3 times, most recently from f6fac61 to d6a999d Compare September 8, 2024 10:52
@renovate renovate bot force-pushed the renovate/npm-axios-vulnerability branch 8 times, most recently from d354898 to f6c6c3b Compare September 17, 2024 20:47
@renovate renovate bot force-pushed the renovate/npm-axios-vulnerability branch 5 times, most recently from 846d69b to 0ff9212 Compare September 25, 2024 20:15
@renovate renovate bot force-pushed the renovate/npm-axios-vulnerability branch 4 times, most recently from 86ee953 to 9235fb6 Compare November 25, 2024 18:46
@renovate renovate bot changed the title fix(deps): update dependency axios to v1.7.4 [security] Update dependency axios to v1.7.4 [SECURITY] Nov 30, 2024
@renovate renovate bot force-pushed the renovate/npm-axios-vulnerability branch 10 times, most recently from fe4e895 to b0bd1f9 Compare December 5, 2024 19:22
@renovate renovate bot changed the title Update dependency axios to v1.7.4 [SECURITY] fix(deps): update dependency axios to v1.7.4 [security] Dec 6, 2024
@renovate renovate bot force-pushed the renovate/npm-axios-vulnerability branch from b0bd1f9 to 2e5e331 Compare December 6, 2024 12:47
@renovate renovate bot force-pushed the renovate/npm-axios-vulnerability branch 7 times, most recently from a10bf4f to 9a769a4 Compare December 20, 2024 16:51
@renovate renovate bot force-pushed the renovate/npm-axios-vulnerability branch from 9a769a4 to 07d53e1 Compare December 22, 2024 05:56
@renovate renovate bot force-pushed the renovate/npm-axios-vulnerability branch from 07d53e1 to 8344941 Compare December 23, 2024 15:50
@iamitprakash iamitprakash merged commit 9a75c3c into develop Dec 23, 2024
3 checks passed
@iamitprakash iamitprakash deleted the renovate/npm-axios-vulnerability branch December 23, 2024 19:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants