Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

DXE-4672 bump axios version to fix snyk vulnerability #239

Open
glhrmv opened this issue Jan 28, 2025 · 3 comments
Open

DXE-4672 bump axios version to fix snyk vulnerability #239

glhrmv opened this issue Jan 28, 2025 · 3 comments

Comments

@glhrmv
Copy link

glhrmv commented Jan 28, 2025

Hi all, can we get this upgrade in?

https://security.snyk.io/vuln/SNYK-JS-AXIOS-7361793

@lsadlon
Copy link

lsadlon commented Jan 29, 2025

Hi @glhrmv

Thanks for reporting it. I created internal ticket to investigate it.

BR,
Lukasz

@lsadlon lsadlon changed the title bump axios version to fix snyk vulnerability DXE-4672 bump axios version to fix snyk vulnerability Jan 29, 2025
@glhrmv glhrmv changed the title DXE-4672 bump axios version to fix snyk vulnerability bump axios version to fix snyk vulnerability Jan 30, 2025
@glhrmv glhrmv changed the title bump axios version to fix snyk vulnerability DXE-4672 bump axios version to fix snyk vulnerability Jan 30, 2025
@artbookspirit
Copy link

Hi @glhrmv,

For the axios dependency we specify the version range in package.json as ^1.1.2. This allows you to use all versions of axiom with the major number 1, including the newest 1.7.9. Do you encounter any problems updating your project's dependencies?

Thanks,
Piotr

@glhrmv
Copy link
Author

glhrmv commented Feb 21, 2025

Hi @artbookspirit,

Good point - I'll get back to you soon to see if an easy rm -rf node_modules/ && npm i resolves this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Development

No branches or pull requests

4 participants