Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

web-api@6(chore): bump axios to 1.7.4 to address CVE-2024-39338 #1880

Merged

Conversation

zimeg
Copy link
Member

@zimeg zimeg commented Aug 15, 2024

Summary

This PR backports the axios bump to 1.7.4 to address GHSA-8hc4-vh64-cxmj following #1874

Requirements

@zimeg zimeg added semver:patch security pkg:web-api applies to `@slack/web-api` labels Aug 15, 2024
@zimeg zimeg added this to the web-api@6.12.1 milestone Aug 15, 2024
@zimeg zimeg self-assigned this Aug 15, 2024
@zimeg
Copy link
Member Author

zimeg commented Aug 15, 2024

@filmaj I appreciate ya! 🙏 Going to check dependencies on a few other packages before moving this over to @slack/bolt 👀

@zimeg zimeg merged commit 5df94c3 into slackapi:web-api-6.x Aug 15, 2024
15 checks passed
@zimeg zimeg deleted the web-api-6.x-chore-bump-axios-1.7.4 branch August 15, 2024 21:23
renovate bot referenced this pull request in Unleash/unleash Sep 5, 2024
This PR contains the following updates:

| Package | Change | Age | Adoption | Passing | Confidence |
|---|---|---|---|---|---|
| [@slack/web-api](https://slack.dev/node-slack-sdk/web-api)
([source](https://github.com/slackapi/node-slack-sdk)) |
[`6.12.0` ->
`6.12.1`](https://renovatebot.com/diffs/npm/@slack%2fweb-api/6.12.0/6.12.1)
|
[![age](https://developer.mend.io/api/mc/badges/age/npm/@slack%2fweb-api/6.12.1?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|
[![adoption](https://developer.mend.io/api/mc/badges/adoption/npm/@slack%2fweb-api/6.12.1?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|
[![passing](https://developer.mend.io/api/mc/badges/compatibility/npm/@slack%2fweb-api/6.12.0/6.12.1?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|
[![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@slack%2fweb-api/6.12.0/6.12.1?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|

---

### Release Notes

<details>
<summary>slackapi/node-slack-sdk (@&#8203;slack/web-api)</summary>

###
[`v6.12.1`](https://github.com/slackapi/node-slack-sdk/releases/tag/%40slack/web-api%406.12.1)

[Compare
Source](https://github.com/slackapi/node-slack-sdk/compare/@slack/web-api@6.12.0...@slack/web-api@6.12.1)

#### What's Changed

This patch release bumps the minimum version of axios to 1.7.4 to
address a CVE - see [Axios 1.7.4 release
notes](https://github.com/axios/axios/releases/tag/v1.7.4) for
more information.

##### Changelog

- web-api@6(chore): bump axios to 1.7.4 to address CVE-2024-39338 -
Thanks [@&#8203;zimeg](https://github.com/zimeg)! in
[https://github.com/slackapi/node-slack-sdk/pull/1880](https://github.com/slackapi/node-slack-sdk/pull/1880)

**Full Changelog**:
https://github.com/slackapi/node-slack-sdk/compare/[@&#8203;slack/web-api](https://github.com/slack/web-api)[@&#8203;6](https://github.com/6).12.0...[@&#8203;slack/webhook](https://github.com/slack/webhook)[@&#8203;6](https://github.com/6).12.1

</details>

---

### Configuration

📅 **Schedule**: Branch creation - "after 7pm every weekday,before 5am
every weekday" in timezone Europe/Madrid, Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/Unleash/unleash).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC41OS4yIiwidXBkYXRlZEluVmVyIjoiMzguNTkuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
pkg:web-api applies to `@slack/web-api` security semver:patch
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants