-
Notifications
You must be signed in to change notification settings - Fork 304
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix(deps): update dependency axios to v1.7.4 [security] - autoclosed #3385
Conversation
|
aec0892
to
b7d7b54
Compare
b7d7b54
to
892c6c5
Compare
892c6c5
to
946f47d
Compare
946f47d
to
4ec652b
Compare
4ec652b
to
7b57c8d
Compare
7b57c8d
to
f1762f6
Compare
f1762f6
to
84bd0e7
Compare
84bd0e7
to
843fb79
Compare
843fb79
to
d1980ce
Compare
d1980ce
to
3592c40
Compare
3592c40
to
8567424
Compare
8567424
to
5c794a4
Compare
5c794a4
to
baafa2e
Compare
baafa2e
to
67a15a0
Compare
e590d05
to
2d61cd0
Compare
2d61cd0
to
6c07324
Compare
6c07324
to
9b0a037
Compare
9b0a037
to
7cf218b
Compare
7cf218b
to
40b3fc5
Compare
40b3fc5
to
f899628
Compare
f899628
to
cca31d6
Compare
cca31d6
to
18d46ec
Compare
18d46ec
to
1d3a296
Compare
1d3a296
to
2dd5a74
Compare
2dd5a74
to
3c9559d
Compare
3c9559d
to
24ab0c8
Compare
24ab0c8
to
3a284a7
Compare
This PR contains the following updates:
1.6.8
->1.7.4
GitHub Vulnerability Alerts
CVE-2023-45857
An issue discovered in Axios 0.8.1 through 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.
CVE-2024-39338
axios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative URLs.
Release Notes
axios/axios (axios)
v1.7.4
Compare Source
Bug Fixes
Contributors to this release
v1.7.3
Compare Source
Bug Fixes
Contributors to this release
v1.7.2
Compare Source
Bug Fixes
Contributors to this release
v1.7.1
Compare Source
Bug Fixes
Contributors to this release
v1.7.0
Compare Source
Features
Bug Fixes
Contributors to this release
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR was generated by Mend Renovate. View the repository job log.