[Snyk] Upgrade axios from 1.6.7 to 1.6.8 #1055

Closed
opened 2026-04-05 16:25:08 +02:00 by MrUnknownDE · 0 comments
Owner

Originally created by @simlarsen on 4/5/2024

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade axios from 1.6.7 to 1.6.8.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 1 version ahead of your current version.
  • The recommended version was released 21 days ago, on 2024-03-15.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Information Exposure
SNYK-JS-FOLLOWREDIRECTS-6444610
504/1000
Why? Proof of Concept exploit, Recently disclosed, CVSS 6.5
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: axios from axios GitHub release notes
Commit messages
Package name: axios
  • ab3f0f9 chore(release): v1.6.8 (#6303)
  • 2656612 fix(AxiosHeaders): fix AxiosHeaders conversion to an object during config merging (#6243)
  • 7320430 fix(import): use named export for EventEmitter;
  • 8786e0f fix(vulnerability): update follow-redirects to 1.15.6 (#6300)
  • d844227 chore: update and bump deps (#6238)
  • caa0625 docs: update README responseEncoding types (#6194)
  • 41c4584 docs: Update README.md to point to current axios version in CDN links (#6196)
  • bf6974f chore(ci): add npm tag action; (#6231)

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

*Originally created by @simlarsen on 4/5/2024* <p>This PR was automatically created by Snyk using the credentials of a real user.</p><br /><h3>Snyk has created this PR to upgrade axios from 1.6.7 to 1.6.8.</h3> :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project. <hr/> - The recommended version is **1 version** ahead of your current version. - The recommended version was released **21 days ago**, on 2024-03-15. The recommended version fixes: Severity | Issue | PriorityScore (*) | Exploit Maturity | :-------------------------:|:-------------------------|-------------------------|:------------------------- <img src="https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png" width="20" height="20" title="medium severity"/> | Information Exposure<br/> [SNYK-JS-FOLLOWREDIRECTS-6444610](https://snyk.io/vuln/SNYK-JS-FOLLOWREDIRECTS-6444610) | **504/1000** <br/> **Why?** Proof of Concept exploit, Recently disclosed, CVSS 6.5 | Proof of Concept (*) Note that the real score may have changed since the PR was raised. <details> <summary><b>Release notes</b></summary> <br/> <details> <summary>Package name: <b>axios</b></summary> <ul> <li> <b>1.6.8</b> - <a href="https://snyk.io/redirect/github/axios/axios/releases/tag/v1.6.8">2024-03-15</a></br><h2>Release notes:</h2> <h3>Bug Fixes</h3> <ul> <li><strong>AxiosHeaders:</strong> fix AxiosHeaders conversion to an object during config merging (<a href="https://snyk.io/redirect/github/axios/axios/issues/6243" data-hovercard-type="pull_request" data-hovercard-url="/axios/axios/pull/6243/hovercard">#6243</a>) (<a href="https://snyk.io/redirect/github/axios/axios/commit/2656612bc10fe2757e9832b708ed773ab340b5cb">2656612</a>)</li> <li><strong>import:</strong> use named export for EventEmitter; (<a href="https://snyk.io/redirect/github/axios/axios/commit/7320430aef2e1ba2b89488a0eaf42681165498b1">7320430</a>)</li> <li><strong>vulnerability:</strong> update follow-redirects to 1.15.6 (<a href="https://snyk.io/redirect/github/axios/axios/issues/6300" data-hovercard-type="pull_request" data-hovercard-url="/axios/axios/pull/6300/hovercard">#6300</a>) (<a href="https://snyk.io/redirect/github/axios/axios/commit/8786e0ff55a8c68d4ca989801ad26df924042e27">8786e0f</a>)</li> </ul> <h3>Contributors to this release</h3> <ul> <li><a target="_blank" rel="noopener noreferrer nofollow" href="https://avatars.githubusercontent.com/u/4814473?v=4&amp;s=18"><img src="https://avatars.githubusercontent.com/u/4814473?v=4&amp;s=18" alt="avatar" width="18" style="max-width: 100%;"></a> <a href="https://snyk.io/redirect/github/jasonsaayman" title="+4572/-3446 (#6238 )">Jay</a></li> <li><a target="_blank" rel="noopener noreferrer nofollow" href="https://avatars.githubusercontent.com/u/12586868?v=4&amp;s=18"><img src="https://avatars.githubusercontent.com/u/12586868?v=4&amp;s=18" alt="avatar" width="18" style="max-width: 100%;"></a> <a href="https://snyk.io/redirect/github/DigitalBrainJS" title="+30/-0 (#6231 )">Dmitriy Mozgovoy</a></li> <li><a target="_blank" rel="noopener noreferrer nofollow" href="https://avatars.githubusercontent.com/u/68230846?v=4&amp;s=18"><img src="https://avatars.githubusercontent.com/u/68230846?v=4&amp;s=18" alt="avatar" width="18" style="max-width: 100%;"></a> <a href="https://snyk.io/redirect/github/Creaous" title="+9/-9 (#6300 )">Mitchell</a></li> <li><a target="_blank" rel="noopener noreferrer nofollow" href="https://avatars.githubusercontent.com/u/53797821?v=4&amp;s=18"><img src="https://avatars.githubusercontent.com/u/53797821?v=4&amp;s=18" alt="avatar" width="18" style="max-width: 100%;"></a> <a href="https://snyk.io/redirect/github/mannoeu" title="+2/-2 (#6196 )">Emmanuel</a></li> <li><a target="_blank" rel="noopener noreferrer nofollow" href="https://avatars.githubusercontent.com/u/44109284?v=4&amp;s=18"><img src="https://avatars.githubusercontent.com/u/44109284?v=4&amp;s=18" alt="avatar" width="18" style="max-width: 100%;"></a> <a href="https://snyk.io/redirect/github/ljkeller" title="+3/-0 (#6194 )">Lucas Keller</a></li> <li><a target="_blank" rel="noopener noreferrer nofollow" href="https://avatars.githubusercontent.com/u/72791488?v=4&amp;s=18"><img src="https://avatars.githubusercontent.com/u/72791488?v=4&amp;s=18" alt="avatar" width="18" style="max-width: 100%;"></a> <a href="https://snyk.io/redirect/github/ADITYA-176" title="+1/-1 ()">Aditya Mogili</a></li> <li><a target="_blank" rel="noopener noreferrer nofollow" href="https://avatars.githubusercontent.com/u/46135319?v=4&amp;s=18"><img src="https://avatars.githubusercontent.com/u/46135319?v=4&amp;s=18" alt="avatar" width="18" style="max-width: 100%;"></a> <a href="https://snyk.io/redirect/github/petrovmiroslav" title="+1/-1 (#6243 )">Miroslav Petrov</a></li> </ul> </li> <li> <b>1.6.7</b> - <a href="https://snyk.io/redirect/github/axios/axios/releases/tag/v1.6.7">2024-01-25</a></br><h2>Release notes:</h2> <h3>Bug Fixes</h3> <ul> <li>capture async stack only for rejections with native error objects; (<a href="https://snyk.io/redirect/github/axios/axios/issues/6203" data-hovercard-type="pull_request" data-hovercard-url="/axios/axios/pull/6203/hovercard">#6203</a>) (<a href="https://snyk.io/redirect/github/axios/axios/commit/1a08f90f402336e4d00e9ee82f211c6adb1640b0">1a08f90</a>)</li> </ul> <h3>Contributors to this release</h3> <ul> <li><a target="_blank" rel="noopener noreferrer nofollow" href="https://avatars.githubusercontent.com/u/12586868?v=4&amp;s=18"><img src="https://avatars.githubusercontent.com/u/12586868?v=4&amp;s=18" alt="avatar" width="18" style="max-width: 100%;"></a> <a href="https://snyk.io/redirect/github/DigitalBrainJS" title="+30/-26 (#6203 )">Dmitriy Mozgovoy</a></li> <li><a target="_blank" rel="noopener noreferrer nofollow" href="https://avatars.githubusercontent.com/u/73059627?v=4&amp;s=18"><img src="https://avatars.githubusercontent.com/u/73059627?v=4&amp;s=18" alt="avatar" width="18" style="max-width: 100%;"></a> <a href="https://snyk.io/redirect/github/zh-lx" title="+0/-3 (#6186 )">zhoulixiang</a></li> </ul> </li> </ul> from <a href="https://snyk.io/redirect/github/axios/axios/releases">axios GitHub release notes</a> </details> </details> <details> <summary><b>Commit messages</b></summary> </br> <details> <summary>Package name: <b>axios</b></summary> <ul> <li><a href="https://snyk.io/redirect/github/axios/axios/commit/ab3f0f9a94853c821cb00f1112788ecdd3ae7ed1">ab3f0f9</a> chore(release): v1.6.8 (#6303)</li> <li><a href="https://snyk.io/redirect/github/axios/axios/commit/2656612bc10fe2757e9832b708ed773ab340b5cb">2656612</a> fix(AxiosHeaders): fix AxiosHeaders conversion to an object during config merging (#6243)</li> <li><a href="https://snyk.io/redirect/github/axios/axios/commit/7320430aef2e1ba2b89488a0eaf42681165498b1">7320430</a> fix(import): use named export for EventEmitter;</li> <li><a href="https://snyk.io/redirect/github/axios/axios/commit/8786e0ff55a8c68d4ca989801ad26df924042e27">8786e0f</a> fix(vulnerability): update follow-redirects to 1.15.6 (#6300)</li> <li><a href="https://snyk.io/redirect/github/axios/axios/commit/d844227411263fab39d447442879112f8b0c8de5">d844227</a> chore: update and bump deps (#6238)</li> <li><a href="https://snyk.io/redirect/github/axios/axios/commit/caa06252015003990958d7db96f63aa646bc58e8">caa0625</a> docs: update README responseEncoding types (#6194)</li> <li><a href="https://snyk.io/redirect/github/axios/axios/commit/41c4584a41fad1d94cf86331667deff5a0b75044">41c4584</a> docs: Update README.md to point to current axios version in CDN links (#6196)</li> <li><a href="https://snyk.io/redirect/github/axios/axios/commit/bf6974f16af6c72985f094a98d874c5a6adcdc83">bf6974f</a> chore(ci): add npm tag action; (#6231)</li> </ul> <a href="https://snyk.io/redirect/github/axios/axios/compare/a52e4d9af51205959ef924f87bcf90c605e08a1e...ab3f0f9a94853c821cb00f1112788ecdd3ae7ed1">Compare</a> </details> </details> <hr/> **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.* For more information: <img src="https://api.segment.io/v1/pixel/track?data=eyJ3cml0ZUtleSI6InJyWmxZcEdHY2RyTHZsb0lYd0dUcVg4WkFRTnNCOUEwIiwiYW5vbnltb3VzSWQiOiJiMmI1ZWRkYy0zMjM5LTRlZTgtOWZhOS04M2U3NDIxNmFlOTMiLCJldmVudCI6IlBSIHZpZXdlZCIsInByb3BlcnRpZXMiOnsicHJJZCI6ImIyYjVlZGRjLTMyMzktNGVlOC05ZmE5LTgzZTc0MjE2YWU5MyJ9fQ==" width="0" height="0"/> 🧐 [View latest project report](https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/f6446ec8-d441-487e-b58f-38373430e213?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;upgrade-pr) 🛠 [Adjust upgrade PR settings](https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/f6446ec8-d441-487e-b58f-38373430e213/settings/integration?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;upgrade-pr) 🔕 [Ignore this dependency or unsubscribe from future upgrade PRs](https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/f6446ec8-d441-487e-b58f-38373430e213/settings/integration?pkg&#x3D;axios&amp;utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;upgrade-pr#auto-dep-upgrades) <!--- (snyk:metadata:{"prId":"b2b5eddc-3239-4ee8-9fa9-83e74216ae93","prPublicId":"b2b5eddc-3239-4ee8-9fa9-83e74216ae93","dependencies":[{"name":"axios","from":"1.6.7","to":"1.6.8"}],"packageManager":"npm","type":"auto","projectUrl":"https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/f6446ec8-d441-487e-b58f-38373430e213?utm_source=github&utm_medium=referral&page=upgrade-pr","projectPublicId":"f6446ec8-d441-487e-b58f-38373430e213","env":"prod","prType":"upgrade","vulns":["SNYK-JS-FOLLOWREDIRECTS-6444610"],"issuesToFix":[{"issueId":"SNYK-JS-FOLLOWREDIRECTS-6444610","severity":"medium","title":"Information Exposure","exploitMaturity":"proof-of-concept","priorityScore":504,"priorityScoreFactors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"freshness","label":true,"score":71},{"type":"cvssScore","label":"6.5","score":325},{"type":"scoreVersion","label":"v1","score":1}]}],"upgrade":["SNYK-JS-FOLLOWREDIRECTS-6444610"],"upgradeInfo":{"versionsDiff":1,"publishedDate":"2024-03-15T16:32:47.800Z"},"templateVariants":["priorityScore"],"hasFixes":true,"isMajorUpgrade":false,"isBreakingChange":false,"priorityScoreList":[504]}) --->
Sign in to join this conversation.
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github/oneuptime#1055