[Snyk] Upgrade axios from 1.12.0 to 1.12.2 #329

Closed
opened 2026-04-05 16:19:23 +02:00 by MrUnknownDE · 0 comments
Owner

Originally created by @simlarsen on 10/27/2025

snyk-top-banner

Snyk has created this PR to upgrade axios from 1.12.0 to 1.12.2.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 2 versions ahead of your current version.

  • The recommended version was released a month ago.

Issue Score Exploit Maturity
medium severity Improper Verification of Cryptographic Signature
SNYK-JS-PLAYWRIGHTCORE-13553173
190 No Known Exploit
low severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BRACEEXPANSION-9789073
190 Proof of Concept
low severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BRACEEXPANSION-9789073
190 Proof of Concept
Release notes
Package name: axios from axios GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

*Originally created by @simlarsen on 10/27/2025* ![snyk-top-banner](https://res.cloudinary.com/snyk/image/upload/r-d/scm-platform/snyk-pull-requests/pr-banner-default.svg) <h3>Snyk has created this PR to upgrade axios from 1.12.0 to 1.12.2.</h3> :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project. <hr/> - The recommended version is **2 versions** ahead of your current version. - The recommended version was released **a month ago**. #### Issues fixed by the recommended upgrade: | | Issue | Score | Exploit Maturity | :-------------------------:|:-------------------------|:-------------------------|:------------------------- ![medium severity](https://res.cloudinary.com/snyk/image/upload/r-d/scm-platform/snyk-pull-requests//severity-medium.svg 'medium severity') | Improper Verification of Cryptographic Signature<br/>[SNYK-JS-PLAYWRIGHTCORE-13553173](https://snyk.io/vuln/SNYK-JS-PLAYWRIGHTCORE-13553173) | **190** | No Known Exploit ![low severity](https://res.cloudinary.com/snyk/image/upload/r-d/scm-platform/snyk-pull-requests//severity-low.svg 'low severity') | Regular Expression Denial of Service (ReDoS)<br/>[SNYK-JS-BRACEEXPANSION-9789073](https://snyk.io/vuln/SNYK-JS-BRACEEXPANSION-9789073) | **190** | Proof of Concept ![low severity](https://res.cloudinary.com/snyk/image/upload/r-d/scm-platform/snyk-pull-requests//severity-low.svg 'low severity') | Regular Expression Denial of Service (ReDoS)<br/>[SNYK-JS-BRACEEXPANSION-9789073](https://snyk.io/vuln/SNYK-JS-BRACEEXPANSION-9789073) | **190** | Proof of Concept <details> <summary><b>Release notes</b></summary> <br/> <details> <summary>Package name: <b>axios</b></summary> <ul> <li> <b>1.12.2</b> - <a href="https://redirect.github.com/axios/axios/releases/tag/v1.12.2">2025-09-14</a></br><h2>Release notes:</h2> <h3>Bug Fixes</h3> <ul> <li><strong>fetch:</strong> use current global fetch instead of cached one when env fetch is not specified to keep MSW support; (<a href="https://redirect.github.com/axios/axios/issues/7030" data-hovercard-type="pull_request" data-hovercard-url="/axios/axios/pull/7030/hovercard">#7030</a>) (<a href="https://redirect.github.com/axios/axios/commit/cf78825e1229b60d1629ad0bbc8a752ff43c3f53">cf78825</a>)</li> </ul> <h3>Contributors to this release</h3> <ul> <li><a target="_blank" rel="noopener noreferrer nofollow" href="https://avatars.githubusercontent.com/u/12586868?v=4&amp;s=18"><img src="https://avatars.githubusercontent.com/u/12586868?v=4&amp;s=18" alt="avatar" width="18" style="max-width: 100%;"></a> <a href="https://redirect.github.com/DigitalBrainJS" title="+247/-16 (#7030 #7022 #7024 )">Dmitriy Mozgovoy</a></li> <li><a target="_blank" rel="noopener noreferrer nofollow" href="https://avatars.githubusercontent.com/u/189505037?v=4&amp;s=18"><img src="https://avatars.githubusercontent.com/u/189505037?v=4&amp;s=18" alt="avatar" width="18" style="max-width: 100%;"></a> <a href="https://redirect.github.com/noritaka1166" title="+2/-6 (#7028 #7029 )">Noritaka Kobayashi</a></li> </ul> </li> <li> <b>1.12.1</b> - <a href="https://redirect.github.com/axios/axios/releases/tag/v1.12.1">2025-09-12</a></br><h2>Release notes:</h2> <h3>Bug Fixes</h3> <ul> <li><strong>types:</strong> fixed env config types; (<a href="https://redirect.github.com/axios/axios/issues/7020" data-hovercard-type="pull_request" data-hovercard-url="/axios/axios/pull/7020/hovercard">#7020</a>) (<a href="https://redirect.github.com/axios/axios/commit/b5f26b75bdd9afa95016fb67d0cab15fc74cbf05">b5f26b7</a>)</li> </ul> <h3>Contributors to this release</h3> <ul> <li><a target="_blank" rel="noopener noreferrer nofollow" href="https://avatars.githubusercontent.com/u/12586868?v=4&amp;s=18"><img src="https://avatars.githubusercontent.com/u/12586868?v=4&amp;s=18" alt="avatar" width="18" style="max-width: 100%;"></a> <a href="https://redirect.github.com/DigitalBrainJS" title="+10/-4 (#7020 )">Dmitriy Mozgovoy</a></li> </ul> </li> <li> <b>1.12.0</b> - <a href="https://redirect.github.com/axios/axios/releases/tag/v1.12.0">2025-09-11</a></br><h2>Release notes:</h2> <h3>Bug Fixes</h3> <ul> <li>adding build artifacts (<a href="https://redirect.github.com/axios/axios/commit/9ec86de257bfa33856571036279169f385ed92bd">9ec86de</a>)</li> <li>dont add dist on release (<a href="https://redirect.github.com/axios/axios/commit/a2edc3606a4f775d868a67bb3461ff18ce7ecd11">a2edc36</a>)</li> <li><strong>fetch-adapter:</strong> set correct Content-Type for Node FormData (<a href="https://redirect.github.com/axios/axios/issues/6998" data-hovercard-type="pull_request" data-hovercard-url="/axios/axios/pull/6998/hovercard">#6998</a>) (<a href="https://redirect.github.com/axios/axios/commit/a9f47afbf3224d2ca987dbd8188789c7ea853c5d">a9f47af</a>)</li> <li><strong>node:</strong> enforce maxContentLength for data: URLs (<a href="https://redirect.github.com/axios/axios/issues/7011" data-hovercard-type="pull_request" data-hovercard-url="/axios/axios/pull/7011/hovercard">#7011</a>) (<a href="https://redirect.github.com/axios/axios/commit/945435fc51467303768202250debb8d4ae892593">945435f</a>)</li> <li>package exports (<a href="https://redirect.github.com/axios/axios/issues/5627" data-hovercard-type="pull_request" data-hovercard-url="/axios/axios/pull/5627/hovercard">#5627</a>) (<a href="https://redirect.github.com/axios/axios/commit/aa78ac23fc9036163308c0f6bd2bb885e7af3f36">aa78ac2</a>)</li> <li><strong>params:</strong> removing '[' and ']' from URL encode exclude characters (<a href="https://redirect.github.com/axios/axios/issues/3316" data-hovercard-type="issue" data-hovercard-url="/axios/axios/issues/3316/hovercard">#3316</a>) (<a href="https://redirect.github.com/axios/axios/issues/5715" data-hovercard-type="pull_request" data-hovercard-url="/axios/axios/pull/5715/hovercard">#5715</a>) (<a href="https://redirect.github.com/axios/axios/commit/6d84189349c43b1dcdd977b522610660cc4c7042">6d84189</a>)</li> <li>release pr run (<a href="https://redirect.github.com/axios/axios/commit/fd7f404488b2c4f238c2fbe635b58026a634bfd2">fd7f404</a>)</li> <li><strong>types:</strong> change the type guard on isCancel (<a href="https://redirect.github.com/axios/axios/issues/5595" data-hovercard-type="pull_request" data-hovercard-url="/axios/axios/pull/5595/hovercard">#5595</a>) (<a href="https://redirect.github.com/axios/axios/commit/0dbb7fd4f61dc568498cd13a681fa7f907d6ec7e">0dbb7fd</a>)</li> </ul> <h3>Features</h3> <ul> <li><strong>adapter:</strong> surface low‑level network error details; attach original error via cause (<a href="https://redirect.github.com/axios/axios/issues/6982" data-hovercard-type="pull_request" data-hovercard-url="/axios/axios/pull/6982/hovercard">#6982</a>) (<a href="https://redirect.github.com/axios/axios/commit/78b290c57c978ed2ab420b90d97350231c9e5d74">78b290c</a>)</li> <li><strong>fetch:</strong> add fetch, Request, Response env config variables for the adapter; (<a href="https://redirect.github.com/axios/axios/issues/7003" data-hovercard-type="pull_request" data-hovercard-url="/axios/axios/pull/7003/hovercard">#7003</a>) (<a href="https://redirect.github.com/axios/axios/commit/c959ff29013a3bc90cde3ac7ea2d9a3f9c08974b">c959ff2</a>)</li> <li>support reviver on JSON.parse (<a href="https://redirect.github.com/axios/axios/issues/5926" data-hovercard-type="pull_request" data-hovercard-url="/axios/axios/pull/5926/hovercard">#5926</a>) (<a href="https://redirect.github.com/axios/axios/commit/2a9763426e43d996fd60d01afe63fa6e1f5b4fca">2a97634</a>), closes <a href="https://redirect.github.com/axios/axios/issues/5924" data-hovercard-type="issue" data-hovercard-url="/axios/axios/issues/5924/hovercard">#5924</a></li> <li><strong>types:</strong> extend AxiosResponse interface to include custom headers type (<a href="https://redirect.github.com/axios/axios/issues/6782" data-hovercard-type="pull_request" data-hovercard-url="/axios/axios/pull/6782/hovercard">#6782</a>) (<a href="https://redirect.github.com/axios/axios/commit/7960d34eded2de66ffd30b4687f8da0e46c4903e">7960d34</a>)</li> </ul> <h3>Contributors to this release</h3> <ul> <li><a target="_blank" rel="noopener noreferrer nofollow" href="https://avatars.githubusercontent.com/u/22686401?v=4&amp;s=18"><img src="https://avatars.githubusercontent.com/u/22686401?v=4&amp;s=18" alt="avatar" width="18" style="max-width: 100%;"></a> <a href="https://redirect.github.com/WillianAgostini" title="+132/-16760 (#7002 #5926 #6782 )">Willian Agostini</a></li> <li><a target="_blank" rel="noopener noreferrer nofollow" href="https://avatars.githubusercontent.com/u/12586868?v=4&amp;s=18"><img src="https://avatars.githubusercontent.com/u/12586868?v=4&amp;s=18" alt="avatar" width="18" style="max-width: 100%;"></a> <a href="https://redirect.github.com/DigitalBrainJS" title="+4263/-293 (#7006 #7003 )">Dmitriy Mozgovoy</a></li> <li><a target="_blank" rel="noopener noreferrer nofollow" href="https://avatars.githubusercontent.com/u/53833811?v=4&amp;s=18"><img src="https://avatars.githubusercontent.com/u/53833811?v=4&amp;s=18" alt="avatar" width="18" style="max-width: 100%;"></a> <a href="https://redirect.github.com/mkhani01" title="+111/-15 (#6982 )">khani</a></li> <li><a target="_blank" rel="noopener noreferrer nofollow" href="https://avatars.githubusercontent.com/u/7712804?v=4&amp;s=18"><img src="https://avatars.githubusercontent.com/u/7712804?v=4&amp;s=18" alt="avatar" width="18" style="max-width: 100%;"></a> <a href="https://redirect.github.com/AmeerAssadi" title="+123/-0 (#7011 )">Ameer Assadi</a></li> <li><a target="_blank" rel="noopener noreferrer nofollow" href="https://avatars.githubusercontent.com/u/70265727?v=4&amp;s=18"><img src="https://avatars.githubusercontent.com/u/70265727?v=4&amp;s=18" alt="avatar" width="18" style="max-width: 100%;"></a> <a href="https://redirect.github.com/emiedonmokumo" title="+55/-35 (#6998 )">Emiedonmokumo Dick-Boro</a></li> <li><a target="_blank" rel="noopener noreferrer nofollow" href="https://avatars.githubusercontent.com/u/47859767?v=4&amp;s=18"><img src="https://avatars.githubusercontent.com/u/47859767?v=4&amp;s=18" alt="avatar" width="18" style="max-width: 100%;"></a> <a href="https://redirect.github.com/opsysdebug" title="+8/-8 (#6980 )">Zeroday BYTE</a></li> <li><a target="_blank" rel="noopener noreferrer nofollow" href="https://avatars.githubusercontent.com/u/4814473?v=4&amp;s=18"><img src="https://avatars.githubusercontent.com/u/4814473?v=4&amp;s=18" alt="avatar" width="18" style="max-width: 100%;"></a> <a href="https://redirect.github.com/jasonsaayman" title="+7/-7 (#6985 #6985 )">Jason Saayman</a></li> <li><a target="_blank" rel="noopener noreferrer nofollow" href="https://avatars.githubusercontent.com/u/13010755?v=4&amp;s=18"><img src="https://avatars.githubusercontent.com/u/13010755?v=4&amp;s=18" alt="avatar" width="18" style="max-width: 100%;"></a> <a href="https://redirect.github.com/HealGaren" title="+5/-7 (#5715 )">최예찬</a></li> <li><a target="_blank" rel="noopener noreferrer nofollow" href="https://avatars.githubusercontent.com/u/7002604?v=4&amp;s=18"><img src="https://avatars.githubusercontent.com/u/7002604?v=4&amp;s=18" alt="avatar" width="18" style="max-width: 100%;"></a> <a href="https://redirect.github.com/gligorkot" title="+3/-1 (#5627 )">Gligor Kotushevski</a></li> <li><a target="_blank" rel="noopener noreferrer nofollow" href="https://avatars.githubusercontent.com/u/15893?v=4&amp;s=18"><img src="https://avatars.githubusercontent.com/u/15893?v=4&amp;s=18" alt="avatar" width="18" style="max-width: 100%;"></a> <a href="https://redirect.github.com/adimit" title="+2/-1 (#5595 )">Aleksandar Dimitrov</a></li> </ul> </li> </ul> from <a href="https://redirect.github.com/axios/axios/releases">axios GitHub release notes</a> </details> </details> --- > [!IMPORTANT] > > - Check the changes in this PR to ensure they won't cause issues with your project. > - This PR was automatically created by Snyk using the credentials of a real user. > - Max score is 1000. Note that the real score may have changed since the PR was raised. --- **Note:** _You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs._ **For more information:** <img src="https://api.segment.io/v1/pixel/track?data=eyJ3cml0ZUtleSI6InJyWmxZcEdHY2RyTHZsb0lYd0dUcVg4WkFRTnNCOUEwIiwiYW5vbnltb3VzSWQiOiJjOWYyMDg1Ni03MzQxLTQ5YTItYWE0Yy0wMGE5MGUwMTYyY2UiLCJldmVudCI6IlBSIHZpZXdlZCIsInByb3BlcnRpZXMiOnsicHJJZCI6ImM5ZjIwODU2LTczNDEtNDlhMi1hYTRjLTAwYTkwZTAxNjJjZSJ9fQ==" width="0" height="0"/> > - 🧐 [View latest project report](https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/49c81d9c-12c2-4e8e-b9e8-72f98b1b595c?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;upgrade-pr) > - 📜 [Customise PR templates](https://docs.snyk.io/scan-using-snyk/pull-requests/snyk-fix-pull-or-merge-requests/customize-pr-templates?utm_source=&utm_content=fix-pr-template) > - 🛠 [Adjust upgrade PR settings](https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/49c81d9c-12c2-4e8e-b9e8-72f98b1b595c/settings/integration?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;upgrade-pr) > - 🔕 [Ignore this dependency or unsubscribe from future upgrade PRs](https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/49c81d9c-12c2-4e8e-b9e8-72f98b1b595c/settings/integration?pkg&#x3D;axios&amp;utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;upgrade-pr#auto-dep-upgrades) [//]: # 'snyk:metadata:{"breakingChangeRiskLevel":null,"FF_showPullRequestBreakingChanges":null,"FF_showPullRequestBreakingChangesWebSearch":null,"customTemplate":{"variablesUsed":[],"fieldsUsed":[]},"dependencies":[{"name":"axios","from":"1.12.0","to":"1.12.2"}],"env":"prod","hasFixes":true,"isBreakingChange":false,"isMajorUpgrade":false,"issuesToFix":["SNYK-JS-PLAYWRIGHTCORE-13553173","SNYK-JS-BRACEEXPANSION-9789073","SNYK-JS-BRACEEXPANSION-9789073"],"prId":"c9f20856-7341-49a2-aa4c-00a90e0162ce","prPublicId":"c9f20856-7341-49a2-aa4c-00a90e0162ce","packageManager":"npm","priorityScoreList":[500,190],"projectPublicId":"49c81d9c-12c2-4e8e-b9e8-72f98b1b595c","projectUrl":"https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/49c81d9c-12c2-4e8e-b9e8-72f98b1b595c?utm_source=github&utm_medium=referral&page=upgrade-pr","prType":"upgrade","templateFieldSources":{"branchName":"default","commitMessage":"default","description":"default","title":"default"},"templateVariants":["priorityScore"],"type":"auto","upgrade":["SNYK-JS-PLAYWRIGHTCORE-13553173","SNYK-JS-BRACEEXPANSION-9789073","SNYK-JS-BRACEEXPANSION-9789073"],"upgradeInfo":{"versionsDiff":2,"publishedDate":"2025-09-14T12:59:27.346Z"},"vulns":["SNYK-JS-PLAYWRIGHTCORE-13553173","SNYK-JS-BRACEEXPANSION-9789073","SNYK-JS-BRACEEXPANSION-9789073"]}'
Sign in to join this conversation.
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github/oneuptime#329