Prod: Bump axios from 1.16.1 to 1.19.0 - #81
Merged
Conversation
Member
|
@dependabot rebase |
Bumps [axios](https://github.com/axios/axios) from 1.16.1 to 1.19.0. - [Release notes](https://github.com/axios/axios/releases) - [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md) - [Commits](axios/axios@v1.16.1...v1.19.0) --- updated-dependencies: - dependency-name: axios dependency-version: 1.18.1 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/npm_and_yarn/axios-1.18.1
branch
from
August 3, 2026 08:20
a6bbe6b to
af3b630
Compare
|
textbook
approved these changes
Aug 3, 2026
Member
There was a problem hiding this comment.
-
Resolves CVEs (1 high severity, 9 moderate):
- 🔴 Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning - GHSA-gcfj-64vw-6mp9
- 🟡 Axios: Excessive recursion in formDataToJSON can cause denial of service - GHSA-42h9-826w-cgv3
- 🟡 Axios: Prototype pollution auth subfields can inject Basic auth - GHSA-xj6q-8x83-jv6g
- 🟡 Axios: Deep formToJSON Key Recursion Can Cause Denial of Service - GHSA-pmv8-rq9r-6j72
- 🟡 Axios: Fetch adapter
ReadableStreamuploads bypassmaxBodyLength- GHSA-jqh4-m9w3-8hp9 - 🟡 Axios: Prototype pollution gadgets can alter axios request construction - GHSA-mmx7-hfxf-jppx
- 🟡 Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios - GHSA-f4gw-2p7v-4548
- 🟡 Axios form serializer maxDepth bypass via {} metatoken - GHSA-hcpx-6fm6-wx23
- 🟡 Axios: Nested axios option objects can consume polluted prototype values - GHSA-7q8q-rj6j-mhjq
- 🟡 Axios: HTTP/2 streamed uploads bypass
maxBodyLength- GHSA-mwf2-3pr3-8698
-
Used only by Slack client
$ npm ls axios @codeyourfuture/gitbot@0.1.0 path/to/gitbot └─┬ @slack/web-api@7.17.0 └── axios@1.16.1
-
Everything still passing in CI
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Bumps axios from 1.16.1 to 1.19.0.
Release notes
Sourced from axios's releases.
... (truncated)
Changelog
Sourced from axios's changelog.
... (truncated)
Commits
311fcc5chore(release): prepare release 1.19.0 (#11095)cb4fd74chore(deps): bump axios from 1.16.1 to 1.18.1 in /docs (#11088)004c93achore(deps): bump actions/setup-node from 6.4.0 to 7.0.0 in the github-action...122eddechore(deps-dev): bump the development_dependencies group with 3 updates (#11089)c44f8d0ci: use bundled npm for v1 publish (#11083)878bb29fix(sandbox): resolve TypeError on constant variable path assignment (#11073)a092baefix(core): synchronous interceptors swallow errors and proceed with request (...3041b8ffeat(HttpStatusCode): add missing 520 status code (#11067)58b16c8refactor(helpers): extract duplicated setFormDataHeaders into a shared helper...3077e62feat(types): Allow the Params property to be typed, instead ofany(#11081)