Commit fc3c091
noel-enquanta
Bump axios to 1.15.0 to fix GHSA-3p68-rc4w-qgx5 / GHSA-fvcv-3m26-pcqx
axios <=1.14.0 has an SSRF via NO_PROXY bypass and header-injection
cloud-metadata exfil vulnerability. Bump to ^1.15.0.
Also add npm overrides for diff (>=8.0.3) and serialize-javascript
(>=7.0.5) to clear mocha-transitive advisories. npm audit now reports
0 vulnerabilities.1 parent 24f6c05 commit fc3c091
1 file changed
Lines changed: 6 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | | - | |
| 3 | + | |
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
| |||
27 | 27 | | |
28 | 28 | | |
29 | 29 | | |
30 | | - | |
| 30 | + | |
31 | 31 | | |
32 | 32 | | |
33 | 33 | | |
34 | 34 | | |
35 | 35 | | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
36 | 40 | | |
37 | 41 | | |
38 | 42 | | |
| |||
0 commit comments