Skip to content
This repository has been archived by the owner on Apr 2, 2024. It is now read-only.

chore(deps): update dependency axios to v0.28.0 [security] #110

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Jun 27, 2022

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
axios (source) 0.21.0 -> 0.28.0 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2020-28168

Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.

CVE-2021-3749

axios before v0.21.2 is vulnerable to Inefficient Regular Expression Complexity.

CVE-2023-45857

An issue discovered in Axios 0.8.1 through 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.


Release Notes

axios/axios (axios)

v0.28.0

Compare Source

Release notes:

Bug Fixes
Backports from v1.x:
  • Allow null indexes on formSerializer and paramsSerializer v0.x (#​4961)
  • Fixing content-type header repeated #​4745
  • Fixed timeout error message for HTTP 4738
  • Added axios.formToJSON method (#​4735)
  • URL params serializer (#​4734)
  • Fixed toFormData Blob issue on node>v17 #​4728
  • Adding types for progress event callbacks #​4675
  • Fixed max body length defaults #​4731
  • Added data URL support for node.js (#​4725)
  • Added isCancel type assert (#​4293)
  • Added the ability for the url-encoded-form serializer to respect the formSerializer config (#​4721)
  • Add string[] to AxiosRequestHeaders type (#​4322)
  • Allow type definition for axios instance methods (#​4224)
  • Fixed AxiosError stack capturing; (#​4718)
  • Fixed AxiosError status code type; (#​4717)
  • Adding Canceler parameters config and request (#​4711)
  • fix(types): allow to specify partial default headers for instance creation (#​4185)
  • Added blob to the list of protocols supported by the browser (#​4678)
  • Fixing Z_BUF_ERROR when no content (#​4701)
  • Fixed race condition on immediate requests cancellation (#​4261)
  • Added a clear() function to the request and response interceptors object so a user can ensure that all interceptors have been removed from an Axios instance https://github.com/axios/axios/pull/4248
  • Added generic AxiosAbortSignal TS interface to avoid importing AbortController polyfill (#​4229)
  • Fix TS definition for AxiosRequestTransformer (#​4201)
  • Use type alias instead of interface for AxiosPromise (#​4505)
  • Include request and config when creating a CanceledError instance (#​4659)
  • Added generic TS types for the exposed toFormData helper (#​4668)
  • Optimized the code that checks cancellation (#​4587)
  • Replaced webpack with rollup (#​4596)
  • Added stack trace to AxiosError (#​4624)
  • Updated AxiosError.config to be optional in the type definition (#​4665)
  • Removed incorrect argument for NetworkError constructor (#​4656)

v0.27.2

Compare Source

Fixes and Functionality:

  • Fixed FormData posting in browser environment by reverting #​3785 (#​4640)
  • Enhanced protocol parsing implementation (#​4639)
  • Fixed bundle size

v0.27.1

Compare Source

Fixes and Functionality:
  • Removed import of url module in browser build due to huge size overhead and builds being broken (#​4594)
  • Bumped follow-redirects to ^1.14.9 (#​4615)

v0.27.0

Compare Source

Breaking changes:
  • New toFormData helper function that allows the implementor to pass an object and allow axios to convert it to FormData (#​3757)
  • Removed functionality that removed the the Content-Type request header when passing FormData (#​3785)
  • (*) Refactored error handling implementing AxiosError as a constructor, this is a large change to error handling on the whole (#​3645)
  • Separated responsibility for FormData instantiation between transformRequest and toFormData (#​4470)
  • (*) Improved and fixed multiple issues with FormData support (#​4448)
QOL and DevX improvements:
  • Added a multipart/form-data testing playground allowing contributors to debug changes easily (#​4465)
Fixes and Functionality:
  • Refactored project file structure to avoid circular imports (#​4515) & (#​4516)
  • Bumped follow-redirects to ^1.14.9 (#​4562)
Internal and Tests:
  • Updated dev dependencies to latest version
Documentation:
  • Fixing incorrect link in changelog (#​4551)
Notes:
  • (*) Please read these pull requests before updating, these changes are very impactful and far reaching.

v0.26.1

Compare Source

Fixes and Functionality:
  • Refactored project file structure to avoid circular imports (#​4220)

v0.26.0

Compare Source

Fixes and Functionality:
  • Fixed The timeoutErrorMessage property in config not work with Node.js (#​3581)
  • Added errors to be displayed when the query parsing process itself fails (#​3961)
  • Fix/remove url required (#​4426)
  • Update follow-redirects dependency due to Vulnerability (#​4462)
  • Bump karma from 6.3.11 to 6.3.14 (#​4461)
  • Bump follow-redirects from 1.14.7 to 1.14.8 (#​4473)

v0.25.0

Compare Source

Breaking changes:
  • Fixing maxBodyLength enforcement (#​3786)
  • Don't rely on strict mode behaviour for arguments (#​3470)
  • Adding error handling when missing url (#​3791)
  • Update isAbsoluteURL.js removing escaping of non-special characters (#​3809)
  • Use native Array.isArray() in utils.js (#​3836)
  • Adding error handling inside stream end callback (#​3967)
Fixes and Functionality:
  • Added aborted even handler (#​3916)
  • Header types expanded allowing boolean and number types (#​4144)
  • Fix cancel signature allowing cancel message to be undefined (#​3153)
  • Updated type checks to be formulated better (#​3342)
  • Avoid unnecessary buffer allocations (#​3321)
  • Adding a socket handler to keep TCP connection live when processing long living requests (#​3422)
  • Added toFormData helper function (#​3757)
  • Adding responseEncoding prop type in AxiosRequestConfig (#​3918)
Internal and Tests:
  • Adding axios-test-instance to ecosystem (#​3786)
  • Optimize the logic of isAxiosError (#​3546)
  • Add tests and documentation to display how multiple inceptors work (#​3564)
  • Updating follow-redirects to version 1.14.7 (#​4379)
Documentation:
  • Fixing changelog to show corrext pull request (#​4219)
  • Update upgrade guide for https proxy setting (#​3604)

Huge thanks to everyone who contributed to this release via code (authors listed below) or via reviews and triaging on GitHub:

v0.24.0

Compare Source

Breaking changes:
  • Revert: change type of AxiosResponse to any, please read lengthy discussion here: (#​4141) pull request: (#​4186)

Huge thanks to everyone who contributed to this release via code (authors listed below) or via reviews and triaging on GitHub:

v0.23.0

Compare Source

Breaking changes:
  • Distinguish request and response data types (#​4116)
  • Change never type to unknown (#​4142)
  • Fixed TransitionalOptions typings (#​4147)
Fixes and Functionality:
  • Adding globalObject: 'this' to webpack config (#​3176)
  • Adding insecureHTTPParser type to AxiosRequestConfig (#​4066)
  • Fix missing semicolon in typings (#​4115)
  • Fix response headers types (#​4136)
Internal and Tests:
  • Improve timeout error when timeout is browser default (#​3209)
  • Fix node version on CI (#​4069)
  • Added testing to TypeScript portion of project (#​4140)
Documentation:
  • Rename Angular to AngularJS (#​4114)

Huge thanks to everyone who contributed to this release via code (authors listed below) or via reviews and triaging on GitHub:

v0.22.0

Compare Source

Fixes and Functionality:
  • Caseless header comparing in HTTP adapter (#​2880)
  • Avoid package.json import fixing issues and warnings related to this (#​4041), (#​4065)
  • Fixed cancelToken leakage and added AbortController support (#​3305)
  • Updating CI to run on release branches
  • Bump follow redirects version
  • Fixed default transitional config for custom Axios instance; (#​4052)

Huge thanks to everyone who contributed to this release via code (authors listed below) or via reviews and triaging on GitHub:

v0.21.4

Compare Source

Fixes and Functionality:
  • Fixing JSON transform when data is stringified. Providing backward compatibility and complying to the JSON RFC standard (#​4020)

Huge thanks to everyone who contributed to this release via code (authors listed below) or via reviews and triaging on GitHub:

v0.21.3

Compare Source

Fixes and Functionality:
  • Fixing response interceptor not being called when request interceptor is attached (#​4013)

Huge thanks to everyone who contributed to this release via code (authors listed below) or via reviews and triaging on GitHub:

v0.21.2

Compare Source

Fixes and Functionality:
  • Updating axios requests to be delayed by pre-emptive promise creation (#​2702)
  • Adding "synchronous" and "runWhen" options to interceptors api (#​2702)
  • Updating of transformResponse (#​3377)
  • Adding ability to omit User-Agent header (#​3703)
  • Adding multiple JSON improvements (#​3688, #​3763)
  • Fixing quadratic runtime and extra memory usage when setting a maxContentLength (#​3738)
  • Adding parseInt to config.timeout (#​3781)
  • Adding custom return type support to interceptor (#​3783)
  • Adding security fix for ReDoS vulnerability (#​3980)
Internal and Tests:
  • Updating build dev dependancies (#​3401)
  • Fixing builds running on Travis CI (#​3538)
  • Updating follow rediect version (#​3694, #​3771)
  • Updating karma sauce launcher to fix failing sauce tests (#​3712, #​3717)
  • Updating content-type header for application/json to not contain charset field, according do RFC 8259 (#​2154)
  • Fixing tests by bumping karma-sauce-launcher version (#​3813)
  • Changing testing process from Travis CI to GitHub Actions (#​3938)
Documentation:
  • Updating documentation around the use of AUTH_TOKEN with multiple domain endpoints (#​3539)
  • Remove duplication of item in changelog (#​3523)
  • Fixing gramatical errors (#​2642)
  • Fixing spelling error (#​3567)
  • Moving gitpod metion (#​2637)
  • Adding new axios documentation website link (#​3681, #​3707)
  • Updating documentation around dispatching requests (#​3772)
  • Adding documentation for the type guard isAxiosError (#​3767)
  • Adding explanation of cancel token (#​3803)
  • Updating CI status badge (#​3953)
  • Fixing errors with JSON documentation (#​3936)
  • Fixing README typo under Request Config (#​3825)
  • Adding axios-multi-api to the ecosystem file (#​3817)
  • Adding SECURITY.md to properly disclose security vulnerabilities (#​3981)

Huge thanks to everyone who contributed to this release via code (authors listed below) or via reviews and triaging on GitHub:

v0.21.1

Compare Source

Fixes and Functionality:
  • Hotfix: Prevent SSRF (#​3410)
  • Protocol not parsed when setting proxy config from env vars (#​3070)
  • Updating axios in types to be lower case (#​2797)
  • Adding a type guard for AxiosError (#​2949)
Internal and Tests:
  • Remove the skipping of the socket http test (#​3364)
  • Use different socket for Win32 test (#​3375)

Huge thanks to everyone who contributed to this release via code (authors listed below) or via reviews and triaging on GitHub:


Configuration

📅 Schedule: Branch creation - "" in timezone Europe/Paris, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@sonarcloud
Copy link

sonarcloud bot commented Jun 27, 2022

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
0.0% 0.0% Duplication

@github-actions github-actions bot requested a deployment to cdtn-api-renovate-npm-axios-vulnerability-64xodz June 27, 2022 05:27 In progress
@renovate renovate bot changed the title chore(deps): update dependency axios to v0.21.2 [SECURITY] chore(deps): update dependency axios to v0.21.2 [security] Jun 28, 2022
@renovate renovate bot force-pushed the renovate/npm-axios-vulnerability branch from 02cc33e to fc8563d Compare July 28, 2022 15:52
@github-actions github-actions bot requested a deployment to cdtn-api-renovate-npm-axios-vulnerability-64xodz July 28, 2022 15:55 In progress
@renovate renovate bot force-pushed the renovate/npm-axios-vulnerability branch from fc8563d to 80b0fa1 Compare July 28, 2022 15:55
@sonarcloud
Copy link

sonarcloud bot commented Jul 28, 2022

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
0.0% 0.0% Duplication

@github-actions github-actions bot requested a deployment to cdtn-api-renovate-npm-axios-vulnerability-64xodz July 28, 2022 15:58 In progress
@renovate renovate bot force-pushed the renovate/npm-axios-vulnerability branch from 80b0fa1 to 7393a03 Compare September 13, 2022 09:16
@github-actions github-actions bot requested a deployment to cdtn-api-renovate-npm-axios-vulnerability-64xodz September 13, 2022 09:22 In progress
@renovate renovate bot force-pushed the renovate/npm-axios-vulnerability branch from 7393a03 to f01d5f9 Compare September 13, 2022 09:46
@github-actions github-actions bot requested a deployment to cdtn-api-renovate-npm-axios-vulnerability-64xodz September 13, 2022 09:48 In progress
@renovate renovate bot force-pushed the renovate/npm-axios-vulnerability branch from f01d5f9 to 2fd14ef Compare September 13, 2022 15:48
@sonarcloud
Copy link

sonarcloud bot commented Sep 13, 2022

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
0.0% 0.0% Duplication

@github-actions github-actions bot requested a deployment to cdtn-api-renovate-npm-axios-vulnerability-64xodz September 13, 2022 15:51 In progress
@renovate renovate bot force-pushed the renovate/npm-axios-vulnerability branch from 2fd14ef to 5ebeb20 Compare October 20, 2022 06:56
@github-actions github-actions bot requested a deployment to cdtn-api-renovate-npm-axios-vulnerability-64xodz October 20, 2022 06:58 In progress
@renovate renovate bot force-pushed the renovate/npm-axios-vulnerability branch from 5ebeb20 to b74f6fc Compare October 20, 2022 06:59
@github-actions github-actions bot requested a deployment to cdtn-api-renovate-npm-axios-vulnerability-64xodz October 20, 2022 07:02 In progress
@renovate renovate bot force-pushed the renovate/npm-axios-vulnerability branch from b74f6fc to 3264a69 Compare October 20, 2022 07:02
@sonarcloud
Copy link

sonarcloud bot commented Oct 20, 2022

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
0.0% 0.0% Duplication

@github-actions github-actions bot requested a deployment to cdtn-api-renovate-npm-axios-vulnerability-64xodz October 20, 2022 07:06 In progress
@renovate renovate bot force-pushed the renovate/npm-axios-vulnerability branch from 3264a69 to 749b83a Compare January 31, 2023 19:31
@renovate renovate bot changed the title chore(deps): update dependency axios to v0.21.2 [security] chore(deps): update dependency axios to v0.21.2 [security] - autoclosed Feb 18, 2023
@renovate renovate bot closed this Feb 18, 2023
@renovate renovate bot deleted the renovate/npm-axios-vulnerability branch February 18, 2023 04:37
@renovate renovate bot changed the title chore(deps): update dependency axios to v0.21.2 [security] - autoclosed chore(deps): update dependency axios to v0.21.2 [security] Feb 18, 2023
@renovate renovate bot reopened this Feb 18, 2023
@renovate renovate bot force-pushed the renovate/npm-axios-vulnerability branch from b0e983c to fd4ad4a Compare March 1, 2023 09:20
@sonarcloud
Copy link

sonarcloud bot commented Mar 1, 2023

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
0.0% 0.0% Duplication

@renovate renovate bot force-pushed the renovate/npm-axios-vulnerability branch from fd4ad4a to e5313fc Compare May 3, 2023 14:30
@renovate renovate bot force-pushed the renovate/npm-axios-vulnerability branch from e5313fc to bcb2947 Compare May 3, 2023 19:42
@renovate renovate bot force-pushed the renovate/npm-axios-vulnerability branch from bcb2947 to 0c8daad Compare May 4, 2023 08:32
@sonarcloud
Copy link

sonarcloud bot commented May 4, 2023

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
0.0% 0.0% Duplication

@renovate renovate bot force-pushed the renovate/npm-axios-vulnerability branch from 0c8daad to adf23d8 Compare June 7, 2023 13:15
@socket-security
Copy link

socket-security bot commented Jun 7, 2023

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/[email protected] network Transitive: environment, filesystem +8 1.24 MB jasonsaayman

🚮 Removed packages: npm/[email protected]

View full report↗︎

@renovate renovate bot force-pushed the renovate/npm-axios-vulnerability branch from adf23d8 to 7ecc6ee Compare July 4, 2023 07:49
@renovate renovate bot force-pushed the renovate/npm-axios-vulnerability branch from 7ecc6ee to 1164c94 Compare July 4, 2023 07:52
@sonarcloud
Copy link

sonarcloud bot commented Jul 4, 2023

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
0.0% 0.0% Duplication

@renovate renovate bot force-pushed the renovate/npm-axios-vulnerability branch from 1164c94 to e911d0c Compare November 10, 2023 13:44
@renovate renovate bot changed the title chore(deps): update dependency axios to v0.21.2 [security] chore(deps): update dependency axios to v1 [security] Nov 10, 2023
Copy link

sonarcloud bot commented Nov 10, 2023

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
0.0% 0.0% Duplication

@renovate renovate bot force-pushed the renovate/npm-axios-vulnerability branch from e911d0c to d6b4c2a Compare February 20, 2024 21:45
@renovate renovate bot changed the title chore(deps): update dependency axios to v1 [security] chore(deps): update dependency axios to v0.21.2 [security] Feb 20, 2024
@renovate renovate bot changed the title chore(deps): update dependency axios to v0.21.2 [security] chore(deps): update dependency axios to v0.28.0 [security] Feb 21, 2024
@renovate renovate bot force-pushed the renovate/npm-axios-vulnerability branch from d6b4c2a to c733314 Compare February 21, 2024 07:52
Copy link

sonarcloud bot commented Feb 21, 2024

Quality Gate Passed Quality Gate passed

Issues
0 New issues

Measures
0 Security Hotspots
No data about Coverage
0.0% Duplication on New Code

See analysis details on SonarCloud

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants