Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security issue with axios #168

Closed
jamesots opened this issue Feb 3, 2021 · 4 comments · Fixed by #169
Closed

Security issue with axios #168

jamesots opened this issue Feb 3, 2021 · 4 comments · Fixed by #169
Assignees
Labels
source-plugin Marking issues related to @kentico/gatsby-source-kontent.

Comments

@jamesots
Copy link

jamesots commented Feb 3, 2021

The gatsby-source-kontent package has a dependency on axios v 0.19.2, which has a security advisory open against it: https://npmjs.com/advisories/1594. It would be great if the dependency could be updated to at least v0.21.1, so that this security issue is fixed.

@Simply007
Copy link
Contributor

Thx @jamesots - I will update the packages definition.

Are you in hurry with the release? I was thinking to release it together with the fix to #58, but I can split them.

@jamesots
Copy link
Author

jamesots commented Feb 5, 2021

Not in a desperate hurry, as we're currently using npm-force-resolutions to update the dependency, but it would be nice not to have to hack it. What's the timeframe for releasing the fix to 58?

@Simply007
Copy link
Contributor

My guess is around a week.

@Simply007 Simply007 self-assigned this Feb 8, 2021
@Simply007 Simply007 added the source-plugin Marking issues related to @kentico/gatsby-source-kontent. label Feb 8, 2021
This was referenced Feb 10, 2021
@Simply007
Copy link
Contributor

version 6.3.1 should contain the fix @jamesots. Unfortunately, the priorities have changed, so language codenames are still required in the gatsby config.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
source-plugin Marking issues related to @kentico/gatsby-source-kontent.
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants