Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Release security vulnerability fix for follow-redirects package #4395

Closed
CarlMungazi opened this issue Jan 17, 2022 · 3 comments
Closed

Release security vulnerability fix for follow-redirects package #4395

CarlMungazi opened this issue Jan 17, 2022 · 3 comments

Comments

@CarlMungazi
Copy link

Is your feature request related to a problem? Please describe.

A PR has been merged which fixes a vulnerability with the follow-redirects dependency. However, this fix has not been released.

Describe the solution you'd like

The fix to be released so devs do not have to point to the specific commit that fixed this issue when installing axios

Describe alternatives you've considered

N/A

Additional context

N/A

@bkayranci
Copy link

axios has floating version in the v0.24.0 (latest) version.
package.json

so, you can use folllowing command

yarn upgrade axios

or you can update manually your lock file(yarn.lock).

@CarlMungazi
Copy link
Author

@bkayranci thanks for the response. I know there are ways around it currently (like resolutions etc) but I just opened this issue so whenever the maintainers were ready it could be released with the follow-redirections package pointing at 1.14.7

@jasonsaayman
Copy link
Member

Released 🎉

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants