Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Release] v0.28.0 #6211

Merged
merged 5 commits into from Feb 12, 2024
Merged

[Release] v0.28.0 #6211

merged 5 commits into from Feb 12, 2024

Conversation

DigitalBrainJS
Copy link
Collaborator

@DigitalBrainJS DigitalBrainJS commented Jan 30, 2024

Release notes:

Bug Fixes

Backports from v1.x:

Copy link

@bmuenzenmeyer bmuenzenmeyer left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

so happy to see this progressing!

Copy link

@10hendersonm 10hendersonm left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Any reason the dist/axios.js doesn't seem to be built with Webpack any more?

That's an assumption on my part - the __webpack_require__s are all gone and add/remove of 1,200 lines for a change of constrained scope like this seems offputting.

@DigitalBrainJS
Copy link
Collaborator Author

DigitalBrainJS commented Jan 31, 2024

Any reason the dist/axios.js doesn't seem to be built with Webpack any more?

Yes, that’s right, we switched to rollup almost 2 years ago (#4596), it seems that this and some other commits were originally merged into the 0.x branch and remained unpublished since the 1.x branch was created much later than the merge of these commits. As a result, we have a partial backport from the 1.x branch.

@venusgazer
Copy link

Hi @DigitalBrainJS ,

We appreciate your efforts in addressing the vulnerability in the dependent package. Integrating this fix into our project is a priority for us. However, we've encountered challenges during the upgrade process, particularly transitioning from version 0.27.2 to 1.6.7, leading to build failures.

Could you kindly provide an estimated timeline for when this PR will be merged and deployed? This information is crucial for us to plan our next steps effectively and ensure the timely resolution of the vulnerability.

Thank you once again for your attention to this matter 🙏.

@DigitalBrainJS
Copy link
Collaborator Author

@venusgazer Sorry for the delay. I think the release will be published this weekend, as it requires cooperation with other team members who are currently pretty overworked.

dist/esm/axios.js Fixed Show fixed Hide fixed
dist/esm/axios.js Fixed Show fixed Hide fixed
@DigitalBrainJS DigitalBrainJS merged commit 3b7635a into axios:v0.x Feb 12, 2024
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

4 participants