Skip to content

Commit

Permalink
fix(deps): update dependency axios to ^0.28.0 [security] (#866)
Browse files Browse the repository at this point in the history
[![Mend
Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com)

This PR contains the following updates:

| Package | Change | Age | Adoption | Passing | Confidence |
|---|---|---|---|---|---|
| [axios](https://axios-http.com)
([source](https://togithub.com/axios/axios)) | [`^0.27.0` ->
`^0.28.0`](https://renovatebot.com/diffs/npm/axios/0.27.2/0.28.0) |
[![age](https://developer.mend.io/api/mc/badges/age/npm/axios/0.28.0?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|
[![adoption](https://developer.mend.io/api/mc/badges/adoption/npm/axios/0.28.0?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|
[![passing](https://developer.mend.io/api/mc/badges/compatibility/npm/axios/0.27.2/0.28.0?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|
[![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/axios/0.27.2/0.28.0?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|

### GitHub Vulnerability Alerts

#### [CVE-2023-45857](https://nvd.nist.gov/vuln/detail/CVE-2023-45857)

An issue discovered in Axios 0.8.1 through 1.5.1 inadvertently reveals
the confidential XSRF-TOKEN stored in cookies by including it in the
HTTP header X-XSRF-TOKEN for every request made to any host allowing
attackers to view sensitive information.

---

### Release Notes

<details>
<summary>axios/axios (axios)</summary>

### [`v0.28.0`](https://togithub.com/axios/axios/releases/tag/v0.28.0)

[Compare
Source](https://togithub.com/axios/axios/compare/v0.27.2...v0.28.0)

#### Release notes:

##### Bug Fixes

- fix(security): fixed CVE-2023-45857 by backporting `withXSRFToken`
option to v0.x
([#&#8203;6091](https://togithub.com/axios/axios/issues/6091))

##### Backports from v1.x:

- Allow null indexes on formSerializer and paramsSerializer v0.x
([#&#8203;4961](https://togithub.com/axios/axios/issues/4961))
- Fixing content-type header repeated
[#&#8203;4745](https://togithub.com/axios/axios/issues/4745)
-   Fixed timeout error message for HTTP 4738
- Added `axios.formToJSON` method
([#&#8203;4735](https://togithub.com/axios/axios/issues/4735))
- URL params serializer
([#&#8203;4734](https://togithub.com/axios/axios/issues/4734))
- Fixed toFormData Blob issue on node>v17
[#&#8203;4728](https://togithub.com/axios/axios/issues/4728)
- Adding types for progress event callbacks
[#&#8203;4675](https://togithub.com/axios/axios/issues/4675)
- Fixed max body length defaults
[#&#8203;4731](https://togithub.com/axios/axios/issues/4731)
- Added data URL support for node.js
([#&#8203;4725](https://togithub.com/axios/axios/issues/4725))
- Added isCancel type assert
([#&#8203;4293](https://togithub.com/axios/axios/issues/4293))
- Added the ability for the `url-encoded-form` serializer to respect the
`formSerializer` config
([#&#8203;4721](https://togithub.com/axios/axios/issues/4721))
- Add `string[]` to `AxiosRequestHeaders` type
([#&#8203;4322](https://togithub.com/axios/axios/issues/4322))
- Allow type definition for axios instance methods
([#&#8203;4224](https://togithub.com/axios/axios/issues/4224))
- Fixed `AxiosError` stack capturing;
([#&#8203;4718](https://togithub.com/axios/axios/issues/4718))
- Fixed `AxiosError` status code type;
([#&#8203;4717](https://togithub.com/axios/axios/issues/4717))
- Adding Canceler parameters config and request
([#&#8203;4711](https://togithub.com/axios/axios/issues/4711))
- fix(types): allow to specify partial default headers for instance
creation ([#&#8203;4185](https://togithub.com/axios/axios/issues/4185))
- Added `blob` to the list of protocols supported by the browser
([#&#8203;4678](https://togithub.com/axios/axios/issues/4678))
- Fixing Z_BUF_ERROR when no content
([#&#8203;4701](https://togithub.com/axios/axios/issues/4701))
- Fixed race condition on immediate requests cancellation
([#&#8203;4261](https://togithub.com/axios/axios/issues/4261))
- Added a clear() function to the request and response interceptors
object so a user can ensure that all interceptors have been removed from
an Axios instance
[axios/axios#4248
- Added generic AxiosAbortSignal TS interface to avoid importing
AbortController polyfill
([#&#8203;4229](https://togithub.com/axios/axios/issues/4229))
- Fix TS definition for AxiosRequestTransformer
([#&#8203;4201](https://togithub.com/axios/axios/issues/4201))
- Use type alias instead of interface for AxiosPromise
([#&#8203;4505](https://togithub.com/axios/axios/issues/4505))
- Include request and config when creating a CanceledError instance
([#&#8203;4659](https://togithub.com/axios/axios/issues/4659))
- Added generic TS types for the exposed toFormData helper
([#&#8203;4668](https://togithub.com/axios/axios/issues/4668))
- Optimized the code that checks cancellation
([#&#8203;4587](https://togithub.com/axios/axios/issues/4587))
- Replaced webpack with rollup
([#&#8203;4596](https://togithub.com/axios/axios/issues/4596))
- Added stack trace to AxiosError
([#&#8203;4624](https://togithub.com/axios/axios/issues/4624))
- Updated AxiosError.config to be optional in the type definition
([#&#8203;4665](https://togithub.com/axios/axios/issues/4665))
- Removed incorrect argument for NetworkError constructor
([#&#8203;4656](https://togithub.com/axios/axios/issues/4656))

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Mend
Renovate](https://www.mend.io/free-developer-tools/renovate/). View
repository job log
[here](https://developer.mend.io/github/erezrokah/aws-testing-library).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy40Ni4wIiwidXBkYXRlZEluVmVyIjoiMzcuMjAwLjAiLCJ0YXJnZXRCcmFuY2giOiJtYWluIn0=-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
  • Loading branch information
renovate[bot] committed Feb 22, 2024
1 parent 6baaacd commit 19ccda4
Show file tree
Hide file tree
Showing 2 changed files with 53 additions and 43 deletions.
94 changes: 52 additions & 42 deletions package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion package.json
Expand Up @@ -64,7 +64,7 @@
},
"dependencies": {
"aws-sdk": "^2.678.0",
"axios": "^0.27.0",
"axios": "^0.28.0",
"filter-obj": "^3.0.0",
"jest-diff": "^29.0.0",
"uuid": "^9.0.0"
Expand Down

0 comments on commit 19ccda4

Please sign in to comment.