<#1134 [Snyk] Security upgrade axios from 0.27.2 t...
# pact-js-development
g
#1134 [Snyk] Security upgrade axios from 0.27.2 to 1.6.0 Pull request opened by mefellows This PR was automatically created by Snyk using the credentials of a real user. Snyk has created this PR to fix one or more vulnerable packages in the
npm
dependencies of this project.
Changes included in this PR • Changes to the following files to upgrade the vulnerable dependencies to a fixed version: • package.json • package-lock.json Vulnerabilities that will be fixed With an upgrade: (*) Note that the real score may have changed since the PR was raised. Commit messages Package name: axios The new version differs by 250 commits. • f7adacd chore(release): v1.6.0 (#6031) • 9917e67 chore(ci): fix release-it arg; (#6032) • 96ee232 fix(CSRF): fixed CSRF vulnerability CVE-2023-45857 (#6028) • 7d45ab2 chore(tests): fixed tests to pass in node v19 and v20 with
keep-alive
enabled; (#6021) • 5aaff53 fix(dns): fixed lookup function decorator to work properly in node v20; (#6011) • a48a63a chore(docs): added AxiosHeaders docs; (#5932) • a1c8ad0 fix(types): fix AxiosHeaders types; (#5931) • 2ac731d chore(docs): update readme.md (#5889) • 88fb52b chore(release): v1.5.1 (#5920) • e410779 fix(adapters): improved adapters loading logic to have clear error messages; (#5919) • bc9af51 fix(formdata): fixed automatic addition of the
Content-Type
header for FormData in non-browser environments; (#5917) • 4c89f25 fix(headers): allow
content-encoding
header to handle case-insensitive values (#5890) (#5892) • ae00391 docs(paramsSerializer config within request config): update documentation for paramsSerializer • a989ccd Change isNaN to Number.isNaN • b5b7760 docs: fix CommonJS usage note • 9e62056 fix(types): removed duplicated code • 6365751 chore(release): v1.5.0 (#5838) • 1601f4a feat(export): export adapters without
unsafe
prefix (#5839) • dff74ae docs: linting documentation notes (#5791) • ca73eb8 feat: export getAdapter function (#5324) • 9a414bb fix(adapter): make adapter loading error more clear by using platform-specific adapters explicitly (#5837) • b3e327d fix(dns): fixed
cacheable-lookup
integration; (#5836) • 8fda276 fix(headers): fixed common Content-Type header merging; (#5832) • d8b4ca0 fix(headers): added support for setting header names that overlap with class methods; (#5831) See the full diff Check the changes in this PR to ensure they won't cause issues with your project. * * * Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs. For more information: https://camo.githubusercontent.com/9e5ba6553dd73f0a2212eccb57a07f2fcc1d50f07101507a770c5b442fbfa32e/68747470733a2f2f6170692e7365676d656e742e696f2f76312f706978656c2f747261636b3f646174613d65794a33636d6c305a55746c65534936496e4a79576d785a634564485932527954485a7362306c596430645563566734576b4652546e4e434f5545774969776959573576626e6c746233567a535751694f694a6d4e546c684e7a63794d4330324e5749794c54517a59325974596a45344e4331694e7a686c4d4745334e474e6c595745694c434a6c646d567564434936496c425349485a705a58646c5a434973496e42796233426c636e52705a584d694f6e736963484a4a5a434936496d59314f5745334e7a49774c545931596a49744e444e6a5a6931694d5467304c5749334f475577595463305932566859534a3966513d3d 🧐 View latest project report 🛠️ Adjust project settings 📚 Read more about Snyk's upgrade and patch logic * * * Learn how to fix vulnerabilities with free interactive lessons: 🦉 Cross-site Request Forgery (CSRF) pact-foundation/pact-js GitHub Actions: build-and-test (20.x, macos-latest) GitHub Actions: build-and-test (20.x, windows-latest) Cirrus CI: Task Summary Cirrus CI: Task Summary Cirrus CI: Task Summary Cirrus CI: Task Summary Cirrus CI: Task Summary Cirrus CI: Task Summary ✅ 17 other checks have passed 17/25 successful checks