Skip to content

fix: axios and qs package bump#106

Open
ajasnosz wants to merge 1 commit into
developfrom
fix/bump-packages
Open

fix: axios and qs package bump#106
ajasnosz wants to merge 1 commit into
developfrom
fix/bump-packages

Conversation

@ajasnosz

Copy link
Copy Markdown
Contributor
  • Bump axios from ^1.6.8 to ^1.16.0 (resolves HIGH CVEs: prototype pollution, proxy-auth credential leak, ReDoS, SSRF)
  • Bump qs from 6.15.1 to 6.15.2 (resolves MODERATE CVE-2026-8723: DoS via stringify)
  • Add yarn resolutions to force patched versions of transitive deps pulled through lerna>nx: axios, undici, tmp, form-data, brace-expansion, yaml, tar, js-yaml

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant