Skip to content

Bump axios from 1.16.0 to 1.20.0 - #323

Open
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/axios-1.20.0
Open

dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/axios-1.20.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Contributor

Bumps axios from 1.16.0 to 1.20.0.

Release notes

Sourced from axios's releases.

v1.20.0 — August 19, 2026

This release hardens runtime option handling, adds RFC 9110 status-code aliases, fixes Node.js and XHR reliability issues, and refreshes project tooling and documentation.

⚠️ Breaking Changes & Deprecations

  • HTTP Status Naming: Added ContentTooLarge (413) and UnprocessableContent (422), while retaining PayloadTooLarge and UnprocessableEntity as backward-compatible deprecated aliases. (#11082)

🔒 Security Fixes

  • Runtime Option Handling: Hardened behavioral configuration reads against shared and foreign prototype pollution and normalized unsafe interceptor replacement objects. This also clarifies Fetch redirect and custom implementation behavior, HTTP/2 DNS and proxy handling, CIDR-based NO_PROXY matching, and malformed data URI rejection; see the PR for documented compatibility effects. (#11141)

🐛 Bug Fixes

  • Interceptor Lifecycle: Prevented unbounded handler-array growth by trimming trailing ejected interceptors without changing iteration semantics, and kept interceptor operations safe when the public handlers field is nullish. (#11087, #11118)
  • Request Error Preservation: Prevented custom Error.prepareStackTrace implementations that return non-string values from replacing the original request failure with an unrelated TypeError. (#11109)
  • XHR Reliability: Navigation-canceled requests now reject with ECONNABORTED instead of resolving with status 0, while successful downloads flush their final progress callback during the live loadend dispatch. (#11094, #11121)
  • Node.js Socket Memory: Removed request-context retention from per-socket error listeners, preventing completed response data from being pinned for the lifetime of pooled keep-alive sockets. (#11091)
  • Core Methods and HTTP Errors: Prevented structural method-header buckets from leaking into outgoing headers, standardized invalid DNS lookup and httpVersion failures as AxiosError.ERR_BAD_OPTION_VALUE, and corrected the timeoutErrorMessage merge strategy. (#11096)

🔧 Maintenance & Chores

  • Dependencies: Updated fast-uri, postcss, js-yaml, mocha, development-tooling groups, and GitHub Actions dependencies. (#11092, #11098, #11099, #11106, #11107, #11122, #11123, #11126, #11127, #11133, #11140, #11143, #11144)
  • Documentation: Applied the v1.19.0 documentation updates, added the missing fs import to the README stream example, introduced localized global search, and repaired the interceptor test link. (#11101, #11113, #11097, #11119)
  • Sponsorship: Updated sponsorship links and data and added ScrapingBee as a sponsor. (#11124, #11136, #11137)
  • CI and Release: Switched ESM smoke tests to locked dependencies and synchronized package and runtime version metadata for v1.20.0. (#11128, #11152)

🌟 New Contributors

We are thrilled to welcome our new contributors. Thank you for helping improve axios:

Full Changelog (axios/axios@v1.19.0...v1.20.0)

v1.19.0 - July 22, 2026

This release raises the form-data security floor, adds configuration and type-system capabilities, and fixes NO_PROXY matching, interceptor errors, progress reporting, and serialization edge cases.

🔒 Security Fixes

  • Multipart Form Data: Raised the form-data dependency floor to ^4.0.6, preventing fresh installations from resolving versions affected by the CRLF injection vulnerability GHSA-hmw2-7cc7-3qxx (GHSA-hmw2-7cc7-3qxx). (#11028)

... (truncated)

Changelog

Sourced from axios's changelog.

Changelog

v1.19.0 — July 22, 2026

This release raises the form-data security floor, adds configuration and type-system capabilities, and fixes NO_PROXY matching, interceptor errors, progress reporting, and serialization edge cases.

🔒 Security Fixes

  • Multipart Form Data: Raised the form-data dependency floor to ^4.0.6, preventing fresh installations from resolving versions affected by the CRLF injection vulnerability GHSA-hmw2-7cc7-3qxx (GHSA-hmw2-7cc7-3qxx). (#11028)

🚀 New Features

  • Configuration Extensibility: Preserved own-enumerable symbol-keyed fields through mergeConfig and added a generic params type across public TypeScript declarations, responses, errors, adapters, and serializers. (#11043, #11081)
  • Header Parameter Parsing: Added the opt-in AxiosHeaders.parseParameters() parser for quote-aware, RFC-style HTTP parameter parsing while preserving legacy parsing behavior. (#11051)
  • HTTP Status Codes: Added the missing Cloudflare 520 WebServerReturnsAnUnknownError status and matching ESM/CJS declarations. (#11067)

🐛 Bug Fixes

  • Form Data Conversion: Limited formDataToJSON path splitting to dot and bracket notation, preserving literal punctuation in keys, and removed browser-facing Buffer.from usage from toFormData to avoid unnecessary polyfills. (#11006, #11018)

  • Proxy Bypass: Canonicalized IPv4 shorthand, octal, and hexadecimal forms during NO_PROXY matching and honored * entries within comma- or space-separated bypass lists. (#11029, #11053)

  • Cancellation: Propagated already-aborted input signals immediately when composing abort signals. (#11035)

  • Header Handling: Preserved empty first values for duplicate singleton headers and made AxiosHeaders#getSetCookie() consistently return arrays for present values. (#11036, #11037)

  • URL Handling: Included normalized, safely redacted offending URLs in malformed-protocol errors and removed repeated trailing slashes when combining base URLs. (#11008, #11038)

  • Progress Events: Clamped malformed negative progress values to zero and ensured final Node.js download progress events are delivered before streamed responses close. (#11039, #11040)

  • Error and JSON Serialization: Serialized Set values as arrays in JSON-compatible snapshots and synthesized useful AxiosError messages from otherwise-empty AggregateError instances. (#11044, #11059)

  • Content-Length Enforcement: Corrected base64 data: URL size estimation so maxContentLength is enforced consistently by the HTTP and Fetch adapters. (#11061)

  • Synchronous Interceptors: Prevented requests from being dispatched after synchronous request interceptors fail unless their paired rejection handler resolves successfully. (#11071)

🔧 Maintenance & Chores

  • Dependencies: Updated development and test tooling, the docs fixture's Axios version, and GitHub Actions integrations including Checkout, Setup Node, Setup Deno, and Zizmor. (#11031, #11055, #11056, #11058, #11079, #11080, #11088, #11089, #11090)
  • Build Outputs: Limited sourcemap generation to published minified bundles, removing broken map references from non-minified builds. (#11054)
  • Form Data Internals: Centralized FormData header handling and made the Node.js adapter tolerate getHeaders() returning undefined under the content-only policy. (#11062)
  • Developer Experience: Ignored common local AI-tooling directories and fixed a constant-reassignment crash when the development sandbox serves its root path. (#11032, #11073)
  • Documentation: Updated sponsor information, clarified that baseURL is not a path-security boundary, scoped provenance claims to attested releases, and corrected the configuration-defaults documentation. (#11041, #11068, #11076, #11078)
  • Publishing: Simplified v1 publishing to use the npm version bundled with Node.js 26 and updated package metadata for the 1.19.0 release. (#11083, #11095)

🌟 New Contributors

We are thrilled to welcome our new contributors. Thank you for helping improve Axios:

... (truncated)

Commits
  • 84a9f3b chore(release): prepare release 1.20.0 (#11152)
  • e6824ee fix: core methodList, HTTP adapter errors, and add tests (#11096)
  • d8a919f fix(xhr): flush final progress during the live loadend dispatch (#11121)
  • 2d2a21a fix(interceptors): tolerate nullish handlers in syncHandlerEntries (#11118)
  • d19040b fix: harden runtime option handling (#11141)
  • e0a02dd chore(deps): bump zizmorcore/zizmor-action from 0.6.1 to 0.6.2 in the github-...
  • d10cb3a chore(deps-dev): bump the development_dependencies group with 4 updates (#11143)
  • 2c94646 chore(deps): bump js-yaml and mocha in /tests/smoke/cjs (#11133)
  • 76c12bc chore(deps-dev): bump js-yaml from 4.3.0 to 4.3.1 (#11140)
  • ba98559 docs: add ScrapingBee sponsor (#11137)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [axios](https://github.com/axios/axios) from 1.16.0 to 1.20.0.
- [Release notes](https://github.com/axios/axios/releases)
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)
- [Commits](axios/axios@v1.16.0...v1.20.0)

---
updated-dependencies:
- dependency-name: axios
  dependency-version: 1.20.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies javascript Pull requests that update javascript code labels Oct 7, 2026
@coveralls

Copy link
Copy Markdown

Coverage Status

coverage: 99.184%. remained the same — dependabot/npm_and_yarn/axios-1.20.0 into develop

@dhensby dhensby left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dependabot Review: axios 1.20.0

Package Changes

Package Change Bump Dependency type
axios 1.16.0 → 1.20.0 minor dev (transitive: lerna → nx 16.9.1)
form-data 4.0.5 → 4.0.6 patch dev (transitive: axios)
hasown new entry 2.0.4 (hasown@^2.0.2 stays at 2.0.2) – dev (transitive: form-data)
@types/node new entry >=22.0.0 → 26.6.4 (@types/node@* stays at 20.8.2) – dev (devDependencies of 7 packages)
undici-types new entry 8.9.0 – dev (transitive: @types/node 26.6.4)

Supply-Chain Verification ✅

Every package version that is new in yarn.lock (compared with merge-base 2bc7eef):

Package Version npm publish (UTC) Publisher Evidence Result
axios 1.20.0 2026-08-26 08:20:14Z GitHub Actions (OIDC), same as 1.16.0 SLSA provenance verified: axios/axios@84a9f3b9a4 (refs/tags/v1.20.0, .github/workflows/publish.yml, run 32734096423). The tag commit is signed. Release v1.20.0 by jasonsaayman at 2026-08-24 13:40:40Z, immutable. The timing note below explains the later npm time. ✅
form-data 4.0.6 2026-06-12 17:37:53Z ljharb, same as 4.0.5 No provenance. Tag v4.0.6 is the gitHead, a signed commit at 17:32:07Z. npm publish 6 min later. No GitHub release. 7 tarball files are identical to the source at the tag. README.md differs only in its badge URLs, which the package's own prepack script (update-readme) writes. ✅
hasown 2.0.4 2026-05-28 18:11:39Z ljharb, same as 2.0.2 No provenance. Tag v2.0.4 is the gitHead, a signed commit at 18:11:11Z. npm publish 28 s later. All 10 tarball files are identical to the source at the tag. ✅
@types/node 26.6.4 2026-10-01 22:39:22Z types (DefinitelyTyped), same as 20.8.2 No provenance. The tarball holds only 89 .d.ts files, LICENSE, README.md and package.json, and has no scripts. DefinitelyTyped master has types/node at 26.6.9999 with undici-types ~8.9.0, which agrees with this release. ✅
undici-types 8.9.0 2026-07-24 12:32:56Z GitHub Actions (OIDC) SLSA provenance verified: nodejs/undici@21a8e1ed18 (refs/heads/main, .github/workflows/release.yml) ✅
  • The resolved URL (SHA-1 fragment) and the integrity hash of each new yarn.lock entry match the registry metadata.
  • axios now depends on https-proxy-agent ^5.0.1. axios added this dependency in 1.16.1, to stop HTTPS data going to a proxy in cleartext. The range resolves to the existing https-proxy-agent 5.0.1 entry. mime-types ^2.1.35 also resolves to the existing 2.1.35 entry. Thus no new code comes in for these two packages.
  • axios timing: the tag push starts publish.yml, which runs npm stage publish --provenance in the npm-publish environment. The publish job ran 13:41:04–13:41:30Z on 2026-08-24, and the Sigstore log entry is at 13:41:27Z. A staged version becomes public only after approval, so the npm time is 2 days later. 1.17.0, 1.18.0, 1.18.1 and 1.19.0 show the same gap.
  • No new entry has an install script (preinstall, install or postinstall). axios keeps the prepare script (husky) that 1.16.0 also has. Yarn does not run prepare for registry packages.
  • The diff changes only yarn.lock. The only commit is by dependabot[bot].

CI Status ⚠️

  • windows-test passes on head 5c03222 (job). lerna run test runs all 7 projects, and all 145 tests pass.
  • do-de-stuff fails (job). Lint passes for all 8 projects. All 63 tests of @signpdf/utils pass, but its coverage is below the 100% global Jest threshold: statements 98.85%, branches 96.73%, lines 98.79%. Lines 23 and 32 of extractSignature.js are not covered. Nx then stops the tests of the other 6 projects, and the Coveralls steps fail because lcov.info does not exist.
  • This failure is pre-existing. The develop head 2bc7eef fails the same job with the same coverage numbers (run 37029479197). The previous develop commit, ed3a144, passed (run 28851054123). 2bc7eef changes only extractSignature.js and its test. This PR changes only yarn.lock.
  • Coveralls and Snyk pass.

Breaking Changes / Impact

  • Only nx 16.9.1 uses axios, and lerna 7 uses nx to run the monorepo tasks. No @signpdf/* package depends on axios, and consumers do not use this repository's yarn.lock.
  • The axios 1.17.0–1.19.0 release notes list no breaking changes. 1.20.0 adds the status names ContentTooLarge (413) and UnprocessableContent (422), and keeps PayloadTooLarge and UnprocessableEntity as deprecated aliases. It also hardens option handling against prototype pollution.
  • form-data 4.0.6 and hasown 2.0.4 are patch releases.
  • The new @types/node entry makes yarn.lock agree with the devDependencies range >=22.0.0, which 7 packages have used since ed3a144. Before this PR, yarn.lock still had only the old >=12.0.0 range. The change adds type declarations only.

Approved. All five versions are dev tooling or type declarations. axios and undici-types have verified SLSA provenance. form-data and hasown match the source at their signed tags. The diff changes only yarn.lock. The only CI failure is the coverage failure that develop already has, and all 145 tests pass in windows-test.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants