Repository navigation
Bump axios from 1.16.0 to 1.20.0 - #323
Open
dependabot[bot] wants to merge 1 commit into
Open
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [axios](https://github.com/axios/axios) from 1.16.0 to 1.20.0. - [Release notes](https://github.com/axios/axios/releases) - [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md) - [Commits](axios/axios@v1.16.0...v1.20.0) --- updated-dependencies: - dependency-name: axios dependency-version: 1.20.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
dhensby
approved these changes
Oct 8, 2026
dhensby
left a comment
Collaborator
There was a problem hiding this comment.
Dependabot Review: axios 1.20.0
Package Changes
| Package | Change | Bump | Dependency type |
|---|---|---|---|
axios |
1.16.0 → 1.20.0 | minor | dev (transitive: lerna → nx 16.9.1) |
form-data |
4.0.5 → 4.0.6 | patch | dev (transitive: axios) |
hasown |
new entry 2.0.4 (hasown@^2.0.2 stays at 2.0.2) |
– | dev (transitive: form-data) |
@types/node |
new entry >=22.0.0 → 26.6.4 (@types/node@* stays at 20.8.2) |
– | dev (devDependencies of 7 packages) |
undici-types |
new entry 8.9.0 | – | dev (transitive: @types/node 26.6.4) |
Supply-Chain Verification ✅
Every package version that is new in yarn.lock (compared with merge-base 2bc7eef):
| Package | Version | npm publish (UTC) | Publisher | Evidence | Result |
|---|---|---|---|---|---|
axios |
1.20.0 | 2026-08-26 08:20:14Z | GitHub Actions (OIDC), same as 1.16.0 | SLSA provenance verified: axios/axios@84a9f3b9a4 (refs/tags/v1.20.0, .github/workflows/publish.yml, run 32734096423). The tag commit is signed. Release v1.20.0 by jasonsaayman at 2026-08-24 13:40:40Z, immutable. The timing note below explains the later npm time. |
✅ |
form-data |
4.0.6 | 2026-06-12 17:37:53Z | ljharb, same as 4.0.5 |
No provenance. Tag v4.0.6 is the gitHead, a signed commit at 17:32:07Z. npm publish 6 min later. No GitHub release. 7 tarball files are identical to the source at the tag. README.md differs only in its badge URLs, which the package's own prepack script (update-readme) writes. |
✅ |
hasown |
2.0.4 | 2026-05-28 18:11:39Z | ljharb, same as 2.0.2 |
No provenance. Tag v2.0.4 is the gitHead, a signed commit at 18:11:11Z. npm publish 28 s later. All 10 tarball files are identical to the source at the tag. |
✅ |
@types/node |
26.6.4 | 2026-10-01 22:39:22Z | types (DefinitelyTyped), same as 20.8.2 |
No provenance. The tarball holds only 89 .d.ts files, LICENSE, README.md and package.json, and has no scripts. DefinitelyTyped master has types/node at 26.6.9999 with undici-types ~8.9.0, which agrees with this release. |
✅ |
undici-types |
8.9.0 | 2026-07-24 12:32:56Z | GitHub Actions (OIDC) | SLSA provenance verified: nodejs/undici@21a8e1ed18 (refs/heads/main, .github/workflows/release.yml) |
✅ |
- The
resolvedURL (SHA-1 fragment) and theintegrityhash of each newyarn.lockentry match the registry metadata. axiosnow depends onhttps-proxy-agent ^5.0.1. axios added this dependency in 1.16.1, to stop HTTPS data going to a proxy in cleartext. The range resolves to the existinghttps-proxy-agent5.0.1 entry.mime-types ^2.1.35also resolves to the existing 2.1.35 entry. Thus no new code comes in for these two packages.axiostiming: the tag push startspublish.yml, which runsnpm stage publish --provenancein thenpm-publishenvironment. The publish job ran 13:41:04–13:41:30Z on 2026-08-24, and the Sigstore log entry is at 13:41:27Z. A staged version becomes public only after approval, so the npm time is 2 days later. 1.17.0, 1.18.0, 1.18.1 and 1.19.0 show the same gap.- No new entry has an install script (
preinstall,installorpostinstall).axioskeeps thepreparescript (husky) that 1.16.0 also has. Yarn does not runpreparefor registry packages. - The diff changes only
yarn.lock. The only commit is bydependabot[bot].
CI Status ⚠️
windows-testpasses on head5c03222(job).lerna run testruns all 7 projects, and all 145 tests pass.do-de-stufffails (job). Lint passes for all 8 projects. All 63 tests of@signpdf/utilspass, but its coverage is below the 100% global Jest threshold: statements 98.85%, branches 96.73%, lines 98.79%. Lines 23 and 32 ofextractSignature.jsare not covered. Nx then stops the tests of the other 6 projects, and the Coveralls steps fail becauselcov.infodoes not exist.- This failure is pre-existing. The
develophead2bc7eeffails the same job with the same coverage numbers (run 37029479197). The previousdevelopcommit,ed3a144, passed (run 28851054123).2bc7eefchanges onlyextractSignature.jsand its test. This PR changes onlyyarn.lock. - Coveralls and Snyk pass.
Breaking Changes / Impact
- Only
nx16.9.1 usesaxios, andlerna7 usesnxto run the monorepo tasks. No@signpdf/*package depends onaxios, and consumers do not use this repository'syarn.lock. - The
axios1.17.0–1.19.0 release notes list no breaking changes. 1.20.0 adds the status namesContentTooLarge(413) andUnprocessableContent(422), and keepsPayloadTooLargeandUnprocessableEntityas deprecated aliases. It also hardens option handling against prototype pollution. form-data4.0.6 andhasown2.0.4 are patch releases.- The new
@types/nodeentry makesyarn.lockagree with thedevDependenciesrange>=22.0.0, which 7 packages have used sinceed3a144. Before this PR,yarn.lockstill had only the old>=12.0.0range. The change adds type declarations only.
Approved. All five versions are dev tooling or type declarations. axios and undici-types have verified SLSA provenance. form-data and hasown match the source at their signed tags. The diff changes only yarn.lock. The only CI failure is the coverage failure that develop already has, and all 145 tests pass in windows-test.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps axios from 1.16.0 to 1.20.0.
Release notes
Sourced from axios's releases.
... (truncated)
Changelog
Sourced from axios's changelog.
... (truncated)
Commits
84a9f3bchore(release): prepare release 1.20.0 (#11152)e6824eefix: core methodList, HTTP adapter errors, and add tests (#11096)d8a919ffix(xhr): flush final progress during the live loadend dispatch (#11121)2d2a21afix(interceptors): tolerate nullish handlers in syncHandlerEntries (#11118)d19040bfix: harden runtime option handling (#11141)e0a02ddchore(deps): bump zizmorcore/zizmor-action from 0.6.1 to 0.6.2 in the github-...d10cb3achore(deps-dev): bump the development_dependencies group with 4 updates (#11143)2c94646chore(deps): bump js-yaml and mocha in /tests/smoke/cjs (#11133)76c12bcchore(deps-dev): bump js-yaml from 4.3.0 to 4.3.1 (#11140)ba98559docs: add ScrapingBee sponsor (#11137)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.