Skip to content

Bump axios to ^1.6.7 #52

@razvanphp

Description

@razvanphp

This library depends on a very old version of axios that is vulnerable, see npm audit output:

# npm audit report

axios  0.8.1 - 1.5.1
Severity: moderate
Axios Cross-Site Request Forgery Vulnerability - https://github.com/advisories/GHSA-wf5p-g6vw-rhxx
No fix available
node_modules/axios
  react-axios  *
  Depends on vulnerable versions of axios
  node_modules/react-axios

2 moderate severity vulnerabilities

Some issues need review, and may require choosing
a different dependency.

Can we bump the version and tag the release please?

Thank you!
R

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions