-
Notifications
You must be signed in to change notification settings - Fork 19
Open
Description
This library depends on a very old version of axios that is vulnerable, see npm audit
output:
# npm audit report
axios 0.8.1 - 1.5.1
Severity: moderate
Axios Cross-Site Request Forgery Vulnerability - https://github.com/advisories/GHSA-wf5p-g6vw-rhxx
No fix available
node_modules/axios
react-axios *
Depends on vulnerable versions of axios
node_modules/react-axios
2 moderate severity vulnerabilities
Some issues need review, and may require choosing
a different dependency.
Can we bump the version and tag the release please?
Thank you!
R
xaviercasahugasequra
Metadata
Metadata
Assignees
Labels
No labels