Skip to content

fix: bump axios 1.14.0 → 1.15.0 (Dependabot #4, #5) - #670

Merged
kevincodex1 merged 2 commits into
Twigpine:mainfrom
Vasanthdev2004:fix/axios-dependabot-1.15.0
Apr 14, 2026
Merged

kevincodex1 merged 2 commits into
Twigpine:mainfrom
Vasanthdev2004:fix/axios-dependabot-1.15.0

Conversation

@Vasanthdev2004

Copy link
Copy Markdown
Collaborator

Summary

Bump axios from 1.14.0 to 1.15.0 to resolve two critical Dependabot security alerts:

Alert Severity CVE Fix
#5 — Unrestricted Cloud Metadata Exfiltration via Header Injection Chain Critical GHSA-r6w3-5fpr-6h7c ≥ 1.15.0
#4 — NO_PROXY Hostname Normalization Bypass Leads to SSRF Critical GHSA-8hrq-hm5q-jqrc ≥ 1.15.0

Changes

  • package.json: "axios": "1.14.0" → "axios": "1.15.0"

Validation

  • axios@1.15.0 exists on npm
  • Lockfile update needed on install (bun.lock)
  • CI should pass — this is a patch-level dependency bump with no API changes

Already-fixed alerts (no action needed)

root added 2 commits April 13, 2026 15:03
Resolve two critical Dependabot alerts:
- Twigpine#5: Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
- Twigpine#4: NO_PROXY Hostname Normalization Bypass Leads to SSRF

Both require axios >= 1.15.0.
CI failed with 'lockfile had changes, but lockfile is frozen'.
Regenerated lockfile after axios bump.
@kevincodex1
kevincodex1 requested a review from gnanam1990 April 13, 2026 15:08
@kevincodex1
kevincodex1 merged commit a07e5ef into Twigpine:main Apr 14, 2026
1 check passed
C1ph3r404 pushed a commit to C1ph3r404/openclaude that referenced this pull request Apr 29, 2026
* fix: bump axios 1.14.0 → 1.15.0 (Dependabot #4, #5)

Resolve two critical Dependabot alerts:
- #5: Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
- #4: NO_PROXY Hostname Normalization Bypass Leads to SSRF

Both require axios >= 1.15.0.

* fix: update bun.lock for axios 1.15.0

CI failed with 'lockfile had changes, but lockfile is frozen'.
Regenerated lockfile after axios bump.

---------

Co-authored-by: root <root@vm7508.lumadock.com>
The-FOOL-00 pushed a commit to The-FOOL-00/openclaude that referenced this pull request May 24, 2026
…wigpine#670)

* fix: bump axios 1.14.0 → 1.15.0 (Dependabot Twigpine#4, Twigpine#5)

Resolve two critical Dependabot alerts:
- Twigpine#5: Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
- Twigpine#4: NO_PROXY Hostname Normalization Bypass Leads to SSRF

Both require axios >= 1.15.0.

* fix: update bun.lock for axios 1.15.0

CI failed with 'lockfile had changes, but lockfile is frozen'.
Regenerated lockfile after axios bump.

---------

Co-authored-by: root <root@vm7508.lumadock.com>
discopops pushed a commit to discopops/openclaude that referenced this pull request May 28, 2026
…wigpine#670)

* fix: bump axios 1.14.0 → 1.15.0 (Dependabot Twigpine#4, Twigpine#5)

Resolve two critical Dependabot alerts:
- Twigpine#5: Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
- Twigpine#4: NO_PROXY Hostname Normalization Bypass Leads to SSRF

Both require axios >= 1.15.0.

* fix: update bun.lock for axios 1.15.0

CI failed with 'lockfile had changes, but lockfile is frozen'.
Regenerated lockfile after axios bump.

---------

Co-authored-by: root <root@vm7508.lumadock.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants