Skip to content

chore(deps): bump axios to ^1.8.2 for GHSA-jr5f-v2jv-69x6#476

Open
rachit367 wants to merge 1 commit into
razorpay:masterfrom
rachit367:bump-axios-1.8.2
Open

chore(deps): bump axios to ^1.8.2 for GHSA-jr5f-v2jv-69x6#476
rachit367 wants to merge 1 commit into
razorpay:masterfrom
rachit367:bump-axios-1.8.2

Conversation

@rachit367
Copy link
Copy Markdown

Addresses #439.

package.json currently pins axios: ^1.6.8, and the resolved version in package-lock.json is 1.6.8. That version is affected by GHSA-jr5f-v2jv-69x6 (SSRF / credential leakage via absolute URL in requests). The fix landed in axios 1.8.2.

Bumps the constraint to ^1.8.2. Only package.json is changed — I didn't run npm install here, so the lockfile is not regenerated in this commit. Happy to push a lockfile update separately if you'd prefer it in this PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant