Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): bump axios to 1.7.4 to address CVE #2201

Merged
merged 1 commit into from
Aug 14, 2024

Conversation

helzahalim
Copy link
Contributor

@helzahalim helzahalim commented Aug 14, 2024

Bump to axios 1.7.4 to for sec vuln fix.

https://github.com/axios/axios/releases/tag/v1.7.4

Summary

Describe the goal of this PR. Mention any related Issue numbers.

Requirements (place an x in each [ ])

Copy link

Thanks for the contribution! Before we can merge this, we need @helzahalim to sign the Salesforce Inc. Contributor License Agreement.

@zimeg zimeg added security semver:patch dependencies Pull requests that update a dependency file labels Aug 14, 2024
@zimeg
Copy link
Member

zimeg commented Aug 14, 2024

Hi @helzahalim 👋 Thanks for raising this so quickly! To merge this PR we'll need the salesforce-cla check to pass - more details can be found from the above comment.

Once that's passing, we can merge! But in the meantime I'll be checking to see if @dependabot can help keep an eye on all of these packages 🙏

@zimeg zimeg changed the title Update package.json chore(deps): bump axios to 1.7.4 to address CVE Aug 14, 2024
@helzahalim
Copy link
Contributor Author

I have signed in though You already signed the CLA on 2024-08-14 , seems like there is an error when i clicked the build.

Oops, an error occurred
This exception has been logged with id 86fdkgjd7.

@helzahalim
Copy link
Contributor Author

Unfortunately after upgrading to 1.7.4, it still doesnt fix the vulnerability. Going to close this PR

axios/axios#6545

@helzahalim helzahalim closed this Aug 14, 2024
@zimeg
Copy link
Member

zimeg commented Aug 14, 2024

@helzahalim Thanks for signing the CLA! Sometimes the bot is slow to update and would require we close and reopen the PR. Sometimes that does the trick 😏

Also thank you for following along with the upstream fixes 🙏 I'll keep an eye on these too, but feel free to share findings you find, whatever you might find!

And I also didn't discover tricks with @dependabot around raising these updates more frequently than the scheduled updates... Oh well, @dependabot is still great to me 👑

@helzahalim
Copy link
Contributor Author

I reopen this @zimeg . Apparently just like the bot, Snyk takes awhile to update..

Copy link

codecov bot commented Aug 14, 2024

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 82.07%. Comparing base (a717253) to head (3c1cb96).

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #2201   +/-   ##
=======================================
  Coverage   82.07%   82.07%           
=======================================
  Files          18       18           
  Lines        1545     1545           
  Branches      443      443           
=======================================
  Hits         1268     1268           
  Misses        179      179           
  Partials       98       98           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@filmaj filmaj merged commit dab982a into slackapi:main Aug 14, 2024
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
cla:signed dependencies Pull requests that update a dependency file security semver:patch
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants