Skip to content

Axios dependency security vulnerability #283

Open
@ricardograca-scratch

Description

@ricardograca-scratch

Summary

npm audit indicates there's a security vulnerability in the version of Axios used here: GHSA-8hc4-vh64-cxmj

Expected Behavior

No security vulnerabilities.

Current Behavior

# npm audit report

axios  1.3.2 - 1.7.3
Severity: high
Server-Side Request Forgery in axios - https://github.com/advisories/GHSA-8hc4-vh64-cxmj
fix available via `npm audit fix`
node_modules/@lob/lob-typescript-sdk/node_modules/axios

Possible Solution

Upgrade axios to version 1.7.4.

Steps to Reproduce

  1. Add @lob/lob-typescript-sdk as a dependency to your project
  2. Run npm install && npm audit

I can provide a PR if that's acceptable.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions