-
Notifications
You must be signed in to change notification settings - Fork 11
Open
Description
Description
- Axios outdated and has a security vulnerability
Debug Log as shown here:
│ high │ Server-Side Request Forgery │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ axios │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ >=0.21.1 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ arweave-bundles │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ arweave-bundles > arweave > axios │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://www.npmjs.com/advisories/1594 │
Solution
Can update the package.json and yarn.lock file with.
yarn add axiosAnd then republish as a new npm version.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels