Skip to content

Bump axios to v1.13.2 to fix Snyk issues#144

Merged
JoshSEdwards merged 5 commits intovinyldns:masterfrom
JoshSEdwards:snyk-fixes
Dec 11, 2025
Merged

Bump axios to v1.13.2 to fix Snyk issues#144
JoshSEdwards merged 5 commits intovinyldns:masterfrom
JoshSEdwards:snyk-fixes

Conversation

@JoshSEdwards
Copy link
Contributor

@JoshSEdwards JoshSEdwards commented Dec 9, 2025

This PR updates the client’s HTTP dependency to address Snyk-reported vulnerabilities:

  • Changed: Bump axios from 0.26.0 to ^1.13.2 (resolves multiple SSRF, ReDoS, CSRF, and resource exhaustion issues).
  • Transitive fix: New axios version pulls in follow-redirects >= 1.15.6, resolving its reported vulnerabilities.
  • CI/runtime: Update GitHub Actions verify workflow to use Node 25 so npm ci works correctly with the v3 package-lock.json.
  • Behavioral impact: No code changes required; our usage of axios (simple config + resp.data) remains compatible with 1.x.
  • Validation: gmake tests (unit tests, eslint, docs generation) all pass, and snyk test reports no vulnerable paths.

@snyk-io
Copy link

snyk-io bot commented Dec 9, 2025

Snyk checks have passed. No issues have been found so far.

Status Scanner Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues
Licenses 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

Copy link

@arpit4ever arpit4ever left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Minor change.

@JoshSEdwards JoshSEdwards changed the title Bump axios to v1.12.0 to fix Snyk issues Bump axios to v1.13.2 to fix Snyk issues Dec 10, 2025
Copy link
Member

@nspadaccino nspadaccino left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good

Copy link

@arpit4ever arpit4ever left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@JoshSEdwards JoshSEdwards merged commit edaae2c into vinyldns:master Dec 11, 2025
4 checks passed
@JoshSEdwards JoshSEdwards deleted the snyk-fixes branch December 11, 2025 15:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants