Skip to content

fix(deps): patch axios, moment and brace-expansion advisories - #215

Open
TartanLeGrand wants to merge 1 commit into
BananaOps:mainfrom
TartanLeGrand:fix/web-deps-audit
Open

TartanLeGrand wants to merge 1 commit into
BananaOps:mainfrom
TartanLeGrand:fix/web-deps-audit

Conversation

@TartanLeGrand

Copy link
Copy Markdown
Contributor

What

npm audit on main reports three advisories published since #206:

Package Severity Advisory Change
axios (direct) high prototype pollution gadgets in the fetch adapter and option handling 1.18.1 to 1.20.0
brace-expansion (transitive) high quadratic-time expansion, CPU denial of service 5.0.9 to 5.0.12
moment (transitive, via moment-timezone) moderate path traversal through a crafted locale name 2.30.1 to 2.31.0

Lockfile only, every bump stays inside the ranges already declared in package.json.

axios 1.20 notes

The release lists one "breaking change": new status names ContentTooLarge (413) and UnprocessableContent (422), with the old names kept as aliases. One behaviour fix worth knowing: an XHR canceled by a page navigation now rejects with ECONNABORTED instead of resolving with status 0. The web code uses neither the status names nor a status 0 check.

Checks

  • npm audit: 0 vulnerabilities (was 3).
  • npm run build and npm run build:static: green.
  • tsc --noEmit: 122 errors and eslint .: 78 errors / 165 warnings, both identical to main.

Note

#201 regenerates the same lockfile; whichever merges second needs a rebase.

npm audit reported three advisories on main: axios prototype pollution
gadgets (high, direct dependency), brace-expansion quadratic expansion
(high) and moment locale path traversal (moderate). Lockfile only:
axios 1.18.1 to 1.20.0, moment 2.30.1 to 2.31.0, brace-expansion 5.0.9
to 5.0.12.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant