Skip to content

JavaScript GCP KMS Storage: bump axios floor to ^1.19.0 (KSM-1533) - #1196

Merged
mgallego-keeper merged 1 commit into
release/storage/javascript/gcp-kms/v1.1.0from
fix/KSM-1533-axios-cve-bump
Sep 24, 2026
Merged

mgallego-keeper merged 1 commit into
release/storage/javascript/gcp-kms/v1.1.0from
fix/KSM-1533-axios-cve-bump

Conversation

@stas-schaller

Copy link
Copy Markdown
Collaborator

Summary

JavaScript GCP KMS Storage: raises the declared axios floor so this package's own bearer-token requests can't resolve to an unpatched version.

Changes

Maintenance

  • The declared floor of ^1.13.5 didn't guarantee a patched axios on rawEncrypt/rawDecrypt's axios.post calls, which carry a live GCP OAuth bearer token in the Authorization header. A consumer who already pins an older axios kept that version through npm's dedupe. Six advisories were fixed between 1.15.1 and 1.16.0 (GHSA-6chq-wfr3-2hj9, GHSA-pf86-5x62-jrwf, GHSA-q8qp-cvcw-x6jj, GHSA-p92q-9vqr-4j8v, GHSA-35jp-ww65-95wh, GHSA-hfxv-24rg-xrqf). Floor raised to ^1.19.0, lockfile refreshed. (KSM-1533)

Testing

cd sdk/javascript/packages/gcp
npm test

124/124 passing. npm run build and npm run lint also clean.

Breaking Changes

None.

Related Issues

  • Jira: KSM-1533

The declared floor of ^1.13.5 doesn't guarantee a patched axios for
this package's own bearer-token requests in rawEncrypt/rawDecrypt. Six
advisories (GHSA-6chq-wfr3-2hj9, GHSA-pf86-5x62-jrwf, GHSA-q8qp-cvcw-x6jj,
GHSA-p92q-9vqr-4j8v, GHSA-35jp-ww65-95wh, GHSA-hfxv-24rg-xrqf) were fixed
between 1.15.1 and 1.16.0; a consumer who already pins an old axios
keeps that vulnerable version through npm's dedupe.

@mgallego-keeper mgallego-keeper left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Summary

This PR raises the declared axios floor from ^1.13.5 to ^1.19.0 in package.json. It also updates the matching lockfile line and adds a CHANGELOG.md entry.

Verification

I checked the release branch lockfile before this PR. It already resolved axios to 1.19.0, from the earlier KSM-1218 lockfile refresh. So this PR only raises the declared range to match. It has no effect on dependency resolution.

I merged this PR onto the release branch tip and ran npm ci and the full test suite. All 124 tests pass.

I checked the six named advisories against the GitHub Advisory Database:

Each one is fixed at axios 1.16.0. The new floor of ^1.19.0 is above that fix.

One suggestion, not a blocker

src/utils.ts sends a live GCP OAuth bearer token through axios.post in rawEncrypt and rawDecrypt. I could not test this call against a real Cloud KMS key in this review, since that needs live GCP credentials. A quick smoke test of both calls against the new axios version, before this ships, would close that gap.

Merge order

See the note on #1189 for the overlap and merge order across #1196 to #1200. This PR has no file overlap with any of the other four beyond package.json, package-lock.json, and CHANGELOG.md, and none of those overlaps conflict.

@mgallego-keeper

Copy link
Copy Markdown
Contributor

Filed KSM-1537 to track the live smoke test mentioned above. It covers the rawEncrypt/rawDecrypt round trip against a real Cloud KMS key, on the new axios version. Not a blocker for this PR.

@mgallego-keeper
mgallego-keeper merged commit cce7efc into release/storage/javascript/gcp-kms/v1.1.0 Sep 24, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants