Repository navigation
JavaScript GCP KMS Storage: bump axios floor to ^1.19.0 (KSM-1533) - #1196
Conversation
The declared floor of ^1.13.5 doesn't guarantee a patched axios for this package's own bearer-token requests in rawEncrypt/rawDecrypt. Six advisories (GHSA-6chq-wfr3-2hj9, GHSA-pf86-5x62-jrwf, GHSA-q8qp-cvcw-x6jj, GHSA-p92q-9vqr-4j8v, GHSA-35jp-ww65-95wh, GHSA-hfxv-24rg-xrqf) were fixed between 1.15.1 and 1.16.0; a consumer who already pins an old axios keeps that vulnerable version through npm's dedupe.
mgallego-keeper
left a comment
There was a problem hiding this comment.
Summary
This PR raises the declared axios floor from ^1.13.5 to ^1.19.0 in package.json. It also updates the matching lockfile line and adds a CHANGELOG.md entry.
Verification
I checked the release branch lockfile before this PR. It already resolved axios to 1.19.0, from the earlier KSM-1218 lockfile refresh. So this PR only raises the declared range to match. It has no effect on dependency resolution.
I merged this PR onto the release branch tip and ran npm ci and the full test suite. All 124 tests pass.
I checked the six named advisories against the GitHub Advisory Database:
- GHSA-6chq-wfr3-2hj9
- GHSA-pf86-5x62-jrwf
- GHSA-q8qp-cvcw-x6jj
- GHSA-p92q-9vqr-4j8v
- GHSA-35jp-ww65-95wh
- GHSA-hfxv-24rg-xrqf
Each one is fixed at axios 1.16.0. The new floor of ^1.19.0 is above that fix.
One suggestion, not a blocker
src/utils.ts sends a live GCP OAuth bearer token through axios.post in rawEncrypt and rawDecrypt. I could not test this call against a real Cloud KMS key in this review, since that needs live GCP credentials. A quick smoke test of both calls against the new axios version, before this ships, would close that gap.
Merge order
See the note on #1189 for the overlap and merge order across #1196 to #1200. This PR has no file overlap with any of the other four beyond package.json, package-lock.json, and CHANGELOG.md, and none of those overlaps conflict.
|
Filed KSM-1537 to track the live smoke test mentioned above. It covers the rawEncrypt/rawDecrypt round trip against a real Cloud KMS key, on the new axios version. Not a blocker for this PR. |
cce7efc
into
release/storage/javascript/gcp-kms/v1.1.0
Summary
JavaScript GCP KMS Storage: raises the declared axios floor so this package's own bearer-token requests can't resolve to an unpatched version.
Changes
Maintenance
^1.13.5didn't guarantee a patched axios onrawEncrypt/rawDecrypt'saxios.postcalls, which carry a live GCP OAuth bearer token in the Authorization header. A consumer who already pins an older axios kept that version through npm's dedupe. Six advisories were fixed between 1.15.1 and 1.16.0 (GHSA-6chq-wfr3-2hj9,GHSA-pf86-5x62-jrwf,GHSA-q8qp-cvcw-x6jj,GHSA-p92q-9vqr-4j8v,GHSA-35jp-ww65-95wh,GHSA-hfxv-24rg-xrqf). Floor raised to^1.19.0, lockfile refreshed. (KSM-1533)Testing
124/124 passing.
npm run buildandnpm run lintalso clean.Breaking Changes
None.
Related Issues