-
Notifications
You must be signed in to change notification settings - Fork 662
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Medium vulnerability : Update Axios to 1.7.8 #2115
Comments
Hi, @s-dupuis! 👋 Thanks for submitting this. I will come out with a PR to bump the minimum version of Axios in the |
Also looks like this needs to be updated for |
Bumping to @s-dupuis The issues linked in that PR hint at this being a possible warning, but I'm not finding a CVE for it. Do you know if this might've been posted somewhere? |
Whoops, for some reason this auto-closed although I just merged the PR only. I will be releasing web-api and webhook versions with this updated version tomorrow! Also as surfaced by @zimeg I'll take a look at Bolt JS to see if we need to update the min axios version there too! |
@zimeg @hello-ashleyintech I made a mistake when creating this issue, this is indeed a medium vulnerability. Thank you for the quick fix ! |
PR to release: #2118 |
This has now been released to |
Axios fixed this vulnerability in axios/axios#6714.
Packages:
Select all that apply:
@slack/web-api
@slack/rtm-api
@slack/webhooks
@slack/oauth
@slack/socket-mode
@slack/types
Requirements
Please read the Contributing guidelines and Code of Conduct before creating this issue or pull request. By submitting, you are agreeing to those rules.
The text was updated successfully, but these errors were encountered: