Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Medium vulnerability : Update Axios to 1.7.8 #2115

Closed
1 of 7 tasks
s-dupuis opened this issue Dec 5, 2024 · 8 comments · Fixed by #2116
Closed
1 of 7 tasks

Medium vulnerability : Update Axios to 1.7.8 #2115

s-dupuis opened this issue Dec 5, 2024 · 8 comments · Fixed by #2116
Assignees
Labels
enhancement M-T: A feature request for new functionality good first issue pkg:web-api applies to `@slack/web-api` pkg:webhook applies to `@slack/webhook`

Comments

@s-dupuis
Copy link

s-dupuis commented Dec 5, 2024

Axios fixed this vulnerability in axios/axios#6714.

Packages:

Select all that apply:

  • @slack/web-api
  • @slack/rtm-api
  • @slack/webhooks
  • @slack/oauth
  • @slack/socket-mode
  • @slack/types
  • I don't know

Requirements

Please read the Contributing guidelines and Code of Conduct before creating this issue or pull request. By submitting, you are agreeing to those rules.

@hello-ashleyintech hello-ashleyintech self-assigned this Dec 5, 2024
@hello-ashleyintech hello-ashleyintech added good first issue enhancement M-T: A feature request for new functionality pkg:webhook applies to `@slack/webhook` and removed untriaged labels Dec 5, 2024
@hello-ashleyintech
Copy link
Contributor

Hi, @s-dupuis! 👋 Thanks for submitting this.

I will come out with a PR to bump the minimum version of Axios in the webhook package to 1.7.8 shortly. If the package is ready to release, I will also release it!

@hello-ashleyintech
Copy link
Contributor

hello-ashleyintech commented Dec 5, 2024

Also looks like this needs to be updated for web-api interactive-messages - this is deprecated, so just web-api in addition to webhook!

@zimeg
Copy link
Member

zimeg commented Dec 5, 2024

Bumping to 1.7.8 seems good - I'm not sure if the changes in 1.7.9 are needed - but I'm wondering where this was noted as a major vulnerability? 🤔

@s-dupuis The issues linked in that PR hint at this being a possible warning, but I'm not finding a CVE for it. Do you know if this might've been posted somewhere?

@hello-ashleyintech
Copy link
Contributor

@zimeg I'm seeing Snyk listing it as a medium vuln (versions <1.7.8) here!

@hello-ashleyintech
Copy link
Contributor

Whoops, for some reason this auto-closed although I just merged the PR only. I will be releasing web-api and webhook versions with this updated version tomorrow! Also as surfaced by @zimeg I'll take a look at Bolt JS to see if we need to update the min axios version there too!

@s-dupuis s-dupuis changed the title Major vulnerability : Update Axios to 1.7.8 Medium vulnerability : Update Axios to 1.7.8 Dec 6, 2024
@s-dupuis
Copy link
Author

s-dupuis commented Dec 6, 2024

@zimeg @hello-ashleyintech I made a mistake when creating this issue, this is indeed a medium vulnerability. Thank you for the quick fix !

@hello-ashleyintech
Copy link
Contributor

PR to release: #2118

@hello-ashleyintech
Copy link
Contributor

This has now been released to @slack/[email protected] and @slack/[email protected], both available on NPM now! ✨ closing this issue since the root of the issue has been resolved- I will be updating these dependency versions in other packages, as well as BoltJS , in separate PRs on Monday!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement M-T: A feature request for new functionality good first issue pkg:web-api applies to `@slack/web-api` pkg:webhook applies to `@slack/webhook`
Projects
None yet
3 participants