Skip to content

Commit ed232b8

Browse files
authored
chore: bump axios to ^1.18.0 to resolve moderate security advisories (#33541)
<!-- Please submit this PR as a draft initially. Do not mark it as "Ready for review" until this PR meets the canonical Definition of Ready For Review in `docs/readme/ready-for-review.md`. In short: the template must be materially complete (not just section titles present), all status checks must be currently passing, and the only expected follow-up commits must be reviewer-driven. --> <!-- mms-check directive vocabulary — read by .github/scripts/shared/pr-template-checks.ts at module load to build the validation plan. Directives are invisible in rendered markdown and must NOT be removed or edited without updating the validator registry. type=text Section must contain non-placeholder prose. type=changelog Section must have a valid CHANGELOG entry: line. type=issue-link Section must have a Fixes:/Closes:/Refs: line with a value. type=manual-testing Section must have real testing steps or an explicit N/A. type=screenshot Section must have evidence (image/URL) or an explicit N/A. type=checklist Section must have all checkboxes consciously checked. required=true|false Whether a missing/invalid section runs the validator at all. blocking=true|false Whether a failure of this check fails the CI workflow. Default: false — failures are shown as warnings in the sticky comment but do not block the PR. Sections without a directive are checked for structural presence only. --> ## **Description** <!-- mms-check: type=text required=true --> <!-- Write a short description of the changes included in this pull request, also include relevant motivation and context. Have in mind the following questions: 1. What is the reason for the change? 2. What is the improvement/solution? --> `yarn audit:ci` was failing because `axios@1.16.1` was locked across the entire dependency tree, triggering three moderate-severity advisories. The `resolutions` override in `package.json` was pinning axios to `^1.16.0`, which kept the vulnerable `1.16.1` in `yarn.lock` even though newer patched versions exist. This PR bumps axios to `^1.18.0` (resolves to `1.18.1`) in both the direct dependency and the resolutions override, then relocks so every dependent (Appium, Ledger, on-ramp-sdk, sats-connect, stellar-sdk, etc.) uses the patched version. ### Advisories resolved | Advisory | Issue | Fixed in | |---|---|---| | [GHSA-42h9-826w-cgv3](GHSA-42h9-826w-cgv3) | Excessive recursion in `formDataToJSON` → DoS | 1.18.0 | | [GHSA-xj6q-8x83-jv6g](GHSA-xj6q-8x83-jv6g) | Prototype pollution in auth subfields → Basic auth injection | 1.18.0 | | [GHSA-pmv8-rq9r-6j72](GHSA-pmv8-rq9r-6j72) | Deep `formToJSON` key recursion → DoS | 1.18.0 | ## Changes - `package.json`: bump `axios` `^1.16.0` → `^1.18.0` (direct dependency + `resolutions`) - `yarn.lock`: relock — `axios@1.16.1` → `axios@1.18.1` ## **Changelog** <!-- mms-check: type=changelog required=true blocking=true --> <!-- If this PR is not End-User-Facing and should not show up in the CHANGELOG, you can choose to either: 1. Write `CHANGELOG entry: null` 2. Label with `no-changelog` If this PR is End-User-Facing, please write a short User-Facing description in the past tense like: `CHANGELOG entry: Added a new tab for users to see their NFTs` `CHANGELOG entry: Fixed a bug that was causing some NFTs to flicker` (This helps the Release Engineer do their job more quickly and accurately) --> CHANGELOG entry:null ## **Related issues** <!-- mms-check: type=issue-link required=true --> Fixes: CI audit failing ## **Manual testing steps** <!-- mms-check: type=manual-testing required=true --> 1. Run `yarn audit:ci` → passes with `No audit suggestions` (exit code 0) 2. Run `yarn why axios` → all dependents resolve to `axios@npm:1.18.1` 3. Smoke test flows that use axios (on-ramp/buy, Ledger connection, Appium E2E) to confirm no regressions ## **Screenshots/Recordings** <!-- mms-check: type=screenshot required=true --> <!-- If applicable, add screenshots and/or recordings to visualize the before and after of your change. --> N/A ## **Pre-merge author checklist** <!-- mms-check: type=checklist required=true --> <!-- Every checklist item must be consciously assessed before marking this PR as "Ready for review". A checked box means you deliberately considered that responsibility, not that you literally performed every action listed. Unchecked boxes are ambiguous: they are not an implicit "N/A" and they are not a silent "skip". See `docs/readme/ready-for-review.md` for the full checklist semantics. --> - [x] I've followed [MetaMask Contributor Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask Mobile Coding Standards](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/CODING_GUIDELINES.md). - [x] I've completed the PR template to the best of my ability - [ ] I've included tests if applicable - [ ] I've documented my code using [JSDoc](https://jsdoc.app/) format if applicable - [ ] I've applied the right labels on the PR (see [labeling guidelines](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/LABELING_GUIDELINES.md)). Not required for external contributors. #### Performance checks (if applicable) - [ ] I've tested on Android - Ideally on a mid-range device; emulator is acceptable - [ ] I've tested with a power user scenario - Use these [power-user SRPs](https://consensyssoftware.atlassian.net/wiki/spaces/TL1/pages/edit-v2/401401446401?draftShareId=9d77e1e1-4bdc-4be1-9ebb-ccd916988d93) to import wallets with many accounts and tokens - [ ] I've instrumented key operations with Sentry traces for production performance metrics - See [`trace()`](/app/util/trace.ts) for usage and [`addToken`](/app/components/Views/AddAsset/components/AddCustomToken/AddCustomToken.tsx#L274) for an example For performance guidelines and tooling, see the [Performance Guide](https://consensyssoftware.atlassian.net/wiki/spaces/TL1/pages/400085549067/Performance+Guide+for+Engineers). ## **Pre-merge reviewer checklist** <!-- Reviewer checklist items follow the same semantics as the author checklist: an unchecked box is ambiguous, a checked box means the reviewer consciously assessed that responsibility. See `docs/readme/ready-for-review.md`. --> - [ ] I've manually tested the PR (e.g. pull and build branch, run the app, test code being changed). - [ ] I confirm that this PR addresses all acceptance criteria described in the ticket it closes and includes the necessary testing evidence such as recordings and or screenshots.
1 parent dc7702a commit ed232b8

2 files changed

Lines changed: 7 additions & 7 deletions

File tree

package.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -191,7 +191,7 @@
191191
"@unrs/resolver-binding-wasm32-wasi": "npm:npm-empty-package@1.0.0",
192192
"d3-color": "3.1.0",
193193
"napi-postinstall": "npm:npm-empty-package@1.0.0",
194-
"axios": "^1.16.0",
194+
"axios": "^1.18.0",
195195
"lodash": "4.18.1",
196196
"redux-persist-filesystem-storage/react-native-blob-util": "^0.19.9",
197197
"@segment/sovran-react-native/react-native-get-random-values": "^2.0.0",
@@ -425,7 +425,7 @@
425425
"@walletconnect/utils": "^2.23.0",
426426
"@xmldom/xmldom": "^0.8.13",
427427
"asyncstorage-down": "4.2.0",
428-
"axios": "^1.16.0",
428+
"axios": "^1.18.0",
429429
"bignumber.js": "^9.0.1",
430430
"bitcoin-address-validation": "2.2.3",
431431
"bnjs4": "npm:bn.js@^4.12.3",

yarn.lock

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -23151,15 +23151,15 @@ __metadata:
2315123151
languageName: node
2315223152
linkType: hard
2315323153

23154-
"axios@npm:^1.16.0":
23155-
version: 1.16.1
23156-
resolution: "axios@npm:1.16.1"
23154+
"axios@npm:^1.18.0":
23155+
version: 1.18.1
23156+
resolution: "axios@npm:1.18.1"
2315723157
dependencies:
2315823158
follow-redirects: "npm:^1.16.0"
2315923159
form-data: "npm:^4.0.5"
2316023160
https-proxy-agent: "npm:^5.0.1"
2316123161
proxy-from-env: "npm:^2.1.0"
23162-
checksum: 10/9b6218cf96321cfbbf8f160658d695367114bcf4fb62492bdc1ccd647f184b5c71ae400e5ecaaf41079bc561de2ecbaf1fec63f398b3ec53389beff7694df64c
23162+
checksum: 10/c4cdced3ee0a9bf7dcae189fbc74a124aa079d4f04dbd995e602d39c1419476e8d021f87ee39ac8d8398e5a55e6d0b986238b3645f0d9177ac80de87c2a73f18
2316323163
languageName: node
2316423164
linkType: hard
2316523165

@@ -36143,7 +36143,7 @@ __metadata:
3614336143
appium-xcuitest-driver: "npm:9.5.0"
3614436144
assert: "npm:^1.5.0"
3614536145
asyncstorage-down: "npm:4.2.0"
36146-
axios: "npm:^1.16.0"
36146+
axios: "npm:^1.18.0"
3614736147
babel-jest: "npm:^29.7.0"
3614836148
babel-loader: "npm:^9.1.3"
3614936149
babel-plugin-inline-import: "npm:^3.0.0"

0 commit comments

Comments
 (0)