Commit ed232b8
authored
chore: bump axios to ^1.18.0 to resolve moderate security advisories (#33541)
<!--
Please submit this PR as a draft initially.
Do not mark it as "Ready for review" until this PR meets the canonical
Definition of Ready For Review in `docs/readme/ready-for-review.md`.
In short: the template must be materially complete (not just section
titles
present), all status checks must be currently passing, and the only
expected
follow-up commits must be reviewer-driven.
-->
<!--
mms-check directive vocabulary — read by
.github/scripts/shared/pr-template-checks.ts
at module load to build the validation plan. Directives are invisible in
rendered
markdown and must NOT be removed or edited without updating the
validator registry.
type=text Section must contain non-placeholder prose.
type=changelog Section must have a valid CHANGELOG entry: line.
type=issue-link Section must have a Fixes:/Closes:/Refs: line with a
value.
type=manual-testing Section must have real testing steps or an explicit
N/A.
type=screenshot Section must have evidence (image/URL) or an explicit
N/A.
type=checklist Section must have all checkboxes consciously checked.
required=true|false Whether a missing/invalid section runs the validator
at all.
blocking=true|false Whether a failure of this check fails the CI
workflow.
Default: false — failures are shown as warnings in the sticky
comment but do not block the PR.
Sections without a directive are checked for structural presence only.
-->
## **Description**
<!-- mms-check: type=text required=true -->
<!--
Write a short description of the changes included in this pull request,
also include relevant motivation and context. Have in mind the following
questions:
1. What is the reason for the change?
2. What is the improvement/solution?
-->
`yarn audit:ci` was failing because `axios@1.16.1` was locked across the
entire
dependency tree, triggering three moderate-severity advisories.
The `resolutions` override in `package.json` was pinning axios to
`^1.16.0`,
which kept the vulnerable `1.16.1` in `yarn.lock` even though newer
patched
versions exist. This PR bumps axios to `^1.18.0` (resolves to `1.18.1`)
in both
the direct dependency and the resolutions override, then relocks so
every
dependent (Appium, Ledger, on-ramp-sdk, sats-connect, stellar-sdk, etc.)
uses
the patched version.
### Advisories resolved
| Advisory | Issue | Fixed in |
|---|---|---|
|
[GHSA-42h9-826w-cgv3](GHSA-42h9-826w-cgv3)
| Excessive recursion in `formDataToJSON` → DoS | 1.18.0 |
|
[GHSA-xj6q-8x83-jv6g](GHSA-xj6q-8x83-jv6g)
| Prototype pollution in auth subfields → Basic auth injection | 1.18.0
|
|
[GHSA-pmv8-rq9r-6j72](GHSA-pmv8-rq9r-6j72)
| Deep `formToJSON` key recursion → DoS | 1.18.0 |
## Changes
- `package.json`: bump `axios` `^1.16.0` → `^1.18.0` (direct dependency
+ `resolutions`)
- `yarn.lock`: relock — `axios@1.16.1` → `axios@1.18.1`
## **Changelog**
<!-- mms-check: type=changelog required=true blocking=true -->
<!--
If this PR is not End-User-Facing and should not show up in the
CHANGELOG, you can choose to either:
1. Write `CHANGELOG entry: null`
2. Label with `no-changelog`
If this PR is End-User-Facing, please write a short User-Facing
description in the past tense like:
`CHANGELOG entry: Added a new tab for users to see their NFTs`
`CHANGELOG entry: Fixed a bug that was causing some NFTs to flicker`
(This helps the Release Engineer do their job more quickly and
accurately)
-->
CHANGELOG entry:null
## **Related issues**
<!-- mms-check: type=issue-link required=true -->
Fixes: CI audit failing
## **Manual testing steps**
<!-- mms-check: type=manual-testing required=true -->
1. Run `yarn audit:ci` → passes with `No audit suggestions` (exit code
0)
2. Run `yarn why axios` → all dependents resolve to `axios@npm:1.18.1`
3. Smoke test flows that use axios (on-ramp/buy, Ledger connection,
Appium E2E) to confirm no regressions
## **Screenshots/Recordings**
<!-- mms-check: type=screenshot required=true -->
<!-- If applicable, add screenshots and/or recordings to visualize the
before and after of your change. -->
N/A
## **Pre-merge author checklist**
<!-- mms-check: type=checklist required=true -->
<!--
Every checklist item must be consciously assessed before marking this PR
as
"Ready for review". A checked box means you deliberately considered that
responsibility, not that you literally performed every action listed.
Unchecked boxes are ambiguous: they are not an implicit "N/A" and they
are not
a silent "skip". See `docs/readme/ready-for-review.md` for the full
checklist
semantics.
-->
- [x] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask Mobile
Coding
Standards](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [x] I've completed the PR template to the best of my ability
- [ ] I've included tests if applicable
- [ ] I've documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [ ] I've applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.
#### Performance checks (if applicable)
- [ ] I've tested on Android
- Ideally on a mid-range device; emulator is acceptable
- [ ] I've tested with a power user scenario
- Use these [power-user
SRPs](https://consensyssoftware.atlassian.net/wiki/spaces/TL1/pages/edit-v2/401401446401?draftShareId=9d77e1e1-4bdc-4be1-9ebb-ccd916988d93)
to import wallets with many accounts and tokens
- [ ] I've instrumented key operations with Sentry traces for production
performance metrics
- See [`trace()`](/app/util/trace.ts) for usage and
[`addToken`](/app/components/Views/AddAsset/components/AddCustomToken/AddCustomToken.tsx#L274)
for an example
For performance guidelines and tooling, see the [Performance
Guide](https://consensyssoftware.atlassian.net/wiki/spaces/TL1/pages/400085549067/Performance+Guide+for+Engineers).
## **Pre-merge reviewer checklist**
<!--
Reviewer checklist items follow the same semantics as the author
checklist: an
unchecked box is ambiguous, a checked box means the reviewer consciously
assessed that responsibility. See `docs/readme/ready-for-review.md`.
-->
- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.1 parent dc7702a commit ed232b8
2 files changed
Lines changed: 7 additions & 7 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
191 | 191 | | |
192 | 192 | | |
193 | 193 | | |
194 | | - | |
| 194 | + | |
195 | 195 | | |
196 | 196 | | |
197 | 197 | | |
| |||
425 | 425 | | |
426 | 426 | | |
427 | 427 | | |
428 | | - | |
| 428 | + | |
429 | 429 | | |
430 | 430 | | |
431 | 431 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
23151 | 23151 | | |
23152 | 23152 | | |
23153 | 23153 | | |
23154 | | - | |
23155 | | - | |
23156 | | - | |
| 23154 | + | |
| 23155 | + | |
| 23156 | + | |
23157 | 23157 | | |
23158 | 23158 | | |
23159 | 23159 | | |
23160 | 23160 | | |
23161 | 23161 | | |
23162 | | - | |
| 23162 | + | |
23163 | 23163 | | |
23164 | 23164 | | |
23165 | 23165 | | |
| |||
36143 | 36143 | | |
36144 | 36144 | | |
36145 | 36145 | | |
36146 | | - | |
| 36146 | + | |
36147 | 36147 | | |
36148 | 36148 | | |
36149 | 36149 | | |
| |||
0 commit comments