Skip to content

chore(deps): upgrade axios to 1.15.0#117

Merged
limichange merged 1 commit into
mainfrom
chore/upgrade-axios-1.15.0
Apr 13, 2026
Merged

chore(deps): upgrade axios to 1.15.0#117
limichange merged 1 commit into
mainfrom
chore/upgrade-axios-1.15.0

Conversation

@originalix
Copy link
Copy Markdown
Contributor

Summary

  • Upgrade axios from 1.12.2 to 1.15.0 to fix critical security vulnerabilities
  • NO_PROXY Hostname Normalization Bypass → SSRF (Critical)
  • Unrestricted Cloud Metadata Exfiltration via Header Injection Chain (Critical)
  • Unintended Proxy or Intermediary / Confused Deputy (Critical)

Test plan

  • Verify firmware update download and verification flow works correctly
  • Check no regressions in HTTP request handling

🤖 Generated with Claude Code

Fixes CVE: NO_PROXY Hostname Normalization Bypass (SSRF), Unrestricted Cloud Metadata Exfiltration via Header Injection Chain, Unintended Proxy or Intermediary (Confused Deputy).

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@revan-zhang
Copy link
Copy Markdown
Contributor

revan-zhang commented Apr 13, 2026

Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues
Licenses 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@socket-security
Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedaxios@​1.15.09110010095100

View full report

@limichange limichange merged commit 94e0684 into main Apr 13, 2026
9 checks passed
@limichange limichange deleted the chore/upgrade-axios-1.15.0 branch April 13, 2026 02:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants