Commit e6ba205
fix(deps): upgrade axios to 1.15.0 to patch CVE-2025-62718 (#102)
Pins axios >= 1.15.0 as a direct dependency to override the transitive
dependency from x402-stacks, fixing the NO_PROXY hostname normalization
bypass (SSRF) vulnerability (GHSA-3p68-rc4w-qgx5, CVSS 9.3).
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>1 parent 546d6ac commit e6ba205
2 files changed
Lines changed: 13 additions & 8 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
32 | 32 | | |
33 | 33 | | |
34 | 34 | | |
| 35 | + | |
35 | 36 | | |
36 | 37 | | |
37 | 38 | | |
| |||
0 commit comments