Commit 954d5b7
fix(http): bump axios 1.14.0 → 1.15.0 (critical SSRF vulnerability)
GHSA-3p68-rc4w-qgx5: Axios <1.15.0 has a NO_PROXY hostname normalization
bypass that leads to SSRF. Bumps to 1.15.0 in both fs-http (direct dep)
and fs-loading (dev dep).
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>1 parent 8cc666d commit 954d5b7
3 files changed
Lines changed: 7 additions & 7 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
41 | 41 | | |
42 | 42 | | |
43 | 43 | | |
44 | | - | |
| 44 | + | |
45 | 45 | | |
46 | 46 | | |
47 | 47 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
43 | 43 | | |
44 | 44 | | |
45 | 45 | | |
46 | | - | |
| 46 | + | |
47 | 47 | | |
48 | 48 | | |
49 | 49 | | |
| |||
0 commit comments