Skip to content

fix: axios and qs package bump#107

Merged
ajasnosz merged 2 commits into
mainfrom
develop
Jun 29, 2026
Merged

fix: axios and qs package bump#107
ajasnosz merged 2 commits into
mainfrom
develop

Conversation

@ajasnosz

Copy link
Copy Markdown
Contributor
  • Bump axios from ^1.6.8 to ^1.16.0 (resolves HIGH CVEs: prototype pollution, proxy-auth credential leak, ReDoS, SSRF)
  • Bump qs from 6.15.1 to 6.15.2 (resolves MODERATE GHSA-q8mj-m7cp-5q26: DoS via stringify)
  • Add yarn resolutions to force patched versions of transitive deps pulled through lerna>nx: axios, undici, tmp, form-data, brace-expansion, yaml, tar, js-yaml

ajasnosz and others added 2 commits June 29, 2026 09:59
## [1.2.2-beta.1](v1.2.1...v1.2.2-beta.1) (2026-06-29)

### Bug Fixes

* axios and qs package bump ([#106](#106)) ([12f5518](12f5518))
@ajasnosz ajasnosz merged commit 4ddd636 into main Jun 29, 2026
15 checks passed
@ajasnosz ajasnosz deleted the develop branch June 29, 2026 08:52
splunk-ta-helper Bot pushed a commit that referenced this pull request Jun 29, 2026
## [1.2.2](v1.2.1...v1.2.2) (2026-06-29)

### Bug Fixes

* axios and qs package bump ([#107](#107)) ([4ddd636](4ddd636)), closes [#106](#106) [#106](#106)
@splunk-ta-helper

Copy link
Copy Markdown

🎉 This PR is included in version 1.2.2 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants