Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(deps): update dependency axios to v0.21.4 #145

Merged
merged 1 commit into from
Sep 23, 2021
Merged

fix(deps): update dependency axios to v0.21.4 #145

merged 1 commit into from
Sep 23, 2021

Conversation

gul-leanix
Copy link
Contributor

PR Checklist

Please check if your PR fulfills the following requirements:

PR Type

What kind of change does this PR introduce?

[x] Bugfix
[ ] Feature
[ ] Code style update (formatting, local variables)
[ ] Refactoring (no functional changes, no api changes)
[ ] Build related changes
[ ] CI related changes
[ ] Other... Please describe:

What is the current behavior?

The currently used axios version is vulnerable to a ReDoS vulnerability.

Issue Number: #142

What is the new behavior?

By updating the axios dependency, the vulnerability is closed.

Does this PR introduce a breaking change?

[ ] Yes
[x] No

The previous version of axios contained a known security vulnerability:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3749
@lnmunhoz
Copy link

Hey guys, please update this 👍

@nvanexan
Copy link

Will this be approved soon?

@BeigeBox
Copy link

Are there any particular test cases this is waiting on? It seems like this is a super straightforward PR? Can the community help in some way, or are we just waiting for someone authorized to merge it in?

@GeneralistDev
Copy link

Can we prefer #149 over this?

@kamilmysliwiec kamilmysliwiec merged commit d960f91 into nestjs:master Sep 23, 2021
@kamilmysliwiec
Copy link
Member

LGTM

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

6 participants