chore(deps): Bump axios from 0.27.2 to 1.8.4 - #12244
Security Report
You have successfully remediated 1 vulnerabilities, but introduced 2 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Suggested Fix | Issue | |
|---|---|---|---|---|---|
CVE-2025-58754Path to dependency file: /package.json Path to vulnerable library: /.yarn/cache/axios-npm-1.8.4-8cf735eb2b-a10f0dd836.zip Dependency Hierarchy: -> ibmdotcom-services-2.37.0.tgz (Root Library) -> ❌ axios-1.8.4.tgz (Vulnerable Library) |
7.5 | axios-1.8.4.tgz | Upgrade to version: https://github.com/axios/axios.git - v1.12.0,axios - 0.30.2 | #12351 | |
CVE-2025-58754Path to dependency file: /package.json Path to vulnerable library: /.yarn/cache/axios-npm-1.8.4-8cf735eb2b-a10f0dd836.zip Dependency Hierarchy: -> ibmdotcom-utilities-2.37.0.tgz (Root Library) -> ❌ axios-1.8.4.tgz (Vulnerable Library) |
7.5 | axios-1.8.4.tgz | Upgrade to version: https://github.com/axios/axios.git - v1.12.0,axios - 0.30.2 | #12350 |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2025-58754 | axios-1.8.2.tgz |
Base branch total remaining vulnerabilities: 20
Base branch commit: 6e231eeba86b027625ff60ed63925fbb6a0146c8
Total libraries scanned: 360
Scan token: 918d53f3f1fe4d78ba7e61d1a2e51bb6