Skip to content

chore(deps): Bump axios from 0.27.2 to 1.8.4 - #12244

Closed
dependabot[bot] wants to merge 3 commits into
mainfrom
dependabot/npm_and_yarn/axios-1.8.4
Closed

chore(deps): Bump axios from 0.27.2 to 1.8.4#12244
dependabot[bot] wants to merge 3 commits into
mainfrom
dependabot/npm_and_yarn/axios-1.8.4

Merge branch 'main' into dependabot/npm_and_yarn/axios-1.8.4

1429557
Select commit
Loading
Failed to load commit list.
IBM Mend app / Mend Security Check failed Dec 2, 2025 in 2h 6m 4s

Security Report

You have successfully remediated 1 vulnerabilities, but introduced 2 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Suggested Fix Issue
CVE-2025-58754

Path to dependency file: /package.json

Path to vulnerable library: /.yarn/cache/axios-npm-1.8.4-8cf735eb2b-a10f0dd836.zip

Dependency Hierarchy:

-> ibmdotcom-services-2.37.0.tgz (Root Library)

   -> ❌ axios-1.8.4.tgz (Vulnerable Library)

High 7.5 axios-1.8.4.tgz Upgrade to version: https://github.com/axios/axios.git - v1.12.0,axios - 0.30.2 #12351
CVE-2025-58754

Path to dependency file: /package.json

Path to vulnerable library: /.yarn/cache/axios-npm-1.8.4-8cf735eb2b-a10f0dd836.zip

Dependency Hierarchy:

-> ibmdotcom-utilities-2.37.0.tgz (Root Library)

   -> ❌ axios-1.8.4.tgz (Vulnerable Library)

High 7.5 axios-1.8.4.tgz Upgrade to version: https://github.com/axios/axios.git - v1.12.0,axios - 0.30.2 #12350

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2025-58754 axios-1.8.2.tgz

Base branch total remaining vulnerabilities: 20
Base branch commit: 6e231eeba86b027625ff60ed63925fbb6a0146c8


Total libraries scanned: 360

Scan token: 918d53f3f1fe4d78ba7e61d1a2e51bb6