Commit a8e53b6
authored
chore(deps): resolve open Dependabot security alerts (#9456)
Bumps three dependencies flagged by Dependabot, closing all 7 open alerts:
- axios 1.16.0 -> 1.18.1 (catalog), closing 5 alerts:
GHSA-gcfj-64vw-6mp9 (high, inherited proxy after interceptor config clone),
GHSA-hcpx-6fm6-wx23, GHSA-mwf2-3pr3-8698, GHSA-f4gw-2p7v-4548,
GHSA-xj6q-8x83-jv6g. Dependabot proposed 1.18.0; 1.18.1 is a pure bugfix
release on top of it that also fixes runtime crashes and AxiosError
circular-serialisation, so it is used instead. Supersedes PR #9447.
- brace-expansion 5.0.6 -> 5.0.7 (override), closing GHSA-3jxr-9vmj-r5cp
(high, DoS via exponential-time expansion of consecutive {} groups).
- morgan -> 1.11.0 (new override), closing GHSA-4vj7-5mj6-jm8m (log forging
via unneutralized control characters in :remote-user). Pulled in
transitively by @react-router/serve.
Verified: check:types 28/28, check:lint 16/16, build 16/16.1 parent 7cef741 commit a8e53b6
2 files changed
Lines changed: 54 additions & 45 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
91 | 91 | | |
92 | 92 | | |
93 | 93 | | |
94 | | - | |
| 94 | + | |
95 | 95 | | |
96 | 96 | | |
97 | 97 | | |
| |||
195 | 195 | | |
196 | 196 | | |
197 | 197 | | |
198 | | - | |
| 198 | + | |
199 | 199 | | |
200 | 200 | | |
201 | 201 | | |
| |||
237 | 237 | | |
238 | 238 | | |
239 | 239 | | |
| 240 | + | |
240 | 241 | | |
241 | 242 | | |
242 | 243 | | |
| |||
0 commit comments