Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Server-Side Request Forgery in axios #394

Open
mfulton26 opened this issue Oct 21, 2024 · 0 comments
Open

Server-Side Request Forgery in axios #394

mfulton26 opened this issue Oct 21, 2024 · 0 comments

Comments

@mfulton26
Copy link

bug

What is the current behavior?

adding bundlesize to a package.json file causes a vulnerable version of axios to transitively get added to node_modules

What is the expected behavior?

transitive dependencies are able to be updated (especially for patches), often without a bundlesize version publication by leveraging version ranges

Other relevant information.

GHSA-8hc4-vh64-cxmj

siddharthkp/github-build#25

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant