Skip to content

chore(deps): bump axios from 1.13.5 to 1.15.0#287

Merged
jeylost merged 1 commit intomainfrom
chore/bump-axios
Apr 15, 2026
Merged

chore(deps): bump axios from 1.13.5 to 1.15.0#287
jeylost merged 1 commit intomainfrom
chore/bump-axios

Conversation

@jeylost
Copy link
Copy Markdown
Contributor

@jeylost jeylost commented Apr 15, 2026

What/Why/How?

This PR addresses npm-axios < 1.15.0/CVE-2025-62718

Reference

Testing

Screenshots (optional)

Check yourself

  • Code is linted
  • Tested
  • All new/updated code is covered with tests

Security

  • Security impact of change has been considered
  • Code follows company security practices and guidelines

@jeylost jeylost requested a review from a team as a code owner April 15, 2026 11:30
Copy link
Copy Markdown

@redocly redocly bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

marketing-site AI Review: 🟢 Completed

Note

Low Risk

Standard dependency update to address a known security vulnerability (CVE-2025-62718). Minor version bumps for popular libraries like axios are generally safe, but standard CI checks should be verified to ensure no breaking behavior in network requests.

Overview

Bumps the axios version from 1.13.5 to 1.15.0 in package.json overrides. This also updates the package-lock.json and upgrades its transitive dependency proxy-from-env from 1.1.0 to 2.1.0.

@jeylost jeylost merged commit aeea9b1 into main Apr 15, 2026
7 checks passed
@jeylost jeylost deleted the chore/bump-axios branch April 15, 2026 11:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants