Skip to content

Conversation

@learningdeveloper-dev
Copy link

Updating axios and public-ips dependency to fix the npm audit seen for the packages.
Also, modified gitignore to excluded error.log, .nyc_output & coverage folder from the commit

@learningdeveloper-dev learningdeveloper-dev deleted the fix/package_upgrade branch April 27, 2025 06:52
@learningdeveloper-dev learningdeveloper-dev restored the fix/package_upgrade branch April 27, 2025 06:52
@learningdeveloper-dev learningdeveloper-dev deleted the fix/package_upgrade branch April 27, 2025 06:52
@learningdeveloper-dev learningdeveloper-dev restored the fix/package_upgrade branch April 27, 2025 07:05
@learningdeveloper-dev learningdeveloper-dev changed the base branch from develop to main April 27, 2025 07:05
@learningdeveloper-dev
Copy link
Author


axios  <=0.29.0
Severity: high
Axios vulnerable to Server-Side Request Forgery - https://github.com/advisories/GHSA-4w2v-q235-vp99
Axios Cross-Site Request Forgery Vulnerability - https://github.com/advisories/GHSA-wf5p-g6vw-rhxx
axios Inefficient Regular Expression Complexity vulnerability - https://github.com/advisories/GHSA-cph5-m8f7-6c5x
axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL - https://github.com/advisories/GHSA-jr5f-v2jv-69x6
No fix available
node_modules/smartapi-javascript/node_modules/axios
  smartapi-javascript  *
  Depends on vulnerable versions of axios
  Depends on vulnerable versions of public-ip
  node_modules/smartapi-javascript

got  <11.8.5
Severity: moderate
Got allows a redirect to a UNIX socket - https://github.com/advisories/GHSA-pfrx-2q88-qq97
fix available via `npm audit fix`
node_modules/got
  public-ip  2.1.0 - 4.0.4
  Depends on vulnerable versions of got
  node_modules/public-ip

4 vulnerabilities (2 moderate, 2 high)

To address issues that do not require attention, run:
  npm audit fix

Some issues need review, and may require choosing
a different dependency.```

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants