Skip to content

Conversation

@learningdeveloper-dev
Copy link

Updated axios and public ip dependency to fix npm audit issues.

npm audit report

axios  <=0.29.0
Severity: high
Axios vulnerable to Server-Side Request Forgery - https://github.com/advisories/GHSA-4w2v-q235-vp99
Axios Cross-Site Request Forgery Vulnerability - https://github.com/advisories/GHSA-wf5p-g6vw-rhxx
axios Inefficient Regular Expression Complexity vulnerability - https://github.com/advisories/GHSA-cph5-m8f7-6c5x
axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL - https://github.com/advisories/GHSA-jr5f-v2jv-69x6
No fix available
node_modules/smartapi-javascript/node_modules/axios
  smartapi-javascript  *
  Depends on vulnerable versions of axios
  Depends on vulnerable versions of public-ip
  node_modules/smartapi-javascript

got  <11.8.5
Severity: moderate
Got allows a redirect to a UNIX socket - https://github.com/advisories/GHSA-pfrx-2q88-qq97
fix available via `npm audit fix`
node_modules/got
  public-ip  2.1.0 - 4.0.4
  Depends on vulnerable versions of got
  node_modules/public-ip

4 vulnerabilities (2 moderate, 2 high)

To address issues that do not require attention, run:
  npm audit fix

Some issues need review, and may require choosing
a different dependency.

@vbhv4GitHub
Copy link

Someone please merge this one.

@learningdeveloper-dev
Copy link
Author

@gulshan178 Can you please review and comment on this

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants