Fix CVE-2023-26159 updating to axios v1.6.4
luiof opened this issue ยท 2 comments
luiof commented
We are seeing a vulnerability in the node sdk core package.
The new axios version has been released https://github.com/axios/axios/releases/tag/v1.6.4 so it is possible to fix the vulnerability.
pyrooka commented
Thanks for reporting this issue! It will be solved as soon as the linked PR gets merged in.
ibm-devx-sdk commented
๐ This issue has been resolved in version 4.2.2 ๐
The release is available on:
npm package (@latest dist-tag)
- GitHub release
Your semantic-release bot ๐ฆ๐