IBM/node-sdk-core

Fix CVE-2023-26159 updating to axios v1.6.4

luiof opened this issue ยท 2 comments

luiof commented

We are seeing a vulnerability in the node sdk core package.
The new axios version has been released https://github.com/axios/axios/releases/tag/v1.6.4 so it is possible to fix the vulnerability.

Thanks for reporting this issue! It will be solved as soon as the linked PR gets merged in.

๐ŸŽ‰ This issue has been resolved in version 4.2.2 ๐ŸŽ‰

The release is available on:

Your semantic-release bot ๐Ÿ“ฆ๐Ÿš€