Package requires a security update
plamber opened this issue ยท 2 comments
plamber commented
Describe the bug
We recently upgraded to the latest version 1.17.0 and we receive a high severity vulnerability caused by axios.
Server-Side Request Forgery in axios - GHSA-8hc4-vh64-cxmj
Would it be possible to update the package with the hotfixes?
Thank you
Mopholo commented
This advisory says that a vulnerability still exists and isn't resolved until axios 1.7.3
liuweiGL commented
๐ This issue has been resolved in version 1.17.6 ๐
The release is available on:
Your semantic-release bot ๐ฆ๐