Skip to content

fix(reference): upgrade axios to 1.15.0 to address critical vulnerability#5161

Merged
robert-hebel-sb merged 2 commits intomainfrom
fix/address-critical-axios-vulnerability
Apr 13, 2026
Merged

fix(reference): upgrade axios to 1.15.0 to address critical vulnerability#5161
robert-hebel-sb merged 2 commits intomainfrom
fix/address-critical-axios-vulnerability

Conversation

@robert-hebel-sb
Copy link
Copy Markdown
Contributor

@robert-hebel-sb robert-hebel-sb commented Apr 10, 2026

Summary

  • Bumps axios from ^1.12.2 to ^1.15.0 in packages/apidom-reference/package.json
  • Updates transitive dependency proxy-from-env from ^1.1.0 to ^2.1.0 (required by new axios version)
  • Also includes minor updates to dev dependencies (@microsoft/api-extractor, @rushstack/*, vite, lodash, etc.) pulled in by npm install

…lity

Bumps axios from ^1.12.2 to ^1.15.0 in apidom-reference package.
Also updates proxy-from-env from ^1.1.0 to ^2.1.0 as required by
the new axios version.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@robert-hebel-sb robert-hebel-sb added the security fix Security fix generated by WhiteSource label Apr 10, 2026
@robert-hebel-sb robert-hebel-sb merged commit 1425b24 into main Apr 13, 2026
9 checks passed
@robert-hebel-sb robert-hebel-sb deleted the fix/address-critical-axios-vulnerability branch April 13, 2026 09:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fix Security fix generated by WhiteSource

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants