Bump axios to 1.7.4 to resolve vulnerability #567
Labels
bug
This issue is a bug.
p1
This is a high priority issue
pending-release
This issue will be fixed by an approved PR that hasn't been released yet.
Describe the bug
AWS SDK JavaScript team received a report for vulnerability in
axios
library which is a dependency ofaws-crt
, which in turn is a dependency of some SDK client packages.Reported in
aws-sdk-js-v3
: aws/aws-sdk-js-v3#6381Affected
axios
versions: >= 1.3.2, <= 1.7.3Current version used in CRT:
^1.7.2
Expected Behavior
No vulnerabilities!
Current Behavior
Reproduction Steps
Possible Solution
Consider bumping axios to
^1.7.4
Additional Information/Context
No response
aws-crt-nodejs version used
latest
nodejs version used
20
Operating System and version
macOS
The text was updated successfully, but these errors were encountered: