Skip to content

Commit 6b46e37

Browse files
authored
Merge pull request #8465 from BitGo/fix/deps-axios-cve-2025-62718
fix(deps): pin axios to 1.15.0 for CVE-2025-62718
2 parents 811c442 + 45f6e05 commit 6b46e37

File tree

2 files changed

+12
-7
lines changed

2 files changed

+12
-7
lines changed

package.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -102,7 +102,7 @@
102102
"@polkadot/keyring": "13.5.6",
103103
"elliptic": "^6.6.1",
104104
"cookie": "^0.7.1",
105-
"axios": "^1.13.0",
105+
"axios": "1.15.0",
106106
"canvg": "4.0.3",
107107
"**/stellar-sdk/**/bignumber.js": "4.1.0",
108108
"**/stellar-base/**/bignumber.js": "4.1.0",
@@ -165,7 +165,7 @@
165165
"test:prepare-release": "mocha --require tsx ./scripts/tests/prepareRelease/prepare-release-main.test.ts"
166166
},
167167
"dependencies": {
168-
"axios": "^1.13.0",
168+
"axios": "1.15.0",
169169
"terser": "^5.14.2",
170170
"tmp": "^0.2.3",
171171
"bigint-buffer": "npm:@trufflesuite/bigint-buffer@1.1.10"

yarn.lock

Lines changed: 10 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -7552,14 +7552,14 @@ aws4@^1.8.0:
75527552
resolved "https://registry.npmjs.org/aws4/-/aws4-1.13.2.tgz"
75537553
integrity sha512-lHe62zvbTB5eEABUVi/AwVh0ZKY9rMMDhmm+eeyuuUQbQ3+J+fONVQOZyj+DdrvD4BY33uYniyRJ4UJIaSKAfw==
75547554

7555-
axios@0.25.0, axios@0.27.2, axios@1.7.4, axios@^0.21.2, axios@^0.26.1, axios@^1.13.0, axios@^1.6.0, axios@^1.8.3:
7556-
version "1.13.5"
7557-
resolved "https://registry.npmjs.org/axios/-/axios-1.13.5.tgz#5e464688fa127e11a660a2c49441c009f6567a43"
7558-
integrity sha512-cz4ur7Vb0xS4/KUN0tPWe44eqxrIu31me+fbang3ijiNscE129POzipJJA6zniq2C/Z6sJCjMimjS8Lc/GAs8Q==
7555+
axios@0.25.0, axios@0.27.2, axios@1.15.0, axios@1.7.4, axios@^0.21.2, axios@^0.26.1, axios@^1.13.0, axios@^1.6.0, axios@^1.8.3:
7556+
version "1.15.0"
7557+
resolved "https://registry.npmjs.org/axios/-/axios-1.15.0.tgz#0fcee91ef03d386514474904b27863b2c683bf4f"
7558+
integrity sha512-wWyJDlAatxk30ZJer+GeCWS209sA42X+N5jU2jy6oHTp7ufw8uzUTVFBX9+wTfAlhiJXGS0Bq7X6efruWjuK9Q==
75597559
dependencies:
75607560
follow-redirects "^1.15.11"
75617561
form-data "^4.0.5"
7562-
proxy-from-env "^1.1.0"
7562+
proxy-from-env "^2.1.0"
75637563

75647564
b4a@^1.6.4:
75657565
version "1.7.3"
@@ -17476,6 +17476,11 @@ proxy-from-env@^1.1.0:
1747617476
resolved "https://registry.npmjs.org/proxy-from-env/-/proxy-from-env-1.1.0.tgz"
1747717477
integrity sha512-D+zkORCbA9f1tdWRK0RaCR3GPv50cMxcrz4X8k5LTSUD1Dkw47mKJEZQNunItRTkWwgtaUSo1RVFRIG9ZXiFYg==
1747817478

17479+
proxy-from-env@^2.1.0:
17480+
version "2.1.0"
17481+
resolved "https://registry.npmjs.org/proxy-from-env/-/proxy-from-env-2.1.0.tgz#a7487568adad577cfaaa7e88c49cab3ab3081aba"
17482+
integrity sha512-cJ+oHTW1VAEa8cJslgmUZrc+sjRKgAKl3Zyse6+PV38hZe/V6Z14TbCuXcan9F9ghlz4QrFr2c92TNF82UkYHA==
17483+
1747917484
proxyquire@^2.1.3:
1748017485
version "2.1.3"
1748117486
resolved "https://registry.npmjs.org/proxyquire/-/proxyquire-2.1.3.tgz"

0 commit comments

Comments
 (0)