Skip to content

security: resolve open dependabot alerts - #26

Merged
Niharika-Shipthis merged 3 commits into
developfrom
bug/dependabot-alerts-sept
Sep 3, 2026
Merged

Niharika-Shipthis merged 3 commits into
developfrom
bug/dependabot-alerts-sept

Conversation

@muhammadali-1105

Copy link
Copy Markdown
Contributor
  • axios ^1.17.0 -> ^1.18.0 (proxy leak, prototype pollution, formDataToJSON DoS, maxBodyLength bypasses)
  • add overrides: form-data ^4.0.6 (CRLF injection), fast-uri ^3.1.5 (host confusion), js-yaml ^3.15.1 (quadratic CPU DoS), brace-expansion ^5.0.7 (DoS), @babel/core ^7.29.6 (arbitrary file read)

- axios ^1.17.0 -> ^1.18.0 (proxy leak, prototype pollution, formDataToJSON DoS, maxBodyLength bypasses)
- add overrides: form-data ^4.0.6 (CRLF injection), fast-uri ^3.1.5 (host confusion),
  js-yaml ^3.15.1 (quadratic CPU DoS), brace-expansion ^5.0.7 (DoS), @babel/core ^7.29.6 (arbitrary file read)
… functions

- Implemented a new integration test suite for the internalRequest function, covering various scenarios including successful GET requests, error handling, and query parameter serialization.
- Added tests for the uploadFile function to ensure proper handling of multipart/form-data uploads and filename sanitization.
- Updated package.json to adjust dependency overrides for minimatch and brace-expansion.
@Niharika-Shipthis
Niharika-Shipthis merged commit e973ba5 into develop Sep 3, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants