[Snyk] Upgrade axios from 0.27.2 to 0.30.2#622
[Snyk] Upgrade axios from 0.27.2 to 0.30.2#622macpro-snyk-service-account wants to merge 2 commits intomasterfrom
Conversation
Snyk has created this PR to upgrade axios from 0.27.2 to 0.30.2. See this package in yarn: axios See this project in Snyk: https://app.snyk.io/org/macpro-macpro/project/77c22646-6ddf-417a-a629-defd670f4bc8?utm_source=github&utm_medium=referral&page=upgrade-pr
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
|
This upgrade includes a significant behavioral change in version 0.28.0 that may affect network requests in certain environments. Axios now automatically reads proxy settings from environment variables, which can cause requests to fail if a proxy is configured unexpectedly. Additionally, there are reports of changes to the default parameter serialization for GET requests. Source: GitHub Issues
|
|
This upgrade to axios includes behavioral changes in version 0.28.0 that may require attention. Specifically, there are changes to default proxy handling and URL parameter serialization that could affect applications in certain environments or with specific API request patterns. Source: Package documentation
|
Snyk has created this PR to upgrade axios from 0.27.2 to 0.30.2. See this package in yarn: axios See this project in Snyk: https://app.snyk.io/org/macpro-macpro/project/77c22646-6ddf-417a-a629-defd670f4bc8?utm_source=github&utm_medium=referral&page=upgrade-pr
|
This upgrade includes a notable behavioral change in version 0.28.0 that may affect applications in specific network environments. Axios will now automatically use proxy settings from environment variables, which can lead to unexpected connection failures. Highlights:
Source: Package documentation
|
Snyk has created this PR to upgrade axios from 0.27.2 to 0.30.2.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version is 6 versions ahead of your current version.
The recommended version was released 2 months ago.
This upgrade to axios crosses multiple minor versions, introducing a notable breaking change in how proxy environment variables are handled starting in v0.28.0. While not an API signature change, it can unexpectedly alter request routing in environments where proxy variables are set.
Source: Package documentation
Recommendation: Verify application behavior in environments where
npm_config_proxyor other proxy environment variables might be set before merging.Issues fixed by the recommended upgrade:
SNYK-JS-AXIOS-6032459
SNYK-JS-FOLLOWREDIRECTS-6141137
SNYK-JS-AXIOS-6124857
SNYK-JS-AXIOS-9292519
SNYK-JS-AXIOS-9403194
SNYK-JS-FOLLOWREDIRECTS-6444610
SNYK-JS-FORMDATA-10841150
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information: