Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update Axios Version To 0.21.4 #1294

Closed
LuisOsta opened this issue Sep 4, 2021 · 4 comments
Closed

Update Axios Version To 0.21.4 #1294

LuisOsta opened this issue Sep 4, 2021 · 4 comments
Labels
status: help wanted requesting help from the community type: security known security issue

Comments

@LuisOsta
Copy link
Contributor

LuisOsta commented Sep 4, 2021

Issue Summary

Recently axios released a new version 0.21.2 that patched the security issue described here.

Currently
Since the SendGrid client uses the old version of axios, it will doesn't have the patch fix. You can see the version it specifies here

@LuisOsta LuisOsta changed the title Update Axios Version With Security Patch Update Axios Version To 0.21.2 Sep 4, 2021
@eshanholtz
Copy link
Contributor

This issue has been added to our internal backlog to be prioritized. Pull requests and +1s on the issue summary will help it move up the backlog.

@eshanholtz eshanholtz added status: help wanted requesting help from the community type: security known security issue labels Sep 7, 2021
@LuisOsta
Copy link
Contributor Author

LuisOsta commented Sep 7, 2021

@eshanholtz Thanks for the quick reply! I've gone ahead and made the PR necessary to fix this issue.

It actually turns out that the necessary fix version is 0.21.4

@LuisOsta LuisOsta changed the title Update Axios Version To 0.21.2 Update Axios Version To 0.21.4 Sep 7, 2021
@LuisOsta
Copy link
Contributor Author

LuisOsta commented Sep 7, 2021

You can see here that 0.21.4 doesn't have this vulnerability - https://www.sourceclear.com/vulnerability-database/libraries/axios/javascript/npm/lid-11324/summary

@LuisOsta
Copy link
Contributor Author

LuisOsta commented Sep 9, 2021

Just an update that the PR is ready and approved but just hasn't been merged in yet. In case anyone is following this thread

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
status: help wanted requesting help from the community type: security known security issue
Projects
None yet
Development

No branches or pull requests

3 participants