Skip to content
This repository was archived by the owner on Apr 2, 2026. It is now read-only.

EM-000: Pin axios version to prevent supply chain attack - #286

Merged
baseilos merged 1 commit into
mainfrom
security/pin-axios-version
Apr 1, 2026
Merged

baseilos merged 1 commit into
mainfrom
security/pin-axios-version

Conversation

@syedad218

Copy link
Copy Markdown
Contributor

Summary

  • Adds axios 1.13.5 to existing overrides, preventing automatic upgrade to compromised versions (1.14.1 / 0.30.4) from the axios npm supply chain attack
  • axios is not a direct dependency in this repo but is pulled in transitively

Test plan

  • Verify npm install resolves axios to 1.13.5
  • Verify existing tests pass

🤖 Generated with Claude Code

Add overrides to pin axios at 1.13.5, preventing automatic
upgrade to compromised versions (1.14.1 / 0.30.4).

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@baseilos baseilos changed the title Pin transitive axios version to prevent supply chain attack EM-000: Pin axios version to prevent supply chain attack Apr 1, 2026
@baseilos
baseilos merged commit 9faff21 into main Apr 1, 2026
3 checks passed
@baseilos
baseilos deleted the security/pin-axios-version branch April 1, 2026 07:56
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants