Skip to content

Medium vulnerability : Update Axios to 1.8.2 #2169

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
2 of 7 tasks
JacobWilson01 opened this issue Mar 10, 2025 · 4 comments
Open
2 of 7 tasks

Medium vulnerability : Update Axios to 1.8.2 #2169

JacobWilson01 opened this issue Mar 10, 2025 · 4 comments
Labels
auto-triage-skip dependencies Pull requests that update a dependency file pkg:web-api applies to `@slack/web-api` pkg:webhook applies to `@slack/webhook` security

Comments

@JacobWilson01
Copy link

Mediumn Axios vulnerability fixed in 1.8.2:

Vulnerability: https://security.snyk.io/vuln/SNYK-JS-AXIOS-9292519

Packages:

Select all that apply:

  • @slack/web-api
  • @slack/rtm-api
  • @slack/webhooks
  • @slack/oauth
  • @slack/socket-mode
  • @slack/types
  • I don't know

Requirements

Please read the Contributing guidelines and Code of Conduct before creating this issue or pull request. By submitting, you are agreeing to those rules.

@zimeg zimeg added security pkg:web-api applies to `@slack/web-api` pkg:webhook applies to `@slack/webhook` dependencies Pull requests that update a dependency file and removed untriaged labels Mar 11, 2025
@zimeg
Copy link
Member

zimeg commented Mar 11, 2025

Hey @JacobWilson01 👋 Thanks for sharing this - we'll look into patching it soon! 🔒 ✨

Copy link

👋 It looks like this issue has been open for 30 days with no activity. We'll mark this as stale for now, and wait 10 days for an update or for further comment before closing this issue out. If you think this issue needs to be prioritized, please comment to get the thread going again! Maintainers also review issues marked as stale on a regular basis and comment or adjust status if the issue needs to be reprioritized.

@ajschmidt8
Copy link

@zimeg, it looks like this was addressed in #2172 and #2173, but no release was published. Do you know when these changes will be released?

@zimeg
Copy link
Member

zimeg commented Apr 22, 2025

@ajschmidt8 Thanks for following up! 🙏 ✨

Updates for a supported axios were included in releases @slack/[email protected] and @slack/[email protected] and are available for installation now! 🎁

I apologize for the confusion this open issue causes, but I am hoping to track downstream usage in the following PRs here too:

Though I don't have an exact timeline for those releases. FWIW your comment is a very helpful bump 😉

Of course I am also open to discussion about this, but IMO the rollout isn't quite finished across all packages 👀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
auto-triage-skip dependencies Pull requests that update a dependency file pkg:web-api applies to `@slack/web-api` pkg:webhook applies to `@slack/webhook` security
Projects
None yet
Development

No branches or pull requests

3 participants