Skip to content
This repository has been archived by the owner on Mar 7, 2025. It is now read-only.

[Snyk] Upgrade react-axios from 2.0.3 to 2.0.6 #48

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

mmkobylin1
Copy link
Contributor

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade react-axios from 2.0.3 to 2.0.6.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 3 versions ahead of your current version.
  • The recommended version was released 2 years ago, on 2022-06-04.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Prototype Pollution
SNYK-JS-LOADERUTILS-3043105
375/1000
Why? CVSS 7.5
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
375/1000
Why? CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-LOADERUTILS-3042992
375/1000
Why? CVSS 7.5
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-LOADERUTILS-3105943
375/1000
Why? CVSS 7.5
No Known Exploit
Prototype Pollution
SNYK-JS-MINIMIST-559764
375/1000
Why? CVSS 7.5
Proof of Concept
Prototype Pollution
SNYK-JS-JSON5-3182856
375/1000
Why? CVSS 7.5
Proof of Concept
Prototype Pollution
SNYK-JS-MINIMIST-559764
375/1000
Why? CVSS 7.5
Proof of Concept
Prototype Pollution
SNYK-JS-MINIMIST-2429795
375/1000
Why? CVSS 7.5
Proof of Concept
Prototype Pollution
SNYK-JS-MINIMIST-2429795
375/1000
Why? CVSS 7.5
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: react-axios
  • 2.0.6 - 2022-06-04

    Updating the supported peer dependencies to include React ^18.0.0.
    Fixing an issue with GET requests that was providing the data attribute when it does not support it.

    Full Changelog: v2.0.5...v2.0.6

  • 2.0.5 - 2021-03-04

    This release has the following updates:
    Updating legacy context methods and removing UNSAFE_ lifecycle methods to be compatible with React.StrictMode.

  • 2.0.4 - 2020-12-17

    2.0.4

  • 2.0.3 - 2018-11-23

    This release has the following updates:
    New withAxios(options)(ComponentToBeWrapped) HoC to allow the consumer more flexibility to create complex Request components.
    Renaming onReload(props) to makeRequest(props). This change is transparent and the actual function name is up to the consumers implementation of the Request child callback function.

from react-axios GitHub release notes
Commit messages
Package name: react-axios
  • e094995 2.0.6
  • b0097ff bumping versions and adding react 18 to the supported peer deps.
  • 195a042 GET requests do not have data
  • 91dd6a5 2.0.5
  • 279628f Fixing React strict mode errors. Removed UNSAFE_ lifecycle methods and legacy context references.
  • b5eb008 2.0.4
  • 67d5157 add release to package.json scripts.
  • 287d911 updating peer dependancies fixing warnings.
  • bcdd77e removing yarn lock file

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants