Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion src/ui/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -98,7 +98,7 @@
"apollo3-cache-persist": "^0.9.1",
"app": "link:./src",
"assets": "link:./assets",
"axios": "^0.21.4",
"axios": "^0.30.2",
"cross-fetch": "^3.1.5",
"date-fns": "^2.29.3",
"google-protobuf": "^3.15.5",
Expand Down
64 changes: 63 additions & 1 deletion src/ui/yarn.lock
Original file line number Diff line number Diff line change
Expand Up @@ -2783,7 +2783,7 @@
app: "link:./src"
archiver: ^5.0.2
assets: "link:./assets"
axios: ^0.21.4
axios: ^0.30.2
babel-jest: ^27.3.1
canvas: ^2.11.2
case-sensitive-paths-webpack-plugin: ^2.1.2
Expand Down Expand Up @@ -4658,6 +4658,17 @@
languageName: node
linkType: hard

"axios@npm:^0.30.2":
version: 0.30.2
resolution: "axios@npm:0.30.2"
dependencies:
follow-redirects: ^1.15.4
form-data: ^4.0.4
proxy-from-env: ^1.1.0
checksum: c21a17bab1385c1b9aad0d3a293397be418a24d16ef02b34bb332a40c4ae645ce4e06ff2cf44acd5fb3cacea6fe6e6ea018ed581e0cd21fdfbd74e4e94f54f92
languageName: node
linkType: hard
Comment on lines +4661 to +4670

Check failure

Code scanning / trivy-fs

axios: Axios DoS via lack of data size check High

Package: axios
Installed Version: 0.30.2
Vulnerability CVE-2025-58754
Severity: HIGH
Fixed Version: 1.12.0
Link: CVE-2025-58754

"b4a@npm:^1.6.4":
version: 1.6.4
resolution: "b4a@npm:1.6.4"
Expand Down Expand Up @@ -6998,6 +7009,18 @@
languageName: node
linkType: hard

"es-set-tostringtag@npm:^2.1.0":
version: 2.1.0
resolution: "es-set-tostringtag@npm:2.1.0"
dependencies:
es-errors: ^1.3.0
get-intrinsic: ^1.2.6
has-tostringtag: ^1.0.2
hasown: ^2.0.2
checksum: 789f35de4be3dc8d11fdcb91bc26af4ae3e6d602caa93299a8c45cf05d36cc5081454ae2a6d3afa09cceca214b76c046e4f8151e092e6fc7feeb5efb9e794fc6
languageName: node
linkType: hard

"es-shim-unscopables@npm:^1.0.0":
version: 1.0.0
resolution: "es-shim-unscopables@npm:1.0.0"
Expand Down Expand Up @@ -8119,6 +8142,16 @@
languageName: node
linkType: hard

"follow-redirects@npm:^1.15.4":
version: 1.15.11
resolution: "follow-redirects@npm:1.15.11"
peerDependenciesMeta:
debug:
optional: true
checksum: 20bf55e9504f59e6cc3743ba27edb2ebf41edea1baab34799408f2c050f73f0c612728db21c691276296d2795ea8a812dc532a98e8793619fcab91abe06d017f
languageName: node
linkType: hard

"for-each@npm:^0.3.3":
version: 0.3.3
resolution: "for-each@npm:0.3.3"
Expand Down Expand Up @@ -8153,6 +8186,19 @@
languageName: node
linkType: hard

"form-data@npm:^4.0.4":
version: 4.0.4
resolution: "form-data@npm:4.0.4"
dependencies:
asynckit: ^0.4.0
combined-stream: ^1.0.8
es-set-tostringtag: ^2.1.0
hasown: ^2.0.2
mime-types: ^2.1.12
checksum: 9b7788836df9fa5a6999e0c02515b001946b2a868cfe53f026c69e2c537a2ff9fbfb8e9d2b678744628f3dc7a2d6e14e4e45dfaf68aa6239727f0bdb8ce0abf2
languageName: node
linkType: hard

"form-data@npm:~2.3.2":
version: 2.3.3
resolution: "form-data@npm:2.3.3"
Expand Down Expand Up @@ -8741,6 +8787,15 @@
languageName: node
linkType: hard

"has-tostringtag@npm:^1.0.2":
version: 1.0.2
resolution: "has-tostringtag@npm:1.0.2"
dependencies:
has-symbols: ^1.0.3
checksum: 999d60bb753ad714356b2c6c87b7fb74f32463b8426e159397da4bde5bca7e598ab1073f4d8d4deafac297f2eb311484cd177af242776bf05f0d11565680468d
languageName: node
linkType: hard

"has-unicode@npm:^2.0.0, has-unicode@npm:^2.0.1":
version: 2.0.1
resolution: "has-unicode@npm:2.0.1"
Expand Down Expand Up @@ -12692,6 +12747,13 @@
languageName: node
linkType: hard

"proxy-from-env@npm:^1.1.0":
version: 1.1.0
resolution: "proxy-from-env@npm:1.1.0"
checksum: ed7fcc2ba0a33404958e34d95d18638249a68c430e30fcb6c478497d72739ba64ce9810a24f53a7d921d0c065e5b78e3822759800698167256b04659366ca4d4
languageName: node
linkType: hard

"psl@npm:^1.1.33":
version: 1.8.0
resolution: "psl@npm:1.8.0"
Expand Down
Loading