fix: resolve dependabot security vulnerabilities

- axios: 0.21.4 -> 1.13.5 (prototype pollution DoS)
- semver: force >=7.5.2 (ReDoS)
This commit is contained in:
2026-02-14 13:08:00 +03:00
parent 4b24072c79
commit c44469b8d1
2 changed files with 20 additions and 27 deletions
+3 -1
View File
@@ -45,6 +45,8 @@
"@types/node": "^22.10.5" "@types/node": "^22.10.5"
}, },
"resolutions": { "resolutions": {
"typescript": "^5.5.4" "typescript": "^5.5.4",
"axios": "^1.13.5",
"semver": "^7.5.2"
} }
} }
+17 -26
View File
@@ -2521,12 +2521,14 @@ __metadata:
languageName: node languageName: node
linkType: hard linkType: hard
"axios@npm:^0.21.1": "axios@npm:^1.13.5":
version: 0.21.4 version: 1.13.5
resolution: "axios@npm:0.21.4" resolution: "axios@npm:1.13.5"
dependencies: dependencies:
follow-redirects: "npm:^1.14.0" follow-redirects: "npm:^1.15.11"
checksum: 10/da644592cb6f8f9f8c64fdabd7e1396d6769d7a4c1ea5f8ae8beb5c2eb90a823e3a574352b0b934ac62edc762c0f52647753dc54f7d07279127a7e5c4cd20272 form-data: "npm:^4.0.5"
proxy-from-env: "npm:^1.1.0"
checksum: 10/db726d09902565ef9a0632893530028310e2ec2b95b727114eca1b101450b00014133dfc3871cffc87983fb922bca7e4874d7e2826d1550a377a157cdf3f05b6
languageName: node languageName: node
linkType: hard linkType: hard
@@ -4868,7 +4870,7 @@ __metadata:
languageName: node languageName: node
linkType: hard linkType: hard
"follow-redirects@npm:^1.0.0, follow-redirects@npm:^1.14.0": "follow-redirects@npm:^1.0.0, follow-redirects@npm:^1.15.11":
version: 1.15.11 version: 1.15.11
resolution: "follow-redirects@npm:1.15.11" resolution: "follow-redirects@npm:1.15.11"
peerDependenciesMeta: peerDependenciesMeta:
@@ -4901,7 +4903,7 @@ __metadata:
languageName: node languageName: node
linkType: hard linkType: hard
"form-data@npm:^4.0.0": "form-data@npm:^4.0.0, form-data@npm:^4.0.5":
version: 4.0.5 version: 4.0.5
resolution: "form-data@npm:4.0.5" resolution: "form-data@npm:4.0.5"
dependencies: dependencies:
@@ -8072,6 +8074,13 @@ __metadata:
languageName: node languageName: node
linkType: hard linkType: hard
"proxy-from-env@npm:^1.1.0":
version: 1.1.0
resolution: "proxy-from-env@npm:1.1.0"
checksum: 10/f0bb4a87cfd18f77bc2fba23ae49c3b378fb35143af16cc478171c623eebe181678f09439707ad80081d340d1593cd54a33a0113f3ccb3f4bc9451488780ee23
languageName: node
linkType: hard
"psl@npm:^1.1.33": "psl@npm:^1.1.33":
version: 1.15.0 version: 1.15.0
resolution: "psl@npm:1.15.0" resolution: "psl@npm:1.15.0"
@@ -8832,25 +8841,7 @@ __metadata:
languageName: node languageName: node
linkType: hard linkType: hard
"semver@npm:2 || 3 || 4 || 5": "semver@npm:^7.5.2":
version: 5.7.2
resolution: "semver@npm:5.7.2"
bin:
semver: bin/semver
checksum: 10/fca14418a174d4b4ef1fecb32c5941e3412d52a4d3d85165924ce3a47fbc7073372c26faf7484ceb4bbc2bde25880c6b97e492473dc7e9708fdfb1c6a02d546e
languageName: node
linkType: hard
"semver@npm:^6.0.0, semver@npm:^6.2.0, semver@npm:^6.3.0, semver@npm:^6.3.1":
version: 6.3.1
resolution: "semver@npm:6.3.1"
bin:
semver: bin/semver.js
checksum: 10/1ef3a85bd02a760c6ef76a45b8c1ce18226de40831e02a00bad78485390b98b6ccaa31046245fc63bba4a47a6a592b6c7eedc65cc47126e60489f9cc1ce3ed7e
languageName: node
linkType: hard
"semver@npm:^7.0.0, semver@npm:^7.3.4, semver@npm:^7.3.5, semver@npm:^7.3.7, semver@npm:^7.5.3, semver@npm:^7.5.4, semver@npm:^7.7.1":
version: 7.7.4 version: 7.7.4
resolution: "semver@npm:7.7.4" resolution: "semver@npm:7.7.4"
bin: bin: