chore(deps): bump axios from 1.16.0 to 1.18.0 - #27
Conversation
Bumps [axios](https://github.com/axios/axios) from 1.16.0 to 1.18.0. - [Release notes](https://github.com/axios/axios/releases) - [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md) - [Commits](axios/axios@v1.16.0...v1.18.0) --- updated-dependencies: - dependency-name: axios dependency-version: 1.18.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
joshuanapoli
left a comment
There was a problem hiding this comment.
Summary
Minor bump of the direct runtime dependency axios 1.16.0→1.18.0 (package.json ^1.15.2→^1.18.0, plus lockfile/PnP/cache). axios is used in src/workable-api.ts for well-formed same-origin GETs against the Workable API (Bearer auth) and one presigned-S3 download. The release is security hardening plus bug fixes.
Risks
Low. The potentially breaking 1.17/1.18 changes — stricter URL validation (ERR_INVALID_URL), cross-origin redirect header stripping, validateStatus: undefined now opt-in via a transitional flag — do not apply here: all requests use well-formed same-origin https://{subdomain}.workable.com/... URLs, auth headers are not sent cross-origin, and the S3 download carries no credentials. The bump adds stable transitive deps https-proxy-agent@5.0.1 + agent-base@6. Note: unit tests mock axios, so green CI does not exercise live HTTP behavior — but the changes are hardening and the bump is semver-compatible.
Analysis
- Reviewed the 1.17/1.18 changelog; none of the hardened paths are triggered by the current usage.
- Confirmed usage is limited to simple GETs in
src/workable-api.ts(mocked in tests). - CI
testcheck passes. Low regression risk — approving and merging.
Bumps axios from 1.16.0 to 1.18.0.
Release notes
Sourced from axios's releases.
... (truncated)
Changelog
Sourced from axios's changelog.
... (truncated)
Commits
2d06f96chore(release): prepare release 1.18.0 (#11003)32fc489fix: malformed http urls (#11000)b40ce49chore(deps-dev): bump the development_dependencies group with 10 updates (#10...fe964f9docs: mark proxy config as Node.js only (#10995)5f229d2chore(deps): bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions ...fae9d4edocs: clarify package update PR policy (#10992)28ab2cechore(deps-dev): bump the development_dependencies group with 2 updates (#10989)a8e4f13fix(core): keep default validateStatus when request passes undefined (#10899)614f455docs: publish v1.17.0 release notes (#10988)6bb12c1fix: custom auth headers not stripped on cross-origin redirects (#10892)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.