Skip to content

Wiz: Upgrade axios to 3.0.0-beta-20250912184522 (resolves 1 finding)#425

Closed
wiz-0f98cca50a[bot] wants to merge 1 commit into
mainfrom
wiz-remediation-2026-04-24-6bdc234b8ccf
Closed

Wiz: Upgrade axios to 3.0.0-beta-20250912184522 (resolves 1 finding)#425
wiz-0f98cca50a[bot] wants to merge 1 commit into
mainfrom
wiz-remediation-2026-04-24-6bdc234b8ccf

Conversation

@wiz-0f98cca50a
Copy link
Copy Markdown

Wiz Remediation Pull Request Banner

Wiz has created this PR to fix 1 finding detected in this project

Changes were made to the following file(s):

  • packages/demo/frontend/package.json

Vulnerabilities:

Component Findings Locations
axios
1.13.6 → 3.0.0-beta-20250912184522
Medium CVE-2026-40175 /packages/demo/frontend/package.json

To detect these findings earlier in the dev lifecycle, try using Wiz Code VS Code Extension.

@wiz-0f98cca50a wiz-0f98cca50a Bot requested a review from a team as a code owner April 24, 2026 08:17
@wiz-0f98cca50a wiz-0f98cca50a Bot requested a review from its-everdred April 24, 2026 08:17
@netlify
Copy link
Copy Markdown

netlify Bot commented Apr 24, 2026

Deploy Preview for actions-ui failed. Why did it fail? →

Name Link
🔨 Latest commit f84b0bd
🔍 Latest deploy log https://app.netlify.com/projects/actions-ui/deploys/69eb270a0524920008d93dba

tremarkley
tremarkley previously approved these changes Apr 24, 2026
@tremarkley tremarkley dismissed their stale review April 24, 2026 16:26

removing this review. looking closer this doesnt look right

@jefr90
Copy link
Copy Markdown
Contributor

jefr90 commented May 15, 2026

Closing: axios 3.0.0-beta is a pre-release dependency, not suitable for the SDK. We'll address the underlying vuln via a stable upgrade when available.

@jefr90 jefr90 closed this May 15, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants