Skip to content

Conversation

behcet
Copy link
Contributor

@behcet behcet commented Aug 11, 2025

Summary

This PR updates axios to 1.11.0 to address GHSA-fjxv-7rqg-78g4

A few minor releases for axios happened with this change, but AFAICT no other changes are needed.

This PR includes these changes:

Requirements (place an x in each [ ])

@mwbrooks mwbrooks added semver:patch pkg:web-api applies to `@slack/web-api` dependencies Pull requests that update a dependency file labels Aug 12, 2025
@mwbrooks mwbrooks added this to the [email protected] milestone Aug 12, 2025
@mwbrooks mwbrooks changed the title Bump axios to 1.11.0 for the latest changes chore(deps): bump axios from ^1.8.3 to ^1.11.0 in @slack/web-api Aug 12, 2025
@mwbrooks
Copy link
Member

Hey @behcet 👋🏻

Thanks a lot for the PR that bumps axios to be a minimum of 1.11.0. This is a good way to address the vulnerability in form-data, which is fixed in [email protected].

Appreciate that you've taken the time to sign the CLA as well. 🙇🏻 I'll approve our CI/CD to run and then drop an approval on the PR! 🚀

Copy link

codecov bot commented Aug 12, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 92.74%. Comparing base (a11d81d) to head (2dbe0f5).
⚠️ Report is 1 commits behind head on main.

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #2332   +/-   ##
=======================================
  Coverage   92.74%   92.74%           
=======================================
  Files          38       38           
  Lines       10660    10660           
  Branches      687      687           
=======================================
  Hits         9887     9887           
  Misses        761      761           
  Partials       12       12           
Flag Coverage Δ
cli-hooks 95.23% <ø> (ø)
cli-test 94.74% <ø> (ø)
oauth 77.39% <ø> (ø)
socket-mode 61.87% <ø> (ø)
web-api 97.99% <ø> (ø)
webhook 96.66% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Copy link
Member

@mwbrooks mwbrooks left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Thanks @behcet 🚀 🌙 ✨

@mwbrooks mwbrooks merged commit c2a8c84 into slackapi:main Aug 12, 2025
57 checks passed
@zimeg
Copy link
Member

zimeg commented Aug 22, 2025

🗣️ Thanks again for sharing this! It's now released in @slack/[email protected]!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
cla:signed dependencies Pull requests that update a dependency file pkg:web-api applies to `@slack/web-api` semver:patch
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants