Commit e4fd5ea
fix: upgrade nx transitive dep axios 1.12.0 → 1.15.0 (SECURE-3216)
Reinstall lerna to re-resolve nx 22.6.4 → 22.6.5, which upgrades its
transitive axios dependency from 1.12.0 to 1.15.0, addressing:
- CVE-2026-40175 (CRLF header injection / SSRF, CVSS 9.9)
- CVE-2025-62718 (NO_PROXY hostname normalization bypass, CVSS 9.3)
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>1 parent 5a1f209 commit e4fd5ea
2 files changed
Lines changed: 144 additions & 157 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
52 | 52 | | |
53 | 53 | | |
54 | 54 | | |
55 | | - | |
| 55 | + | |
56 | 56 | | |
57 | 57 | | |
58 | 58 | | |
| |||
0 commit comments