Commit e3fe0bd
security: pin axios to 1.13.4 — supply chain attack on 1.14.1
CVE: axios@1.14.1 pulls plain-crypto-js@4.2.1 (malware dropper)
Ref: https://x.com/feross
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>1 parent 289d584 commit e3fe0bd
1 file changed
+1
-1
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
19 | | - | |
| 19 | + | |
20 | 20 | | |
21 | 21 | | |
22 | 22 | | |
| |||
0 commit comments