fix(deps): patch axios security alerts and deduplicate dependencies - #4357
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe ChangesAxios dependency update
Priority: ➖ Normal Estimated code review effort: 1 (Trivial) | ~3 minutes Change: Other Merge Risk: ⚪ Minimal · up to The Axios dependency update is paired with its lockfile resolution, and no concrete merge-blocking regression is established. Proceed with normal checks. Architecture SummaryArchitecture risk: 🔵 Low · up to The change affects 1 system. Changed systems: Architecture concerns Review detailsSystems and components
Before / after behavior
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Description
Upgrade Axios 1.18.0 → 1.20.0 to address all twelve Dependabot alerts (#383–#394; CVE-2026-101898–101909). Deduplicate compatible
form-data,follow-redirects, andhasownversions without overrides. Overlaps #4354, with deduplication included.Production risk
Low expected compatibility risk, but broad production impact. After backport, a stable 4.34 release updates the
4and4.34CDN aliases. Apps using these aliases receive the change on their next bundle load. A regression could affect loading, autosave, attachments, submission, session refresh, or PDF requests.Axios ships in the browser bundle; the three deduplicated dependencies do not. Current calls use explicit methods and preserve interceptor config/headers. No complete exploit path was identified, but upstream fixes are available for all alerts. The main browser behavior change to watch is navigation-cancelled XHR now rejecting with
ECONNABORTED; this can affect errors and retries. Upstream changes.Before release, verify backport CI/Cypress and smoke-test saving/reloading, attachments, submission, session expiry, PDF, and navigation during requests. The existing rollback workflow can restore the previous release to the floating aliases; loaded pages need a reload. Rollback temporarily restores the vulnerabilities.
Verification/QA