Skip to content

fix(deps): patch axios security alerts and deduplicate dependencies - #4357

Merged
martinothamar merged 1 commit into
Altinn:mainfrom
martinothamar-agent:fix/axios-security-dedupe
Oct 2, 2026
Merged

martinothamar merged 1 commit into
Altinn:mainfrom
martinothamar-agent:fix/axios-security-dedupe

Conversation

@martinothamar-agent

@martinothamar-agent martinothamar-agent commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Description

Upgrade Axios 1.18.0 → 1.20.0 to address all twelve Dependabot alerts (#383–#394; CVE-2026-101898–101909). Deduplicate compatible form-data, follow-redirects, and hasown versions without overrides. Overlaps #4354, with deduplication included.

Production risk

Low expected compatibility risk, but broad production impact. After backport, a stable 4.34 release updates the 4 and 4.34 CDN aliases. Apps using these aliases receive the change on their next bundle load. A regression could affect loading, autosave, attachments, submission, session refresh, or PDF requests.

Axios ships in the browser bundle; the three deduplicated dependencies do not. Current calls use explicit methods and preserve interceptor config/headers. No complete exploit path was identified, but upstream fixes are available for all alerts. The main browser behavior change to watch is navigation-cancelled XHR now rejecting with ECONNABORTED; this can affect errors and retries. Upstream changes.

Before release, verify backport CI/Cypress and smoke-test saving/reloading, attachments, submission, session expiry, PDF, and navigation during requests. The existing rollback workflow can restore the previous release to the floating aliases; loaded pages need a reload. Rollback temporarily restores the vulnerabilities.

Verification/QA

  • Passed: immutable install, targeted dedupe check, type checks, lint, production build, and 165 unit suites (3,605 tests).
  • Passed: unmocked jsdom XHR checks for JSON requests, raw File uploads, PDF trace headers, and HTTP errors.
  • Remaining: real-browser/backend validation of the backported release. Most unit tests mock Axios.
  • No documentation, accessibility, or Studio changes required. Backport recommended.

@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 72f4fa77-b88c-4e62-9884-982b93dc5ecc

📥 Commits

Reviewing files that changed from the base of the PR and between 0252308 and 4069d59.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (1)
  • package.json

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The axios dependency version in package.json changed from 1.18.0 to 1.20.0.

Changes

Axios dependency update

Layer / File(s) Summary
Axios version update
package.json
The dependency version changed from 1.18.0 to 1.20.0.

Priority: ➖ Normal

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 4069d

The Axios dependency update is paired with its lockfile resolution, and no concrete merge-blocking regression is established. Proceed with normal checks.

Architecture Summary

Architecture risk: 🔵 Low · up to 4069d

The change affects 1 system.

Changed systems: package.json

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — package.json (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in package.json: The axios dependency version changed from 1.18.0 to 1.20.0.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly identifies the Axios dependency security update and dependency deduplication. It is concise and relevant to the main changes.
Description check ✅ Passed The description provides a detailed change summary, production risk assessment, verification results, remaining validation, and impact on documentation, accessibility, and Studio. It omits explicit Re…
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@martinothamar martinothamar added kind/dependencies Pull requests that update a dependency file dependencies Pull requests that update a dependency file backport This PR should be cherry-picked onto older release branches labels Oct 1, 2026
@martinothamar
martinothamar merged commit 7af5af9 into Altinn:main Oct 2, 2026
10 of 14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport This PR should be cherry-picked onto older release branches dependencies Pull requests that update a dependency file kind/dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants