Skip to content

unpin and upgrade axios version #4

@micalevisk

Description

@micalevisk

Hi! Thank you for this lib!

I was wondering why did you fixed the version of axios dependency. Why not use the semver range ^0.21.1 instead? (or even ^0.24.0)

"axios": "0.21.1",

Also, npm audit reports this vulnerability of [email protected]

axios  <=0.21.1
Severity: high
Incorrect Comparison in axios - https://github.com/advisories/GHSA-cph5-m8f7-6c5x
No fix available
node_modules/nestjs-http-promise/node_modules/axios
  nestjs-http-promise  *
  Depends on vulnerable versions of axios
  node_modules/nestjs-http-promise

Metadata

Metadata

Assignees

Labels

featurefeature to add

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions