From e3cd5b4c5c92ff1107f03f04d691ba8ed214da4d Mon Sep 17 00:00:00 2001
From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com>
Date: Wed, 18 Dec 2024 16:15:14 +0100
Subject: [PATCH] fix(lambda): bump axios from 1.7.7 to 1.7.9 in /lambdas
(#4305)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Bumps [axios](https://github.com/axios/axios) from 1.7.7 to 1.7.9.
Release notes
Sourced from axios's
releases.
Release v1.7.9
Release notes:
Reverts
Contributors to this release
Release v1.7.8
Release notes:
Bug Fixes
- allow passing a callback as paramsSerializer to buildURL (#6680)
(eac4619)
- core: fixed config merging bug (#6668)
(5d99fe4)
- fixed width form to not shrink after 'Send Request' button is
clicked (#6644)
(7ccd5fd)
- http: add support for File objects as payload in
http adapter (#6588)
(#6605)
(6841d8d)
- http: fixed proxy-from-env module import (#5222)
(12b3295)
- http: use
globalThis.TextEncoder
when
available (#6634)
(df956d1)
- ios11 breaks when build (#6608)
(7638952)
- types: add missing types for mergeConfig function
(#6590)
(00de614)
- types: export CJS types from ESM (#6218)
(c71811b)
- updated stream aborted error message to be more clear (#6615)
(cc3217a)
- use URL API instead of DOM to fix a potential vulnerability warning;
(#6714)
(0a8d6e1)
Contributors to this release
Changelog
Sourced from axios's
changelog.
1.7.9
(2024-12-04)
Reverts
Contributors to this release
1.7.8
(2024-11-25)
Bug Fixes
- allow passing a callback as paramsSerializer to buildURL (#6680)
(eac4619)
- core: fixed config merging bug (#6668)
(5d99fe4)
- fixed width form to not shrink after 'Send Request' button is
clicked (#6644)
(7ccd5fd)
- http: add support for File objects as payload in
http adapter (#6588)
(#6605)
(6841d8d)
- http: fixed proxy-from-env module import (#5222)
(12b3295)
- http: use
globalThis.TextEncoder
when
available (#6634)
(df956d1)
- ios11 breaks when build (#6608)
(7638952)
- types: add missing types for mergeConfig function
(#6590)
(00de614)
- types: export CJS types from ESM (#6218)
(c71811b)
- updated stream aborted error message to be more clear (#6615)
(cc3217a)
- use URL API instead of DOM to fix a potential vulnerability warning;
(#6714)
(0a8d6e1)
Contributors to this release
Commits
[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=axios&package-manager=npm_and_yarn&previous-version=1.7.7&new-version=1.7.9)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
Signed-off-by: dependabot[bot]
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
---
lambdas/functions/gh-agent-syncer/package.json | 2 +-
lambdas/yarn.lock | 15 +++++++++++++--
2 files changed, 14 insertions(+), 3 deletions(-)
diff --git a/lambdas/functions/gh-agent-syncer/package.json b/lambdas/functions/gh-agent-syncer/package.json
index 89294494f..6f9ec78e2 100644
--- a/lambdas/functions/gh-agent-syncer/package.json
+++ b/lambdas/functions/gh-agent-syncer/package.json
@@ -42,7 +42,7 @@
"@aws-sdk/types": "^3.696.0",
"@middy/core": "^4.7.0",
"@octokit/rest": "20.1.1",
- "axios": "^1.7.7"
+ "axios": "^1.7.9"
},
"nx": {
"includedScripts": [
diff --git a/lambdas/yarn.lock b/lambdas/yarn.lock
index a6167863b..6f717e232 100644
--- a/lambdas/yarn.lock
+++ b/lambdas/yarn.lock
@@ -250,7 +250,7 @@ __metadata:
"@vercel/ncc": "npm:^0.38.3"
aws-sdk-client-mock: "npm:^4.1.0"
aws-sdk-client-mock-jest: "npm:^4.1.0"
- axios: "npm:^1.7.7"
+ axios: "npm:^1.7.9"
eslint: "npm:^8.57.0"
eslint-plugin-prettier: "npm:5.2.1"
jest: "npm:^29.7.0"
@@ -5956,7 +5956,7 @@ __metadata:
languageName: node
linkType: hard
-"axios@npm:^1.7.4, axios@npm:^1.7.7":
+"axios@npm:^1.7.4":
version: 1.7.7
resolution: "axios@npm:1.7.7"
dependencies:
@@ -5967,6 +5967,17 @@ __metadata:
languageName: node
linkType: hard
+"axios@npm:^1.7.9":
+ version: 1.7.9
+ resolution: "axios@npm:1.7.9"
+ dependencies:
+ follow-redirects: "npm:^1.15.6"
+ form-data: "npm:^4.0.0"
+ proxy-from-env: "npm:^1.1.0"
+ checksum: 10c0/b7a41e24b59fee5f0f26c1fc844b45b17442832eb3a0fb42dd4f1430eb4abc571fe168e67913e8a1d91c993232bd1d1ab03e20e4d1fee8c6147649b576fc1b0b
+ languageName: node
+ linkType: hard
+
"babel-jest@npm:^29.7.0":
version: 29.7.0
resolution: "babel-jest@npm:29.7.0"