Skip to content

UID2-8009: preventive upgrade axios to 1.20.0 (CVE-2026-101898) - #228

Merged
swibi-ttd merged 1 commit into
mainfrom
swi-cve-2026-101898
Oct 2, 2026
Merged

swibi-ttd merged 1 commit into
mainfrom
swi-cve-2026-101898

Conversation

@swibi-ttd

Copy link
Copy Markdown
Contributor

Preventive update for CVE-2026-101898 (HIGH, axios): 1.18.1 → 1.20.0.

Regenerated with npm update axios --package-lock-only --prefix web-integrations/google-secure-signals/client-server, npm update axios --package-lock-only --prefix web-integrations/google-secure-signals/server-side, npm update axios --package-lock-only --prefix web-integrations/prebid-integrations/client-server, npm update axios --package-lock-only --prefix web-integrations/javascript-sdk/client-server, npm update axios --package-lock-only --prefix web-integrations/server-side.

Verified with trivy fs: CVE-2026-101898 was reported before the change and is gone after it (20 finding(s) before, 8 after).


Opened by uid2-vul-scan-agent (general_use_claude-opus-4-8). The assessment and fix rationale are on the ticket named in the title.

@swibi-ttd swibi-ttd changed the title [TICKET] preventive upgrade axios to 1.20.0 (CVE-2026-101898) UID2-8009: preventive upgrade axios to 1.20.0 (CVE-2026-101898) Oct 1, 2026
@swibi-ttd
swibi-ttd force-pushed the swi-cve-2026-101898 branch from f330637 to 362eb58 Compare October 2, 2026 00:54
@swibi-ttd
swibi-ttd merged commit bfcaba9 into main Oct 2, 2026
1 of 3 checks passed
@swibi-ttd
swibi-ttd deleted the swi-cve-2026-101898 branch October 2, 2026 03:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants