Skip to content

Commit 5d15171

Browse files
fix: add axios override to patch SSRF vulnerability (APS-18720)
Adds npm override for axios >=1.15.0 to fix GHSA-3p68-rc4w-qgx5 (NO_PROXY hostname normalization bypass leads to SSRF). The package is a transitive dev dependency. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
1 parent 53ce6a9 commit 5d15171

1 file changed

Lines changed: 5 additions & 1 deletion

File tree

package.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,12 +20,16 @@
2020
},
2121
"homepage": "https://github.com/browserstack/codecept-js-playwright-browserstack#readme",
2222
"devDependencies": {
23-
"browserstack-node-sdk": "latest",
23+
"browserstack-node-sdk": "^1.22.0",
2424
"codeceptjs": "^3.2.3",
2525
"playwright": "^1.41.2"
2626
},
2727
"dependencies": {
2828
"browserstack-local": "^1.5.2",
2929
"dotenv": "^16.0.0"
30+
},
31+
"overrides": {
32+
"serialize-javascript": ">=7.0.3",
33+
"axios": ">=1.15.0"
3034
}
3135
}

0 commit comments

Comments
 (0)