Skip to content

fix(deps): patch axios and brace-expansion vulnerabilities - #20

Merged
redanthrax merged 1 commit into
masterfrom
fix/pnpm-audit-vulnerabilities
Oct 1, 2026
Merged

redanthrax merged 1 commit into
masterfrom
fix/pnpm-audit-vulnerabilities

Conversation

@redanthrax

Copy link
Copy Markdown
Owner

pnpm audit reported 15 vulnerabilities (9 high, 6 moderate), all transitive via n8n-workflow (axios) and the eslint community-nodes plugin (brace-expansion via minimatch).

  • Pin axios to 1.20.0 (fixes ReDoS, prototype pollution, HTTP/2 DoS/ bypass, header injection, proxy bypass advisories)
  • Bump brace-expansion pin from 5.0.9 to 5.0.12 (fixes ReDoS/stack exhaustion advisories)

pnpm audit now reports no known vulnerabilities.

pnpm audit reported 15 vulnerabilities (9 high, 6 moderate), all
transitive via n8n-workflow (axios) and the eslint community-nodes
plugin (brace-expansion via minimatch).

- Pin axios to 1.20.0 (fixes ReDoS, prototype pollution, HTTP/2 DoS/
  bypass, header injection, proxy bypass advisories)
- Bump brace-expansion pin from 5.0.9 to 5.0.12 (fixes ReDoS/stack
  exhaustion advisories)

pnpm audit now reports no known vulnerabilities.
@redanthrax
redanthrax merged commit 80877ae into master Oct 1, 2026
1 check passed
@redanthrax redanthrax mentioned this pull request Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant