Skip to content

Conversation

@soinclined
Copy link
Contributor

Security: Override axios to 1.12.0 to fix DoS vulnerability

Summary

Adds npm override to force all transitive axios dependencies to use version 1.12.0, which patches a DoS vulnerability due to lack of data size check identified by Dependabot.

axios is not a direct dependency in this project, but comes in transitively through:

  • @dynamic-labs/sdk-api-core (was using axios 1.9.0)
  • @stellar/stellar-sdk (was using axios 1.9.0)

axios 1.12.0 is backward compatible with previous 1.x versions according to the release notes.

Review & Testing Checklist for Human

  • Test core functionality that uses @dynamic-labs/sdk-api-core and @stellar/stellar-sdk to ensure the axios override doesn't break these packages
  • Verify Dependabot alert is resolved after the changes are deployed
  • Test critical user flows end-to-end to catch any subtle behavioral changes from the axios upgrade

Notes

Adds npm override to force all transitive axios dependencies to use
version 1.12.0, which patches a DoS vulnerability due to lack of data
size check identified by Dependabot.

Current transitive dependencies affected:
- @dynamic-labs/sdk-api-core (was using axios 1.9.0)
- @stellar/stellar-sdk (was using axios 1.9.0)

axios 1.12.0 is backward compatible with previous 1.x versions.

Co-Authored-By: Penelope <[email protected]>
@devin-ai-integration
Copy link
Contributor

Original prompt from Penelope
in crossmint/server-stellar-wallets crossmint/crossmint-onramp crossmint/trump-frontend and crossmint/worldstore-emailer, is it possible to upgrade axios to version 1.12.0 without breaking anything else?

@devin-ai-integration
Copy link
Contributor

🤖 Devin AI Engineer

I'll be helping with this pull request! Here's what you should know:

✅ I will automatically:

  • Address comments on this PR. Add '(aside)' to your comment to have me ignore it.
  • Look at CI failures and help fix them

Note: I can only respond to comments from users who have write access to this repository.

⚙️ Control Options:

  • Disable automatic comment and CI monitoring

@vercel
Copy link

vercel bot commented Oct 2, 2025

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Preview Comments Updated (UTC)
crossmint-onramp Ready Ready Preview Comment Oct 2, 2025 5:32pm

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant