Skip to content

chore(deps): bump axios from 1.13.2 to 1.13.5 in /integration_tests/contracts#1973

Merged
JayT106 merged 6 commits intomainfrom
dependabot/npm_and_yarn/integration_tests/contracts/axios-1.13.5
Apr 16, 2026
Merged

chore(deps): bump axios from 1.13.2 to 1.13.5 in /integration_tests/contracts#1973
JayT106 merged 6 commits intomainfrom
dependabot/npm_and_yarn/integration_tests/contracts/axios-1.13.5

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Feb 19, 2026

Bumps axios from 1.13.2 to 1.13.5.

Release notes

Sourced from axios's releases.

v1.13.5

Release 1.13.5

Highlights

  • Security: Fixed a potential Denial of Service issue involving the __proto__ key in mergeConfig. (PR #7369)
  • Bug fix: Resolved an issue where AxiosError could be missing the status field on and after v1.13.3. (PR #7368)

Changes

Security

  • Fix Denial of Service via __proto__ key in mergeConfig. (PR #7369)

Fixes

  • Fix/5657. (PR #7313)
  • Ensure status is present in AxiosError on and after v1.13.3. (PR #7368)

Features / Improvements

  • Add input validation to isAbsoluteURL. (PR #7326)
  • Refactor: bump minor package versions. (PR #7356)

Documentation

  • Clarify object-check comment. (PR #7323)
  • Fix deprecated Buffer constructor usage and README formatting. (PR #7371)

CI / Maintenance

  • Chore: fix issues with YAML. (PR #7355)
  • CI: update workflow YAMLs. (PR #7372)
  • CI: fix run condition. (PR #7373)
  • Dev deps: bump karma-sourcemap-loader from 0.3.8 to 0.4.0. (PR #7360)
  • Chore(release): prepare release 1.13.5. (PR #7379)

New Contributors

Full Changelog: axios/axios@v1.13.4...v1.13.5

v1.13.4

Overview

The release addresses issues discovered in v1.13.3 and includes significant CI/CD improvements.

Full Changelog: v1.13.3...v1.13.4

What's New in v1.13.4

Bug Fixes

  • fix: issues with version 1.13.3 (#7352) (ee90dfc)
    • Fixed issues discovered in v1.13.3 release

... (truncated)

Changelog

Sourced from axios's changelog.

Changelog

1.13.3 (2026-01-20)

Bug Fixes

  • http2: Use port 443 for HTTPS connections by default. (#7256) (d7e6065)
  • interceptor: handle the error in the same interceptor (#6269) (5945e40)
  • main field in package.json should correspond to cjs artifacts (#5756) (7373fbf)
  • package.json: add 'bun' package.json 'exports' condition. Load the Node.js build in Bun instead of the browser build (#5754) (b89217e)
  • silentJSONParsing=false should throw on invalid JSON (#7253) (#7257) (7d19335)
  • turn AxiosError into a native error (#5394) (#5558) (1c6a86d)
  • types: add handlers to AxiosInterceptorManager interface (#5551) (8d1271b)
  • types: restore AxiosError.cause type from unknown to Error (#7327) (d8233d9)
  • unclear error message is thrown when specifying an empty proxy authorization (#6314) (6ef867e)

Features

Reverts

  • Revert "fix: silentJSONParsing=false should throw on invalid JSON (#7253) (#7…" (#7298) (a4230f5), closes #7253 #7 #7298
  • deps: bump peter-evans/create-pull-request from 7 to 8 in the github-actions group (#7334) (2d6ad5e)

Contributors to this release

... (truncated)

Commits
  • 29f7542 chore(release): prepare release 1.13.5 (#7379)
  • 431c3a3 ci: fix run condition (#7373)
  • 9ff3a78 ci: update ymls (#7372)
  • 265b712 docs: fix deprecated Buffer constructor and formatting issues in README (#7371)
  • 475e75a feat: add input validation to isAbsoluteURL (#7326)
  • 28c7215 fix: Denial of Service via proto Key in mergeConfig (#7369)
  • 04cf019 docs: clarify object check comment (#7323)
  • 696fa75 fix: status is missing in AxiosError on and after v1.13.3 (#7368)
  • 569f028 fix: added a option to choose between legacy and the new request/response int...
  • 44b7c9f chore(deps-dev): bump karma-sourcemap-loader (#7360)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for axios since your current version.


Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [axios](https://github.com/axios/axios) from 1.13.2 to 1.13.5.
- [Release notes](https://github.com/axios/axios/releases)
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)
- [Commits](axios/axios@v1.13.2...v1.13.5)

---
updated-dependencies:
- dependency-name: axios
  dependency-version: 1.13.5
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Feb 19, 2026
@dependabot dependabot Bot requested a review from a team as a code owner February 19, 2026 10:33
@dependabot dependabot Bot requested review from XinyuCRO and randy-cro and removed request for a team February 19, 2026 10:33
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Feb 19, 2026
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github Apr 16, 2026

A newer version of axios exists, but since this PR has been edited by someone other than Dependabot I haven't updated it. You'll get a PR for the updated version as normal once this PR is merged.

@JayT106 JayT106 enabled auto-merge April 16, 2026 18:18
@JayT106
Copy link
Copy Markdown
Contributor

JayT106 commented Apr 16, 2026

@claude review PR

@github-actions
Copy link
Copy Markdown

github-actions Bot commented Apr 16, 2026

Claude finished @JayT106's task in 58s —— View job


PR Review: chore(deps): bump axios from 1.13.2 to 1.13.5

  • Gather context and understand the PR
  • Read changed files and relevant code
  • Analyze security implications
  • Provide review feedback

Summary

This is a dependabot bump of axios from 1.13.21.13.5 in integration_tests/contracts/package-lock.json. Only the lock file is changed — package.json already uses "axios": "^1.12.0" as an override, so this is fully within range.

Changes in package-lock.json

Field Before After
version 1.13.2 1.13.5
follow-redirects (min) ^1.15.6 ^1.15.11
form-data (min) ^4.0.4 ^4.0.5
integrity sha512-VPk9... sha512-cz4u...

Security Assessment

This upgrade is recommended. v1.13.5 contains an important security fix:

  • DoS fix (v1.13.5): axios/axios#7369 — Fixes a potential Denial of Service vulnerability via the __proto__ key in mergeConfig. This is a prototype pollution-adjacent issue.
  • Bug fix (v1.13.5): axios/axios#7368AxiosError was missing the status field on versions >= 1.13.3.

Code Quality

  • The diff is clean and minimal — only the lock file entries for axios are touched.
  • The follow-redirects minimum requirement bump (^1.15.6^1.15.11) is a positive sign; this transitive dependency has had its own historical CVEs.
  • No direct usage of axios was found in the TypeScript/JavaScript integration test code — it appears as a transitive/override dependency only, so runtime behavior changes are low risk.

Verdict

Approve. This is a low-risk, security-positive dependency bump. No functional changes to the repo code are included. The only concern is the compatibility score badge shown by Dependabot, which reflects test pass rates across the broader ecosystem — the fix is straightforward and the upgrade is safe to merge.


@JayT106 JayT106 added this pull request to the merge queue Apr 16, 2026
Merged via the queue into main with commit 5fad4c3 Apr 16, 2026
38 checks passed
@dependabot dependabot Bot deleted the dependabot/npm_and_yarn/integration_tests/contracts/axios-1.13.5 branch April 16, 2026 21:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant