Skip to content

chore(deps): Bump axios from 1.12.0 to 1.13.5#4

Open
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/npm_and_yarn/axios-1.13.5
Open

chore(deps): Bump axios from 1.12.0 to 1.13.5#4
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/npm_and_yarn/axios-1.13.5

Conversation

@dependabot
Copy link

@dependabot dependabot bot commented on behalf of github Feb 11, 2026

Bumps axios from 1.12.0 to 1.13.5.

Release notes

Sourced from axios's releases.

v1.13.5

Release 1.13.5

Highlights

  • Security: Fixed a potential Denial of Service issue involving the __proto__ key in mergeConfig. (PR #7369)
  • Bug fix: Resolved an issue where AxiosError could be missing the status field on and after v1.13.3. (PR #7368)

Changes

Security

  • Fix Denial of Service via __proto__ key in mergeConfig. (PR #7369)

Fixes

  • Fix/5657. (PR #7313)
  • Ensure status is present in AxiosError on and after v1.13.3. (PR #7368)

Features / Improvements

  • Add input validation to isAbsoluteURL. (PR #7326)
  • Refactor: bump minor package versions. (PR #7356)

Documentation

  • Clarify object-check comment. (PR #7323)
  • Fix deprecated Buffer constructor usage and README formatting. (PR #7371)

CI / Maintenance

  • Chore: fix issues with YAML. (PR #7355)
  • CI: update workflow YAMLs. (PR #7372)
  • CI: fix run condition. (PR #7373)
  • Dev deps: bump karma-sourcemap-loader from 0.3.8 to 0.4.0. (PR #7360)
  • Chore(release): prepare release 1.13.5. (PR #7379)

New Contributors

Full Changelog: axios/axios@v1.13.4...v1.13.5

v1.13.4

Overview

The release addresses issues discovered in v1.13.3 and includes significant CI/CD improvements.

Full Changelog: v1.13.3...v1.13.4

What's New in v1.13.4

Bug Fixes

  • fix: issues with version 1.13.3 (#7352) (ee90dfc)
    • Fixed issues discovered in v1.13.3 release

... (truncated)

Changelog

Sourced from axios's changelog.

Changelog

1.13.3 (2026-01-20)

Bug Fixes

  • http2: Use port 443 for HTTPS connections by default. (#7256) (d7e6065)
  • interceptor: handle the error in the same interceptor (#6269) (5945e40)
  • main field in package.json should correspond to cjs artifacts (#5756) (7373fbf)
  • package.json: add 'bun' package.json 'exports' condition. Load the Node.js build in Bun instead of the browser build (#5754) (b89217e)
  • silentJSONParsing=false should throw on invalid JSON (#7253) (#7257) (7d19335)
  • turn AxiosError into a native error (#5394) (#5558) (1c6a86d)
  • types: add handlers to AxiosInterceptorManager interface (#5551) (8d1271b)
  • types: restore AxiosError.cause type from unknown to Error (#7327) (d8233d9)
  • unclear error message is thrown when specifying an empty proxy authorization (#6314) (6ef867e)

Features

Reverts

  • Revert "fix: silentJSONParsing=false should throw on invalid JSON (#7253) (#7…" (#7298) (a4230f5), closes #7253 #7 #7298
  • deps: bump peter-evans/create-pull-request from 7 to 8 in the github-actions group (#7334) (2d6ad5e)

Contributors to this release

... (truncated)

Commits
  • 29f7542 chore(release): prepare release 1.13.5 (#7379)
  • 431c3a3 ci: fix run condition (#7373)
  • 9ff3a78 ci: update ymls (#7372)
  • 265b712 docs: fix deprecated Buffer constructor and formatting issues in README (#7371)
  • 475e75a feat: add input validation to isAbsoluteURL (#7326)
  • 28c7215 fix: Denial of Service via proto Key in mergeConfig (#7369)
  • 04cf019 docs: clarify object check comment (#7323)
  • 696fa75 fix: status is missing in AxiosError on and after v1.13.3 (#7368)
  • 569f028 fix: added a option to choose between legacy and the new request/response int...
  • 44b7c9f chore(deps-dev): bump karma-sourcemap-loader (#7360)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for axios since your current version.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [axios](https://github.com/axios/axios) from 1.12.0 to 1.13.5.
- [Release notes](https://github.com/axios/axios/releases)
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)
- [Commits](axios/axios@v1.12.0...v1.13.5)

---
updated-dependencies:
- dependency-name: axios
  dependency-version: 1.13.5
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Feb 11, 2026
@appmod-pr-genie
Copy link

Coding Standards Logo Configure Coding Standards

To enable comprehensive code quality checks for your pull requests, please configure coding standards for this repository.
Please visit the Coding Standards Configuration Page to set up the standards that align with your project's requirements.

Note: For now, Core Standards are used for analysis until you configure your own coding standards.


🧞 Quick Guide for PR-Genie

Tip

  • Use [email-to: reviewer1@techolution.com, reviewer2@techolution.com] in the PR description to get an email notification when the PR Analysis is complete.

  • You can include the relevant User Story IDs (from User Story Mode) like [TSP-001] or [TSP-001-A][TSP-002-B] in your PR title to generate a Functional Assessment of your PR.

Automated by Appmod Quality Assurance System

@appmod-pr-genie
Copy link

Functional Assessment

Verdict: ❌ Incomplete

Requirements Met? Overall Progress Completed Incomplete

🧠 User Story ID: AXIOS-UPGRADE-A — Upgrade Axios Dependency to v1.13.5

📝 Feature Completeness

The Requirement was..

Update axios to version 1.13.5 to address security vulnerabilities (DoS via proto pollution) and fix critical bugs like missing status fields in AxiosError.

This is what is built...

The version number for axios was updated in the pnpm-workspace.yaml file. However, no lockfile updates or code-level error handling changes were found.


📊 Implementation Status

ID Feature/Sub-Feature Status Files
1 Dependency Management Incomplete pnpm-workspace.yaml
1.1 └─ Update package.json/workspace version Completed pnpm-workspace.yaml
1.2 └─ Update lockfiles Not Started
ID Feature/Sub-Feature Status Files
2 Error Handling Improvements Not Started
2.1 └─ Utilize restored AxiosError.cause type Not Started
2.2 └─ Native error object behavior Not Started

✅ Completed Components

ID Feature Summary
1.1 Update package.json/workspace version Implemented: Axios version changed from 1.12.0 to 1.13.5.

❌ Gaps & Issues

ID Feature Gap/Issue Priority
1 Dependency Management Implemented: Updated version to 1.13.5 in workspace config. Missing: Corresponding lockfile updates (package-lock.json/pnpm-lock.yaml) to ensure sub-dependencies are resolved. High
1.2 Update lockfiles Missing: No changes detected in lockfiles to lock the specific sub-dependencies. High
2 Error Handling Improvements Missing: No code changes found utilizing the restored AxiosError.cause type or native error object behaviors. Medium
2.1 Utilize restored AxiosError.cause type Missing: No implementation of the updated error cause type in the codebase. Medium
2.2 Native error object behavior Missing: No verification or implementation of native error stack trace logic. Low

Completed Incomplete


🎯 Conclusion & Final Assessment

Important

🟢 Completed Features: Key completed features include the version increment of the axios library within the pnpm-workspace.yaml file to 1.13.5.

🔴 Incomplete Features: Key incomplete features include the absence of lockfile updates, lack of code-level implementation for AxiosError improvements, and no evidence of testing for the security fixes or URL validation.

@appmod-pr-genie
Copy link

⚙️ DevOps and Release Automation

🟢 Status: Passed

🌟 Excellent work! Your code passed the DevOps review. This dependency update for 'axios' resolves a security vulnerability and improves reliability without introducing any operational risks.


🎯 Conclusion

  • Continue the excellent practice of promptly applying security updates for dependencies to mitigate potential vulnerabilities and ensure system stability.

@appmod-pr-genie
Copy link

🔍 Technical Quality Assessment

📋 Summary

We are updating a core piece of software that helps our system communicate with other services. This update fixes a security weakness that could have allowed someone to intentionally slow down or crash our system, and it fixes a bug that was causing missing information in error reports.

💼 Business Impact

  • What Changed: We replaced an older version of a background tool (axios) with a newer, safer version. This change is mostly 'under the hood' and won't change how the website looks to users.
  • Why It Matters: This is important because it closes a security hole that could be used to knock our services offline (Denial of Service). It also helps our technical team troubleshoot problems faster by ensuring error messages contain all the necessary details.
  • User Experience: Customers won't see any visual changes, but they will benefit from a more stable and secure platform that is less likely to experience unexpected downtime.

🎯 Purpose & Scope

  • Primary Purpose: Security Improvement and Bug Fix
  • Scope: The system's internal communication tools (affects how our app talks to other web services)
  • Files Changed: 1 files (0 added, 1 modified, 0 deleted)

📊 Change Analysis

Files by Category:

  • Core Logic: 0 files
  • API/Routes: 0 files
  • Tests: 0 files
  • Configuration: 1 files
  • Documentation: 0 files
  • Others: 0 files

Impact Distribution:

  • High Impact: 0 files
  • Medium Impact: 0 files
  • Low Impact: 1 files

⚠️ Issues & Risks

  • Total Issues: 0 across 0 files
  • Critical Issues: 0
  • Major Issues: 0
  • Minor Issues: 0
  • Technical Risk Level: Low

Key Concerns:

  • [FOR DEVELOPERS] Ensure that any custom error handling logic that worked around the missing 'status' field is still compatible.

🚀 Recommendations

For Developers:

  • [FOR DEVELOPERS] Verify that the application builds correctly with the new axios version and that basic API calls function as expected.

For Stakeholders:

  • Approve this update as part of routine security maintenance to keep our systems protected and reliable.

For ProjectManagers:

  • Schedule this change for the next regular deployment cycle; no special user training or communication is required.

Click to Expand File Summaries
File Status Description Impact Issues Detected
pnpm-workspace.yaml Modified ( +1/ -1) Updated axios dependency version from 1.12.0 to 1.13.5 in the pnpm workspace catalog. Low – This is a minor version bump for axios. According to the release notes, it includes a security fix for a potential Denial of Service issue and a bug fix for AxiosError status fields. It is unlikely to break existing functionality but improves security. 0

@appmod-pr-genie
Copy link

Coding Standards Logo Compliance & Security Assessment

🌟 Excellent work! Your code passed all coding standards checks with zero violations. 👏

@appmod-pr-genie
Copy link

Appmod Quality Check: PASSED✅

Quality gate passed - This pull request meets the quality standards.

📊 Quality Metrics

Metric Value Status
Quality Score 100%
Issues Found 0
CS Violations 0
Risk Level Low

🎯 Assessment

Ready for merge - All quality checks have passed successfully.

📋 View Detailed Report for comprehensive analysis and recommendations.


Automated by Appmod Quality Assurance System

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants