Bump axios and serverless
Type: Pull Request
State: Open
Association: None
Comments: 0
(8 months ago)
(8 months ago)
dependencies javascript
Bumps axios to 1.12.2 and updates ancestor dependency serverless. These dependencies need to be updated together.
Updates axios from 0.19.2 to 1.12.2
Release notes
Sourced from axios's releases.
Release v1.12.2
Release notes:
Bug Fixes
- fetch: use current global fetch instead of cached one when env fetch is not specified to keep MSW support; (#7030) (cf78825)
Contributors to this release
Release v1.12.1
Release notes:
Bug Fixes
Contributors to this release
Release v1.12.0
Release notes:
Bug Fixes
- adding build artifacts (9ec86de)
- dont add dist on release (a2edc36)
- fetch-adapter: set correct Content-Type for Node FormData (#6998) (a9f47af)
- node: enforce maxContentLength for data: URLs (#7011) (945435f)
- package exports (#5627) (aa78ac2)
- params: removing '[' and ']' from URL encode exclude characters (#3316) (#5715) (6d84189)
- release pr run (fd7f404)
- types: change the type guard on isCancel (#5595) (0dbb7fd)
Features
- adapter: surface low‑level network error details; attach original error via cause (#6982) (78b290c)
- fetch: add fetch, Request, Response env config variables for the adapter; (#7003) (c959ff2)
- support reviver on JSON.parse (#5926) (2a97634), closes #5924
- types: extend AxiosResponse interface to include custom headers type (#6782) (7960d34)
Contributors to this release
... (truncated)
Changelog
Sourced from axios's changelog.
1.12.2 (2025-09-14)
Bug Fixes
- fetch: use current global fetch instead of cached one when env fetch is not specified to keep MSW support; (#7030) (cf78825)
Contributors to this release
1.12.1 (2025-09-12)
Bug Fixes
Contributors to this release
1.12.0 (2025-09-11)
Bug Fixes
- adding build artifacts (9ec86de)
- dont add dist on release (a2edc36)
- fetch-adapter: set correct Content-Type for Node FormData (#6998) (a9f47af)
- node: enforce maxContentLength for data: URLs (#7011) (945435f)
- package exports (#5627) (aa78ac2)
- params: removing '[' and ']' from URL encode exclude characters (#3316) (#5715) (6d84189)
- release pr run (fd7f404)
- types: change the type guard on isCancel (#5595) (0dbb7fd)
Features
- adapter: surface low‑level network error details; attach original error via cause (#6982) (78b290c)
- fetch: add fetch, Request, Response env config variables for the adapter; (#7003) (c959ff2)
- support reviver on JSON.parse (#5926) (2a97634), closes #5924
- types: extend AxiosResponse interface to include custom headers type (#6782) (7960d34)
Contributors to this release
... (truncated)
Commits
e5a3336chore(release): v1.12.2 (#7031)38726c7refactor: change if in else to else if (#7028)cf78825fix(fetch): use current global fetch instead of cached one when env fetch is ...c26d00frefactor: remove redundant assignment (#7029)9fb41a8chore(ci): add local HTTP server for Karma tests; (#7022)19f9f36docs(readme): add custom fetch section; (#7024)3cac78cchore(release): v1.12.1 (#7021)b5f26b7fix(types): fixed env config types; (#7020)0d8ad6echore(release): v1.12.0 (#7013)fd7f404fix: release pr run- Additional commits viewable in compare view
Maintainer changes
This version was pushed to npm by jasonsaayman, a new releaser for axios since your current version.
Updates serverless from 1.70.1 to 4.19.1
Release notes
Sourced from serverless's releases.
4.19.1
Bug Fixes
- Serverless Framework
- Fixes proxy support for requests to the Serverless Platform API
4.19.0
Features
- Serverless Framework
Bug Fixes
- Serverless Framework
- Prevent logical ID collisions for Kafka
EventSourceMappings, fixes serverless/serverless#13112- Improve handling of named and default exports in CommonJS modules when using Serverless Variables, fixes serverless/serverless#13106
- Fixes proxy support in AWS SDK
Maintenance
- Serverless Framework
- Replace deprecated
url.parsewith WHATWGURL, fixes Node.js DEP0169- Bump
axios, fixes https://github.com/advisories/GHSA-4hjh-wcwx-xvwj4.18.2
Bug Fixes
- Serverless Framework
- Fixes building functions with esbuild in dev mode
4.18.1
Bug Fixes
- Serverless Framework
- Skips esbuild build when prebuilt artifacts are provided
- Respects AWS_REGION env variable
- Bumps jackson to 2.15.0 in invoke-bridge and to address CVE-2025-52999 and CVE-2025-49128
- Bumps form-data to 4.0.4 to address CVE-2025-7783
4.18.0
Features
- Serverless Framework
- Adds support for deploying custom domain names for your HTTP, Rest & WebSocket APIs. Please see the docs for more info.
4.17.2
Bug Fixes
... (truncated)
Changelog
Sourced from serverless's changelog.
Changelog
All notable changes to this project will be documented in this file. See standard-version for commit guidelines.
3.38.0 (2023-11-21)
Features
3.37.0 (2023-11-16)
Features
Bug Fixes
- bump platform-client version for axios (#12260) (10980b9)
- Update pkg config to include axios cjs (#12261) (b21afaf)
3.36.0 (2023-10-23)
Features
Bug Fixes
- Dashboard documentation improvements (bb4d7c8)
- Fix menu for dashboard documentation (8f266af)
- Improve dashboard documentation (ad8bbf1)
- Improve dashboard documentation (f67df7f)
- Minor dashboard doc improvements (#12177) (f1fa19c)
3.35.2 (2023-09-16)
Bug Fixes
3.35.1 (2023-09-16)
Bug Fixes
3.35.0 (2023-09-15)
Features
... (truncated)
Commits
3110342add recent features to readmee2681bdchore: update readme to include serverless MCP and container framework1003a32docs: update SECURITY.md (#13026)ec4957fchore: automate CLA signing (#13019)c4cebaechore: automate CLA signing87b4f5bdocs: read license key from aws ssm (#12986)3f37cbadocs(dev-mode): added note regarding vpc (#12977)d262ac3feat: add support for ap-southeast-5 and ca-west-1 (#12981)2aea99dfix: correctly resolve layer package artifact and docker image paths (#12972)3704754fix(esbuild): track files added to the zip file (#12966)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the Security Alerts page.
Pull Request Statistics
1
2
+19319
-17352
Package Dependencies
Security Advisories
Jackson-core Vulnerable to Memory Disclosure via Source Snippet in JsonLocation
jackson-core can throw a StackoverflowError when processing deeply nested data
form-data uses unsafe random function in form-data for choosing boundary
Technical Details
| ID: | 8855598 |
| UUID: | 2874574176 |
| Node ID: | PR_kwDOD6QCg86rVoVg |
| Host: | GitHub |
| Repository: | joncode/serverless-stack-api |
| Merge State: | Unknown |