SONARAZDO-574 Bump axios and sonarqube-scanner#568
SONARAZDO-574 Bump axios and sonarqube-scanner#568dependabot[bot] wants to merge 1 commit intomasterfrom
Conversation
Bumps [axios](https://github.com/axios/axios) to 1.15.0 and updates ancestor dependency [sonarqube-scanner](https://github.com/SonarSource/sonar-scanner-npm). These dependencies need to be updated together. Updates `axios` from 1.8.2 to 1.15.0 - [Release notes](https://github.com/axios/axios/releases) - [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md) - [Commits](axios/axios@v1.8.2...v1.15.0) Updates `sonarqube-scanner` from 4.3.0 to 4.3.6 - [Release notes](https://github.com/SonarSource/sonar-scanner-npm/releases) - [Commits](SonarSource/sonar-scanner-npm@4.3.0...4.3.6) --- updated-dependencies: - dependency-name: axios dependency-version: 1.15.0 dependency-type: indirect - dependency-name: sonarqube-scanner dependency-version: 4.3.6 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
Summary
Updates axios from 1.8.2 to 1.15.0 and sonarqube-scanner from 4.3.0 to 4.3.6. These are pure dependency bumps with no code changes. Key points:
What reviewers should knowWhat to check:
|
|
|





Bumps axios to 1.15.0 and updates ancestor dependency sonarqube-scanner. These dependencies need to be updated together.
Updates
axiosfrom 1.8.2 to 1.15.0Release notes
Sourced from axios's releases.
... (truncated)
Changelog
Sourced from axios's changelog.
... (truncated)
Commits
772a4e5chore(release): prepare release 1.15.0 (#10671)4b07137chore(deps-dev): bump vite from 8.0.0 to 8.0.5 in /tests/smoke/esm (#10663)51e57b3chore(deps-dev): bump vite from 8.0.2 to 8.0.5 (#10664)fba1a77chore(deps-dev): bump vite from 8.0.2 to 8.0.5 in /tests/module/esm (#10665)0bf6e28chore(deps): bump denoland/setup-deno in the github-actions group (#10669)8107157chore(deps-dev): bump the development_dependencies group with 4 updates (#10670)e66530eci: require npm-publish environment for releases (#10666)49f23cbchore(sponsor): update sponsor block (#10668)3631854fix: unrestricted cloud metadata exfiltration via header injection chain (#10...fb3befbfix: no_proxy hostname normalization bypass leads to ssrf (#10661)Maintainer changes
This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for axios since your current version.
Install script changes
This version modifies
preparescript that runs during installation. Review the package contents before updating.Updates
sonarqube-scannerfrom 4.3.0 to 4.3.6Release notes
Sourced from sonarqube-scanner's releases.
Commits
510835aUpdate dependency typescript to v6 (#480)f1c2319Update dependency knip to v6 (#478)5efbea6SCANNPM-142 Switch npm publish to OIDC Trusted Publisher (#482)b8436f9Update dependency axios to v1.15.0 (#476)a14553cUpdate dependency@typescript-eslint/parserto v8.58.1 (#475)a8f84bfUpdate dependency@types/nodeto v24.12.2 (#474)76b9bf5Update dependency adm-zip to v0.5.17 (#472)1246ea2Update dependency slugify to v1.6.9 (#473)655319fUpdate dependency eslint to v10.2.0 (#477)bd9265dUpdate dependency proxy-from-env to v2 (#479)Maintainer changes
This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for sonarqube-scanner since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.