Repository navigation
fix(sei-global-wallet): raise the axios override to 1.20.0 - #354
Conversation
Twelve Axios advisories published on 2026-09-30 cover every release below 1.20.0, including the 1.18.0 that the README override blocks and the consumer verifier pinned, so the nightly consumer smoke went red without any change in this repository. The wallet-only npm consumer, which must audit clean, reported axios plus the eight Dynamic packages above it in the dependency chain. Dynamic still pins axios@1.16.0 exactly, so the fix stays a root override: the verifier's override set, all three README blocks, and the workspace override move to 1.20.0, the first release with no open advisory. It keeps the exports and dependencies of 1.18.0 apart from a form-data floor of ^4.0.6, which the lockfile already satisfied. The README's Axios note described only the Node HTTP adapter issue that 1.18.0 cleared. It now covers the new set, including the toFormData and fetch-adapter gadgets that also apply in browsers. Co-authored-by: Cursor <cursoragent@cursor.com>
PR SummaryLow Risk Overview The README Axios security note is rewritten to reflect the current advisory set (Node-only transports vs browser-relevant A Reviewed by Cursor Bugbot for commit 503f10b. Bugbot is set up for automated code reviews on this repo. Configure here. |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #354 +/- ##
=======================================
Coverage 97.82% 97.82%
=======================================
Files 81 81
Lines 5652 5652
=======================================
Hits 5529 5529
Misses 123 123
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
There was a problem hiding this comment.
This PR raises the axios override from 1.18.0 to 1.20.0 everywhere it appears: the root override, bun.lock, the verifier's base overrides and all three README override blocks. It also includes a patch changeset. The changes are consistent and I found no correctness or security problems. My only notes are non-blocking.
Findings: 0 blocking | 3 non-blocking | 0 posted inline
Blockers
- None at the file/PR level.
Non-blocking
- The Cursor review file was empty, so that second-opinion pass gave no output. Codex reported no material issues.
scripts/documented-overrides.test.tsandscripts/dynamic-package-lock.test.tsstill useaxios: '1.18.0'in their fixtures. These are synthetic parser inputs, so nothing is functionally wrong. Bumping them to 1.20.0 is optional and would stop future greps for stale pins from matching them.- The advisory claims can't be checked from the diff: twelve advisories, 1.20.0 being the first clean release, and 1.19.0 still affected. Linking the GHSA IDs in the changeset or README would let readers verify the override choice and make it easier to tell when the override can be removed later.
Co-authored-by: Cursor <cursoragent@cursor.com>
There was a problem hiding this comment.
This PR moves the axios override from 1.18.0 to 1.20.0 in five places: the root package.json, bun.lock, the verifier's base override set, and all three README override blocks. It also includes a patch changeset as REVIEW_GUIDELINES §3 asks. The change is consistent across all of them and I found no correctness or security problems.
Findings: 0 blocking | 3 non-blocking | 0 posted inline
Blockers
- None at the file/PR level.
Non-blocking
- The Cursor review file (
cursor-review.md) was empty, so that pass produced no output. Codex reported no material issues, and I agree. scripts/documented-overrides.test.tsstill usesaxios: '1.18.0'in its README fixture. That fixture is self-contained and only tests the parser, not the real README, so it is correct as written. Updating it to1.20.0is optional and would only stop a future grep for stale pins from matching it.- I could not check the advisory IDs or the claim that 1.20.0 is the first clean release against the GitHub advisory database from the diff alone. The PR's verification steps (a clean wallet-only npm audit, plus the Bun and full npm consumer runs) are the evidence for that claim. The lockfile entry's
form-data ^4.0.6floor matches the description.
Fixes the scheduled Sei Global Wallet Consumer Smoke failure, which has been red since October 1.
Twelve Axios advisories published on 2026-09-30 (seven high, five medium) cover every release below
1.20.0, including the1.18.0we override Dynamic's exactaxios@1.16.0pin to. The wallet-only npm consumer, which is held to a strictly clean audit, reportedaxiosplus the eight Dynamic packages above it in the dependency chain.Changes
axiosoverride from1.18.0to1.20.0in the verifier's override set, all three README override blocks, and the workspace root override.bun.lockchanges only the axios entry.1.20.0is the first release with no open advisory (1.19.0still carries all twelve), and it ships the same exports and dependencies as1.18.0apart from aform-datafloor of^4.0.6.1.18.0cleared. The high-severity issues against Dynamic's pin are in Node-only transports or are prototype-pollution gadgets, and thetoFormDataand fetch-adapter gadgets also apply in browsers.@sei-js/sei-global-walletpatch changeset, since the override guidance ships in the package README.Verification
bun run test:sei-global-wallet-release(full run, without the fast-check flag) passes locally: the wallet-only npm consumer audits clean, and the full npm and Bun consumers report only advisories already in the waiver.bun run test:create-sei-releasepasses locally. The changeset makes that workflow run on this PR as well; the generated apps don't depend on axios, and the only finding is the existing moderatedecode-uri-componentadvisory.bun run check(Biome and typecheck) andbun run test:scripts(48 tests) pass.No published dependency or peer range changes.