Skip to content

Bump axios, @elastic.io/component-commons-library and elasticio-sailor-nodejs#57

Open
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/npm_and_yarn/multi-ee9e6ee0e9
Open

Bump axios, @elastic.io/component-commons-library and elasticio-sailor-nodejs#57
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/npm_and_yarn/multi-ee9e6ee0e9

Conversation

@dependabot
Copy link

@dependabot dependabot bot commented on behalf of github Feb 10, 2026

Bumps axios to 1.13.5 and updates ancestor dependencies axios, @elastic.io/component-commons-library and elasticio-sailor-nodejs. These dependencies need to be updated together.

Updates axios from 0.26.1 to 1.13.5

Release notes

Sourced from axios's releases.

v1.13.5

Release 1.13.5

Highlights

  • Security: Fixed a potential Denial of Service issue involving the __proto__ key in mergeConfig. (PR #7369)
  • Bug fix: Resolved an issue where AxiosError could be missing the status field on and after v1.13.3. (PR #7368)

Changes

Security

  • Fix Denial of Service via __proto__ key in mergeConfig. (PR #7369)

Fixes

  • Fix/5657. (PR #7313)
  • Ensure status is present in AxiosError on and after v1.13.3. (PR #7368)

Features / Improvements

  • Add input validation to isAbsoluteURL. (PR #7326)
  • Refactor: bump minor package versions. (PR #7356)

Documentation

  • Clarify object-check comment. (PR #7323)
  • Fix deprecated Buffer constructor usage and README formatting. (PR #7371)

CI / Maintenance

  • Chore: fix issues with YAML. (PR #7355)
  • CI: update workflow YAMLs. (PR #7372)
  • CI: fix run condition. (PR #7373)
  • Dev deps: bump karma-sourcemap-loader from 0.3.8 to 0.4.0. (PR #7360)
  • Chore(release): prepare release 1.13.5. (PR #7379)

New Contributors

Full Changelog: axios/axios@v1.13.4...v1.13.5

v1.13.4

Overview

The release addresses issues discovered in v1.13.3 and includes significant CI/CD improvements.

Full Changelog: v1.13.3...v1.13.4

What's New in v1.13.4

Bug Fixes

  • fix: issues with version 1.13.3 (#7352) (ee90dfc)
    • Fixed issues discovered in v1.13.3 release

... (truncated)

Commits
  • 29f7542 chore(release): prepare release 1.13.5 (#7379)
  • 431c3a3 ci: fix run condition (#7373)
  • 9ff3a78 ci: update ymls (#7372)
  • 265b712 docs: fix deprecated Buffer constructor and formatting issues in README (#7371)
  • 475e75a feat: add input validation to isAbsoluteURL (#7326)
  • 28c7215 fix: Denial of Service via proto Key in mergeConfig (#7369)
  • 04cf019 docs: clarify object check comment (#7323)
  • 696fa75 fix: status is missing in AxiosError on and after v1.13.3 (#7368)
  • 569f028 fix: added a option to choose between legacy and the new request/response int...
  • 44b7c9f chore(deps-dev): bump karma-sourcemap-loader (#7360)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for axios since your current version.


Updates @elastic.io/component-commons-library from 2.0.2 to 4.0.0

Release notes

Sourced from @​elastic.io/component-commons-library's releases.

4.0.0

  • BREAKING CHANGE – All clients named *RestClient have been removed except for PlatformApiRestClient. Any removed client logic should now be implemented within components.
  • PlatformApiRestClient has been migrated from the request library to axios.
  • The following libraries have been removed from the main dependencies:
    • @​elastic.io/ntlm-client
    • async
    • bunyan-serializers
    • elasticio-node
    • better-npm-audit
    • remove-leading-slash
    • remove-trailing-slash
    • request
  • The axiosReqWithRetryOnServerError function can now operate without requiring a context.

3.2.2

  • Updated maester-client to 6.0.0

3.2.1

  • Updated maester-client and other dependencies

3.2.0

  • Added new functions:
    • isNumberNaN(number)
    • timestamp(date)
    • isDateValid(date)
    • timeToString(date)
  • Updated @​elastic.io/jsonata-moment to 1.1.6 to fix a vulnerability found in jsonata 1.8.6

3.1.6

  • Changed environment variable API_REQUEST_TIMEOUT maxValue to 120 sec (used to be 20 sec)

3.1.5

  • Updated @​elasticio/maester-client to v5.0.1

3.1.4

Add possibility to set RetryOptions for methods getAttachment and uploadAttachment on AttachmentProcessor class.

3.1.2

Update jsonata-moment to 1.1.5 to support Jsonata 1.8.6

3.1.0

  • Added method fetchSecretById for PlatformApiLogicClient
  • Added method refreshTokenBySecretId for PlatformApiLogicClient
  • Added User-Agent headers to PlatformApiRestClient
  • Added new REST client FacelessRestClient
Changelog

Sourced from @​elastic.io/component-commons-library's changelog.

4.0.0 (August 05, 2025)

  • BREAKING CHANGE – All clients named *RestClient have been removed except for PlatformApiRestClient. Any removed client logic should now be implemented within components.
  • PlatformApiRestClient has been migrated from the request library to axios.
  • The following libraries have been removed from the main dependencies:
    • @​elastic.io/ntlm-client
    • async
    • bunyan-serializers
    • elasticio-node
    • better-npm-audit
    • remove-leading-slash
    • remove-trailing-slash
    • request
  • The axiosReqWithRetryOnServerError function can now operate without requiring a context.

3.2.2 (March 21, 2025)

  • Updated maester-client to 6.0.0

3.2.1 (September 11, 2024)

  • Updated maester-client

3.2.0 (March 22, 2024)

  • Added new functions:
    • isNumberNaN(number)
    • timestamp(date)
    • isDateValid(date)
    • timeToString(date)
  • Updated @​elastic.io/jsonata-moment to 1.1.6 to fix a vulnerability found in jsonata 1.8.6

3.1.6 (January 24, 2024)

  • Changed environment variable API_REQUEST_TIMEOUT maxValue to 120 sec (used to be 20 sec)

3.1.5 (December 29, 2022)

  • Updated @​elasticio/maester-client to v5.0.1

3.1.4 (November 29, 2022)

  • To fix the incorrect deploy of 3.1.3

3.1.3 (November 29, 2022)

  • Add possibility to set RetryOptions for methods getAttachment and uploadAttachment oa AttachmentProcessor class.

3.1.2 (October 28, 2022)

  • To fix the incorrect deploy of 3.1.1

3.1.1 (October 21, 2022)

  • Update jsonata-moment to 1.1.5

3.1.0 (September 9, 2022)

  • Added method fetchSecretById for PlatformApiLogicClient
  • Added method refreshTokenBySecretId for PlatformApiLogicClient
  • Added User-Agent headers to PlatformApiRestClient

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by if0s, a new releaser for @​elastic.io/component-commons-library since your current version.


Updates elasticio-sailor-nodejs from 2.6.27 to 2.7.8

Release notes

Sourced from elasticio-sailor-nodejs's releases.

2.7.8

  • Wait for connection before ack/nack (#7855)

2.7.7

  • Add message deduplication logic (WARNING - does not work for step deployments)

2.7.6

  • Updated elasticio-rest-node to version 2.0.0 to address a vulnerability
  • Removed request related libraries from main dependencies

2.7.5

  • @​elastic.io/maester-client updated to 6.0.0 to get rid of the vulnerability

2.7.4

  • Fixed error location if component use Rebound functionality

2.7.3

  • @​elastic.io/maester-client updated to 5.0.3 to get rid of the vulnerability

2.7.2

2.7.0 (September 15, 2022)

  • Add AMQP_PERSISTENT_MESSAGES configuration env var to enable persistent delivery mode.

v2.6.28

What's Changed

  • Fix: "sailor-nodejs ignores errors from maester during lightweight message upload" #6233
Changelog

Sourced from elasticio-sailor-nodejs's changelog.

2.7.8 (February 4, 2026)

  • Ensure connection before ack/nack of the message #7855

2.7.7 (November 19, 2025)

  • Improve handling of cases when connection to RabbitMQ is re-established. #7855

2.7.6 (August 1, 2025)

  • Updated elasticio-rest-node to version 2.0.0 to address a vulnerability
  • Removed request related libraries from main dependencies

2.7.5 (March 21, 2025)

  • @​elastic.io/maester-client updated to 6.0.0 to get rid of the vulnerability

2.7.4 (November 14, 2024)

  • Fixed error location if component use Rebound functionality

2.7.3 (September 12, 2024)

  • @​elastic.io/maester-client updated to 5.0.3 to get rid of the vulnerability

2.7.2 (March 22, 2024)

2.7.1 (October 20, 2022)

  • Replaced object-storage-client with maester-client

2.7.0 (September 15, 2022)

  • Add AMQP_PERSISTENT_MESSAGES configuration env var to enable persistent delivery mode.

2.6.29 (July 14, 2022)

  • Enabled keep-alive for global HTTPS agent (#6359)

2.6.28 (June 21, 2022)

  • Fix: "sailor-nodejs ignores errors from maester during lightweight message upload" #6233)
Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

…r-nodejs

Bumps [axios](https://github.com/axios/axios) to 1.13.5 and updates ancestor dependencies [axios](https://github.com/axios/axios), [@elastic.io/component-commons-library](https://github.com/elasticio/component-commons-library) and [elasticio-sailor-nodejs](https://github.com/elasticio/sailor-nodejs). These dependencies need to be updated together.


Updates `axios` from 0.26.1 to 1.13.5
- [Release notes](https://github.com/axios/axios/releases)
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)
- [Commits](axios/axios@v0.26.1...v1.13.5)

Updates `@elastic.io/component-commons-library` from 2.0.2 to 4.0.0
- [Release notes](https://github.com/elasticio/component-commons-library/releases)
- [Changelog](https://github.com/elasticio/component-commons-library/blob/master/CHANGELOG.md)
- [Commits](elasticio/component-commons-library@2.0.2...4.0.0)

Updates `elasticio-sailor-nodejs` from 2.6.27 to 2.7.8
- [Release notes](https://github.com/elasticio/sailor-nodejs/releases)
- [Changelog](https://github.com/elasticio/sailor-nodejs/blob/master/CHANGELOG.md)
- [Commits](elasticio/sailor-nodejs@v2.6.27...v2.7.8)

---
updated-dependencies:
- dependency-name: axios
  dependency-version: 1.13.5
  dependency-type: indirect
- dependency-name: "@elastic.io/component-commons-library"
  dependency-version: 4.0.0
  dependency-type: direct:production
- dependency-name: elasticio-sailor-nodejs
  dependency-version: 2.7.8
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Feb 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants