Skip to content

Conversation

@jmaddington
Copy link
Owner

Summary

Details

The request package is deprecated and has SSRF vulnerability with no patched version available.
Since request is a transitive dependency and may be difficult to fully remove, this PR:

  1. Pins request to the latest version (2.88.2)
  2. Adds axios as a direct dependency to provide a modern alternative
  3. Sets up for future work to gradually replace request usage with axios

Test plan

🤖 Generated with Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants