Skip to content

[Snyk] Fix for 1 vulnerabilities#12304

Open
sestinj wants to merge 1 commit intomainfrom
snyk-fix-ab0c6473093a04268e3ae20f5941f799
Open

[Snyk] Fix for 1 vulnerabilities#12304
sestinj wants to merge 1 commit intomainfrom
snyk-fix-ab0c6473093a04268e3ae20f5941f799

Conversation

@sestinj
Copy link
Copy Markdown
Contributor

@sestinj sestinj commented May 5, 2026

snyk-top-banner

Snyk has created this PR to fix 1 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • extensions/vscode/package.json

Vulnerabilities that will be fixed with an upgrade:

Issue Score
critical severity Prototype Pollution
SNYK-JS-AXIOS-16417750
  848  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Prototype Pollution


Summary by cubic

Updates axios to 1.15.2 in the VS Code extension to fix a critical Prototype Pollution vulnerability, and bumps vectordb to 0.21.2.

  • Dependencies
    • axios: ^1.13.1 → ^1.15.2 (fixes SNYK-JS-AXIOS-16417750)
    • vectordb: 0.4.20 → 0.21.2

Written for commit 42c052d. Summary will update on new commits.

@sestinj sestinj requested a review from a team as a code owner May 5, 2026 13:32
@dosubot dosubot Bot added the size:XS This PR changes 0-9 lines, ignoring generated files. label May 5, 2026
@continue
Copy link
Copy Markdown
Contributor

continue Bot commented May 5, 2026

Docs Review: No documentation updates needed.

This PR updates internal dependencies (axios and vectordb) in the VS Code extension to address security vulnerabilities. These changes are transparent to end users and don't affect any documented features, configuration options, or developer workflows.

Copy link
Copy Markdown
Contributor

@cubic-dev-ai cubic-dev-ai Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 1 file

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS This PR changes 0-9 lines, ignoring generated files.

Projects

Status: Todo

Development

Successfully merging this pull request may close these issues.

2 participants