[3f57bfb0] Supersede external PR #344: finish + harden it ourselves (#360)

* chore(deps): bump axios from 1.13.2 to 1.16.0 in /panel

Bumps [axios](https://github.com/axios/axios) from 1.13.2 to 1.16.0.
- [Release notes](https://github.com/axios/axios/releases)
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)
- [Commits](https://github.com/axios/axios/compare/v1.13.2...v1.16.0)

---
updated-dependencies:
- dependency-name: axios
  dependency-version: 1.16.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* [47c230b6] Finish + harden axios dependency bump (supersedes PR #344) (#355)

* [9a0e97fb] Bump axios to ^1.16.0 and verify build/lint/typecheck/test (#349)

* [9a0e97fb] chore(panel): regenerate lockfile for axios ^1.16.0 (1.18.1)

* [9a0e97fb] docs(changelog): document axios ^1.16.0 bump with new transitive deps

---------

Co-authored-by: Frontend Developer 1 <fe-dev-1@roboco.tech>
Co-authored-by: Frontend Documenter <fe-doc@roboco.tech>

* [2b0d5fe8] docs(api-client): record axios 1.16 compatibility audit finding (#352)

Co-authored-by: Frontend Developer 1 <fe-dev-1@roboco.tech>

* [36ae2ab0] Remove stray .venv symlink and harden .gitignore (#359)

* [36ae2ab0] chore(repo): remove stray .venv symlink and harden .gitignore

Removes the tracked .venv symlink at the repository root and drops
the trailing slash on the .gitignore .venv entry so the pattern
matches a symlink or plain file named .venv, not only a real
directory.

* [36ae2ab0] chore(repo): untrack the .venv symlink from the branch

---------

Co-authored-by: Frontend Developer 1 <fe-dev-1@roboco.tech>

---------

Co-authored-by: Frontend Developer 1 <fe-dev-1@roboco.tech>
Co-authored-by: Frontend Documenter <fe-doc@roboco.tech>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Frontend Developer 1 <fe-dev-1@roboco.tech>
Co-authored-by: Frontend Documenter <fe-doc@roboco.tech>
This commit is contained in:
Renzo F
2026-07-09 03:47:43 +02:00
committed by GitHub
co-authored by Frontend Developer 1 Frontend Documenter dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
parent 47c927c598
commit 0888fefdac
4 changed files with 45 additions and 15 deletions
+1 -1
View File
@@ -37,7 +37,7 @@
"@radix-ui/react-tooltip": "^1.2.8",
"@tailwindcss/typography": "^0.5.19",
"@tanstack/react-query": "^5.90.16",
"axios": "^1.13.2",
"axios": "^1.16.0",
"class-variance-authority": "^0.7.1",
"clsx": "^2.1.1",
"date-fns": "^4.1.0",
+37 -13
View File
@@ -75,8 +75,8 @@ importers:
specifier: ^5.90.16
version: 5.90.16(react@19.2.3)
axios:
specifier: ^1.13.2
version: 1.13.2
specifier: ^1.16.0
version: 1.18.1
class-variance-authority:
specifier: ^0.7.1
version: 0.7.1
@@ -1763,6 +1763,10 @@ packages:
engines: {node: '>=0.4.0'}
hasBin: true
agent-base@6.0.2:
resolution: {integrity: sha512-RZNwNclF7+MS/8bDg70amg32dyeZGZxiDuQmZxKLAlQjr3jGyLx+4Kkk58UO7D2QdgFIQCovuSuZESne6RG6XQ==}
engines: {node: '>= 6.0.0'}
ajv@6.12.6:
resolution: {integrity: sha512-j3fVLgvTo527anyYyJOGTYJbG+vnnQYvE0m5mmkc1TK+nxAppkCLMIL0aZ4dblVCNoGShhm+kzE4ZUykBoMg4g==}
@@ -1849,8 +1853,8 @@ packages:
resolution: {integrity: sha512-ilYanEU8vxxBexpJd8cWM4ElSQq4QctCLKih0TSfjIfCQTeyH/6zVrmIJfLPrKTKJRbiG+cfnZbQIjAlJmF1jQ==}
engines: {node: '>=4'}
axios@1.13.2:
resolution: {integrity: sha512-VPk9ebNqPcy5lRGuSlKx752IlDatOjT9paPlm8A7yOuW2Fbvp4X3JznJtT4f0GzGLLiWE9W8onz51SqLYwzGaA==}
axios@1.18.1:
resolution: {integrity: sha512-3nTvFlvpn9Zu/RkHUqtc7/+al4UpRW5az71ap5zccp6e8RAYEzhMTecX8Dz1wWDYrPpUoB1HAQEGEAEvUr7S9g==}
axobject-query@4.1.0:
resolution: {integrity: sha512-qIj0G9wZbMGNLjLmg1PT6v2mE9AH2zlnADJD/2tC6E00hgmhUOfEB6greHPAfLRSufHqROIUTkw6E+M3lH0PTQ==}
@@ -2351,8 +2355,8 @@ packages:
flatted@3.3.3:
resolution: {integrity: sha512-GX+ysw4PBCz0PzosHDepZGANEuFCMLrnRTiEy9McGjmkCQYwRq4A/X786G/fjM/+OjsWSU1ZrY5qyARZmO/uwg==}
follow-redirects@1.15.11:
resolution: {integrity: sha512-deG2P0JfjrTxl50XGCDyfI97ZGVCxIpfKYmfyrQ54n5FO/0gfIES8C/Psl6kWVDolizcaaxZJnTS0QSMxvnsBQ==}
follow-redirects@1.16.0:
resolution: {integrity: sha512-y5rN/uOsadFT/JfYwhxRS5R7Qce+g3zG97+JrtFZlC9klX/W5hD7iiLzScI4nZqUS7DNUdhPgw4xI8W2LuXlUw==}
engines: {node: '>=4.0'}
peerDependencies:
debug: '*'
@@ -2486,6 +2490,10 @@ packages:
html-url-attributes@3.0.1:
resolution: {integrity: sha512-ol6UPyBWqsrO6EJySPz2O7ZSr856WDrEzM5zMqp+FJJLGMW35cLYmmZnl0vztAZxRUoNZJFTCohfjuIJ8I4QBQ==}
https-proxy-agent@5.0.1:
resolution: {integrity: sha512-dFcAjpTQFgoLMzC2VwU+C/CbS7uRL0lWmxDITmqm7C+7F0Odmj6s9l6alZc6AELXhrnggM2CeWSXHGOdX2YtwA==}
engines: {node: '>= 6'}
ignore@5.3.2:
resolution: {integrity: sha512-hsBTNUqQTDwkWtcdYI2i06Y/nUBEsNEDJKjWdigLvegy8kDuJAS8uRlpkkcQpyEXL0Z/pjDy5HBmMjRCJ2gq+g==}
engines: {node: '>= 4'}
@@ -3269,8 +3277,9 @@ packages:
property-information@7.1.0:
resolution: {integrity: sha512-TwEZ+X+yCJmYfL7TPUOcvBZ4QfoT5YenQiJuX//0th53DE6w0xxLEtfK3iyryQFddXuvkIk51EEgrJQ0WJkOmQ==}
proxy-from-env@1.1.0:
resolution: {integrity: sha512-D+zkORCbA9f1tdWRK0RaCR3GPv50cMxcrz4X8k5LTSUD1Dkw47mKJEZQNunItRTkWwgtaUSo1RVFRIG9ZXiFYg==}
proxy-from-env@2.1.0:
resolution: {integrity: sha512-cJ+oHTW1VAEa8cJslgmUZrc+sjRKgAKl3Zyse6+PV38hZe/V6Z14TbCuXcan9F9ghlz4QrFr2c92TNF82UkYHA==}
engines: {node: '>=10'}
punycode@2.3.1:
resolution: {integrity: sha512-vYt7UD1U9Wg6138shLtLOvdAu+8DsC/ilFtEVHcH+wydcSpNE20AfSOduf6MkRFahL5FY7X1oU7nKVZFtfq8Fg==}
@@ -5409,6 +5418,12 @@ snapshots:
acorn@8.15.0: {}
agent-base@6.0.2:
dependencies:
debug: 4.4.3
transitivePeerDependencies:
- supports-color
ajv@6.12.6:
dependencies:
fast-deep-equal: 3.1.3
@@ -5523,13 +5538,15 @@ snapshots:
axe-core@4.11.0: {}
axios@1.13.2:
axios@1.18.1:
dependencies:
follow-redirects: 1.15.11
follow-redirects: 1.16.0
form-data: 4.0.5
proxy-from-env: 1.1.0
https-proxy-agent: 5.0.1
proxy-from-env: 2.1.0
transitivePeerDependencies:
- debug
- supports-color
axobject-query@4.1.0: {}
@@ -6149,7 +6166,7 @@ snapshots:
flatted@3.3.3: {}
follow-redirects@1.15.11: {}
follow-redirects@1.16.0: {}
for-each@0.3.5:
dependencies:
@@ -6296,6 +6313,13 @@ snapshots:
html-url-attributes@3.0.1: {}
https-proxy-agent@5.0.1:
dependencies:
agent-base: 6.0.2
debug: 4.4.3
transitivePeerDependencies:
- supports-color
ignore@5.3.2: {}
ignore@7.0.5: {}
@@ -7244,7 +7268,7 @@ snapshots:
property-information@7.1.0: {}
proxy-from-env@1.1.0: {}
proxy-from-env@2.1.0: {}
punycode@2.3.1: {}
+6
View File
@@ -14,6 +14,12 @@ declare module "axios" {
const RATE_LIMIT_MAX_RETRIES = 3;
// Create axios instance with default config
// axios ^1.16.0 audit (2026-07-09): every call in panel/src rides this
// browser instance (no proxy option, no maxRedirects/adapter override, no
// manual form-data upload). axios's node-only transitives that changed with
// this bump — follow-redirects, proxy-from-env, form-data — are exercised
// only by axios's Node http adapter, which the panel never invokes; no
// compatibility fix is needed here.
const api: AxiosInstance = axios.create({
baseURL: API_URL,
headers: {