pixabay api, https://pixabay.com/api/docs/
<h3>Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.</h3>  #### Changes included in this PR - Changes to the following files to upgrade the vulnerable dependencies to a fixed version: - package.json - package-lock.json #### Vulnerabilities that will be fixed ##### With an upgrade: Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity :-------------------------:|-------------------------|:-------------------------|:-------------------------|:-------------------------  | **616/1000** <br/> **Why?** Proof of Concept exploit, Has a fix available, CVSS 5.9 | Server-Side Request Forgery (SSRF) <br/>[SNYK-JS-AXIOS-1038255](https://snyk.io/vuln/SNYK-JS-AXIOS-1038255) | No | Proof of Concept (*) Note that the real score may have changed since the PR was raised. <details> <summary><b>Commit messages</b></summary> </br> <details> <summary>Package name: <b>axios</b></summary> The new version differs by 250 commits.</br> <ul> <li><a href="https://snyk.io/redirect/github/axios/axios/commit/a64050a6cfbcc708a55a7dc8030d85b1c78cdf38">a64050a</a> Releasing 0.21.1</li> <li><a href="https://snyk.io/redirect/github/axios/axios/commit/d57cd976f3cc0f1c5bb1f0681660e50004781db5">d57cd97</a> Updating changelog for 0.21.1 release</li> <li><a href="https://snyk.io/redirect/github/axios/axios/commit/8b0f373df0574b7cb3c6b531b4092cd670dac6e3">8b0f373</a> Use different socket for Win32 test (#3375)</li> <li><a href="https://snyk.io/redirect/github/axios/axios/commit/e426910be7c417bdbcde9c18cb184ead826fc0e1">e426910</a> Protocol not parsed when setting proxy config from env vars (#3070)</li> <li><a href="https://snyk.io/redirect/github/axios/axios/commit/c7329fefc890050edd51e40e469a154d0117fc55">c7329fe</a> Hotfix: Prevent SSRF (#3410)</li> <li><a href="https://snyk.io/redirect/github/axios/axios/commit/f472e5da5fe76c72db703d6a0f5190e4ad31e642">f472e5d</a> Adding a type guard for `AxiosError` (#2949)</li> <li><a href="https://snyk.io/redirect/github/axios/axios/commit/768825589fd0d36b64a66717ca6df2efd8fb7844">7688255</a> Remove the skipping of the `socket` http test (#3364)</li> <li><a href="https://snyk.io/redirect/github/axios/axios/commit/820fe6e41a96f05fb4781673ce07486f1b37515d">820fe6e</a> Updating axios in types to be lower case (#2797)</li> <li><a href="https://snyk.io/redirect/github/axios/axios/commit/94ca24b5b23f343769a15f325693246e07c177d2">94ca24b</a> Releasing 0.21.0</li> <li><a href="https://snyk.io/redirect/github/axios/axios/commit/2130a0c8acc588c72b53dfef31a11442043ffb06">2130a0c</a> Updating changelog for 0.21.0 release</li> <li><a href="https://snyk.io/redirect/github/axios/axios/commit/fbdc1502b18e1bf7ef4c143b1f3503145a8bce91">fbdc150</a> Lock travis to not use node v15 (#3361)</li> <li><a href="https://snyk.io/redirect/github/axios/axios/commit/3a8b87d48af3c3893fc0560bacb59a4b165968d4">3a8b87d</a> Fixing an issue that type 'null' and 'undefined' is not assignable to validateStatus when typescript strict option is enabled (#3200)</li> <li><a href="https://snyk.io/redirect/github/axios/axios/commit/9a78465a9268dcd360d7663de686709a68560d3d">9a78465</a> Revert "Fixing overwrite Blob/File type as Content-Type in browser. (#1773)" (#3289)</li> <li><a href="https://snyk.io/redirect/github/axios/axios/commit/6d05b96dcae6c82e28b049fce3d4d44e6d15a9bc">6d05b96</a> Fix typos (#3309)</li> <li><a href="https://snyk.io/redirect/github/axios/axios/commit/fa3673710ea6bb3f351b4790bb17998d2f01f342">fa36737</a> fix axios.delete ignores config.data (#3282)</li> <li><a href="https://snyk.io/redirect/github/axios/axios/commit/b7e954eba3911874575ed241ec2ec38ff8af21bb">b7e954e</a> Fixing node types (#3237)</li> <li><a href="https://snyk.io/redirect/github/axios/axios/commit/04d45f20911a02e9457db9e9d104aa156e170b11">04d45f2</a> Fixing requestHeaders.Authorization (#3287)</li> <li><a href="https://snyk.io/redirect/github/axios/axios/commit/e8c6e191410b05c496637768301debdcb7669c65">e8c6e19</a> docs: Fix simple typo, existant -> existent (#3252)</li> <li><a href="https://snyk.io/redirect/github/axios/axios/commit/0d8765562401910c1c509f6739a3bc558721e123">0d87655</a> Releasing 0.20.0</li> <li><a href="https://snyk.io/redirect/github/axios/axios/commit/cd27741ff6c99704e22c66ee7ffde26b57d87d5a">cd27741</a> Updating changelog for 0.20.0 release</li> <li><a href="https://snyk.io/redirect/github/axios/axios/commit/ffea03453f77a8176c51554d5f6c3c6829294649">ffea034</a> Releasing 0.20.0-0</li> <li><a href="https://snyk.io/redirect/github/axios/axios/commit/fe147fbd3b19393e86d25441bdce099aaef90cb1">fe147fb</a> Updating changlog for 0.20.0 beta release</li> <li><a href="https://snyk.io/redirect/github/axios/axios/commit/16aa2ce7fa42e7c46407b78966b7521d8e588a72">16aa2ce</a> Fixing response with utf-8 BOM can not parse to json (#2419)</li> <li><a href="https://snyk.io/redirect/github/axios/axios/commit/c4300a88cf994b9c4b88b065806edb98705a2c5d">c4300a8</a> Adding support for URLSearchParams in node (#1900)</li> </ul> <a href="https://snyk.io/redirect/github/axios/axios/compare/46e275c407f81c44dd9aad419b6e861d8a936580...a64050a6cfbcc708a55a7dc8030d85b1c78cdf38">See the full diff</a> </details> </details> Check the changes in this PR to ensure they won't cause issues with your project. ------------ **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.* For more information: <img src="https://api.segment.io/v1/pixel/track?data=eyJ3cml0ZUtleSI6InJyWmxZcEdHY2RyTHZsb0lYd0dUcVg4WkFRTnNCOUEwIiwiYW5vbnltb3VzSWQiOiIyYjNiOGZkMy1iOTlkLTQ1YWItYWZlMS01MTBkYjM5MTZlYmYiLCJldmVudCI6IlBSIHZpZXdlZCIsInByb3BlcnRpZXMiOnsicHJJZCI6IjJiM2I4ZmQzLWI5OWQtNDVhYi1hZmUxLTUxMGRiMzkxNmViZiJ9fQ==" width="0" height="0"/> 🧐 [View latest project report](https://app.snyk.io/org/dderevjanik/project/5b0007af-8ed0-412d-a31f-ea7f35a48243) 🛠 [Adjust project settings](https://app.snyk.io/org/dderevjanik/project/5b0007af-8ed0-412d-a31f-ea7f35a48243/settings) 📚 [Read more about Snyk's upgrade and patch logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) [//]: # (snyk:metadata:{"prId":"2b3b8fd3-b99d-45ab-afe1-510db3916ebf","dependencies":[{"name":"axios","from":"0.16.2","to":"0.21.1"}],"packageManager":"npm","projectPublicId":"5b0007af-8ed0-412d-a31f-ea7f35a48243","projectUrl":"https://app.snyk.io/org/dderevjanik/project/5b0007af-8ed0-412d-a31f-ea7f35a48243?utm_source=github&utm_medium=fix-pr","type":"auto","patch":[],"vulns":["SNYK-JS-AXIOS-1038255"],"upgrade":["SNYK-JS-AXIOS-1038255"],"isBreakingChange":false,"env":"prod","prType":"fix","templateVariants":["updated-fix-title","priorityScore","merge-advice-badge-shown"],"priorityScoreList":[616]})
This issue appears to be discussing a feature request or bug report related to the repository. Based on the content, it seems to be still under discussion. The issue was opened by snyk-bot and has received 0 comments.