Skip to content

AG-58752 Upgrade @slack/web-api to 8.1.1 to drop vulnerable axios - #34

Merged
slvvko merged 5 commits into
masterfrom
fix/AG-58752
Sep 11, 2026
Merged

slvvko merged 5 commits into
masterfrom
fix/AG-58752

Conversation

@slvvko

@slvvko slvvko commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Summary

Task: AG-58752

Upgrade @slack/web-api from 7.15.1 to 8.1.1 to fix CVE-2026-44486 (HIGH, axios < 1.16.0 leaks Proxy-Authorization to redirect targets in the Node.js adapter).

Since 8.0.0 the Slack SDK no longer depends on axios at all (it uses the native Fetch API), so this removes the vulnerable transitive dependency entirely instead of pinning a patched axios version.

This replaces PR #30, which added axios 1.16.0 as a direct dependency but left the vulnerable transitive axios 1.15.2 in the lockfile — it did not actually fix the CVE.

Changes

  • package.json: @slack/web-api 7.15.1 → 8.1.1 (exact pin, latest stable)
  • yarn.lock: regenerated — axios, form-data, is-stream, is-electron subtrees removed (~190 lines deleted)
  • CHANGELOG.md: Unreleased → Fixed entry
  • bin/: regenerated via yarn build (chunk hash renames only, no src changes)

Why this is safe

  • The codebase only uses WebClient, LogLevel, and chat.postMessage — all unchanged in 8.x
  • No usage of removed options (agent, tls) or deprecated methods (files.upload, rtm.start)
  • Error handling is a plain console.error(error) in a catch block; the new WebAPIPlatformError classes are backward compatible for that pattern
  • Requires Node >= 20; the repo already requires >= 22.17

Verification

  • yarn install — clean
  • yarn build — passes
  • yarn lint — passes
  • yarn test — 10 suites / 34 tests pass
  • yarn why axios — no match (vulnerable dependency removed)
  • Runtime smoke test: WebClient constructs in CJS, real chat.postMessage against the Slack API returns the expected WebAPIPlatformError with an invalid token (native fetch transport works)

@slvvko slvvko changed the title AG-58752 Upgrade @slack/web-api to 8.1.1 to drop vulnerable axios AG-58752 Upgrade @slack/web-api to 8.1.1 to drop vulnerable axios Sep 9, 2026
Comment thread CHANGELOG.md
@slvvko
slvvko marked this pull request as ready for review September 11, 2026 00:07

@totadavid95 totadavid95 left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the @slack/web-api 7.15.1 → 8.1.1 upgrade, lockfile regeneration, and changelog/version updates. The dependency change itself is sound: the codebase only uses WebClient, LogLevel, and chat.postMessage, error handling is a plain console.error(error) (backward compatible with 8.x), and CI is green. One issue to address before merge: the .gitignore change ignores dist/ while the build still outputs to bin/, and it removes the bin/* guard. See the inline comment.

Comment thread .gitignore
Comment thread .gitignore
@slvvko
slvvko requested a review from totadavid95 September 11, 2026 13:12
@slvvko
slvvko merged commit 17df18c into master Sep 11, 2026
1 check passed
@slvvko
slvvko deleted the fix/AG-58752 branch September 11, 2026 13:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants