Skip to content

CVE remediation: vendor axios 1.15.0 locally and enforce secure cookie flags#10

Merged
JakeMF merged 2 commits into
masterfrom
cve-remediation
May 18, 2026
Merged

CVE remediation: vendor axios 1.15.0 locally and enforce secure cookie flags#10
JakeMF merged 2 commits into
masterfrom
cve-remediation

Conversation

@JakeMF
Copy link
Copy Markdown

@JakeMF JakeMF commented May 18, 2026

Summary

  • Vendor axios 1.15.0 locally (replaces CDN reference), eliminating exposure to CDN-hosted CVEs
  • Add web.config with IIS URL Rewrite rules to enforce HttpOnly and Secure flags on all cookies
  • Update Acmebot.csproj to copy web.config to publish output

🤖 Generated with Claude Code

JakeMF and others added 2 commits May 18, 2026 15:09
Co-Authored-By: Jake Farley with Claude Code <noreply@anthropic.com>
…L Rewrite

Co-Authored-By: Jake Farley with Claude Code <noreply@anthropic.com>
@JakeMF JakeMF merged commit a18050b into master May 18, 2026
4 checks passed
@JakeMF JakeMF deleted the cve-remediation branch May 18, 2026 19:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant