Fix axios supply chain vulnerability in CI scripts#5524
Open
sanjuyadav24 wants to merge 3 commits intomasterfrom
Open
Fix axios supply chain vulnerability in CI scripts#5524sanjuyadav24 wants to merge 3 commits intomasterfrom
sanjuyadav24 wants to merge 3 commits intomasterfrom
Conversation
Pin axios to exact versions and add --ignore-scripts to prevent
postinstall script execution in CI pipelines.
Ref: #5517
|
Azure Pipelines: Successfully started running 1 pipeline(s). |
tarunramsinghani
approved these changes
Apr 10, 2026
Contributor
|
/azp run |
|
Commenter does not have sufficient privileges for PR 5524 in repo microsoft/azure-pipelines-agent |
|
Azure Pipelines: Successfully started running 1 pipeline(s). |
|
Azure Pipelines: Successfully started running 1 pipeline(s). |
raujaiswal
approved these changes
Apr 20, 2026
raujaiswal
reviewed
Apr 20, 2026
tarunramsinghani
approved these changes
Apr 20, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Context
AB#2376575
[Pin axios to 1.14.0 and minimist to 1.2.8 with --ignore-scripts in the canary test pipeline step.
dependencies.](Axios supply chain attack - does this need locking to a specific version? #5517)
Description
Pin axios to 1.14.0 and minimist to 1.2.8 with --ignore-scripts in the canary test pipeline step.
dependencies.
Risk Assessment (Low)
Unit Tests Added or Updated (No)
CI pipeline YAML change — no unit-testable code modified. The canary pipeline itself serves as the integration test.
Additional Testing Performed
Change Behind Feature Flag (No)
CI pipeline hardening — feature flags are not applicable to build infrastructure changes.
Tech Design / Approach
No architectural changes.
Documentation Changes Required (Yes/No)
NA
Logging Added/Updated (Yes/No)
NA
Telemetry Added/Updated (Yes/No)
NA
Rollback Scenario and Process (Yes/No)
NA
Dependency Impact Assessed and Regression Tested (Yes/No)
NA