CodeQL fix in change simulation; axios 1.20.0 (v0.24.45)
- analyzeChange mergeFields builds a new row from RouterOS-shaped property
names only, instead of assigning request-supplied keys onto the existing
one (CodeQL js/remote-property-injection). Simulated results unchanged;
a proto field is ignored. - axios 1.20.0 for GHSA-3pq3-5fj3-cg6v, GHSA-542g-h47m-68v8,
GHSA-c29m-xwm3-cm6r, GHSA-mghh-pgcx-3jjj and GHSA-x97p-jq2g-jp4f (all
high, published today), which failed the frontend audit gate.
Checked locally: Change Guard tests, firewall preflight on the TEST switch,
and a browser pass through login, devices and the firewall tab.
Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
Container images (published once CI passes):
ghcr.io/2gt-media-group-llc/mikrotik-manager-backend:0.24.45-betaghcr.io/2gt-media-group-llc/mikrotik-manager-nginx:0.24.45-beta
Documentation: https://2gt-media-group-llc.github.io/mikrotik-manager/