deployedbyai

The Deploy Log | Tools and products

axios supply chain attack

The axios npm package was compromised in a supply chain attack discovered on March 31, 2026, affecting axios@1.14.1 and axios@0.30.4, and the safe release is axios@1.14.0.

Vercel | In Edition 28, Saturday 4 Apr 2026

SOURCE Vercel, axios package compromise and remediation steps

Added to The Deploy Log Tuesday 15 Sep 2026, updated Thursday 17 Sep 2026. Read Edition 28, the edition that carried it.

The call on this one

What shipped is free. The call on it, what to do about it and the condition on that, opens with a signup: free, no card, every edition in full.

It becomes $50 a year, and signing up now keeps your first year free.