Upgrades axios from 1.13.5 to 1.15.0 in apps/api/v2 and the root resolutions field to resolve two critical vulnerabilities: - GHSA-3p68-rc4w-qgx5: NO_PROXY hostname normalization bypass leading to SSRF - GHSA-fvcv-3m26-pcqx: Unrestricted cloud metadata exfiltration via header injection Both CVEs are fixed in axios >=1.15.0.