Announcement icon
Announcements
September 25, 2026

HeroDevs Partners with Axios to Deliver Never-Ending Support for Axios 0.x

Ongoing security fixes for the Axios 0.x line, with funding flowing back to the project that powers HTTP for the JavaScript ecosystem

Give me the TL;DR

Sandy, UT — HeroDevs today announced an official partnership with the Axios project to launch Never-Ending Support (NES) for Axios. Through the partnership, HeroDevs will provide ongoing security fixes for legacy versions of Axios in the 0.x line, while directing funding back to the Axios project to support its continued development and maintenance.

‍

The partnership follows the model HeroDevs has established with Node.js and OpenJS Foundation, Commonhaus Foundation, Drupal Association, Vue, Bootstrap and other cornerstone open source projects: enterprises get secure, drop-in support for versions the community has moved past, and the open source project gets a sustainable funding stream in return.

‍

The Most Depended-on HTTP Client in JavaScript

Axios is the most widely used HTTP client in the JavaScript ecosystem. First released in 2014, the package now averages more than 85 million weekly downloads on npm and sits in the dependency tree of more than 174,000 published packages. It ships in a substantial share of Node.js production applications, often as a transitive dependency pulled in through SDKs, CLIs, and framework integrations. If your application talks to an API, there is a good chance Axios is doing the talking.

‍

That ubiquity is exactly why Axios matters so much to enterprise security teams. When the package was targeted in the March 2026 npm supply chain attack, the attacker published malicious releases on both the current 1.x branch and the legacy 0.x branch, a clear signal that both lines remain in heavy production use around the world.

‍

The Axios 0.x Situation

Axios 1.0 shipped in October 2022, but a large population of production applications still runs on different versions of the 0.x line, pinned there by transitive dependencies, older SDKs, and codebases where an upgrade has never been prioritized. Axios publishes no formal LTS schedule and no per-version maintenance windows: patches land on the latest release, and the maintainers ship security backports to 0.x when they can, as recent as version 0.34.0 was released this month. That volunteer-driven backporting is generous, but it is not a guarantee any enterprise can build a compliance program on.

‍

For teams running 0.x in production, that gap has real consequences. Every new CVE disclosed against Axios becomes a question with no good answer: absorb a potentially breaking upgrade mid-sprint, or keep running a version with a known vulnerability.

‍

What NES for Axios Delivers

NES for Axios gives organizations running 0.x versions, whether 0.24.x, 0.27.x, or earlier, a secure, supported path:

  • Security patches for vulnerabilities of every CVSS severity, delivered as drop-in replacement packages with no breaking API changes
  • CVE remediation SLAs, so audit and compliance teams have a documented answer for every new disclosure
  • Freedom to migrate on your own schedule, with 0.x fully supported while you plan the move to the current 1.x line

"Axios is one of those packages that quietly runs a huge portion of the internet, and the 0.x line in particular is embedded in systems that will not be rewritten this quarter or next," said Robert Nalen, Chief Operating Officer at HeroDevs. "By partnering directly with the Axios project, we can keep those legacy versions secure while making sure the people who actually build and maintain Axios are funded for the enormous value they create."

‍

Funding Axios, Not Just Consuming It

A core term of the partnership is that it funds Axios itself. This continues HeroDevs' broader investment in open source sustainability, which includes serving as the inaugural partner in the OpenJS Foundation's Ecosystem Sustainability Program, joining the Open Source Pledge, and founding the Open Source Sustainability Initiative with the Commonhaus Foundation. The pattern is the same in every case: the enterprises that depend on open source should be the ones funding its future.

‍

"Maintaining Axios at this scale means every release, and every backport, carries weight for millions of applications," said Jason Saayman, Lead Axios Maintainer. "This partnership means organizations that need to stay on 0.x versions get commercial security support, and the Axios project can keep moving forward with funding for new features and new releases."

‍

Getting Started with NES for Axios

Visit the NES for Axios product page or contact the HeroDevs team if you are interested in Axios 0.x support.

‍

About HeroDevs

HeroDevs is a trusted leader in providing secure, never-ending support for deprecated open-source software. The company's mission is to keep these critical technologies running smoothly, securely, and in compliance long after their official end-of-life. From AngularJS to .NET and Spring, HeroDevs Never-Ending Support (NES) solutions give businesses the freedom to plan migrations on their terms while staying protected against vulnerabilities and compliance risks. Serving industries where security and uptime are non-negotiable, including finance, healthcare, and government, HeroDevs has earned the trust of over 800 companies, including nearly a third of the Fortune 100.

‍

About Axios

Axios is a promise-based HTTP client for the browser and Node.js. First released in 2014, it has become the most widely used HTTP client in the JavaScript ecosystem, averaging more than 85 million weekly downloads on npm with more than 174,000 dependent packages. Axios is developed and maintained by an independent open source team. Learn more at axios-http.com.

‍

Media Contact:

HeroDevs

media@herodevs.com

Open Source Insights Delivered Monthly