You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Is your feature request related to a problem? Please describe.
The nivo library fails vulnerability audit due to d3-color library <3.1.0 vulnerable to ReDos. Although the nivo/core library itself has been updated to use d3-color: 3.1.0, the d3-interpolate and d3-scale-chromatic libraries are using 2.x versions. The outdated version of these libraries depend on the d3-color 2.x libraries, which is why the audit continues to fail.
Describe the solution you'd like
Upgrade d3-interpolate and d3-scale-chromatic libraries
Describe alternatives you've considered
N/A
Additional context
The text was updated successfully, but these errors were encountered:
I noticed this as well, upgrading d3-color wasn't enough, that's something I fixed via d9a9c97, and it will be included in the next release (I still need to complete the work on the corresponding PR though 😅).
@plouc was this included in the latest release? I'm unfortunately held back by this task as well since its a high vulnerability dependency. Any update would be great. Thanks!
Is your feature request related to a problem? Please describe.
The nivo library fails vulnerability audit due to d3-color library <3.1.0 vulnerable to ReDos. Although the nivo/core library itself has been updated to use d3-color: 3.1.0, the d3-interpolate and d3-scale-chromatic libraries are using 2.x versions. The outdated version of these libraries depend on the d3-color 2.x libraries, which is why the audit continues to fail.
Describe the solution you'd like
Upgrade d3-interpolate and d3-scale-chromatic libraries
Describe alternatives you've considered
N/A
Additional context
The text was updated successfully, but these errors were encountered: