Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

d3-color vulnerability fix #2348

Closed
decisionsdevin opened this issue May 25, 2023 · 3 comments
Closed

d3-color vulnerability fix #2348

decisionsdevin opened this issue May 25, 2023 · 3 comments

Comments

@decisionsdevin
Copy link

Is your feature request related to a problem? Please describe.
The nivo library fails vulnerability audit due to d3-color library <3.1.0 vulnerable to ReDos. Although the nivo/core library itself has been updated to use d3-color: 3.1.0, the d3-interpolate and d3-scale-chromatic libraries are using 2.x versions. The outdated version of these libraries depend on the d3-color 2.x libraries, which is why the audit continues to fail.

Describe the solution you'd like
Upgrade d3-interpolate and d3-scale-chromatic libraries

Describe alternatives you've considered
N/A

Additional context
Screenshot 2023-05-25 144111

@plouc
Copy link
Owner

plouc commented May 25, 2023

I noticed this as well, upgrading d3-color wasn't enough, that's something I fixed via d9a9c97, and it will be included in the next release (I still need to complete the work on the corresponding PR though 😅).

@plouc plouc closed this as completed May 25, 2023
@jvu1 jvu1 mentioned this issue Jul 27, 2023
@msheahen
Copy link

@plouc was this included in the latest release? I'm unfortunately held back by this task as well since its a high vulnerability dependency. Any update would be great. Thanks!

@pcorpet
Copy link
Contributor

pcorpet commented Aug 8, 2023

Apparently this is part of the theming change (#2337) which is not merged yet. As such we're still waiting for a fix to be released.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants