PeWu / topola

Topola – online genealogy visualization
Apache License 2.0
95 stars 28 forks source link

topola uses outdated d3 libraries with know vulnerabilities #65

Open Bertg opened 3 months ago

Bertg commented 3 months ago

From dependabot

The d3-color module provides representations for various color spaces in the browser. Versions prior to 3.1.0 are vulnerable to a Regular expression Denial of Service. This issue has been patched in version 3.1.0. There are no known workarounds.

If possible, can the project be bumped to use the latest d3 versions?