dagrejs / dagre-d3

A D3-based renderer for Dagre
MIT License
2.83k stars 589 forks source link

Vulnarability issue in package d3-5.16.0.tgz which dagre-d3-0.6.4.tgz package is using #433

Open vbhvag opened 1 year ago

vbhvag commented 1 year ago

Hi Team

Please update d3-5.16.0.tgz to its latest version in dagre-d3-0.6.4.tgz package there is a vulnerability issue for the package.

image

Thanks, Vaibhav Agrawal

tbo47 commented 1 year ago

My fork use the latest version of D3 https://github.com/tbo47/dagre-es

DaanDL commented 8 months ago

That's not a workeable solution as it's used by mermaid, which is used by markdown libaries.

tbo47 commented 8 months ago

Are you sure? It is not in the latest version: https://github.com/mermaid-js/mermaid/blob/develop/packages/mermaid/package.json#L70