dc-js / dc.js

Multi-Dimensional charting built to work natively with crossfilter rendered with d3.js
Apache License 2.0
7.41k stars 1.81k forks source link

High vulnerability found in d3-color #1872

Open TheAndre980 opened 1 year ago

TheAndre980 commented 1 year ago

High vulnerability found (30.09.2022) from npm audit

https://github.com/advisories/GHSA-36jr-mh4h-2g58

┌───────────────┬──────────────────────────────────────────────────────────────┐ │ High │ d3-color vulnerable to ReDoS │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ Package │ d3-color │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ Patched in │ >=3.1.0 │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ Dependency of │ dc │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ Path │ dc > d3 > d3-color │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ More info │ https://github.com/advisories/GHSA-36jr-mh4h-2g58 │ └───────────────┴──────────────────────────────────────────────────────────────┘

My guess would just be to update the d3 lib that has a d3-color fixed