esnet / react-timeseries-charts

Declarative and modular timeseries charting components for React
http://software.es.net/react-timeseries-charts
Other
856 stars 283 forks source link

"merge" lib. dependency #495

Open raul320pl opened 2 years ago

raul320pl commented 2 years ago

🐛Bug report

Describe the bug there is a problem with "merge" dependency: Przechwytywanie

To Reproduce npx create-react-app xxx npm install react-timeseries-charts npm audit

this will return:

merge  <2.1.1
Severity: high
Prototype Pollution in merge - https://github.com/advisories/GHSA-7wpw-2hjm-89gp
No fix available
node_modules/merge
  react-timeseries-charts  *
  Depends on vulnerable versions of merge
  node_modules/react-timeseries-charts