-
-
Notifications
You must be signed in to change notification settings - Fork 1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
D3 dependencies vulnerability #2470
Comments
|
Same issue here, npm audit vulnerabilities are still flagged |
What is the progress on this? Kindly update |
+1 - Here's the npm audit:
|
Hi, same issue here. For my project I need to install By installing only
By installing only
By installing only
|
Any fix for this? |
Hi can we get this in? The vulnerability scan we are required to do is starting to cause issues. |
Looks like there is a PR for this: #2466 can we get this in? |
Please include the non-vulnerable d3 packages on nivo, it would be very nice |
+1 Dependencies :
Npm audit report :
Thanks in advance. |
Must be resolved by #2466. Looking forward to the release. |
|
Solved in |
Not exactly a bug but twas wondering if the
d3-scale-chromatic
version used in@nivo/colors
can be updated to v3.0.0 , the latest version. This would update thed3-color
dependency which is currently at 2.x to 3.x which patches a vulnerability.The version has already been updated to v3.0.0 in
![image](https://private-user-images.githubusercontent.com/23196262/284562211-86e2800d-be11-49f1-8419-7de50203e997.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Mzk0MTYzNjAsIm5iZiI6MTczOTQxNjA2MCwicGF0aCI6Ii8yMzE5NjI2Mi8yODQ1NjIyMTEtODZlMjgwMGQtYmUxMS00OWYxLTg0MTktN2RlNTAyMDNlOTk3LnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNTAyMTMlMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjUwMjEzVDAzMDc0MFomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPTc2Y2JlMGZjMDg1Mzk2NzY4NDhiODJlOGNmNGU3N2U4Y2ZiMWI5N2JkNmMwMzYwY2QwYjc3ZjA5Nzk5MmFkZDImWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0In0.E2wOJ9Gdm6l33fxWrz5MJBGHL76purh8_Klz3UqxVw4)
@nivo/[email protected]
but not in@nivo/[email protected]
The text was updated successfully, but these errors were encountered: