-
-
Notifications
You must be signed in to change notification settings - Fork 1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Upgrade d3-color to >= 3.1.0 to avoid security vunerability #2265
Comments
My
|
There was a PR merged recently that addresses this (https://github.com/plouc/nivo/pull/2142/files) but I don't think there has been a release yet that contains the fix (I'm waiting on it as well) |
Hu @plouc. I'm waiting for the release with the d3-color upgrade too. |
That PR is not sufficient because version 2 is still being installed by |
Hi @plouc! I'm waiting for the release too |
Any update on this? |
|
Describe/explain the bug
d3-color
<v3.1.0
has a high-level security vunerability. The solution is to upgrade the version to3.1.0
or above.To Reproduce
npm audit
with nivo installed.Expected behavior
There should be no security error relating to nivo.
Additional context
Upgrading
d3-color
is the prescribed solution, but it might require upgrading other d3 libraries as well.The text was updated successfully, but these errors were encountered: