-
-
Notifications
You must be signed in to change notification settings - Fork 6.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
d3-color vulnerable to ReDoS - https://github.com/advisories/GHSA-36jr-mh4h-2g58 #3666
Comments
Would love to take this on |
👋🏾 As a dedicated of MermaidJS user, I would also love for this to looked into as well🙇🏾 . It's tripping our security alerts with as a high priority security issue and seems like an important vulnerability to address. Would love to assist in any way if possible. |
It's all great work we solve these vulnerabilities. But it can only be really closed once a package is published. |
Is there an ETA for the release? Same issue as @MgenGlder with security alerts preventing the use of Mermaid 😞 |
can we expect a release this week ? we have corporate freeze for year end developer and would like to close off high severity vulnerabilities |
Do we have an ETA for this release? Hoping to be able to use mermaid once the security concern has been addressed. |
There's a vulnerability reported on packages that dagre-d3 uses
Unfortunately that repo is no longer supported https://github.com/dagrejs/dagre-d3
Are there any plans to mitigate this ..
This is reported by npm audit , but npm install will also display
This will cause serious issues for mermaid going forward as these are reported as high
Thanks
The text was updated successfully, but these errors were encountered: