-
Notifications
You must be signed in to change notification settings - Fork 1.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
"d3-color": "^2.0.0"
is causing high Dependency alert
#1809
Comments
I believe this is a duplicate of #1799 It would be great to see this fixed. d3-color is making my charts pretty, but as a side-effect it's also making my vulnerability check pipelines red and angry looking. |
Getting this message as well. Hopefully this will be resolved soon as there is already #1800 |
#1798 as well |
Fixed in |
@marjan-georgiev It's already some progress that you changed your explicit dependency to By the way, for the project itself the situation regarding vulnerable dependencies is even more critical. I freshly checked out the repository and ran
|
@marjan-georgiev I'm still seeing this issue on 20.1.2
|
Describe the bug
Versions prior to 3.1.0 are vulnerable to a Regular expression Denial of Service. This issue has been patched in version 3.1.0. There are no known workarounds .. and I can't update it because it's a dependency in ngx-charts@20.1.0
References
Screenshots
The text was updated successfully, but these errors were encountered: