Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

d3-color REDoS version patch #331

Conversation

emattiza
Copy link
Contributor

@emattiza emattiza commented Dec 5, 2022

overrides the version of d3-color used by d3-scale -> d3-interpolate to use 3.1.0, which remediates
https://security.snyk.io/vuln/SNYK-JS-D3COLOR-1076592

This addresses #328, and can be removed when d3/d3-interpolate#105 is reopened and merged.

LMK if there is a CLA or other formalities before merge. We are also patching in our install, but wanted to share more broadly in the meantime if this is a nit for react-charts users.

overrides the version of d3-color used by d3-scale -> d3-interpolate
to use 3.1.0, which remediates
https://security.snyk.io/vuln/SNYK-JS-D3COLOR-1076592
@emattiza emattiza changed the title d3-color redos version patch d3-color REDoS version patch Dec 5, 2022
@tannerlinsley
Copy link
Collaborator

Totally reasonable. 👍

@tannerlinsley tannerlinsley merged commit d13a268 into TanStack:beta Dec 5, 2022
@tannerlinsley
Copy link
Collaborator

🎉 This PR is included in version 3.0.0-beta.51 🎉

The release is available on:

Your semantic-release bot 📦🚀

@amitnyc83
Copy link

amitnyc83 commented Jan 31, 2024

Hi there - I am using dx-react-charts as a dependency which has a dependency on react-charts -> d3-scale -> d3-interpolate -> d3-color. Do i just add d3-color v3.1.0 as a peerDependency to fix this issue. Thanks in advance!

# for free to join this conversation on GitHub. Already have an account? # to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants