-
Notifications
You must be signed in to change notification settings - Fork 1.4k
New issue
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
d3-color library security issue #2846
Comments
c3 was last updated in August 2020, over two years ago. Is the c3 package still under maintenance? Packages with |
Same issue with d3-color vulnerability. Any update on when c3 will be updated with latest d3 version 7.6.1 to resolve d30color security vulnerability issue? |
Can we get any update on this. We are also using C3 library in our product and facing this issue. Please help us to resolve the issue. |
I recommend doing what I did: Replace c3 with billboard.js. |
I fixed this in my angular project by adding an override in package.json. It did not have any negative impact on my charts. "overrides": { |
The latest version of c3 uses d3 (^5.8.0) as a dependency, and d3 has a dependency for d3-color.
This d3-color library is exposed to the following security issue,
https://snyk.io/vuln/SNYK-JS-D3COLOR-1076592
It would be great if we can get that issue fixed by updating the d3 dependency.
The text was updated successfully, but these errors were encountered: