Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

d3-color REDoS version patch #331

Conversation

emattiza
Copy link
Contributor

@emattiza emattiza commented Dec 5, 2022

overrides the version of d3-color used by d3-scale -> d3-interpolate to use 3.1.0, which remediates
https://security.snyk.io/vuln/SNYK-JS-D3COLOR-1076592

This addresses #328, and can be removed when d3/d3-interpolate#105 is reopened and merged.

LMK if there is a CLA or other formalities before merge. We are also patching in our install, but wanted to share more broadly in the meantime if this is a nit for react-charts users.

overrides the version of d3-color used by d3-scale -> d3-interpolate
to use 3.1.0, which remediates
https://security.snyk.io/vuln/SNYK-JS-D3COLOR-1076592
@emattiza emattiza changed the title d3-color redos version patch d3-color REDoS version patch Dec 5, 2022
@tannerlinsley
Copy link
Collaborator

Totally reasonable. 👍

@tannerlinsley tannerlinsley merged commit d13a268 into TanStack:beta Dec 5, 2022
@tannerlinsley
Copy link
Collaborator

🎉 This PR is included in version 3.0.0-beta.51 🎉

The release is available on:

Your semantic-release bot 📦🚀

@amitnyc83
Copy link

amitnyc83 commented Jan 31, 2024

Hi there - I am using dx-react-charts as a dependency which has a dependency on react-charts -> d3-scale -> d3-interpolate -> d3-color. Do i just add d3-color v3.1.0 as a peerDependency to fix this issue. Thanks in advance!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants