Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

我使用的是4.1.34版本,当我用npm audit 我发现了高危漏洞关于 d3-color #4423

Closed
adseng opened this issue Dec 8, 2022 · 4 comments
Assignees

Comments

@adseng
Copy link

adseng commented Dec 8, 2022

我又试了 4.2.0 和 4.2.8 版本,都有问题。

这是检查报告

High            d3-color vulnerable to ReDoS

  Package         d3-color

  Patched in      >=3.1.0

  Dependency of   @antv/g2

  Path            @antv/g2 > @antv/g-base > d3-interpolate > d3-color

  More info       https://github.com/advisories/GHSA-36jr-mh4h-2g58


  High            d3-color vulnerable to ReDoS

  Package         d3-color

  Patched in      >=3.1.0

  Dependency of   @antv/g2

  Path            @antv/g2 > @antv/component > @antv/g-base > d3-interpolate >
                  d3-color

  More info       https://github.com/advisories/GHSA-36jr-mh4h-2g58
@hustcc
Copy link
Member

hustcc commented Dec 9, 2022

@xiaoiver G 层升级一下吧!

@xiaoiver xiaoiver self-assigned this Dec 9, 2022
@xiaoiver
Copy link
Contributor

xiaoiver commented Dec 9, 2022

已升级 v3 的 d3-interpolate,G 4.0 相关依赖已更新:

  • @antv/g-base => 0.5.12
  • @antv/g-canvas => 0.5.13
  • @antv/g-math => 0.1.9
  • @antv/g-svg => 0.5.7

需要 G2 4.0 发布新版解决。

@hustcc
Copy link
Member

hustcc commented Dec 12, 2022

已升级 v3 的 d3-interpolate,G 4.0 相关依赖已更新:

  • @antv/g-base => 0.5.12
  • @antv/g-canvas => 0.5.13
  • @antv/g-math => 0.1.9
  • @antv/g-svg => 0.5.7

需要 G2 4.0 发布新版解决。

应该用户直接 update 就可以直接生效吧,G2 没有写死依赖的 G 版本。

@xiaoiver
Copy link
Contributor

嗯是的,NPM 方式使用的话现在重新安装依赖即可。

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants