antvis/G2




The issue has been closed
我使用的是4.1.34版本,当我用npm audit 我发现了高危漏洞关于 d3-color #4423
adseng posted onGitHub
我又试了 4.2.0 和 4.2.8 版本,都有问题。
这是检查报告
High d3-color vulnerable to ReDoS
Package d3-color
Patched in >=3.1.0
Dependency of @antv/g2
Path @antv/g2 > @antv/g-base > d3-interpolate > d3-color
More info https://github.com/advisories/GHSA-36jr-mh4h-2g58
High d3-color vulnerable to ReDoS
Package d3-color
Patched in >=3.1.0
Dependency of @antv/g2
Path @antv/g2 > @antv/component > @antv/g-base > d3-interpolate >
d3-color
More info https://github.com/advisories/GHSA-36jr-mh4h-2g58