-
-
Notifications
You must be signed in to change notification settings - Fork 1.9k
Closed
Description
Following the vulnerability revealed in https://security.snyk.io/vuln/SNYK-JS-D3COLOR-1076592
plotly.js uses d3-interpolate 1.4.1 which still depends on vulnerable d3-color 1.4.1
Given plotly currenlty depends on d3-color 3.8 (see https://github.com/plotly/d3/blob/master/package.js) which is not affected, could we update this dependency to 3.0.1?
Eusebius1920, JakeBamrah, Danilo-Gomez, RedShift1, raulmarindev and 17 more
Metadata
Metadata
Assignees
Labels
No labels