atlas-guide icon indicating copy to clipboard operation
atlas-guide copied to clipboard

[Snyk] Fix for 1 vulnerabilities

Open snyk-bot opened this issue 2 years ago • 0 comments

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-D3COLOR-1076592
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: d3-color The new version differs by 11 commits.
  • 611e1c3 3.0.0
  • 4c2be7e Adopt type=module (#90)
  • 017a463 v2.0.0
  • 7de7354 Merge pull request #75 from d3/two
  • 0ecd740 v2.0.0-rc.1
  • 0eb9594 Merge pull request #76 from d3/radians
  • cc0a51b Merge pull request #77 from d3/document-extensions
  • fd23843 document extensions
  • d86e36b link to https://d3js.org/d3-color.v2.min.js
  • c1b93f1 normalize "degrees" and "radians" for deg2rad conversions
  • 693572b deliberate ES6 syntax

See the full diff

Package name: d3-scale The new version differs by 91 commits.

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

snyk-bot avatar Mar 29 '22 16:03 snyk-bot