antvis / antvis/G2Plot

🐛 [BUG] Snyk vulnerabilities

Open
#3,636 1 comment 0 reactions 0 assignees View on GitHub
Bug
Dominant language
TypeScript
Stars
2.7k
Forks
591
PR merge metrics
No merged PRs in 30d

Description

Hi,
I'm struggling with vulnerabilities in antv/g2plot package, is it possible to update dependencies?

[SNYK-JS-ANSIREGEX-1583908](https://app.snyk.io/vuln/SNYK-JS-ANSIREGEX-1583908)
[SNYK-JS-UGLIFYJS-1727251](https://app.snyk.io/vuln/SNYK-JS-UGLIFYJS-1727251)
For example :

```
@antv/g2plot@2.4.31 › fmin@0.0.2 › rollup@0.25.8 › chalk@1.1.3 › has-ansi@2.0.0 › ansi-regex@2.1.1
@antv/g2plot@2.4.31 › fmin@0.0.2 › rollup@0.25.8 › chalk@1.1.3 › strip-ansi@3.0.1 › ansi-regex@2.1.1
@antv/g2plot@2.4.31 › fmin@0.0.2 › uglify-js@2.8.29
```

Thanks a lot

* **G2Plot Version**: @antv/g2plot@2.4.31
* **Platform**: Ubuntu 22

Contributor guide

Open the contributing guide

Research direction

Start by tracing the Snyk advisories through the dependency chains listed for @antv/g2plot@2.4.31, including rollup, ansi-regex, and uglify-js. No repository files or tests are named; done means the affected dependency paths are updated or removed and the reported vulnerabilities no longer apply.

Written by the indexing model from the issue text.

Assessment

Tech stack
rollup, typescript
Domain
build-system, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.