🐛 [BUG] Snyk vulnerabilities
- Dominant language
- TypeScript
- Stars
- 2.7k
- Forks
- 591
- PR merge metrics
- No merged PRs in 30d
Description
Hi,
I'm struggling with vulnerabilities in antv/g2plot package, is it possible to update dependencies?
[SNYK-JS-ANSIREGEX-1583908](https://app.snyk.io/vuln/SNYK-JS-ANSIREGEX-1583908)
[SNYK-JS-UGLIFYJS-1727251](https://app.snyk.io/vuln/SNYK-JS-UGLIFYJS-1727251)
For example :
```
@antv/g2plot@2.4.31 › fmin@0.0.2 › rollup@0.25.8 › chalk@1.1.3 › has-ansi@2.0.0 › ansi-regex@2.1.1
@antv/g2plot@2.4.31 › fmin@0.0.2 › rollup@0.25.8 › chalk@1.1.3 › strip-ansi@3.0.1 › ansi-regex@2.1.1
@antv/g2plot@2.4.31 › fmin@0.0.2 › uglify-js@2.8.29
```
Thanks a lot
* **G2Plot Version**: @antv/g2plot@2.4.31
* **Platform**: Ubuntu 22
Contributor guide
Research direction
Start by tracing the Snyk advisories through the dependency chains listed for @antv/g2plot@2.4.31, including rollup, ansi-regex, and uglify-js. No repository files or tests are named; done means the affected dependency paths are updated or removed and the reported vulnerabilities no longer apply.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- rollup, typescript
- Domain
- build-system, security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100