d3-color library security issue
Open
- Dominant language
- JavaScript
- Stars
- 9.3k
- Forks
- 1.4k
- Avg merge
- 6d 16h
- Merged PRs (30d)
- 1
Description
The latest version of c3 uses d3 (**^5.8.0**) as a dependency, and d3 has a dependency for d3-color.
This d3-color library is exposed to the following security issue,
https://snyk.io/vuln/SNYK-JS-D3COLOR-1076592
It would be great if we can get that issue fixed by updating the d3 dependency.
* **C3 version**: **0.7.20**
* **D3 version**: **5.16.0**
Contributor guide
Assessment
This issue has not been assessed yet.