plotly / plotly/plotly.js

[BUG]: Phishing warning on fonts.openmaptiles.org

Ouverte
#7,755 2 commentaires 2 réactions 1 personne assignée Voir sur GitHub

@emilykl y travaille déjà.

Depuis le 31/8/2026.

bug P2 size: 1
Langage dominant
JavaScript
Étoiles
18.3k
Forks
2k
Merge moyen
2 j 12 h
PR mergées (30 j)
28

Description

Description

Client raised issue with us, that when accessing the sites containing maps, they get access blocked due to phising alert. Upon investigation I found that the site fonts.openmaptiles.org has phising alert. This site is the source of fonts used by maps.

It seems that Plotly.py is referencing fonts.openmaptiles here: mimeExtension.js, so the true source of the problem is Plotly JS, not sure if i should maybe raise a ticket there instead?

Screenshots/Video

I cannot reproduce what my client experienced exactly, as I don't use the same security. But when accessing the font site I get the phising alert in the browser.

Image
Steps to reproduce

Plotly.py version: plotly==6.6.0

How to know that my map references the compromised source?

  1. Go to a page with the Plotly map using chrome browser
  2. open the devtools in chrome, go to Network
  3. reload the page
  4. use search option to search for openmaptiles
Image
Notes

same issue reported in other libraries:

Since I thought that OpenStreetMap is a problem I tried other map styles, but the file is still showing.

Guide de contribution

Ouvrir le guide de contribution

Par où commencer

  1. Lisez l'issue en entier, puis le guide de contribution du projet.
  2. Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
  3. Forkez le dépôt et travaillez sur une branche.
  4. Ouvrez une pull request qui référence le numéro de l'issue.

Évaluation

Cette issue n'a pas encore été évaluée.

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.