plotly / plotly/plotly.js

[BUG]: Phishing warning on fonts.openmaptiles.org

Aperta
#7,755 2 commenti 2 reazioni 1 assegnatario Vedi su GitHub

@emilykl ci sta già lavorando.

Dal 31/8/2026.

bug P2 size: 1
Lingua principale
JavaScript
Stelle
18.3k
Fork
2k
Merge medio
2g 12h
PR unite (30g)
28

Descrizione

Description

Client raised issue with us, that when accessing the sites containing maps, they get access blocked due to phising alert. Upon investigation I found that the site fonts.openmaptiles.org has phising alert. This site is the source of fonts used by maps.

It seems that Plotly.py is referencing fonts.openmaptiles here: mimeExtension.js, so the true source of the problem is Plotly JS, not sure if i should maybe raise a ticket there instead?

Screenshots/Video

I cannot reproduce what my client experienced exactly, as I don't use the same security. But when accessing the font site I get the phising alert in the browser.

Image
Steps to reproduce

Plotly.py version: plotly==6.6.0

How to know that my map references the compromised source?

  1. Go to a page with the Plotly map using chrome browser
  2. open the devtools in chrome, go to Network
  3. reload the page
  4. use search option to search for openmaptiles
Image
Notes

same issue reported in other libraries:

Since I thought that OpenStreetMap is a problem I tried other map styles, but the file is still showing.

Guida per i contributori

Apri la guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.