Hi, I noticed this vulnerability when doing npm audit; below is the output:
d3-color <3.1.0
Severity: high
d3-color vulnerable to ReDoS - https://github.com/advisories/GHSA-36jr-mh4h-2g58
fix available via `npm audit fix --force`
Will install venn.js@0.2.10, which is a breaking change
node_modules/venn.js/node_modules/d3-color
d3-interpolate 0.1.3 - 2.0.1
Depends on vulnerable versions of d3-color
node_modules/venn.js/node_modules/d3-interpolate
d3-transition 0.0.7 - 2.0.0
Depends on vulnerable versions of d3-color
Depends on vulnerable versions of d3-interpolate
node_modules/venn.js/node_modules/d3-transition
venn.js >=0.2.11
Depends on vulnerable versions of d3-transition
node_modules/venn.js
Is this something that will be fixed?
Hi, I noticed this vulnerability when doing npm audit; below is the output:
Is this something that will be fixed?