Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[CVE] Bump d3-color #79

Merged
merged 5 commits into from
Sep 29, 2022
Merged

Conversation

kaddy645
Copy link
Contributor

@kaddy645 kaddy645 commented Sep 29, 2022

Description

The d3-color module provides representations for various color spaces in the browser. Versions prior to 3.1.0 are vulnerable to a Regular expression Denial of Service. This issue has been patched in version 3.1.0. There are no known workarounds.

Issues Resolved

Issue-78

Check List

  • New functionality includes testing.
  • New functionality has been documented.
  • All tests pass
    • yarn lint
    • yarn test-unit
  • Commits are signed per the DCO using --signoff

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

For more information on following Developer Certificate of Origin and signing off your commits, please check here.

@kaddy645 kaddy645 requested a review from a team as a code owner September 29, 2022 17:40
@kaddy645 kaddy645 changed the title Bump d3 color [CVE] Bump d3-color Sep 29, 2022
@AMoo-Miki AMoo-Miki merged commit fa3d410 into opensearch-project:main Sep 29, 2022
opensearch-trigger-bot bot pushed a commit that referenced this pull request Sep 29, 2022
* Bump React 16.12.0 to 16.14.0 (#55)

Signed-off-by: kaddy645 <[email protected]>

Signed-off-by: kaddy645 <[email protected]>

* [CVE] Bump d3-color

Signed-off-by: Kartik <[email protected]>

Signed-off-by: kaddy645 <[email protected]>
Signed-off-by: Kartik <[email protected]>
(cherry picked from commit fa3d410)
joshuarrrr pushed a commit that referenced this pull request Oct 5, 2022
* Bump React 16.12.0 to 16.14.0 (#55)

Signed-off-by: kaddy645 <[email protected]>

Signed-off-by: kaddy645 <[email protected]>

* [CVE] Bump d3-color

Signed-off-by: Kartik <[email protected]>

Signed-off-by: kaddy645 <[email protected]>
Signed-off-by: Kartik <[email protected]>
(cherry picked from commit fa3d410)

Co-authored-by: Kartik <[email protected]>
@kaddy645 kaddy645 mentioned this pull request Oct 10, 2022
KrooshalUX pushed a commit to KrooshalUX/oui that referenced this pull request Nov 4, 2022
* Bump React 16.12.0 to 16.14.0 (opensearch-project#55)

Signed-off-by: kaddy645 <[email protected]>

Signed-off-by: kaddy645 <[email protected]>

* [CVE] Bump d3-color

Signed-off-by: Kartik <[email protected]>

Signed-off-by: kaddy645 <[email protected]>
Signed-off-by: Kartik <[email protected]>
Signed-off-by: Kroosh Crusius <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants