You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
g2plot 2.4.32 depends on fmin 0.0.2 which depends on rollup < 2.79.2 which has a high severity vulnerability.
rollup <2.79.2
Severity: high
DOM Clobbering Gadget found in rollup bundled scripts that leads to XSS - https://github.com/advisories/GHSA-gcx4-mw62-g8wm
fix available via `npm audit fix`
node_modules/fmin/node_modules/rollup
fmin <=0.0.2
Depends on vulnerable versions of rollup
node_modules/fmin
@antv/g2plot 2.3.33 - 2.4.32
Depends on vulnerable versions of fmin
node_modules/@antv/g2plot
Solution: bump fmin version to 0.0.4
The text was updated successfully, but these errors were encountered:
g2plot 2.4.32 depends on fmin 0.0.2 which depends on rollup < 2.79.2 which has a high severity vulnerability.
Solution: bump fmin version to 0.0.4
The text was updated successfully, but these errors were encountered: