Skip to content

Conversation

@Joshnovski
Copy link

Bumps d3-color from 2.0.0 to 3.1.0

Link to d3-color security vulnerability notes from IBM Support

I am not sure how to formally write a PR, sorry about the informalities.

@alexsocha
Copy link
Member

looks great, but could you update package-lock.json too please (just run npm i)

@Joshnovski
Copy link
Author

Joshnovski commented Feb 24, 2024 via email

@Joshnovski
Copy link
Author

Would you rather I do a more specific install instead? 'npm i d3-color' should be more manageable to look over and leave the other dependencies untouched for the moment. As you know, 'npm i' updates other packages as well based on semver ranges specified in 'package.json' which has resulted in a lot of the older packages being updated too. Over 5000 changes is nuts to check.

@alexsocha
Copy link
Member

alexsocha commented Feb 26, 2024 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants