Uploaded image for project: 'MetaBrainz Sec Management'
  1. MetaBrainz Sec Management
  2. SEC-890

[listenbrainz-server] GHSA-36jr-mh4h-2g58: d3-color < 3.1.0

    • Icon: Task Task
    • Resolution: Invalid
    • Icon: Normal Normal
    • LB
    • None
    • 2,963,431,818

      GHSA-36jr-mh4h-2g58 affects package d3-color < 3.1.0 which metabrainz/listenbrainz-server depends on.

      Please self-assign this ticket and check metabrainz/listenbrainz-server alerts, then:

      • Dismiss the corresponding alert in GitHub if there is a valid reason (patch in progress, no bandwidth, tolerable risk, inaccurate alert, or unused code) for.
      • Create a new ticket in the affected JIRA project, link it to this ticket (do not move this ticket to another project), and address that new ticket.

      In both case, GitHub Bot will close this ticket for you, except if you backport a patch on a vulnerable dependency.

      This ticket has been created by SEC automation.

          [SEC-890] [listenbrainz-server] GHSA-36jr-mh4h-2g58: d3-color < 3.1.0

          GitHub Bot added a comment -

          Alert has been resolved according to GitHub.

          GitHub Bot added a comment - Alert has been resolved according to GitHub.

          GitHub Bot added a comment -

          Alert dismissed by MonkeyDo on GitHub for the following reason:
          A fix has already been started

          GitHub Bot added a comment - Alert dismissed by MonkeyDo on GitHub for the following reason: A fix has already been started

          yvanzo added a comment -

          dependabot bot reopened this from #2388 March 12, 2023 14:10

          The above comment by kartik1712 is probably still current.

          yvanzo added a comment - dependabot bot reopened this from #2388 March 12, 2023 14:10 The above comment by kartik1712 is probably still current.

          yvanzo added a comment -

          Actually fixed or invalid, the resolution field has not been set by GitHub bot in due time.

          yvanzo added a comment - Actually fixed or invalid, the resolution field has not been set by GitHub bot in due time.

          GitHub Bot added a comment -

          Alert has been resolved according to GitHub.

          GitHub Bot added a comment - Alert has been resolved according to GitHub.

          amCap1712 added a comment -

          Need to update nivo/color once it merges https://github.com/plouc/nivo/pull/2142 and releases a new version.

          amCap1712 added a comment - Need to update nivo/color once it merges https://github.com/plouc/nivo/pull/2142 and releases a new version.

            kartik1712 amCap1712
            github-bot GitHub Bot
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved:

                Version Package