Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security] Bump d3 from 6.7.0 to 7.6.1 #3781

Closed
wants to merge 1 commit into from
Closed

Conversation

eatyourgreens
Copy link
Contributor

@eatyourgreens eatyourgreens commented Oct 14, 2022

  • Bump d3 to the latest version, including a security patch for d3-color.

The project app builds and runs. I can use the PH-TESS light curve viewer, which is built with d3. The progress bar on the project home page also works without problems.

However, tests fail because of #3779.

Package

app-project
lib-classifier

Linked Issue and/or Talk Post

How to Review

Load Planet Hunters TESS in the browser, or run the project and classifier storybooks. d3 is used for the Light Curve Viewer and the project progress bar.

Checklist

PR Creator - Please cater the checklist to fit the review needed for your code changes.
PR Reviewer - Use the checklist during your review. Each point should be checkmarked or discussed before PR approval.

General

  • Tests are passing locally and on Github
  • Documentation is up to date and changelog has been updated if appropriate
  • You can yarn panic && yarn bootstrap or docker-compose up --build and FEM works as expected
  • FEM works in all major desktop browsers: Firefox, Chrome, Edge, Safari (Use Browserstack account as needed)
  • FEM works in a mobile browser

General UX

Example Staging Project: i-fancy-cats

  • All pages of a FEM project load: Home Page, Classify Page, and About Pages
  • Can submit a classification
  • Can sign-in and sign-out
  • The component is accessible

Maintenance

  • If not from dependabot, the PR creator has described the update (major, minor, or patch version, changelog)

@eatyourgreens eatyourgreens added dependencies Pull requests that update a dependency file security Pull requests that address a security vulnerability labels Oct 14, 2022
@eatyourgreens eatyourgreens requested a review from a team October 14, 2022 21:37
@eatyourgreens eatyourgreens force-pushed the d3-7.6.1 branch 2 times, most recently from 8d3f5d0 to eec4b6b Compare October 17, 2022 13:46
@eatyourgreens eatyourgreens force-pushed the d3-7.6.1 branch 2 times, most recently from bfa7550 to 2b5d6e8 Compare November 23, 2022 20:08
@eatyourgreens eatyourgreens force-pushed the d3-7.6.1 branch 5 times, most recently from 20a0008 to d1c0f2c Compare December 2, 2022 14:24
@eatyourgreens eatyourgreens force-pushed the d3-7.6.1 branch 2 times, most recently from b3cab96 to ca90bfd Compare December 6, 2022 17:53
- Bump `d3` to the latest version, including a security patch for `d3-color`.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file security Pull requests that address a security vulnerability
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants