Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

能否基于 4.3.2 发布一个 4.x 的修复了原型污染问题的版本? #1106

Open
duwenbin0316 opened this issue Dec 5, 2024 · 2 comments

Comments

@duwenbin0316
Copy link

我们是用的是 echarts v4,内部安全审计检测出 zrender 4.3.2 存在原型污染,修复需要升级到 zrender v5,但是与 ecahrts v4 不适配了。项目很大,升级 echarts 成本也非常高。
我在 fork 的项目中提了一个 commint,参考 #826 的修复方式,但是没有在主仓库中找到 4.x 的分支,所以没法提交 PR。
我创建的 commit 地址:duwenbin0316@bab4ed8
希望作者可以基于 4.3.2 发布一个修复的版本,万分感谢!

@plainheart
Copy link
Collaborator

plainheart commented Dec 6, 2024

感谢反馈,已安排,顺利的话下周会完成~ (拉了个安全修复分支 4.3.3-security-fix

@plainheart
Copy link
Collaborator

已发 v4.3.3

@plainheart plainheart reopened this Dec 6, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants