fix(deps): update dependency plotly.js to v2 [security]#219
Open
renovate[bot] wants to merge 1 commit intomasterfrom
Open
fix(deps): update dependency plotly.js to v2 [security]#219renovate[bot] wants to merge 1 commit intomasterfrom
renovate[bot] wants to merge 1 commit intomasterfrom
Conversation
f8ef7ee to
70f8b3c
Compare
70f8b3c to
1471bca
Compare
1471bca to
fdd03ad
Compare
fdd03ad to
3447646
Compare
3447646 to
97338ae
Compare
97338ae to
2c0f27f
Compare
2c0f27f to
44d36e8
Compare
44d36e8 to
70ee8f6
Compare
7bbc067 to
320a373
Compare
320a373 to
323b5ae
Compare
323b5ae to
7769773
Compare
7769773 to
fb2c80d
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.58.4→2.25.2GitHub Vulnerability Alerts
CVE-2023-46308
In Plotly plotly.js before 2.25.2, plot API calls have a risk of proto being polluted in expandObjectPaths or nestedProperty.
Release Notes
plotly/plotly.js (plotly.js)
v2.25.2Compare Source
Changed
hrlocale [#6690],with thanks to @Mkranj for the contribution!
Fixed
v2.25.1Compare Source
Fixed
v2.25.0Compare Source
Fixed
v2.24.3Compare Source
Added
with thanks to @apparebit for the contribution!
newshape[#6653]Fixed
zmin,zmax,cminandcmax) [#6625],with thanks to @lvlte for the contribution!
with thanks to @baurt for the contribution!
v2.24.2Compare Source
Fixed
hovertemplatenot showing delta on totals similar(https://redirect.github.com/plotly/plotly.js/issues/6635)y.js/issues/6635\))v2.24.1Compare Source
Fixed
(regression introduced in 2.24.0)(https://redirect.github.com/plotly/plotly.js/issues/6632)y.js/issues/6632\))
v2.24.0Compare Source
Fixed
(regression introduced in 2.24.0)(https://redirect.github.com/plotly/plotly.js/issues/6632)y.js/issues/6632\))
v2.23.2Compare Source
Fixed
with thanks to the Volkswagen Center of Excellence for Battery Systems for sponsoring development!
v2.23.1Compare Source
Fixed
zsmoothis set to false [#6605], with thanks to @lvlte for the contribution!v2.23.0Compare Source
Added
legend.xrefandlegend.yrefto enable container-referenced positioning of legends [#6589], with thanks to Gamma Technologies for sponsoring the related development.colorbar.xrefandcolorbar.yrefto enable container-referenced positioning of colorbars [#6593], with thanks to Gamma Technologies for sponsoring the related development.Changed
zsmoothis set to false [#6574], with thanks to @lvlte for the contribution!v2.22.0Compare Source
Fixed
hovertemplatenot showing delta on totals similar(https://redirect.github.com/plotly/plotly.js/issues/6635)y.js/issues/6635\))v2.21.0Compare Source
Added
texttemplateto shape.label for parametric shapes i.e. line, rect and circle [#6527],with thanks to the Volkswagen Center of Excellence for Battery Systems for sponsoring development!
with thanks to @CallumNZ for the contribution!
Fixed
with thanks to @bmaranville for the contribution!
zsmoothis set to "fast" [#6565],with thanks to @lvlte for the contribution!
v2.20.0Compare Source
Added
title.automarginto enable automatic top and bottom margining for both container and paper referenced titles [#6428],with thanks to Gamma Technologies for sponsoring the related development.
v2.19.1Compare Source
Fixed
with thanks to @jay-bis for the contribution!
v2.19.0Compare Source
Added
labelattribute to shapes [#6454],with thanks to the Volkswagen Center of Excellence for Battery Systems for sponsoring development!
labelaliasto various axes namely cartesian, gl3d, polar, smith, ternary, carpet,indicator and colorbar [#6481],
this feature was anonymously sponsored: thank you to our sponsor!
Changed
is-mobiledependency [#6517]Fixed
hovermode: 'x'|'y'[#6442],with thanks to @dagroe for the contribution!
v2.18.2Compare Source
Fixed
with thanks to @Gagaro for the contribution!
with thanks to @andresrcs for the contribution!
v2.18.1Compare Source
Changed
d3-interpolateandd3-colorto v3 to address audit warnings [#6463]Fixed
vector-effectCSS to static plots [#6445]v2.18.0Compare Source
Added
synctickmode option [#6356, #6443],with thanks to @filipesantiagoAM and @VictorBezak for the contribution!
Changed
is-mobile[#6432]Fixed
requirejsAMD loader (regression introduced in 2.17.0) [#6440]v2.17.1Compare Source
Fixed
v2.17.0Compare Source
Fixed
with thanks to @Gagaro for the contribution!
with thanks to @andresrcs for the contribution!
v2.16.5Compare Source
Fixed
staticPlotis set to true [#6393]v2.16.4Compare Source
Fixed
scattermapboxredraw (regression introduced in 2.16.0) [#6387]v2.16.3Compare Source
Fixed
with thanks to @filipesantiagoAM for the contribution!
v2.16.2Compare Source
Fixed
v2.16.1Compare Source
Fixed
choroplethmapboxselection when adding new traces on top [#6345]v2.16.0Compare Source
Fixed
scattermapboxredraw (regression introduced in 2.16.0) [#6387]v2.15.1Compare Source
Fixed
v2.15.0Compare Source
Fixed
v2.14.0Compare Source
Added
with thanks to @Andy2003 for the contribution!
editSelectionoption to config [#6285]Changed
nllocale to confirm with expected nl format [#6261],with thanks to @eirvandelden for the contribution!
v2.13.3Compare Source
Fixed
v2.13.2Compare Source
Fixed
sankeyselect error (regression introduced in 2.13.0) [#6265]sankeytraces to fix select error [#6267]dragmodes when an existing selection is modified [#6262]v2.13.1Compare Source
Fixed
selectionsto undefined eventData (regression introduced in 2.13.0) [#6260]v2.13.0Compare Source
Fixed
v2.12.1Compare Source
Fixed
dragmodeis set to false [#6147],with thanks to @jonfunkhouser for the contribution!
v2.12.0Compare Source
Added
griddashaxis property to cartesian, polar, smith, ternary and geo subplots and addgriddashandminorgriddashtocarpettrace [6144], with thanks to @njwhite for the contribution!minorticks and grid lines on cartesian axis types includingminor.tickmode,minor.tickvals,minor.tickcolor,minor.ticklen,minor.tickwidth,minor.dtick,minor.tick0,minor.nticks,minor.ticks,minor.showgrid,minor.gridcolor,minor.griddashandminor.gridwidth[6166]Changed
with thanks to @junov for the contribution!
Fixed
v2.11.1Compare Source
Fixed
v2.11.0Compare Source
Added
parcoords,splom,scattergl,scatterpolarglto the "strict" bundle [#6083]scattersmithtrace to the "strict" bundle [#6135]v2.10.1Compare Source
Fixed
mesh3dgeneration whenalphahullis a positive number (regression introduced in 2.5.1) [#6133]v2.10.0Compare Source
Added
typesetMathattribute to config [#6073],with thanks to Equinor for sponsoring the related development!
fillpatternoptions toscattertrace [#6101],with thanks to @s417-lama for the contribution!
v2.9.0Compare Source
Added
ticklabelstepto reduce labels on 2D axes and colorbars [#6088],this feature was anonymously sponsored: thank you to our sponsor!
Changed
Fixed
v2.8.3Compare Source
Fixed
texttempateforhistogramtrace [#6070]v2.8.2Compare Source
Fixed
texttemplateforhistogram,bar,funnelandwaterfalltraces [#6069]v2.8.1Compare Source
Fixed
textfontis set to "auto" forheatmap,histogram2d,contourandhistogram2dcontourtraces [#6061]v2.8.0Compare Source
Added
legend.grouptitlefontandhoverlabel.grouptitlefont[#6040]texttemplateandtextfonttoheatmapandhistogram2dtraces as well ashistogram2dcontourandcontourtraces whencoloringis set "heatmap" [#6028]Fixed
piechart post-aggregation instead of during summation [#6051],with thanks to @destiny-wu for the contribution!
v2.7.0Compare Source
Added
texttemplate,textposition,textfont,textangle,outsidetextfont,insidetextfont,insidetextanchor,constraintextandcliponaxistohistogramtrace [#6038]Changed
probe-image-sizemodule to v7.2.2 [#6036]Fixed
uirevisionandautorange. Because we pushautorangeandrangeback intolayout,there can be times it looks like we're applying GUI-driven changes on top of explicit autorange and other times
it's an implicit autorange, even though the user's intent was always implicit. This fix treats them as equivalent. [#6046]
v2.6.4Compare Source
Fixed
v2.6.3Compare Source
Fixed
with thanks to @SabineWren for the contribution!
v2.6.2Compare Source
Fixed
v2.6.1Compare Source
Fixed
v2.6.0Compare Source
Added
with thanks to @thierryVergult for the contribution!
Fixed
have hoverinfo: "none" (regression introduced in 2.6.0)(https://redirect.github.com/plotly/plotly.js/issues/6614)y.js/issues/6614\)),
with thanks to @Domino987 for the contribution!
v2.5.1Compare Source
Fixed
mesh3dgeneration whenalphahullis a positive number (regression introduced in 2.5.1) [#6133]v2.5.0Compare Source
Changed
d3-interpolateandd3-colorto v3 to address audit warnings [#6463]Fixed
vector-effectCSS to static plots [#6445]v2.4.2Compare Source
Fixed
(regression introduced in 2.3.0) [#5913]
v2.4.1Compare Source
Fixed
groupclickis set to "toggleitem" [#5909]v2.4.0Compare Source
Added
legend.groupclickoptions [#5849, #5906],with thanks to @brussee for the contribution!
slidercomponent [#5856],with thanks to @keul for the contribution!
bboxof hover items in event data [#5512]Changed
reglmodule from version 1.6.1 to version 2.1.0 [#5870]Fixed
lib.promiseErrorin lib.syncOrAsync [#5878],with thanks to @jklimke for the contribution!
hoverlabel.fontfor group titles in unified hover modes [#5895]v2.3.1Compare Source
Fixed
parcoords,splom,scatterglandscatterpolarglin the "strict" bundle so that it could be used with CSP without WebGL warning [#5865]v2.3.0Compare Source
Fixed
(regression introduced in 2.3.0) [#5913]
v2.2.1Compare Source
Fixed
v2.2.0Compare Source
Added
this feature was anonymously sponsored: thank you to our sponsor!
this feature was anonymously sponsored: thank you to our sponsor!
Changed
Fixed
rangebreaksto improve performance [#5659],with thanks to @spasovski for the contribution!
v2.1.0Compare Source
Added
legend.groupclickoptions [#5849, #5906],with thanks to @brussee for the contribution!
slidercomponent [#5856],with thanks to @keul for the contribution!
bboxof hover items in event data [#5512]Changed
reglmodule from version 1.6.1 to version 2.1.0 [#5870]Fixed
lib.promiseErrorin lib.syncOrAsync [#5878],with thanks to @jklimke for the contribution!
hoverlabel.fontfor group titles in unified hover modes [#5895]v2.0.0Compare Source
Added
d3.formatmethod from d3@v3 to version 1.4.5 ofd3-formatmodule [#5125, #5842]scattergl,splomandparcoordsby implementingplotGlPixelRatiofor those traces [#5500]Changed
d3.geomethod from d3@v3 to version 1.12.1 ofd3-geomodule and version 2.9.0 ofd3-geo-projectionmodule [#5112]d3.interpolatemethod from d3@v3 to version 1.4.0 ofd3-interpolatemodule inicicle,indicator,parcats,sunburstandtreemap[#5826]regl-scatter2d,regl-line2dandregl-error2dmodules to use version 1.1.0 ofto-float32module to improve the performance [#5786],with thanks to @Seranicio for the contribution!
constraintrangeinparcoordstrace to pass validation [#5673]publish-distjob on CircleCI [#5815]XMLHttpRequestinstead ofd3.json[#5832]Fixed
with thanks to @rlreamy for the contribution!
with thanks to @andreafonso for the contribution!
in order not to obscure referring data points and fit inside plotting area [#5846]
v1.58.5Compare Source
Fixed
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.