[Snyk] Upgrade chart.js from 4.4.3 to 4.4.9 #60
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade chart.js from 4.4.3 to 4.4.9.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version is 6 versions ahead of your current version.
The recommended version was released 2 months ago.
Issues fixed by the recommended upgrade:
SNYK-JS-CROSSSPAWN-8303230
SNYK-JS-MICROMATCH-6838728
SNYK-JS-NANOID-8492085
SNYK-JS-BRACEEXPANSION-9789073
Release notes
Package name: chart.js
-
4.4.9 - 2025-04-15
- npm
- Migration guide
- Docs
- API
- Samples
- #12037 Update docs
- #12057 fix: respect dataset clipping area when filling line charts
- #12039 Add docs on using from Node.js
- #12062 Bump version to 4.4.9
-
4.4.8 - 2025-02-19
- npm
- Migration guide
- Docs
- API
- Samples
- #12034 [fix] Handle non-primitives in isNumber
- #12035 Export ...ParsedData interfaces
- #12012 Fix helpers `Chart` type
- #11991 Bugfix: TypeError in Interaction due to out-of-bounds index
- #11986 Bugfix: return nearest non-null point on interaction when spanGaps=true
- #11984 Bugfix: span gaps over null values beyond scale limits
- #12035 Export ...ParsedData interfaces
- #12012 Fix helpers `Chart` type
- #12010 Type fixes for time adapters
- #12005 Correct broken link in animations.md
- #11997 Update linear-step-size.md
- #12036 chore: bump to v4.4.8
-
4.4.7 - 2024-12-01
- npm
- Migration guide
- Docs
- API
- Samples
- #11521 fix: correct typing for doughnut, pie, and polarArea charts
- #11948 Export TRBL from geometric
- #11968 Add documentation about setting default tooltip fonts
- #11962 Show correct title in multi series pie chart example
- #11969 Chore: bump version to 4.4.7
- #11959 Bump cross-spawn from 6.0.5 to 6.0.6
- #11501 Simplify check undefinded
-
4.4.6 - 2024-10-28
- npm
- Migration guide
- Docs
- API
- Samples
- #11938 Fix: applyStack() returned the sum of all values for hidden dataset indices, which causes incorrect animations when showing/hiding stacked datasets.
- #11943 chore: version bump for 4.4.6 release
- #11933 Fix 404 to samples in release drafter
-
4.4.5 - 2024-10-15
- npm
- Migration guide
- Docs
- API
- Samples
- #11927 Don't apply default colors in the colors plugin when defaults are used
- #11907 Avoid error if borderOpts.dash is undefined
- #11882 Fix initial dataset stacks
- #11931 Allow array's in backgroundColor defaults and add hover background and border color to defaults
- #11930 Fix typo in time.md
- #11932 Bump package version to 4.4.5
- #11875 Bump socket.io from 4.6.1 to 4.7.5
-
4.4.4 - 2024-08-20
- npm
- Migration guide
- Docs
- API
- Samples
- #11873 Check if range method exists on element before executing it
- #11863 Return false from the average tooltip positioner on no valid data
- #11858 Bugfix/issue 11804 tooltip show for all invisible
- #11851 fix: Unset _resizeBeforeDraw before _resize() call to avoid possible recursion
- #11844 fix issue #11717
- #11788 Fix drawing angle lines on reversed radial scale
- #11867 fix(types): exclude DeepPartial<unknown[]> from ChartOptions interface
- #11862 fix(types): add xCenter and yCenter properties to RadialLinearScale interface
- #11817 Remove box padding from legend types
- #11796 Add fit method to LegendElement interface
- #11780 types: Allow passing undefined for chart options
- #11871 Add radial linear scale to docs section of samples
- #11823 Update OffscreenCanvas documentation, as it is widely available now
- #11781 Fix some typos
- #11874 Bump package version to 4.4.4
-
4.4.3 - 2024-05-17
- npm
- Migration guide
- Docs
- API
- Samples
- #11754 Fix error when object prototype is frozen
- #11764 do not attempt to clear canvas if one does not exist
- #11755 #11450 hide bar by dataindex
- #11690 Create parsed object with correct keys
- #11707 platform.isAttached should return false if canvas is false-y
- #11762 Update license year
- #11776 Bump to 4.4.3
- #11773 Bump pnpm/action-setup from 3.0.0 to 4.0.0
- #11720 Bump follow-redirects from 1.15.4 to 1.15.6
from chart.js GitHub release notesEssential Links
Bugs Fixed
Documentation
Development
Thanks to @ LeeLenaleee, @ adrianbrs and @ joshkel
Essential Links
Bugs Fixed
Types
Documentation
Development
Thanks to @ etimberg, @ joshkel, @ marisst, @ pensono and @ prems51
Essential Links
Types
Documentation
Development
Thanks to @ Connormiha, @ DustinEwan, @ LeeLenaleee, @ dependabot and @ dependabot[bot]
Essential Links
Bugs Fixed
Development
Thanks to @ DeyLak, @ LeeLenaleee and @ etimberg
Essential Links
Bugs Fixed
Types
Documentation
Development
Thanks to @ HieroglypH, @ LeeLenaleee, @ dependabot, @ dependabot[bot] and @ dregad
Essential Links
Bugs Fixed
Types
Documentation
Development
Thanks to @ CatchABus, @ LeeLenaleee, @ MichelHMachado, @ artus9033, @ huqingkun, @ jdufresne and @ joliss
Essential Links
Bugs Fixed
Documentation
Development
Thanks to @ DAcodedBEAT, @ EricWittrock, @ LeeLenaleee, @ LiamSwayne, @ dependabot and @ dependabot[bot]
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
Summary by Sourcery
Bump Chart.js to v4.4.9 to address security vulnerabilities in its dependencies
Bug Fixes:
Chores: