Browse Source

feat: add @antv/g2 override to block compromised versions

The npm @antv/* packages (g2, g6, x6, l7, f2, data-set) were
compromised in a supply-chain attack on 2026-05-19. Malicious
versions embed credential-stealing payloads in preinstall scripts.

This project depends on @antv/g2@5.4.8 via @ant-design/plots,
which is safe. However, the semver range ^5.2.7 would allow
npm to resolve 5.5.8 or 5.6.8 (compromised) on a fresh install
or lockfile regeneration.

Add an npm override to constrain @antv/g2 to >=5.2.7 <5.5.8,
preventing resolution of the known-malicious versions. This can
be relaxed once clean versions above 5.6.8 are published.

Ref: https://socket.dev/blog/antv-packages-compromised
Ref: https://github.com/antvis/G2/issues/7394

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
pull/11798/head
afc163 5 months ago
parent
commit
fa70c3eafc
  1. 3
      package.json

3
package.json

@ -88,6 +88,9 @@
"ts-node": "^10.9.2",
"typescript": "^6.0.3"
},
"overrides": {
"@antv/g2": ">=5.2.7 <5.5.8"
},
"engines": {
"node": ">=20.0.0"
},

Loading…
Cancel
Save