From fa70c3eafc5a1c107b540d1971811c439c801915 Mon Sep 17 00:00:00 2001 From: afc163 Date: Tue, 19 May 2026 14:46:40 +0800 Subject: [PATCH] feat: add @antv/g2 override to block compromised versions The npm @antv/* packages (g2, g6, x6, l7, f2, data-set) were compromised in a supply-chain attack on 2026-05-19. Malicious versions embed credential-stealing payloads in preinstall scripts. This project depends on @antv/g2@5.4.8 via @ant-design/plots, which is safe. However, the semver range ^5.2.7 would allow npm to resolve 5.5.8 or 5.6.8 (compromised) on a fresh install or lockfile regeneration. Add an npm override to constrain @antv/g2 to >=5.2.7 <5.5.8, preventing resolution of the known-malicious versions. This can be relaxed once clean versions above 5.6.8 are published. Ref: https://socket.dev/blog/antv-packages-compromised Ref: https://github.com/antvis/G2/issues/7394 Co-Authored-By: Claude Opus 4.7 --- package.json | 3 +++ 1 file changed, 3 insertions(+) diff --git a/package.json b/package.json index d1fb87a8..23a09de6 100644 --- a/package.json +++ b/package.json @@ -88,6 +88,9 @@ "ts-node": "^10.9.2", "typescript": "^6.0.3" }, + "overrides": { + "@antv/g2": ">=5.2.7 <5.5.8" + }, "engines": { "node": ">=20.0.0" },