Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Audit #32

Open
jakebrown58 opened this issue Oct 28, 2020 · 1 comment
Open

Security Audit #32

jakebrown58 opened this issue Oct 28, 2020 · 1 comment

Comments

@jakebrown58
Copy link

Dependency cwebp-bin was upgraded to 6.0.0 on May 29th, but a new version of this library was not released, so upstream dependencies are flagging this for an npm security audit.

@yob
Copy link

yob commented Dec 4, 2021

A new release that allows cwebp-bin to be >= 6.1.2 would be super useful.

Prior to that version cwebp-bin depends on the seemingly abandoned logalot, which pulls in a hilariously large number of outdated dependencies. Including (eventually) trim-newlines, which has a DOS vulnerability: GHSA-7p7h-4mm5-852v

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants