Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade Jimp to address minimist security vuln. #5

Merged
merged 1 commit into from
Mar 30, 2020
Merged

Upgrade Jimp to address minimist security vuln. #5

merged 1 commit into from
Mar 30, 2020

Conversation

karlhorky
Copy link

Since the pull request for Jimp addressing minimist security vulnerability (https://www.npmjs.com/advisories/1179) was accepted, it would be good to upgrade to at least 0.9.6:

jimp-dev/jimp#857

Original fix in mkdirp: isaacs/node-mkdirp#7 (comment)

It seems like the last minor releases have not changed anything breaking...?

If this is accepted and released as a minor or patch, this will also enable Gatsby projects to fix the security issues without breaking semver, since gatsby-plugin-sharp and gatsby-transformer-sharp depend on potrace@^2.1.2:

@tooolbox
Copy link
Owner

@karlhorky
Copy link
Author

karlhorky commented Mar 30, 2020

Thanks @tooolbox!

Looks like this is already in the next Gatsby pull request to bump dependencies: gatsbyjs/gatsby#22434

Edit: Ah, Gatsby was actually upgraded separately, in this pull request. These patch versions are the versions to look for:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants