Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependency update needed to address nomalize-url CVE-2021-33502 #64

Open
arborrow opened this issue Jun 10, 2021 · 1 comment
Open

Dependency update needed to address nomalize-url CVE-2021-33502 #64

arborrow opened this issue Jun 10, 2021 · 1 comment

Comments

@arborrow
Copy link

Below are the current packages and available versions in parentheses related to CVE-2021-33502

[email protected]
│ └─┬ [email protected]
│ └─┬ [email protected]
│ └─┬ [email protected] (8.0.0)
│ └─┬ [email protected] (11.8.2)
│ └─┬ [email protected] (7.0.2)
│ └── [email protected] (6.0.1)

Looks like download (and bin-wrapper) may be where updates are lagging which are packages contributed by @kevva as referenced in #63. So it may be best to eliminate dependence upon bin-wrapper and look for an alternative.

@hkjeffchan
Copy link

Maintained a forked version at https://github.com/hkjeffchan/imagemin-mozjpeg/ if you are interested

  • Support CJS
  • Updated dependency
  • No binary shipped and you can specify your binary path

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants