Skip to content

[Snyk] Security upgrade sharp from 0.31.3 to 0.32.6 #4

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

oumao
Copy link
Owner

@oumao oumao commented Sep 29, 2023

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
critical severity 980/1000
Why? Currently trending on Twitter, Mature exploit, Recently disclosed, Has a fix available, CVSS 9.6
Heap-based Buffer Overflow
SNYK-JS-SHARP-5922108
No Mature

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: sharp The new version differs by 143 commits.
  • eefaa99 Release v0.32.6
  • dbce6fa Upgrade to libvips v8.14.5
  • af0fcb3 Docs: changelog for #3799
  • c6f54e5 Bump devDeps
  • 846563e TypeScript: add definitions for block and unblock (#3799)
  • 9c217ab Ensure withMetadata can add RGB16 profiles #3773
  • e7381e5 Alternative fix for 4340d60, uses existing StaySequential
  • 4340d60 Ensure composite tile images fully decoded #3767
  • 7f64d46 Docs: add missing returns property to raw
  • 67e927b Docs: ensure all functions include method signature #3777
  • 9c7713e Docs: remove mention of EXIF from flip/flop ops
  • 8be6da1 Docs: clarify when rotate op will remove EXIF Orientation
  • 9563568 Ensure withMetadata skips default profile for RGB16 #3773
  • 44a0ee3 Release v0.32.5
  • ccd51c8 Upgrade to libvips v8.14.4
  • bb7469b Ensure withMetadata adds default sRGB profile #3761
  • a2cac61 Simplify 90/270 orient-before-resize logic (#3762)
  • 5c19f6d Ensure resize fit=inside respects 90/270 rotate #3756
  • 3d01775 Docs: changelog entries for #3748 #3755 #3758
  • 87562a5 TypeScript: Ensure WebpOptions minSize is boolean (#3758)
  • 2829e17 Fix build with musl 1.2.4 (#3755)
  • ffefbd2 TypeScript: add missing WebpPresetEnum (#3748)
  • bc8f983 Tests: ensure Jimp benchmark uses bicubic as resizing kernel (#3745)
  • 440936a Tests: update benchmark deps and container (#3744)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

@what-the-diff
Copy link

what-the-diff bot commented Sep 29, 2023

PR Summary

  • Added New Dependency b4a
    A new component b4a version 1.6.4 has been included in the project. This will add new features or improve existing ones.

  • Upgraded Various Dependencies
    Various components of the project like detect-libc, fast-fifo, node-addon-api, range-parser, and semver have been updated with their latest versions. This will improve the application performance, stability, and include any new features added in these versions.

  • Enhanced 'sharp' Component
    The 'sharp' component, a key element of our project, was upgraded to version 0.32.6. Furthermore, new dependencies b4a, tar-fs, tar-stream, streamx, and queue-tick were attached to sharp, enhancing its feature set and overall performance.

  • Updated Package specifications
    The package specifications in package.json have been updated to reflect the new version of the 'sharp' component. This modification ensures everyone working on the project is aware of the current version used.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants