adamwolf / adamwolf/screenshat

Security: vulnerable dependency image-size (CVE-2025-71329/71330) — maintained drop-in available

Aberta Para iniciantes
#27 0 comentários 0 reações 0 responsáveis Ver no GitHub
Linguagem predominante
JavaScript
Estrelas
4
Forks
0
Métricas de merge de PRs
Nenhum PR com merge em 30d

Descrição

## Context

This package depends on npm **`image-size`**. Upstream is **archived** and the latest release (**2.0.2**) remains affected by:

- **CVE-2025-71329** — DoS via infinite loop (JXL/HEIF/JP2 zero-size boxes)
- **CVE-2025-71330** — DoS via infinite loop (ICNS zero entry length)

`npm audit fix` will **not** switch package names automatically.

## Maintained drop-in

Community MIT fork with the same public API as `image-size@2.0.2`:

- **npm:** https://www.npmjs.com/package/image-size-next (`image-size-next@2.1.0`)
- **GitHub:** https://github.com/lcf2212dev/image-size-next
- **Announcement:** https://github.com/lcf2212dev/image-size-next/blob/main/ANNOUNCE.md

Not affiliated with the original `image-size` maintainer — honest community fork only.

## Migration options

**A — Direct dependency**

```bash
npm install image-size-next
```

```diff
- import { imageSize } from 'image-size'
+ import { imageSize } from 'image-size-next'
```

**B — Force transitive resolution (npm 8.3+)**

```json
{
"overrides": {
"image-size": "npm:image-size-next@2.1.0"
}
}
```

## Ask

Happy to open a PR for **`screenshat`** if useful. Thanks for maintaining open source.

cc @adamwolf

Guia de contribuição

Abrir o guia de contribuição

Direção de pesquisa

Inspect the dependency manifest (package.json) and lockfile to locate the current `image-size` entry. Apply either a direct replacement to `image-size-next` or the `overrides` strategy shown in the issue, then run `npm install` and `npm audit` to verify the vulnerable versions are no longer present. If the project has tests or CI checks, run them to confirm no breakage, and mark done when dependency graph is updated without CVE-2025-71329/71330 exposure.

Escrita pelo modelo de indexação a partir do texto da issue.

Avaliação

Stack de tecnologia
javascript, node.js
Domínio
security
Tipo de issue
Bug
Dificuldade
2/5
Tempo estimado
1-3 horas
Status de atividade
Pouca atividade
Clareza
Razoavelmente clara
Facilidade para iniciantes
68/100

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.