adamwolf / adamwolf/screenshat
Security: vulnerable dependency image-size (CVE-2025-71329/71330) — maintained drop-in available
- Linguagem predominante
- JavaScript
- Estrelas
- 4
- Forks
- 0
- Métricas de merge de PRs
- Nenhum PR com merge em 30d
Descrição
## Context
This package depends on npm **`image-size`**. Upstream is **archived** and the latest release (**2.0.2**) remains affected by:
- **CVE-2025-71329** — DoS via infinite loop (JXL/HEIF/JP2 zero-size boxes)
- **CVE-2025-71330** — DoS via infinite loop (ICNS zero entry length)
`npm audit fix` will **not** switch package names automatically.
## Maintained drop-in
Community MIT fork with the same public API as `image-size@2.0.2`:
- **npm:** https://www.npmjs.com/package/image-size-next (`image-size-next@2.1.0`)
- **GitHub:** https://github.com/lcf2212dev/image-size-next
- **Announcement:** https://github.com/lcf2212dev/image-size-next/blob/main/ANNOUNCE.md
Not affiliated with the original `image-size` maintainer — honest community fork only.
## Migration options
**A — Direct dependency**
```bash
npm install image-size-next
```
```diff
- import { imageSize } from 'image-size'
+ import { imageSize } from 'image-size-next'
```
**B — Force transitive resolution (npm 8.3+)**
```json
{
"overrides": {
"image-size": "npm:image-size-next@2.1.0"
}
}
```
## Ask
Happy to open a PR for **`screenshat`** if useful. Thanks for maintaining open source.
cc @adamwolf
Guia de contribuição
Direção de pesquisa
Inspect the dependency manifest (package.json) and lockfile to locate the current `image-size` entry. Apply either a direct replacement to `image-size-next` or the `overrides` strategy shown in the issue, then run `npm install` and `npm audit` to verify the vulnerable versions are no longer present. If the project has tests or CI checks, run them to confirm no breakage, and mark done when dependency graph is updated without CVE-2025-71329/71330 exposure.
Escrita pelo modelo de indexação a partir do texto da issue.
Avaliação
- Stack de tecnologia
- javascript, node.js
- Domínio
- security
- Tipo de issue
- Bug
- Dificuldade
- 2/5
- Tempo estimado
- 1-3 horas
- Status de atividade
- Pouca atividade
- Clareza
- Razoavelmente clara
- Facilidade para iniciantes
- 68/100