callstack / callstack/react-native-image-editor
Security: vulnerable dependency image-size (CVE-2025-71329/71330) — maintained drop-in available
- Langage dominant
- Kotlin
- Étoiles
- 448
- Forks
- 119
- Merge moyen
- 1 j 11 h
- PR mergées (30 j)
- 4
Description
## Context
This package depends on npm **`image-size`**. Upstream is **archived** and the latest release (**2.0.2**) remains affected by:
- **CVE-2025-71329** — DoS via infinite loop (JXL/HEIF/JP2 zero-size boxes)
- **CVE-2025-71330** — DoS via infinite loop (ICNS zero entry length)
`npm audit fix` will **not** switch package names automatically.
## Maintained drop-in
Community MIT fork with the same public API as `image-size@2.0.2`:
- **npm:** https://www.npmjs.com/package/image-size-next (`image-size-next@2.1.0`)
- **GitHub:** https://github.com/lcf2212dev/image-size-next
- **Announcement:** https://github.com/lcf2212dev/image-size-next/blob/main/ANNOUNCE.md
Not affiliated with the original `image-size` maintainer — honest community fork only.
## Migration options
**A — Direct dependency**
```bash
npm install image-size-next
```
```diff
- import { imageSize } from 'image-size'
+ import { imageSize } from 'image-size-next'
```
**B — Force transitive resolution (npm 8.3+)**
```json
{
"overrides": {
"image-size": "npm:image-size-next@2.1.0"
}
}
```
## Ask
Happy to open a PR for **`birken-react-native-community-image-editor`** if useful. Thanks for maintaining open source.
Guide de contribution
Ouvrir le guide de contribution
Piste de recherche
Start by inspecting package.json and searching for the imageSize import shown in the issue. Confirm whether the maintained image-size-next package preserves the current API and check the existing project validation commands. Done means the vulnerable image-size dependency is replaced or overridden without breaking the image editor's existing behavior.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Évaluation
- Stack technique
- javascript, react-native
- Domaine
- mobile-dev, security
- Type d'issue
- Bug
- Difficulté
- 2/5
- Temps estimé
- 1-3 heures
- Activité
- Calme
- Clarté
- Plutôt claire
- Accessibilité débutants
- 62/100