Security: vulnerable dependency image-size (CVE-2025-71329/71330) — maintained drop-in available
- Dominant language
- JavaScript
- Stars
- 1.7k
- Forks
- 1.5k
- Avg merge
- 18m
- Merged PRs (30d)
- 2
Description
## Context
This package depends on npm **`image-size`**. Upstream is **archived** and the latest release (**2.0.2**) remains affected by:
- **CVE-2025-71329** — DoS via infinite loop (JXL/HEIF/JP2 zero-size boxes)
- **CVE-2025-71330** — DoS via infinite loop (ICNS zero entry length)
`npm audit fix` will **not** switch package names automatically.
## Maintained drop-in
Community MIT fork with the same public API as `image-size@2.0.2`:
- **npm:** https://www.npmjs.com/package/image-size-next (`image-size-next@2.1.0`)
- **GitHub:** https://github.com/lcf2212dev/image-size-next
- **Announcement:** https://github.com/lcf2212dev/image-size-next/blob/main/ANNOUNCE.md
Not affiliated with the original `image-size` maintainer — honest community fork only.
## Migration options
**A — Direct dependency**
```bash
npm install image-size-next
```
```diff
- import { imageSize } from 'image-size'
+ import { imageSize } from 'image-size-next'
```
**B — Force transitive resolution (npm 8.3+)**
```json
{
"overrides": {
"image-size": "npm:image-size-next@2.1.0"
}
}
```
## Ask
Happy to open a PR for **`electron-apps`** if useful. Thanks for maintaining open source.
Contributor guide
Research direction
Start by locating the electron-apps package manifest and its image-size dependency; compare the current dependency path with the two migration options in the issue. Done means the vulnerable package is replaced or overridden with image-size-next@2.1.0 while preserving the public API and the project's dependency or security checks pass.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- electron, javascript
- Domain
- security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 55/100