get-me-a-date icon indicating copy to clipboard operation
get-me-a-date copied to clipboard

[Snyk] Security upgrade sharp from 0.27.2 to 0.32.6

Open hfreire opened this issue 9 months ago • 0 comments

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
critical severity 980/1000
Why? Currently trending on Twitter, Mature exploit, Recently disclosed, Has a fix available, CVSS 9.6
Heap-based Buffer Overflow
SNYK-JS-SHARP-5922108
No Mature

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: sharp The new version differs by 250 commits.
  • eefaa99 Release v0.32.6
  • dbce6fa Upgrade to libvips v8.14.5
  • af0fcb3 Docs: changelog for #3799
  • c6f54e5 Bump devDeps
  • 846563e TypeScript: add definitions for block and unblock (#3799)
  • 9c217ab Ensure withMetadata can add RGB16 profiles #3773
  • e7381e5 Alternative fix for 4340d60, uses existing StaySequential
  • 4340d60 Ensure composite tile images fully decoded #3767
  • 7f64d46 Docs: add missing returns property to raw
  • 67e927b Docs: ensure all functions include method signature #3777
  • 9c7713e Docs: remove mention of EXIF from flip/flop ops
  • 8be6da1 Docs: clarify when rotate op will remove EXIF Orientation
  • 9563568 Ensure withMetadata skips default profile for RGB16 #3773
  • 44a0ee3 Release v0.32.5
  • ccd51c8 Upgrade to libvips v8.14.4
  • bb7469b Ensure withMetadata adds default sRGB profile #3761
  • a2cac61 Simplify 90/270 orient-before-resize logic (#3762)
  • 5c19f6d Ensure resize fit=inside respects 90/270 rotate #3756
  • 3d01775 Docs: changelog entries for #3748 #3755 #3758
  • 87562a5 TypeScript: Ensure WebpOptions minSize is boolean (#3758)
  • 2829e17 Fix build with musl 1.2.4 (#3755)
  • ffefbd2 TypeScript: add missing WebpPresetEnum (#3748)
  • bc8f983 Tests: ensure Jimp benchmark uses bicubic as resizing kernel (#3745)
  • 440936a Tests: update benchmark deps and container (#3744)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

hfreire avatar Sep 28 '23 20:09 hfreire