grunt-contrib-imagemin icon indicating copy to clipboard operation
grunt-contrib-imagemin copied to clipboard

found 9 high severity vulnerabilities: decompress

Open badfeather opened this issue 5 years ago • 3 comments

More info

It looks like decompress hasn't been updated since 2017. I found this alternative in another thread.

badfeather avatar Mar 01 '20 18:03 badfeather

Any comments on this...?

Therealskythe avatar Mar 11 '20 18:03 Therealskythe

I get the following audit report with 6 vulnerabilities:

 === npm audit security report ===                        
                                                                                
# Run  npm update decompress --depth 6  to resolve 6 vulnerabilities
                                                                                
  High            Arbitrary File Write                                          
                                                                                
  Package         decompress                                                    
                                                                                
  Dependency of   grunt-contrib-imagemin [dev]                                  
                                                                                
  Path            grunt-contrib-imagemin > imagemin-jpegtran > jpegtran-bin >   
                  bin-build > decompress                                        
                                                                                
  More info       https://npmjs.com/advisories/1217                             
                                                                                


                                                                                
  High            Arbitrary File Write                                          
                                                                                
  Package         decompress                                                    
                                                                                
  Dependency of   imagemin-jpegtran [dev]                                       
                                                                                
  Path            imagemin-jpegtran > jpegtran-bin > bin-build > decompress     
                                                                                
  More info       https://npmjs.com/advisories/1217                             
                                                                                


                                                                                
  High            Arbitrary File Write                                          
                                                                                
  Package         decompress                                                    
                                                                                
  Dependency of   grunt-contrib-imagemin [dev]                                  
                                                                                
  Path            grunt-contrib-imagemin > imagemin-jpegtran > jpegtran-bin >   
                  bin-build > download > decompress                             
                                                                                
  More info       https://npmjs.com/advisories/1217                             
                                                                                


                                                                                
  High            Arbitrary File Write                                          
                                                                                
  Package         decompress                                                    
                                                                                
  Dependency of   imagemin-jpegtran [dev]                                       
                                                                                
  Path            imagemin-jpegtran > jpegtran-bin > bin-build > download >     
                  decompress                                                    
                                                                                
  More info       https://npmjs.com/advisories/1217                             
                                                                                


                                                                                
  High            Arbitrary File Write                                          
                                                                                
  Package         decompress                                                    
                                                                                
  Dependency of   grunt-contrib-imagemin [dev]                                  
                                                                                
  Path            grunt-contrib-imagemin > imagemin-jpegtran > jpegtran-bin >   
                  bin-wrapper > download > decompress                           
                                                                                
  More info       https://npmjs.com/advisories/1217                             
                                                                                


                                                                                
  High            Arbitrary File Write                                          
                                                                                
  Package         decompress                                                    
                                                                                
  Dependency of   imagemin-jpegtran [dev]                                       
                                                                                
  Path            imagemin-jpegtran > jpegtran-bin > bin-wrapper > download >   
                  decompress                                                    
                                                                                
  More info       https://npmjs.com/advisories/1217              

rvalitov avatar Apr 09 '20 18:04 rvalitov

Any news on this?

noahcooper avatar Nov 06 '20 02:11 noahcooper