tensei
tensei copied to clipboard
[Snyk] Security upgrade sharp from 0.27.2 to 0.30.5
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- packages/media/package.json
Vulnerabilities that will be fixed
With an upgrade:
Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
---|---|---|---|---|
![]() |
611/1000 Why? Recently disclosed, Has a fix available, CVSS 6.5 |
Remote Code Execution (RCE) SNYK-JS-SHARP-2848109 |
No | No Known Exploit |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: sharp
The new version differs by 250 commits.- db654de Release v0.30.5
- a6aeef6 Install: pass `PKG_CONFIG_PATH` via env rather than substitution
- 7bf6cbd Docs: correct links to libvips documentation
- 04c31b3 Install: warn about filesystem owner running npm v8+ as root
- ee9cdb6 Bump deps
- 8960eb8 Docs: changelog entry for #3218
- 54d9dc4 Fix rotate-then-extract for EXIF orientation 2 (#3218)
- 51b4a7c Add support for --libc flag to improve cross-platform install (#3160)
- 5b03579 Docs: more details about concurrency, parallelism, threads
- 58c2af3 Docs: improve output format info for toBuffer
- ee948ac Docs: changelog and credit for #3196
- 66a3ce5 Allow installation of prebuilt libvips binary from filesystem (#3196)
- 75e5afc Docs: fix typo in gif example (#3201)
- d396a4e Release v0.30.4
- ae1dbcd Bump deps
- 4c29368 Docs: EXIF metadata unsupported for TIFF output #3074
- 36e5596 Docs: mention npm's foreground-scripts option to aid debugging
- 985e881 Bump deps
- 0b11671 Docs: changelog for #3178
- 9deac83 Add missing file name to 'Input file is missing' error message (#3178)
- 5d36f5f Improve error message for SVG render above limit #3167
- 926572b Control sensitivity to invalid images via failOn
- d0c8e95 Docs: expand info about use with worker threads
- b0ca23c Docs: changelog and credit for #3146
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.