-
-
Notifications
You must be signed in to change notification settings - Fork 156
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Vulnerabilities detected with decompress #342
Comments
Decompress has a PR in-progress: kevva/decompress#73 |
|
I'm just now realizing that @sindresorhus merged fix for Thanks for all the great work Sindre! 👏 |
@sindresorhus is it a matter of waiting for I'm not clear as to where |
@colorful-tones |
Hi there, there seems to be a vulnerability with a dependency :
Arbitrary File Write with Package "decompress"
Path : gulp-imagemin > imagemin-optipng > optipng-bin > bin-wrapper > download > decompress
Path : gulp-imagemin > imagemin-mozjpeg > mozjpeg > bin-wrapper > download > decompress
Path : gulp-imagemin > imagemin-gifsicle > gifsicle > bin-wrapper > download > decompress
Path : gulp-imagemin > imagemin-optipng > optipng-bin > bin-build > download > decompress
Path : gulp-imagemin > imagemin-mozjpeg > mozjpeg > bin-build > download > decompress
Path : gulp-imagemin > imagemin-gifsicle > gifsicle > bin-build > download > decompress
Path : gulp-imagemin > imagemin-optipng > optipng-bin > bin-build > decompress
Path : gulp-imagemin > imagemin-mozjpeg > mozjpeg > bin-build > decompress
Path : gulp-imagemin > imagemin-gifsicle > gifsicle > bin-build > decompress
More info : https://npmjs.com/advisories/1217
Thanks for your work !
The text was updated successfully, but these errors were encountered: