fix(deps): alias image-size to image-size-next@2.1.1 (CVE-2025-71329/71330) - #164
Open
lcf2212dev wants to merge 1 commit into
Open
lcf2212dev wants to merge 1 commit into
lcf2212dev wants to merge 1 commit into
Conversation
CVE-2025-71329 / CVE-2025-71330. Not affiliated with the original image-size maintainer.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why this PR
codeceptjs-resemblehelperis a CodeceptJS visual-diff helper (canonical repocodeceptjs/codeceptjs-resemblehelper). Defaultmasterpins runtimeimage-size@2.0.2exactly andsrc/index.tsdoesconst sizeOf = require("image-size")before ResembleJS. That is the 2.x line (image-size-next@2.1.1), not 1.2.2.Published
codeceptjs-resemblehelper@2.0.0still depends onimage-size@2.0.2(dependencies). Upstreamimage-sizeis archived. That coordinate remains affected by:There is no patched release on the original package name.
npm audit fixcannot rename the coordinate. This is a follow-up to #162 with a one-line alias so installs stop fetching the vulnerable tarball.Change
Alias the published 2.x runtime dependency:
Call sites left untouched:
src/index.ts:9const sizeOf = require("image-size");image-size-next@2.1.1is a MIT community fork with the same 2.x public API. Compare: lcf2212dev/image-size-next@v2.0.2...v2.1.1This is the 2.x pin (2.x named
imageSizeexport (CJS also exposesexports.default/exports.imageSize). Do not useimage-size-next@1.2.2here (CJS 1.x default export / Metro line).)Hub: lcf2212dev/image-size-next#3
I maintain
image-size-nextand am not affiliated with the originalimage-sizeauthor, nor with this project. Happy to drop the alias if you prefer vendoring the size helper.Test plan
image-size→image-size-next@2.1.1require/importofimage-sizeneeds no source edits