Skip to content

Patch vulnerabilities - #104

Merged
weili-govtech merged 4 commits into
mainfrom
patch-vulnerabilities
Sep 14, 2026
Merged

weili-govtech merged 4 commits into
mainfrom
patch-vulnerabilities

Conversation

@weili-govtech

Copy link
Copy Markdown
Contributor

Changes

  • Resolved 6 advisories (@babel/core, baseline-browser-mapping, brace-expansion, browserslist, fast-uri, js-yaml)
  • Replaced image-size with an internal parser

Resolve high/moderate/low severity advisories for @babel/core,
baseline-browser-mapping, brace-expansion, browserslist, fast-uri and
js-yaml via npm audit fix (lockfile-only, no direct dependency bumps
required).
image-size has an unpatched high-severity DoS vulnerability affecting
all versions (GHSA-w3rx-r6r6-pgpr, GHSA-5p2g-fcmc-qvqq) with no fix
available. Since it was only used to read width/height for jpg/png
uploads, replace it with a small internal parser that reads PNG IHDR
and JPEG SOF markers directly, guarding against the same
zero-length-segment infinite loop bug class.
@weili-govtech weili-govtech self-assigned this Sep 11, 2026
Comment thread src/utils/image-helper.ts
Comment thread src/utils/image-helper.ts Outdated
Comment thread src/utils/image-helper.ts
@weili-govtech
weili-govtech merged commit 1bf3c82 into main Sep 14, 2026
1 check passed
@weili-govtech
weili-govtech deleted the patch-vulnerabilities branch September 14, 2026 07:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants