11ty / eleventy-img

Utility to perform build-time image transformations.
https://www.11ty.dev/docs/plugins/image/
433 stars 53 forks source link

Upgrade minimum version of sharp to 0.32.5 #188

Closed lovell closed 9 months ago

lovell commented 11 months ago

I'm unsure how many people will be processing untrusted input images via 11ty, however I highly recommend a new patch release is published with v0.32.5 as a minimum version of sharp (more details available shortly).

zachleat commented 9 months ago

This change been packaged with eleventy-img v3.1.1, thank you!

lovell commented 9 months ago

Thank you. For anyone visiting this in the future, commit https://github.com/11ty/eleventy-img/commit/96585744645b30564b958bec8a3f65a9621866c8 upgraded sharp to v0.32.6.