jimp-dev / jimp

An image processing library written entirely in JavaScript for Node, with zero external or native dependencies.
MIT License
13.61k stars 756 forks source link

Unable to install jimp library through npm bcz of vulnerabilities checks #1289

Open RagaviMuthukrishnan opened 2 months ago

RagaviMuthukrishnan commented 2 months ago

phin <3.7.1 Severity: moderate phin may include sensitive headers in subsequent requests after redirect - https://github.com/advisories/GHSA-x565-32qp-m3vf fix available via npm audit fix --forceWill install jimp@0.3.11, which is a breaking change node_modules/phin load-bmfont >=1.4.0 Depends on vulnerable versions of phin node_modules/load-bmfont @jimp/plugin-print >=0.4.0 Depends on vulnerable versions of load-bmfont node_modules/@jimp/plugin-print @jimp/plugins >=0.4.0 Depends on vulnerable versions of @jimp/plugin-print node_modules/@jimp/plugins jimp >=0.4.0 Depends on vulnerable versions of @jimp/plugins node_modules/jimp

5 moderate severity vulnerabilities

RamK777-stack commented 1 month ago

Related #1291

CC52-dev commented 1 week ago

@hipstersmoothie fix this