kavu / webp-loader

WebP image loader & converter for Webpack
MIT License
93 stars 17 forks source link

Dangerous vulnerability in dependency #15

Open fvonellerts opened 4 years ago

fvonellerts commented 4 years ago

Hey, thanks for creating this package!

The npm audit just alerted me that the "decompress" package suffers a Arbitrary File Write vulnerability: https://www.npmjs.com/advisories/1217. It is used by the imagemin dependencies in this plugin.

Would be nice if you could take a look. Greetings, Fabian

techEgab commented 3 months ago

Other Citical Vulnerabilities to count: