sindresorhus / gulp-imagemin

Minify PNG, JPEG, GIF and SVG images
MIT License
1.9k stars 157 forks source link

Security issues #367

Open Erick1422 opened 2 years ago

Erick1422 commented 2 years ago

NPM audit is recording about several moderate level vulnerabilities in dependencies required by gulp-imagemin.

WhatsApp Image 2021-12-13 at 9 34 34 AM

rosdyana commented 2 years ago

Adding more detail about this vuln.

https://snyk.io/test/npm/gulp-imagemin https://nvd.nist.gov/vuln/detail/CVE-2021-43307 https://nvd.nist.gov/vuln/detail/CVE-2021-3795

@sindresorhus Do you have any plan to solve this vuln. ?