turkdevops / apps

A collection of apps built on Electron
https://electronjs.org/apps
1 stars 0 forks source link

[Snyk] Upgrade sharp from 0.28.1 to 0.30.0 #193

Closed snyk-bot closed 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to upgrade sharp from 0.28.1 to 0.30.0.

merge advice :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Information Exposure
SNYK-JS-SIMPLEGET-2361683
547/1000
Why? Proof of Concept exploit, CVSS 8.8
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: sharp from sharp GitHub release notes
Commit messages
Package name: sharp
  • 83bb6a4 Release v0.30.0
  • c72d428 Docs: update performance test results for next release
  • 35a81a7 Upgrade to libvips v8.12.2
  • 9dc8db4 Upgrade to libvips v8.12.2
  • 47ae1f5 Docs: metadata returns resolutionUnit, if present
  • ec17d7f Bump deps: prebuild, for latest detect-libc
  • da5453a Docs: changelog and refresh for #3023
  • f7bed69 Add resolutionUnit to metadata and as tiff option #3023
  • 7aa3402 Ensure delays of the origin image is preserved (#3062)
  • 68823a5 Take page parameter into account when all frames are read (#3059)
  • 1c3ba30 Update simple-get version (#3057)
  • 76f8112 Docs: npm v8
  • 24150ea Docs: Linux x64 binaries require CPU with SSE4.2
  • 51121a1 Bump deps
  • 3b370b6 CI: add Rosetta-emulated x64
  • 884947a Upgrade to modern detect-libc
  • f8340e1 Bump deps
  • 5101f4e CI: Fix linux-arm64v8 docker permission problems with npm v8
  • 161d127 Docs refresh
  • 638d540 Docs: mild blur is a box filter, add examples
  • d8f1298 Ensure rotate-then-extract works with EXIF mirroring #3024
  • d67e09b Add support for IIIF v3 tile-based output
  • 4c3a8a7 Docs: fix example formatting, remove outdated warning
  • 92399ee Docs: correct gif resize example
Compare

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

mistaken-pull-closer[bot] commented 2 years ago

Thanks for your submission.

It appears that you've created a pull request using one of our repository's branches. Since this is almost always a mistake, we're going to go ahead and close this. If it was intentional, please let us know what you were intending and we can see about reopening it.

Thanks again!

pull-dog[bot] commented 2 years ago

*Ruff* :dog: The test environment for this pull request has been destroyed :boom: This may have happened explicitly via a command, because the environment expired, or because the pull request was closed.

What is this? Pull Dog is a GitHub app that makes test environments for your pull requests using Docker, from a `docker-compose.yml` file you specify. It takes 19 seconds to set up (we counted!) and there's a free plan available. Visit our website to learn more.
Commands - `@pull-dog up` to reprovision or provision the server. - `@pull-dog down` to delete the provisioned server.
Troubleshooting Need help? Don't hesitate to file an issue in our repository **Configuration** ```json { "isLazy": false, "dockerComposeYmlFilePaths": [ "docker-compose.yml" ], "expiry": "00:00:00", "conversationMode": "singleComment" } ``` **Trace ID** No trace ID