zouhir / lqip

Low Quality Image Placeholders (LQIP) Module for Node
433 stars 30 forks source link

npm upgrade; update jimp to v0.16.0 #18

Closed mulholo closed 4 years ago

mulholo commented 4 years ago

The older version of jimp was using url-regex which was vulnerable to DDOS attacks (src: https://www.npmjs.com/advisories/1550).

This PR upgrades jimp to a version which no longer depends on url-regex.