Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Snyk reports vulnerability #167

Open
mcandre opened this issue Nov 2, 2023 · 2 comments
Open

Snyk reports vulnerability #167

mcandre opened this issue Nov 2, 2023 · 2 comments

Comments

@mcandre
Copy link

mcandre commented Nov 2, 2023

Please address the security bug identified by Snyk:

https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMDISINTEGRATIONIMAGING-5880692

On a related note, GitHub dependabot claims that updating the transient dependency golang.org/x/image to v0.10.0 or higher is sufficient. However, Snyk continues to report this disintegration/imaging module as vulnerable.

I don't have enough information to determine whether GitHub or Snyk is more accurate. Someone should clarify the situation.

If necessary, fork this repository.

@mcandre
Copy link
Author

mcandre commented Dec 28, 2023

As a workaround, I am using the https://github.com/anthonynsimon/bild library.

@n2p5
Copy link

n2p5 commented Jan 22, 2025

I've made a patch to this to update to the latest version of golang.org/x/image and remove the deprecatedioutils in favor of io and os supported functions. Is there anything I can do to help get this merged and support the release of a 1.6.3?

PR: #175

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants