Skip to content

security: track unfixed image-size parser denial-of-service advisories #454

Description

@leehack

Two new high-severity Dependabot alerts are open after the prior website advisory remediation:\n\n- GHSA-w3rx-r6r6-pgpr: ICNS parser infinite-loop denial of service\n- GHSA-5p2g-fcmc-qvqq: JXL and HEIF parser infinite-loop denial of service\n\nCurrent dependency path: @docusaurus/core@3.10.2 -> @docusaurus/mdx-loader@3.10.2 -> image-size@2.0.2 in website/package-lock.json. GitHub currently reports no first patched version for either alert. The exposure is build-time parsing of documentation images rather than the shipped Dart runtime, but repository contributions can supply image inputs, so keep this P1 open until the dependency is fixed or safely constrained.\n\nAcceptance criteria:\n- update to a non-vulnerable image-size version through an upstream Docusaurus release, override, or narrowly justified replacement;\n- preserve locked website install, production docs build, link validation, and deterministic formatting;\n- verify both Dependabot alerts close without introducing a dependency downgrade or audit regression;\n- if no fixed version exists, document the trust boundary and monitor the advisories rather than suppressing them.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingdependenciesPull requests that update a dependency filepriority:P3Watch or strategic work blocked by upstream/runtime/design dependencies

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions