Skip to content

Conversation

@Proximyst
Copy link
Member

@Proximyst Proximyst commented Oct 29, 2025

This has not been used even once over the last 90 days in GC. It does, however, bring in a 9.8 CRITICAL RCE. Let's just get rid of it.

As part of this, I'm also making other dependencies explicit.

Fixes: CVE-2023-34152

@Proximyst Proximyst self-assigned this Oct 29, 2025
@Proximyst Proximyst requested a review from a team as a code owner October 29, 2025 15:30
Co-authored-by: Matheus Macabu <macabu@users.noreply.github.com>
@github-actions
Copy link

github-actions bot commented Oct 29, 2025

🐳 Docker image built and pushed to GitHub Container Registry.

You can pull it using:

# For the Node.js server:
docker pull ghcr.io/grafana/grafana-image-renderer:dev-pull-834-164af2dcaa6d7fca9b03a7113853db87d4647aec
# For the Go server:
docker pull ghcr.io/grafana/grafana-image-renderer:dev-pull-834-164af2dcaa6d7fca9b03a7113853db87d4647aec-golang

Warning

This is a development image and should not be used in production.
It will be automatically removed after 2 weeks.

No more depending on stuff we don't declare.
@Proximyst Proximyst merged commit bb26aec into master Oct 29, 2025
38 of 46 checks passed
@Proximyst Proximyst deleted the mariell/remove-jimp branch October 29, 2025 15:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants