Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update SVGO requested #57

Closed
rogiervanhetschip opened this issue Jan 21, 2020 · 5 comments
Closed

Update SVGO requested #57

rogiervanhetschip opened this issue Jan 21, 2020 · 5 comments

Comments

@rogiervanhetschip
Copy link

Judging by https://github.com/kamsar/Dianoga/blob/3.0/src/Dianoga/Dianoga%20Tools/SVGO/node_modules/svgo/package.json , Dianoga's SVGO is on version 0.6.2, which uses js-yaml < 3.13.1 (affected by vulnerability WS-2019-0063) and lodash < 4.17.12 (affected by vulnerabilities CVE-2019-10744 and CVE-2018-16487).

By now, SVGO 1.3.2 has been released, which should use versions of js-yaml and lodash not affected by these vulnerabilities. Any chance of an upgrade to the newest SVGO?

Thanks in advance!

@markgibbons25
Copy link
Collaborator

@rogiervanhetschip
Copy link
Author

Hi! OK, we'll try it tomorrow and let you know.

@markgibbons25
Copy link
Collaborator

How'd it go? Looking for feedback on this process to get SVGO in painlessly

@rogiervanhetschip
Copy link
Author

No feedback yet, I'm afraid: I tried to get this working on Tuesday, but Dianoga does not seem to resize images, even without SVGO. Getting back to you as soon as possible, but have to find the time as this is not on our current sprint.

markgibbons25 added a commit that referenced this issue Apr 17, 2020
…Also an optimization to properly dispose of the Process handle when done.
@markgibbons25
Copy link
Collaborator

Changed to use https://github.com/twardoch/svgop

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants