Skip to content

Security Audit Fixes#392

Merged
vladikoff merged 2 commits intogruntjs:masterfrom
whyisjake:issue-391
Mar 31, 2020
Merged

Security Audit Fixes#392
vladikoff merged 2 commits intogruntjs:masterfrom
whyisjake:issue-391

Conversation

@whyisjake
Copy link
Copy Markdown
Contributor

As part of a security audit, would like to upstream these changes into grunt-contrib-imagemin.

@jsf-clabot
Copy link
Copy Markdown

jsf-clabot commented Mar 3, 2020

CLA assistant check
All committers have signed the CLA.

@whyisjake
Copy link
Copy Markdown
Contributor Author

This is a fix for #391

@whyisjake
Copy link
Copy Markdown
Contributor Author

WordPress core issue here: https://core.trac.wordpress.org/ticket/49547#comment:4

@whyisjake
Copy link
Copy Markdown
Contributor Author

@sindresorhus, @kevva, @XhmikosR, or @vladikoff any ideas on how to get this merged/released?

@vladikoff
Copy link
Copy Markdown
Member

I can take a look...

@XhmikosR
Copy link
Copy Markdown
Member

For what is worth, there's no fix for the latest decompress AFAICT. That being said, this can land since tests pass, and even be more updated later and drop Node < 10 support.

@whyisjake
Copy link
Copy Markdown
Contributor Author

Cool, can we get a :shipit: then?

@vladikoff vladikoff merged commit bc556d2 into gruntjs:master Mar 31, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants