-
Notifications
You must be signed in to change notification settings - Fork 2.8k
V13: bumped imagesharp to prevent CVE-2025-27598 #18602
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
V13: bumped imagesharp to prevent CVE-2025-27598 #18602
Conversation
Hi there @RolandKock, thank you for this contribution! 👍 While we wait for one of the Core Collaborators team to have a look at your work, we wanted to let you know about that we have a checklist for some of the things we will consider during review:
Don't worry if you got something wrong. We like to think of a pull request as the start of a conversation, we're happy to provide guidance on improving your contribution. If you realize that you might want to make some changes then you can do that by adding new commits to the branch you created for this work and pushing new commits. They should then automatically show up as updates to this pull request. Thanks, from your friendly Umbraco GitHub bot 🤖 🙂 |
@AndyButland Seems more like it |
Solves #18599 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks @RolandKock - I'll merge this in and up to 15 to include in upcoming releases.
# Conflicts: # Directory.Packages.props
# Conflicts: # Directory.Packages.props
# Conflicts: # Directory.Packages.props
Prerequisites
If there's an existing issue for this PR then this fixes
Description
Updated dependencies for SixLabors.ImageSharp:
[email protected] -> 3.1.7
[email protected] -> 2.1.10
GHSA-2cmq-823j-5qj8