Skip to content

V13: bumped imagesharp to prevent CVE-2025-27598 #18602

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Conversation

RolandKock
Copy link
Contributor

Prerequisites

  • I have added steps to test this contribution in the description below

If there's an existing issue for this PR then this fixes

Description

Updated dependencies for SixLabors.ImageSharp:
[email protected] -> 3.1.7
[email protected] -> 2.1.10

GHSA-2cmq-823j-5qj8

Copy link

github-actions bot commented Mar 7, 2025

Hi there @RolandKock, thank you for this contribution! 👍

While we wait for one of the Core Collaborators team to have a look at your work, we wanted to let you know about that we have a checklist for some of the things we will consider during review:

  • It's clear what problem this is solving, there's a connected issue or a description of what the changes do and how to test them
  • The automated tests all pass (see "Checks" tab on this PR)
  • The level of security for this contribution is the same or improved
  • The level of performance for this contribution is the same or improved
  • Avoids creating breaking changes; note that behavioral changes might also be perceived as breaking
  • If this is a new feature, Umbraco HQ provided guidance on the implementation beforehand
  • 💡 The contribution looks original and the contributor is presumably allowed to share it

Don't worry if you got something wrong. We like to think of a pull request as the start of a conversation, we're happy to provide guidance on improving your contribution.

If you realize that you might want to make some changes then you can do that by adding new commits to the branch you created for this work and pushing new commits. They should then automatically show up as updates to this pull request.

Thanks, from your friendly Umbraco GitHub bot 🤖 🙂

@RolandKock
Copy link
Contributor Author

@AndyButland Seems more like it

@RolandKock
Copy link
Contributor Author

Solves #18599

Copy link
Contributor

@AndyButland AndyButland left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @RolandKock - I'll merge this in and up to 15 to include in upcoming releases.

@lauraneto lauraneto linked an issue Mar 7, 2025 that may be closed by this pull request
@AndyButland AndyButland merged commit 78a8d01 into umbraco:v13/contrib Mar 9, 2025
20 checks passed
AndyButland added a commit that referenced this pull request Mar 9, 2025
# Conflicts:
#	Directory.Packages.props
AndyButland added a commit that referenced this pull request Mar 9, 2025
# Conflicts:
#	Directory.Packages.props
AndyButland added a commit that referenced this pull request Mar 11, 2025
# Conflicts:
#	Directory.Packages.props
@RolandKock RolandKock deleted the v13/bugfix/18599-upgrade-imagesharp branch March 11, 2025 11:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Out-of-bounds Write in [email protected] used by [email protected]
2 participants