imagemin / mozjpeg-bin

mozjpeg bin-wrapper that makes it seamlessly available as a local dependency

Home Page:https://github.com/mozilla/mozjpeg

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Resolve dependency on logsalot related to CVE-2021-33623

arborrow opened this issue · comments

I created a similar issue upstream in the imagemin-mozjpeg project.

At issue is the dependency in this package upon what appears to be an abandoned project (logsalot) contributed by @kevva. It looks like it should be reasonably trivial to switch to a different package to generate the logs. https://www.npmjs.com/package/better-logging may be a contender.

Thanks for your consideration about how best to resolve this so as to address CVE-2021-33623.

Solved on v7.1.1.