-
-
Notifications
You must be signed in to change notification settings - Fork 287
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
SixLabors.ImageSharp.Drawing has potential vulnerability #627
Comments
It looks like SixLabors.ImageSharp.Drawing is not netstandard anymore, so this will need a bit more work than just upgrading the package. |
I think that's a minor issue. ReportGenerator uses ImageSharp to generate images/badges. It does not process arbitrary images from outside. So it's not possible to exploit the vulnerability in this context. |
Yes I believe it's quite a non-issue. Would you mind if I tried to contribute and fix it as a small project for myself? |
Sure. Maybe there a way to replace ImageSharp completely, as it's only used for some simple rendering. |
I think I will remove ImageSharp completely.
|
Made the necessary changes in ae8c4fc.
|
Describe the bug
SixLabors.ImageSharp.Drawing version needs to be upgraded to 2.0.0 or later.
Previous versions use SixLabors.ImageSharp with a potential vulnerability that was fixed in PR SixLabors/ImageSharp#2524
The text was updated successfully, but these errors were encountered: