Skip to content

Security issues in "image-size" dependency #4455

Description

@cluick

Hi Folks,

Less 4.6.6 has an optional dependency to the "image-size" package, which is archived on Github and has open security vulnerabilities (e.g. CVE-2025-71329). Would it be possible to replace the package by a more up-to-date alternative (e.g.: https://github.com/nodeca/probe-image-size)?

Thank you and best regards,
Christof

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions