Skip to content

fix(metro): replace unmaintained image-size dependency - #1800

Open
ufolux wants to merge 1 commit into
react:mainfrom
ufolux:fix/replace-image-size
Open

fix(metro): replace unmaintained image-size dependency#1800
ufolux wants to merge 1 commit into
react:mainfrom
ufolux:fix/replace-image-size

Conversation

@ufolux

@ufolux ufolux commented Jul 27, 2026

Copy link
Copy Markdown

Summary

Metro only needs dimensions for its explicitly supported asset formats. The generic image-size detector also enables unrelated parsers, including JXL, HEIF, JP2, and ICNS parsers affected by CVE-2025-71329 and CVE-2025-71330.

This change:

  • replaces the archived image-size dependency with an exact probe-image-size@7.3.0 dependency
  • selects one parser from probe-image-size/sync based on Metro's existing asset type allowlist instead of auto-detecting content
  • adds a small Metro-owned KTX1/KTX2 header parser
  • rejects malformed and format-mismatched image assets with a contextual error
  • reuses the first asset Buffer already read for hashing and removes image-size from yarn.lock

Changelog: [Fix] Select image parsers by Metro asset type and replace the unmaintained image-size dependency

Fixes #1607
Refs #1762

Test plan

  • ./node_modules/.bin/flow check
  • node node_modules/eslint/bin/eslint.js . --cache
  • node node_modules/prettier/bin/prettier.cjs --check .
  • node scripts/build.js
  • node node_modules/jest/bin/jest.js --runInBand --silent — 141/141 suites passed; 2564 tests passed, 14 skipped, 0 failed
  • Added regression coverage for PNG, JPEG, GIF, BMP, WebP, PSD, SVG, TIFF, KTX1, KTX2, format mismatches, truncated headers, and malformed JXL/HEIF/ICNS zero-length payloads.

@meta-cla

meta-cla Bot commented Jul 27, 2026

Copy link
Copy Markdown

Hi @ufolux!

Thank you for your pull request and welcome to our community.

Action Required

In order to merge any pull request (code, docs, etc.), we require contributors to sign our Contributor License Agreement, and we don't seem to have one on file for you.

Process

In order for us to review and merge your suggested changes, please sign at https://code.facebook.com/cla. If you are contributing on behalf of someone else (eg your employer), the individual CLA may not be sufficient and your employer may need to sign the corporate CLA.

Once the CLA is signed, our tooling will perform checks and validations. Afterwards, the pull request will be tagged with CLA signed. The tagging process may take up to 1 hour after signing. Please give it that time before contacting us about it.

If you have received this in error or have any questions, please contact us at cla@meta.com. Thanks!

@meta-cla

meta-cla Bot commented Jul 27, 2026

Copy link
Copy Markdown

Thank you for signing our Contributor License Agreement. We can now accept your code for this (and any) Meta Open Source project. Thanks!

@meta-cla meta-cla Bot added the CLA Signed This label is managed by the Facebook bot. Authors need to sign the CLA before a PR can be reviewed. label Jul 27, 2026
@facebook-github-tools facebook-github-tools Bot added the Shared with Meta Applied via automation to indicate that an Issue or Pull Request has been shared with the team. label Jul 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CLA Signed This label is managed by the Facebook bot. Authors need to sign the CLA before a PR can be reviewed. Shared with Meta Applied via automation to indicate that an Issue or Pull Request has been shared with the team.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Dependabot alerts: image-size Denial of Service via Infinite Loop during Image Processing

1 participant