Skip to content

chore(deps): bump exifreader from 4.41.0 to 4.41.1 in /packages/frontend - #1368

Open
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/packages/frontend/exifreader-4.41.1
Open

dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/packages/frontend/exifreader-4.41.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 17, 2026

Copy link
Copy Markdown
Contributor

Bumps exifreader from 4.41.0 to 4.41.1.

Release notes

Sourced from exifreader's releases.

4.41.1: ESM deep-import fix and HEIC/AVIF DoS security fix

Fixed

  • The src directory is now correctly declared as ES modules through a nested package.json type marker that ships with the npm package. Node-native ESM deep imports such as import 'exifreader/src/exif-reader.js' work now instead of crashing, and require() of the same files works on Node 22.12 and later. The default entry points are unchanged.

Security

  • Fixed a denial-of-service vulnerability (GHSA-pj96-35fp-cfcc) where a crafted HEIC or AVIF file could trigger excessive memory allocation and crash the process during metadata parsing. See the advisory for details. Reported by @​alienkeric.

Full Changelog: mattiasw/ExifReader@v4.41.0...v4.41.1

Changelog

Sourced from exifreader's changelog.

[4.41.1] - 2026-07-18

Fixed

  • The src directory is now correctly declared as ES modules through a nested package.json type marker that ships with the npm package. Node-native ESM deep imports such as import 'exifreader/src/exif-reader.js' work now instead of crashing, and require() of the same files works on Node 22.12 and later. The default entry points are unchanged.

Security

  • Fixed a denial-of-service vulnerability where a crafted HEIC or AVIF file could trigger excessive memory allocation and crash the process during metadata parsing (GHSA-pj96-35fp-cfcc). Reported by @​alienkeric.
Commits
  • 20dfd6e 4.41.1
  • 7440989 Update changelog for 4.41.1
  • 17b901c Fix denial-of-service on crafted HEIC/AVIF metadata (GHSA-pj96-35fp-cfcc)
  • 6e2a930 Bump the all-dependencies group with 2 updates
  • 30623d3 Bump systeminformation from 5.31.6 to 5.31.17
  • 2718a31 Bump websocket-driver from 0.7.4 to 0.7.5
  • 252bc74 Bump ws from 8.18.0 to 8.21.0
  • 87fc9d8 Bump the all-dependencies group across 1 directory with 6 updates
  • f3de2e6 Upgrade actions/checkout to v7
  • 9c308b3 Bump the all-dependencies group with 4 updates
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [exifreader](https://github.com/mattiasw/ExifReader) from 4.41.0 to 4.41.1.
- [Release notes](https://github.com/mattiasw/ExifReader/releases)
- [Changelog](https://github.com/mattiasw/ExifReader/blob/main/CHANGELOG.md)
- [Commits](mattiasw/ExifReader@v4.41.0...v4.41.1)

---
updated-dependencies:
- dependency-name: exifreader
  dependency-version: 4.41.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Sep 17, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Docker 起動・検証に失敗しました

エラーログ
…(省略)
ibxrandr2:amd64 (2:1.5.2-2+b1) ...
#13 24.08 Setting up libvdpau1:amd64 (1.5-2) ...
#13 24.08 Setting up libtheora0:amd64 (1.1.1+dfsg.1-16.1+deb12u1) ...
#13 24.09 Setting up libcairo-gobject2:amd64 (1.16.0-7) ...
#13 24.09 Setting up libxss1:amd64 (1:1.2.3-1) ...
#13 24.09 Setting up libpangoft2-1.0-0:amd64 (1.50.12+ds-1) ...
#13 24.09 Setting up libva-x11-2:amd64 (2.17.0-1) ...
#13 24.09 Setting up libpangocairo-1.0-0:amd64 (1.50.12+ds-1) ...
#13 24.10 Setting up libglx-mesa0:amd64 (22.3.6-1+deb12u2) ...
#13 24.10 Setting up libxi6:amd64 (2:1.8-1+b1) ...
#13 24.10 Setting up libglx0:amd64 (1.6.0-1) ...
#13 24.10 Setting up libsphinxbase3:amd64 (0.8+5prealpha+1-16) ...
#13 24.10 Setting up libxcursor1:amd64 (1:1.2.1-1) ...
#13 24.11 Setting up librsvg2-2:amd64 (2.54.7+dfsg-1~deb12u1) ...
#13 24.11 Setting up libpocketsphinx3:amd64 (0.8+5prealpha+1-15) ...
#13 24.11 Setting up libavutil57:amd64 (7:5.1.9-0+deb12u1) ...
#13 24.11 Setting up libgl1:amd64 (1.6.0-1) ...
#13 24.11 Setting up libswresample4:amd64 (7:5.1.9-0+deb12u1) ...
#13 24.11 Setting up libpostproc56:amd64 (7:5.1.9-0+deb12u1) ...
#13 24.12 Setting up libavcodec59:amd64 (7:5.1.9-0+deb12u1) ...
#13 24.12 Setting up libsdl2-2.0-0:amd64 (2.26.5+dfsg-1) ...
#13 24.12 Setting up libswscale6:amd64 (7:5.1.9-0+deb12u1) ...
#13 24.12 Setting up libchromaprint1:amd64 (1.5.1-2+b1) ...
#13 24.12 Setting up libavformat59:amd64 (7:5.1.9-0+deb12u1) ...
#13 24.13 Setting up libavfilter8:amd64 (7:5.1.9-0+deb12u1) ...
#13 24.13 Setting up libavdevice59:amd64 (7:5.1.9-0+deb12u1) ...
#13 24.13 Setting up ffmpeg (7:5.1.9-0+deb12u1) ...
#13 24.13 Processing triggers for libc-bin (2.36-9+deb12u14) ...
#13 24.18 useradd warning: misskey's uid 991 outside of the UID_MIN 1000 and UID_MAX 60000 range.
#13 DONE 24.8s

#41 [native-builder 19/23] RUN --mount=type=cache,target=/root/.local/share/pnpm/store,sharing=locked 	pnpm i --frozen-lockfile --aggregate-output
#41 0.839 Scope: all 12 workspace projects
#41 1.103 ? Verifying lockfile against supply-chain policies (2185 entries)...
#41 1.521 
#41 1.521    ╭─────────────────────────────────────────╮
#41 1.521    │                                         │
#41 1.521    │   Update available! 11.5.2 → 12.4.2.    │
#41 1.521    │   Changelog: https://pnpm.io/v/12.4.2   │
#41 1.521    │    To update, run: pnpm add -g pnpm     │
#41 1.521    │                                         │
#41 1.521    ╰─────────────────────────────────────────╯
#41 1.521 
#41 ...

#42 [runner  3/17] COPY ./package.json ./package.json
#42 DONE 0.1s

#43 [runner  4/17] RUN node -e "console.log(JSON.parse(require('node:fs').readFileSync('./package.json')).packageManager)" | xargs npm install -g
#43 ...

#44 [target-builder 12/12] RUN --mount=type=cache,target=/root/.local/share/pnpm/store,sharing=locked 	pnpm i --frozen-lockfile --aggregate-output
#44 ...

#43 [runner  4/17] RUN node -e "console.log(JSON.parse(require('node:fs').readFileSync('./package.json')).packageManager)" | xargs npm install -g
#43 1.568 
#43 1.568 added 1 package in 1s
#43 1.568 
#43 1.568 1 package is looking for funding
#43 1.568   run `npm fund` for details
#43 1.570 npm notice
#43 1.570 npm notice New major version of npm available! 11.16.0 -> 12.0.2
#43 1.570 npm notice Changelog: https://github.com/npm/cli/releases/tag/v12.0.2
#43 1.570 npm notice To update run: npm install -g npm@12.0.2
#43 1.570 npm notice
#43 DONE 1.7s

#41 [native-builder 19/23] RUN --mount=type=cache,target=/root/.local/share/pnpm/store,sharing=locked 	pnpm i --frozen-lockfile --aggregate-output
#41 ...

#45 [runner  5/17] WORKDIR /cherrypick
#45 DONE 0.0s

#44 [target-builder 12/12] RUN --mount=type=cache,target=/root/.local/share/pnpm/store,sharing=locked 	pnpm i --frozen-lockfile --aggregate-output
#44 ...

#41 [native-builder 19/23] RUN --mount=type=cache,target=/root/.local/share/pnpm/store,sharing=locked 	pnpm i --frozen-lockfile --aggregate-output
#41 11.40 ✓ Lockfile passes supply-chain policies (2185 entries in 10.2s)
#41 11.43 [ERR_PNPM_OUTDATED_LOCKFILE] Cannot install with "frozen-lockfile" because pnpm-lock.yaml is not up to date with <ROOT>/packages/frontend/package.json
#41 11.43 
#41 11.43 Note that in CI environments this setting is true by default. If you still need to run install in such cases, use "pnpm install --no-frozen-lockfile"
#41 11.43 
#41 11.43   Failure reason:
#41 11.43   specifiers in the lockfile don't match specifiers in package.json:
#41 11.43 * 1 dependencies are mismatched:
#41 11.43   - exifreader (lockfile: 4.41.0, manifest: 4.41.1)
#41 11.43 
#41 ERROR: process "/bin/sh -c pnpm i --frozen-lockfile --aggregate-output" did not complete successfully: exit code: 1

#44 [target-builder 12/12] RUN --mount=type=cache,target=/root/.local/share/pnpm/store,sharing=locked 	pnpm i --frozen-lockfile --aggregate-output
#44 CANCELED
------
 > [native-builder 19/23] RUN --mount=type=cache,target=/root/.local/share/pnpm/store,sharing=locked 	pnpm i --frozen-lockfile --aggregate-output:
11.40 ✓ Lockfile passes supply-chain policies (2185 entries in 10.2s)
11.43 [ERR_PNPM_OUTDATED_LOCKFILE] Cannot install with "frozen-lockfile" because pnpm-lock.yaml is not up to date with <ROOT>/packages/frontend/package.json
11.43 
11.43 Note that in CI environments this setting is true by default. If you still need to run install in such cases, use "pnpm install --no-frozen-lockfile"
11.43 
11.43   Failure reason:
11.43   specifiers in the lockfile don't match specifiers in package.json:
11.43 * 1 dependencies are mismatched:
11.43   - exifreader (lockfile: 4.41.0, manifest: 4.41.1)
11.43 
------
Dockerfile:38

--------------------

  37 |     

  38 | >>> RUN --mount=type=cache,target=/root/.local/share/pnpm/store,sharing=locked \

  39 | >>> 	pnpm i --frozen-lockfile --aggregate-output

  40 |     

--------------------

failed to solve: process "/bin/sh -c pnpm i --frozen-lockfile --aggregate-output" did not complete successfully: exit code: 1


Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code packages/frontend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants