Skip to content

image-size dependency has a high vulnerability and no longer being maintained - CVE-2025-71330 and CVE-2025-71329 #33387

@stephenjtyrrell

Description

@stephenjtyrrell

Command

build

Is this a regression?

  • Yes, this behavior used to work in the previous version

The previous version in which this bug was not present was

No response

Description

image-size, which is a direct dependency for @angular/build has a high vulnerability and is no longer being maintained - CVE-2025-71330 and CVE-2025-71329.

Minimal Reproduction

.

Exception or Error


Your Environment

22.0.1

Anything else relevant?

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions