Summary
image-size is declared in dependencies but doesn't appear to be referenced anywhere in the published package. It's currently the source of two High-severity advisories with no available fix, which is blocking security gates for consumers.
Evidence
In a clean install of @turbodocx/html-to-docx@1.22.0, image-size appears in exactly one file — package.json:
grep -rl "image-size" node_modules/@turbodocx/html-to-docx
--include=".js" --include=".json" --include="*.ts"
| grep -v "/node_modules/"
→ node_modules/@turbodocx/html-to-docx/package.json
None of the three shipped bundles reference it, and extractPartialStreams is absent from all of them:
grep -c "image-size" dist/html-to-docx.browser.esm.js # 0
grep -c "image-size" dist/html-to-docx.esm.js # 0
grep -c "image-size" dist/html-to-docx.umd.js # 0
Impact on consumers
Snyk reports two High findings (CVSS 8.7) against image-size@2.0.2, both infinite-loop DoS in image parsers — extractPartialStreams() for HEIF/JP2/JXL, and icns.js. There is no fixed version: 2.x ends at 2.0.2, and forcing 1.2.1 via a yarn resolutions override doesn't clear either finding, so the affected range appears to cover all published versions. That leaves consumers with no remediation path other than removing your package.
Request
Could image-size be dropped from dependencies? If it's needed for a code path I've missed, moving it to optionalDependencies would also resolve this for consumers who don't need image sizing.
Summary
image-size is declared in dependencies but doesn't appear to be referenced anywhere in the published package. It's currently the source of two High-severity advisories with no available fix, which is blocking security gates for consumers.
Evidence
In a clean install of @turbodocx/html-to-docx@1.22.0, image-size appears in exactly one file — package.json:
grep -rl "image-size" node_modules/@turbodocx/html-to-docx
--include=".js" --include=".json" --include="*.ts"
| grep -v "/node_modules/"
→ node_modules/@turbodocx/html-to-docx/package.json
None of the three shipped bundles reference it, and extractPartialStreams is absent from all of them:
grep -c "image-size" dist/html-to-docx.browser.esm.js # 0
grep -c "image-size" dist/html-to-docx.esm.js # 0
grep -c "image-size" dist/html-to-docx.umd.js # 0
Impact on consumers
Snyk reports two High findings (CVSS 8.7) against image-size@2.0.2, both infinite-loop DoS in image parsers — extractPartialStreams() for HEIF/JP2/JXL, and icns.js. There is no fixed version: 2.x ends at 2.0.2, and forcing 1.2.1 via a yarn resolutions override doesn't clear either finding, so the affected range appears to cover all published versions. That leaves consumers with no remediation path other than removing your package.
Request
Could image-size be dropped from dependencies? If it's needed for a code path I've missed, moving it to optionalDependencies would also resolve this for consumers who don't need image sizing.