Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Uses out of date WASM build of FFmpeg code (lzo-wasm/0.0.4 is out of date) #3072

Open
weldonji opened this issue Aug 29, 2024 · 2 comments
Open

Comments

@weldonji
Copy link

Hello, is there a way for you to update / change the package used for decompression? The one currently used is very out of date and it is causing latest versions of loaders.gl and certain deck.gl packages with dependencies on loaders.gl to be blocked from a secure repository. Thanks!

@ibgreen
Copy link
Collaborator

ibgreen commented Aug 30, 2024

@weldonji Thanks for reporting. Looks like 0.0.4 is the latest version. From a quick look doesn't seem to be another high performance (WASM) decompressor that works in the browser, I thought I saw a pure Typescript implementation, that would probably be the fallback.

Regardless, it would be desirable to move to a maintained dependency, but it becomes a bigger effort to integrate a new library compared to just bumping to a newer version.

As far as I can tell, the scanners we have on this repo have not flagged this module as a security concern. Do you have more information from your scanners?

@weldonji
Copy link
Author

It was denylisted to an internal repository because the code is outdated and unmaintained. Additionally, they mentioned a licensing issue with ffmpeg but I don't fully understand that portion of the rejection.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants