Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on May 1, 2024 via pnpm

imagemin 3.2.0

Minify images
Package summary
Share
43
issues
3
critical severity
vulnerability
2
license
1
25
high severity
vulnerability
10
license
5
meta
10
7
moderate severity
vulnerability
7
8
low severity
vulnerability
3
license
5
10
licenses
296
MIT
27
ISC
3
BSD
12
other licenses
BSD-3-Clause
3
Apache-2.0
3
BSD-2-Clause
2
N/A
1
+ 3 more
Package created
30 Aug 2013
Version published
15 May 2015
Maintainers
7
Total deps
338
Direct deps
13
License
MIT

Issues

43

3 critical severity issues

critical
Recommendation: Upgrade to version 4.2.1 or later
via: imagemin-gifsicle@4.2.0 & others
Recommendation: Upgrade to version 4.17.12 or later
via: vinyl-fs@1.0.0
Recommendation: Check the package code and files for license information
via: vinyl-fs@1.0.0
Collapse
Expand

25 high severity issues

high
Recommendation: None
via: imagemin-gifsicle@4.2.0 & others
Recommendation: Upgrade to version 3.1.3 or later
via: imagemin-gifsicle@4.2.0 & others
Recommendation: Upgrade to version 3.0.2 or later
via: vinyl-fs@1.0.0
Recommendation: Upgrade to version 4.17.11 or later
via: vinyl-fs@1.0.0
Recommendation: Upgrade to version 5.1.2 or later
via: imagemin-gifsicle@4.2.0 & others
Recommendation: Upgrade to version 3.13.1 or later
via: imagemin-svgo@4.2.1
Recommendation: Upgrade to version 3.0.1 or later
via: meow@3.7.0 & others
Recommendation: Upgrade to version 3.0.5 or later
via: vinyl-fs@1.0.0
Recommendation: None
via: imagemin-gifsicle@4.2.0 & others
Recommendation: Upgrade to version 4.17.21 or later
via: vinyl-fs@1.0.0
Recommendation: Validate that the package complies with your license policy
via: imagemin-gifsicle@4.2.0 & others
Recommendation: Validate that the package complies with your license policy
via: vinyl-fs@1.0.0
Recommendation: Validate that the package complies with your license policy
via: vinyl-fs@1.0.0
Recommendation: Validate that the license expression complies with your license policy
via: imagemin-gifsicle@4.2.0 & others
Recommendation: Read and validate the license terms
via: meow@3.7.0
via: imagemin-gifsicle@4.2.0
via: vinyl-fs@1.0.0
via: imagemin-gifsicle@4.2.0 & others
via: imagemin-jpegtran@4.3.2
via: vinyl-fs@1.0.0
via: vinyl-fs@1.0.0
via: vinyl-fs@1.0.0
via: imagemin-optipng@4.3.0
via: imagemin-svgo@4.2.1
via: buffer-to-vinyl@1.1.0 & others
Collapse
Expand

7 moderate severity issues

moderate
Recommendation: Upgrade to version 4.17.11 or later
via: vinyl-fs@1.0.0
Recommendation: Upgrade to version 3.13.0 or later
via: imagemin-svgo@4.2.1
Recommendation: Upgrade to version 0.6.0 or later
via: imagemin-gifsicle@4.2.0 & others
Recommendation: Upgrade to version 11.8.5 or later
via: imagemin-gifsicle@4.2.0 & others
Recommendation: Upgrade to version 4.17.21 or later
via: vinyl-fs@1.0.0
Recommendation: Upgrade to version 5.7.2 or later
via: imagemin-gifsicle@4.2.0 & others
Recommendation: Upgrade to version 4.17.5 or later
via: vinyl-fs@1.0.0
Collapse
Expand

8 low severity issues

low
Recommendation: Upgrade to version 2.3.1 or later
via: imagemin-gifsicle@4.2.0 & others
Recommendation: Upgrade to version 2.3.1 or later
via: imagemin-gifsicle@4.2.0 & others
Recommendation: Upgrade to version 3.1.4 or later
via: imagemin-gifsicle@4.2.0 & others
Recommendation: Read and validate the license terms
via: imagemin-gifsicle@4.2.0 & others
Recommendation: Read and validate the license terms
via: vinyl-fs@1.0.0
Recommendation: Read and validate the license terms
via: vinyl-fs@1.0.0
Recommendation: Read and validate the license terms
via: meow@3.7.0
Recommendation: Read and validate the license terms
via: meow@3.7.0
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
296 Packages, Including:
@types/keyv@3.1.4
@types/node@20.12.7
@types/responselike@1.0.3
ansi-gray@0.1.1
ansi-regex@2.1.1
ansi-styles@2.2.1
ansi-wrap@0.1.0
archive-type@3.2.0
argparse@1.0.10
arr-diff@2.0.0
arr-flatten@1.1.0
array-differ@1.0.0
array-find-index@1.0.2
array-uniq@1.0.3
array-unique@0.2.1
async-each-series@1.1.0
balanced-match@1.0.2
beeper@1.1.1
bin-build@2.2.0
bin-check@2.0.0
bin-version-check@2.1.0
bin-version@1.0.4
bin-wrapper@3.0.2
bl@1.2.3
brace-expansion@1.1.11
braces@1.8.5
buffer-alloc-unsafe@1.1.0
buffer-alloc@1.2.0
buffer-crc32@0.2.13
buffer-fill@1.0.0
buffer-from@1.1.2
buffer-to-vinyl@1.1.0
camelcase-keys@2.1.0
camelcase@2.1.1
capture-stack-trace@1.0.2
caw@1.2.0
chalk@1.1.3
clap@1.2.3
clone-stats@0.0.1
clone@0.2.0
clone@1.0.4
co@3.1.0
coa@1.0.4
colors@1.1.2
commander@2.20.3
concat-map@0.0.1
concat-stream@1.6.2
console-stream@0.1.1
convert-source-map@1.9.0
core-util-is@1.0.3

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
27 Packages, Including:
color-support@1.1.3
fs.realpath@1.0.0
glob-parent@2.0.0
glob-parent@3.1.0
glob@4.5.3
glob@5.0.15
glob@7.2.3
graceful-fs@3.0.12
graceful-fs@4.2.11
gulp-sourcemaps@1.6.0
hosted-git-info@2.8.9
inflight@1.0.6
inherits@2.0.4
ini@1.3.8
lru-cache@2.7.3
minimatch@2.0.10
minimatch@3.1.2
natives@1.1.6
once@1.4.0
remove-trailing-separator@1.1.0
rimraf@2.7.1
sax@1.2.4
semver@4.3.6
semver@5.7.2
sigmund@1.0.1
signal-exit@3.0.7
wrappy@1.0.2

BSD

Invalid
Not OSI Approved
3 Packages, Including:
duplexer2@0.0.2
glob@3.1.21
graceful-fs@1.2.3

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
3 Packages, Including:
duplexer2@0.1.4
source-map@0.5.7
sprintf-js@1.0.3

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
3 Packages, Including:
spdx-correct@3.2.0
tunnel-agent@0.4.3
validate-npm-package-license@3.0.4

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
2 Packages, Including:
esprima@2.7.3
normalize-package-data@2.5.0

N/A

N/A
1 Packages, Including:
inherits@1.0.2

(BSD-2-Clause OR MIT OR Apache-2.0)

Expression
1 Packages, Including:
rc@1.2.8

Creative Commons Attribution 3.0 Unported

Uncategorized
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
spdx-exceptions@2.5.0

Creative Commons Zero v1.0 Universal

Public Domain
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
spdx-license-ids@3.0.17
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

13
All Dependencies CSV
β“˜ This is a list of imagemin 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
buffer-to-vinyl1.1.01.64 kBMIT
prod optional
1
concat-stream1.6.23.72 kBMIT
prod optional
get-stdin4.0.1978 BMIT
prod optional
imagemin-gifsicle4.2.02.08 kBMIT
prod optional
1
10
3
4
imagemin-jpegtran4.3.22.27 kBMIT
prod optional
1
10
3
4
imagemin-optipng4.3.02.33 kBMIT
prod optional
1
10
3
4
imagemin-svgo4.2.12.01 kBMIT
prod optional
2
1
meow3.7.03.53 kBMIT
prod optional
2
2
optional0.1.41.45 kBMIT
prod
path-exists1.0.01.85 kBMIT
prod
stream-combiner21.1.12.68 kBMIT
prod optional
through20.6.54.28 kBMIT
prod optional
vinyl-fs1.0.05.69 kBMIT
prod
2
10
3
2

Visualizations

Frequently Asked Questions

What does imagemin do?

Imagemin is a powerful npm tool designed to seamlessly minify images. It works by reducing the file size of your images without affecting their quality, making your websites load faster and use less bandwidth. This streamlined performance can also enhance UX, helping to improve your site's SEO.

How do you use imagemin?

Imagemin is incredibly simple to use. To get started, first install the tool via npm, using the command npm install imagemin. Once installed, a typical usage would look like this:

import imagemin from 'imagemin';
import imageminJpegtran from 'imagemin-jpegtran';
import imageminPngquant from 'imagemin-pngquant';

const files = await imagemin(['images/*.{jpg,png}'], {
	destination: 'build/images',
	plugins: [
		imageminJpegtran(),
		imageminPngquant({
			quality: [0.6, 0.8]
		})
	]
});

console.log(files);
//=> [{data: <Buffer 89 50 4e …>, destinationPath: 'build/images/foo.jpg'}, …]

In the example above, the imagemin function takes in an array of file paths or glob patterns of the images to be minified, pointing to their locations on your file system. The function then optimizes these images using different plugins (in this case, imageminJpegtran and imageminPngquant). The resulting minified images are stored in the specified destination folder (build/images).

Where are the imagemin docs?

The documentation for imagemin can be found on its GitHub page or within the readme file in the package. This includes the API, different usages, and related tools. Potential plugins to use with imagemin can be found on npm under the keyword imageminplugin. Be sure to look through these resources for detailed guidance on how to use and customize the tool for your specific needs.