Archiving this repo, because I don't want to deal with the same LLM generated "security advisory" about an inifinite loop over and over again.
I do not wish to participate in this sloppy mess of a platform.
Please do not create issues or advisories for me, and please do not summon me 🙏.
At some point I'll revive this project to address actual issues, but on Codeberg.
This repo on github will not be updated.
Helpyourself security fork
getitcheappro/image-size-patchedcarries narrow denial-of-service fixes for malformed ICNS, HEIF, and JPEG XL containers. Helpyourself pins an audited commit from this fork while upstream has no patched release. The regression tests inspecs/security.spec.tscover all three malformed inputs.
Fast, lightweight NodeJS package to get dimensions of any image file or buffer.
- Zero dependencies
- Supports all major image formats
- Works with both files and buffers
- Minimal memory footprint - reads only image headers
- ESM and CommonJS support
- TypeScript types included
- BMP
- CUR
- DDS
- GIF
- HEIC (HEIF, AVCI, AVIF)
- ICNS
- ICO
- J2C
- JPEG-2000 (JP2)
- JPEG
- JPEG-XL
- KTX (1 and 2)
- PNG
- PNM (PAM, PBM, PFM, PGM, PPM)
- PSD
- SVG
- TGA
- TIFF
- WebP
npm install image-size
# or
yarn add image-size
# or
pnpm add image-sizeBest for streams, network requests, or when you already have the image data in memory.
import { imageSize } from 'image-size'
// or
const { imageSize } = require('image-size')
const dimensions = imageSize(buffer)
console.log(dimensions.width, dimensions.height)Best for local files. Returns a promise.
import { imageSizeFromFile } from 'image-size/fromFile'
// or
const { imageSizeFromFile } = require('image-size/fromFile')
const dimensions = await imageSizeFromFile('photos/image.jpg')
console.log(dimensions.width, dimensions.height)Note: Reading from files has a default concurrency limit of 100
To change this limit, you can call the setConcurrency function like this:
import { setConcurrency } from 'image-size/fromFile'
// or
const { setConcurrency } = require('image-size/fromFile')
setConcurrency(123456)v1.x of this library had a sync API, that internally used sync file reads.
This isn't recommended because this blocks the node.js main thread, which reduces the performance, and prevents this library from being used concurrently.
However if you still need to use this package syncronously, you can read the file syncronously into a buffer, and then pass the buffer to this library.
import { readFileSync } from 'node:fs'
import { imageSize } from 'image-size'
const buffer = readFileSync('photos/image.jpg')
const dimensions = imageSize(buffer)
console.log(dimensions.width, dimensions.height)Useful for quick checks.
npx image-size image1.jpg image2.pngIf the target file/buffer is an HEIF, an ICO, or a CUR file, the width and height will be the ones of the largest image in the set.
An additional images array is available and returns the dimensions of all the available images
import { imageSizeFromFile } from 'image-size/fromFile'
// or
const { imageSizeFromFile } = require('image-size/fromFile')
const { images } = await imageSizeFromFile('images/multi-size.ico')
for (const dimensions of images) {
console.log(dimensions.width, dimensions.height)
}import url from 'node:url'
import http from 'node:http'
import { imageSize } from 'image-size'
const imgUrl = 'http://my-amazing-website.com/image.jpeg'
const options = url.parse(imgUrl)
http.get(options, function (response) {
const chunks = []
response
.on('data', function (chunk) {
chunks.push(chunk)
})
.on('end', function () {
const buffer = Buffer.concat(chunks)
console.log(imageSize(buffer))
})
})import { disableTypes } from 'image-size'
// or
const { disableTypes } = require('image-size')
disableTypes(['tiff', 'ico'])If the orientation is present in the JPEG EXIF metadata, it will be returned by the function. The orientation value is a number between 1 and 8 representing a type of orientation.
import { imageSizeFromFile } from 'image-size/fromFile'
// or
const { imageSizeFromFile } = require('image-size/fromFile')
const { width, height, orientation } = await imageSizeFromFile('images/photo.jpeg')
console.log(width, height, orientation)-
Partial File Reading
- Only reads image headers, not full files
- Some corrupted images might still report dimensions
-
SVG Limitations
- Only supports pixel dimensions and viewBox
- Percentage values not supported
-
File Access
- Reading from files has a default concurrency limit of 100
- Can be adjusted using
setConcurrency()
-
Buffer Requirements
- Some formats (like TIFF) require the full header in buffer
- Streaming partial buffers may not work for all formats
MIT
- Repository: https://github.com/getitcheappro/image-size-patched
- Clone:
git clone https://github.com/getitcheappro/image-size-patched.git - Requirements: Node.js 16 or newer and Corepack/Yarn 4.
- Install: run
corepack enable, thenyarn install --immutable. - Validate: run
yarn lint,yarn test, andyarn build. - Environment variables: none. No
.envfile, database, API key, or external service is required. - Local ports/URLs: none; this repository builds a library and does not start a web server.
- Troubleshooting: if Corepack cannot download Yarn, verify network access to
the npm registry. If a Git-pinned consumer install fails, verify access to
GitHub and do not use
--ignore-scripts, because the pinned source commit is built during installation.
not a direct port, but an attempt to have something like dabble's imagesize as a node module.