Skip to content

chore(deps): bump sharp and next in /app - #151

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/app/multi-602d0ec552
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/app/multi-602d0ec552

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 11, 2026

Copy link
Copy Markdown
Contributor

Bumps sharp to 0.35.4 and updates ancestor dependency next. These dependencies need to be updated together.

Updates sharp from 0.34.5 to 0.35.4

Release notes

Sourced from sharp's releases.

v0.35.4

https://github.com/lovell/sharp-libvips/releases/tag/v1.3.3

v0.35.4-rc.0

... (truncated)

Commits
  • 7f1a0a2 Release v0.35.4
  • f927818 Upgrade to sharp-libvips v1.3.3
  • e802092 Prerelease v0.35.4-rc.0
  • e13eb2f CI: Fix wasm32 build (#4589)
  • a82a0b3 Upgrade to libvips v8.18.6
  • 8044fe4 Bound resize dimensions to coordinate limit
  • 147f859 Docs: changelog entries for #4578 #4584
  • ee5bfb8 Tests: use yauzl directly rather than via extract-zip wrapper
  • 7a77889 Bump uraimo/run-on-arch-action from 3.1.0 to 3.2.0 (#4588)
  • ea5bef2 Improve support for input Streams finishing before output is requested (#4584)
  • Additional commits viewable in compare view

Updates next from 16.2.10 to 16.3.4

Release notes

Sourced from next's releases.

v16.3.4

Follow-up release to v16.3.3 re-enabling AVIF Image Optimization (#97949).

The following bug fixes have been backported. It does not include all pending features/changes on canary.

  • testmode: Fix infinite recursion in testmode passthrough fetch (#97691)
  • Fix build error when aliasing typescript to @​typescript/typescript6 (#97997)
  • Fix unset crossOrigin in Turbopack manifests (#97930)

Credits

Huge thanks to @​eps1lon, @​mischnic, and @​timneutkens for helping!

v16.3.3

This release contains security fixes for the following advisories:

Critical:

v16.3.2

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes

  • [backport] Scope app-entry export validation to files inside the app directory (#97357)
  • [backport] Fix catch-all index page being served for every other slug (#97416)
  • [16.3] Turbopack: don't trace embedded WASM loader helpers (#97353) (#97463)
  • [16.3] Turbopack: retain conditions when replacing resolve request keys (#97453)
  • [16.3.x] Fix Turbopack worker chunk loading with asset prefix (#97419)
  • [16.3.x] Authenticate Turborepo remote caching with OIDC instead of a static PAT (#97603)

Credits

Huge thanks to @​lubieowoce, @​unstubbable, @​timneutkens, @​mischnic, and @​eps1lon for helping!

v16.3.1

What's Changed

... (truncated)

Commits
  • 299180d v16.3.4
  • 12e173d [16.3.x] Re-enable AVIF image optimization and require sharp 0.35.4 (#97949)
  • 5d9022e [backport] Fix unset crossOrigin in Turbopack manifests (#97930)
  • d8f4560 [16.3.x] Fix build error when aliasing typescript to @​typescript/typescript6 ...
  • 656aebf [16.3] testmode: Fix infinite recursion in testmode passthrough fetch (#97691)
  • f37c1d6 [16.3.x] ci: remove pull_request_stats workflow (#97975)
  • a9a1cb7 v16.3.3
  • 968b9fc [16.3.x] Fix ISR misses with backslashes in segments when deployed on Windows
  • 3a15b4a [16.3.x] [next/image]: disable avif image optimization
  • 7378b51 Backport/docs fixes 16.3 (#97649)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [sharp](https://github.com/lovell/sharp) to 0.35.4 and updates ancestor dependency [next](https://github.com/vercel/next.js). These dependencies need to be updated together.


Updates `sharp` from 0.34.5 to 0.35.4
- [Release notes](https://github.com/lovell/sharp/releases)
- [Commits](lovell/sharp@v0.34.5...v0.35.4)

Updates `next` from 16.2.10 to 16.3.4
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v16.2.10...v16.3.4)

---
updated-dependencies:
- dependency-name: sharp
  dependency-version: 0.35.4
  dependency-type: indirect
- dependency-name: next
  dependency-version: 16.3.4
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 11, 2026

@roger-guifav roger-guifav left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

TL;DR

Este PR atualiza o framework do app para uma versão minor mais nova e traz junto, só no lockfile, a biblioteca opcional de processamento de imagens. O código compila, os 680 testes passam e o lint está limpo no head revisado. Falta regerar o inventário de licenças de terceiros, sem isso o gate de licenças do CI fica vermelho.

Verdict: Ajustes necessários

(revisado no head SHA 1fa7911)

Parecer

Intenção: manter o framework de renderização do app e sua dependência opcional de imagem em dia, ambos em passos minor dentro da mesma linha de versão. Fatos fora do diff que pesam: (1) o repo tem um gate de inventário de licenças no workflow de CI que compara os lockfiles com o markdown de licenças em docs/ e falha quando divergem; (2) a biblioteca de imagem não é dependência direta do app — o manifesto não a declara e não há import no código, ela entra como dependência opcional do framework — então o risco do bump é baixo; (3) a exigência de runtime da nova versão da biblioteca de imagem é compatível com a versão de node declarada no projeto; (4) os jobs de CI nem iniciaram neste head por bloqueio de cobrança da conta — o sinal vermelho atual é de infraestrutura, mas o gate de licenças foi reproduzido localmente e falharia assim que o CI voltar. Delta da rodada: primeira revisão deste head. Verdade de produção: config de lint do framework ficou na versão anterior, skew benigno dentro da mesma major. Pergunta de merge: eu mergearia depois de regerar o inventário e ver o CI verde — hoje não.

Críticos (P0)

nenhum.

Bloqueadores de correção (P1)

  1. Inventário de licenças desatualizado. O gate do CI (script gerador em scripts/, âncora de símbolo fail-on-unknown) acusa que o markdown de licenças em docs/ está stale neste head, porque o lockfile mudou e o documento não foi regerado. Reproduzido localmente: no head o check sai com erro; no merge-base ele passa. Aplicar antes do merge: rodar o gerador a partir de app/ e commitar o markdown atualizado.

Endereçar no PR (P2)

nenhum.

Endereçar no PR (P3 / nits)

nenhum.

Acoes que somente o humano pode fazer (ainda...)

  • Destravar a conta para o CI voltar a rodar: neste head os quatro jobs falharam sem iniciar, por bloqueio de cobrança, e só o dono da conta resolve. Depois do fix do inventário, rerodar o workflow.

Verificado

  • diff contra origin/main fresco: 2 arquivos (manifest e lockfile do app), conferido com a API do PR; nenhum código de aplicação tocado.
  • classificação: framework em bump minor; biblioteca de imagem atualizada apenas no lockfile, sem declaração direta e sem imports no código.
  • npm ci, geração do cliente prisma, tsc sem erros, eslint limpo, vitest: 680 testes passando, 8 pulados, nenhum falho (head revisado).
  • gate de licenças: falha no head, passa no merge-base.
  • CI neste head: quatro jobs marcados como falha por bloqueio de cobrança da conta, sem executar etapa alguma.
  • scan de segredos no diff: nenhum padrão comum de chave de git ou cloud encontrado.

Roger (Hermes KVM) - review v2 - 1fa7911

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant