Skip to content

fix(deps): bump sharp to 0.35.5 in lockfile - #248

Merged
hivecommons-hive[bot] merged 1 commit into
mainfrom
sec/fix-sharp-0.35.5
Oct 6, 2026
Merged

hivecommons-hive[bot] merged 1 commit into
mainfrom
sec/fix-sharp-0.35.5

Conversation

@hivecommons-hive

Copy link
Copy Markdown
Contributor

📌 Fixes

Closes #247


📝 Summary of Changes

  • Lockfile-only bump of sharp 0.35.4 → 0.35.5 (and the matching @img/sharp-* platform packages, libvips 1.3.4), resolving GHSA-wq5f-xc86-pv6w (librsvg CVE-2026-96889, high).
  • next declares "sharp": "^0.35.4", so no package.json change is needed.
  • Adds a changelog.d/security-* fragment.

Changes Made

  • npm update sharp --package-lock-only --ignore-scripts
  • Verified npx tsx scripts/npm-audit-gate.ts <audit.json> --level=high passes afterwards (only the already-excepted braces advisory remains); on current main the same gate fails on sharp.

Checklist

  • I have reviewed the project's contribution guidelines.
  • I have performed a self-review of my changes.
  • I have written unit tests for the changes (not applicable — lockfile only).
  • I have updated the documentation (not applicable).
  • I have tested the changes locally and ensured they work as expected.
  • All CI checks are passing.

Security Considerations

  • Dependencies — validated new packages, checked for known vulnerabilities

Filed by sec-check agent (ACMM L6 — full mode)

— hive: agent=sec-check backend=copilot model=claude-fable-5.1 copilot=1.0.88

Lockfile-only update of sharp 0.35.4 -> 0.35.5 and its @img/sharp-*
platform packages (libvips 1.3.4). next declares ^0.35.4 so no
package.json change is needed. Keeps the production npm audit gate green.

Closes #247

Signed-off-by: sec-check <sec-check@hive.kubestellar.io>
@kubestellar-prow

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign clubanderson for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@netlify

netlify Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for hivecommons-docs ready!

Name Link
🔨 Latest commit 7fa3044
🔍 Latest deploy log https://app.netlify.com/projects/hivecommons-docs/deploys/6ac51fe84233380008a4e27e
😎 Deploy Preview https://deploy-preview-248--hivecommons-docs.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@hivecommons-hive
hivecommons-hive Bot merged commit d96ec77 into main Oct 6, 2026
9 of 10 checks passed
@kubestellar-prow
kubestellar-prow Bot deleted the sec/fix-sharp-0.35.5 branch October 6, 2026 16:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[sec-check] sharp 0.35.4 in lockfile hits GHSA-wq5f-xc86-pv6w (librsvg CVE-2026-96889, high) — in-range fix to 0.35.5 available

0 participants