Skip to content

Bump sharp to ^0.35.0 for the libvips advisories - #5

Merged
lsimons merged 1 commit into
mainfrom
bump-sharp-0.35
Jul 31, 2026
Merged

Bump sharp to ^0.35.0 for the libvips advisories#5
lsimons merged 1 commit into
mainfrom
bump-sharp-0.35

Conversation

@lsimons

@lsimons lsimons commented Jul 31, 2026

Copy link
Copy Markdown
Member

Fixes Dependabot alert #1: sharp < 0.35.0 inherits the libvips vulnerabilities CVE-2026-33327, CVE-2026-33328, CVE-2026-35590 and CVE-2026-35591 (high).

  • docs/package.json: sharp ^0.34.5^0.35.0
  • docs/bun.lock: resolves to sharp 0.35.3 (libvips 1.3.x binaries)

Astro declares its optional sharp dependency as ^0.34.0 || ^0.35.0, so no other changes are needed. mise run docs-check (0 errors) and mise run docs-build both pass locally.

Co-Authored-By: lsimons-bot bot@leosimons.com

sharp < 0.35.0 inherits libvips vulnerabilities CVE-2026-33327,
CVE-2026-33328, CVE-2026-35590 and CVE-2026-35591 (Dependabot alert 1).
0.35.x is within the range Astro accepts for its optional sharp
dependency, so this is a straight bump; the lockfile resolves to 0.35.3.

Assisted-by: Claude:claude-opus-5

Co-Authored-By: lsimons-bot <bot@leosimons.com>
@lsimons
lsimons merged commit a67c614 into main Jul 31, 2026
4 checks passed
@lsimons
lsimons deleted the bump-sharp-0.35 branch July 31, 2026 12:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant