Skip to content

fix(deps): patch sharp librsvg vulnerability - #530

Merged
nocoo merged 1 commit into
mainfrom
chore/deps-20261007-054409
Oct 6, 2026
Merged

nocoo merged 1 commit into
mainfrom
chore/deps-20261007-054409

Conversation

@nocoo

@nocoo nocoo commented Oct 6, 2026

Copy link
Copy Markdown
Owner

The current Sharp override pins a version affected by GHSA-wq5f-xc86-pv6w (librsvg CVE-2026-96889). Upgrade it to 0.35.5 and update the matching native/libvips lock records.

Closes #529

Validation: normal staged-index hooks passed strict lint, types, library build and 1,878 tests with all four coverage metrics above 95%. Frozen install, catalog build, library type/pack checks, publint, OSV and Gitleaks passed. Full consumer and browser acceptance remains enforced in CI.

@cloudflare-workers-and-pages

Copy link
Copy Markdown
Contributor

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
✅ Deployment successful!
View logs
theme-basalt a3b142a Oct 06 2026, 09:59 PM

@nocoo
nocoo merged commit 5d25867 into main Oct 6, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[fix-deps][security] sharp 0.35.4 → 0.35.5

1 participant