-
Notifications
You must be signed in to change notification settings - Fork 11
[Snyk] Upgrade sharp from 0.33.5 to 0.34.5 #65
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
Snyk has created this PR to upgrade sharp from 0.33.5 to 0.34.5. See this package in npm: sharp See this project in Snyk: https://app.snyk.io/org/sunwuyuan/project/7f95d725-ca6f-4cce-ab56-8b055b9f632f?utm_source=github&utm_medium=referral&page=upgrade-pr
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Pull request overview
This PR upgrades the sharp image processing library from version 0.34.3 to 0.34.5 to address security vulnerabilities in transitive dependencies. The upgrade is a patch version bump within the 0.34.x series, which according to semver should maintain backward compatibility. The change affects image processing functionality used in src/services/assets.js.
Key Changes:
- Bump
sharpdependency from^0.34.3to^0.34.5in package.json
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Pull Request Review: Upgrade sharp from 0.34.3 to 0.34.5OverviewThis PR upgrades the sharp image processing library from version 0.34.3 to 0.34.5. This is a security-focused dependency upgrade. Security Considerations - POSITIVE
Code Quality - POSITIVE
Potential Issues
Test Coverage - CRITICAL GAPS
RecommendationsIMMEDIATE:
FOLLOW-UP: Final Verdict: APPROVE with CONDITIONSRisk Level: LOW - Sharp has excellent backward compatibility |
Pull Request Review: Sharp Upgrade from 0.33.5 to 0.34.5SummaryThis PR upgrades the Code Quality and Best Practices✅ Positive Aspects
|
Snyk has created this PR to upgrade sharp from 0.33.5 to 0.34.5.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version is 15 versions ahead of your current version.
The recommended version was released a month ago.
Issues fixed by the recommended upgrade:
SNYK-JS-MULTER-10773732
SNYK-JS-VALIDATOR-13653476
SNYK-JS-AXIOS-12613773
SNYK-JS-BODYPARSER-14105059
SNYK-JS-EXPRESS-14157151
SNYK-JS-ONHEADERS-10773729
SNYK-JS-VALIDATOR-13395830
SNYK-JS-BRACEEXPANSION-9789073
SNYK-JS-BRACEEXPANSION-9789073
SNYK-JS-FORMDATA-10841150
Release notes
Package name: sharp
-
0.34.5 - 2025-11-06
-
-
-
-
-
-
-
0.34.5-rc.1 - 2025-11-06
-
-
-
-
-
-
-
0.34.5-rc.0 - 2025-11-05
-
-
-
-
-
-
-
0.34.4 - 2025-09-17
-
-
-
-
-
-
-
-
-
0.34.4-rc.4 - 2025-09-17
-
-
-
-
-
-
-
-
-
0.34.4-rc.3 - 2025-09-15
-
-
-
-
-
-
-
-
0.34.3 - 2025-07-10
-
0.34.3-rc.1 - 2025-07-09
-
0.34.3-rc.0 - 2025-06-14
-
0.34.2 - 2025-05-20
-
0.34.2-rc.0 - 2025-05-14
-
0.34.1 - 2025-04-07
-
0.34.0 - 2025-04-04
-
0.34.0-rc.1 - 2025-04-03
-
0.34.0-rc.0 - 2025-03-16
-
0.33.5 - 2024-08-16
from sharp GitHub release notesUpgrade to libvips v8.17.3 for upstream bug fixes.
Add experimental support for prebuilt Linux RISC-V 64-bit binaries.
Support building from source with npm v12+, deprecate
--build-from-sourceflag.#4458
Add support for BigTIFF output.
#4459
@ throwbi
Improve error messaging when only warnings issued.
#4465
Simplify ICC processing when retaining input profiles.
#4468
Upgrade to libvips v8.17.3 for upstream bug fixes.
Add experimental support for prebuilt Linux RISC-V 64-bit binaries.
Support building from source with npm v12+, deprecate
--build-from-sourceflag.#4458
Add support for BigTIFF output.
#4459
@ throwbi
Improve error messaging when only warnings issued.
#4465
Simplify ICC processing when retaining input profiles.
#4468
Upgrade to libvips v8.17.3 for upstream bug fixes.
Add experimental support for prebuilt Linux RISC-V 64-bit binaries.
Support building from source with npm v12+, deprecate
--build-from-sourceflag.#4458
Add support for BigTIFF output.
#4459
@ throwbi
Improve error messaging when only warnings issued.
#4465
Simplify ICC processing when retaining input profiles.
#4468
Upgrade to libvips v8.17.2 for upstream bug fixes.
Ensure TIFF
subifdand OpenSlidelevelinput options are respected (regression in 0.34.3).Ensure
autoOrientoccurs before non-90 angle rotation.#4425
Ensure
autoOrientremoves existing metadata after shrink-on-load.#4431
TypeScript: Ensure
KernelEnumincludeslinear.#4441
@ BayanBennett
Ensure
unlimitedflag is passed upstream when reading TIFF images.#4446
Support Electron memory cage when reading XMP metadata (regression in 0.34.3).
#4451
Add sharp-libvips rpath for yarn v5 support.
#4452
@ arcanis
Upgrade to libvips v8.17.2 for upstream bug fixes.
Ensure TIFF
subifdand OpenSlidelevelinput options are respected (regression in 0.34.3).Ensure
autoOrientoccurs before non-90 angle rotation.#4425
Ensure
autoOrientremoves existing metadata after shrink-on-load.#4431
TypeScript: Ensure
KernelEnumincludeslinear.#4441
@ BayanBennett
Ensure
unlimitedflag is passed upstream when reading TIFF images.#4446
Support Electron memory cage when reading XMP metadata (regression in 0.34.3).
#4451
Add sharp-libvips rpath for yarn v5 support.
#4452
@ arcanis
Upgrade to libvips v8.17.2 for upstream bug fixes.
Ensure
autoOrientoccurs before non-90 angle rotation.#4425
Ensure
autoOrientremoves existing metadata after shrink-on-load.#4431
TypeScript: Ensure
KernelEnumincludeslinear.#4441
@ BayanBennett
Ensure
unlimitedflag is passed upstream when reading TIFF images.#4446
Support Electron memory cage when reading XMP metadata (regression in 0.34.3).
#4451
Add sharp-libvips rpath for yarn v5 support.
#4452
@ arcanis
No content.
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information: