Skip to content

build(deps): bump sharp from 0.34.5 to 0.35.5 in /website - #1468

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/website/sharp-0.35.5
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/website/sharp-0.35.5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026 •

Copy link
Copy Markdown

Bumps sharp from 0.34.5 to 0.35.5.

Release notes

Sourced from sharp's releases.

v0.35.5

https://github.com/lovell/sharp-libvips/releases/tag/v1.3.4

  • Add upper bounds check on length of linear and GIF delay arrays.

  • Improve error handing when WebAssembly fallback also fails. #4593 @​lazerg

  • TypeScript: Allow multi-frame options for JXL output. #4602 @​ramin-010

  • TypeScript: Remove non-existent named export. #4604

  • Increase accepted dimensions when extending an image. #4605

  • Improve gain map support for extract and rotate operations. #4606

  • Tests: Ensure composite tests pass on big endian platforms. #4609

v0.35.5-rc.1

https://github.com/lovell/sharp-libvips/releases/tag/v1.3.4-rc.1

  • Add upper bounds check on length of linear and GIF delay arrays.

  • Improve error handing when WebAssembly fallback also fails. #4593 @​lazerg

  • TypeScript: Allow multi-frame options for JXL output. #4602 @​ramin-010

  • TypeScript: Remove non-existent named export. #4604

  • Increase accepted dimensions when extending an image. #4605

  • Improve gain map support for extract operation. #4606

... (truncated)

Commits
  • 51a990f Release v0.35.5
  • 96de105 Upgrade to sharp-libvips v1.3.4
  • 3a61390 CI: Configure Dependabot with all package.json locations
  • 4940c50 Improve gain map support for rotate/flip/flop ops
  • 20654aa Prerelease v0.35.5-rc.1
  • ef4f934 CI: Upgrade to Ubuntu 26.04
  • 358df95 Upgrade to libvips v8.18.7
  • 49f4903 Improve gain map support for rotate-then-extract #4606
  • 0e2e55e Silence a couple of compiler/static analysis warnings
  • cef3b8c Improve gain map support for extract operation #4606
  • Additional commits viewable in compare view

@dependabot dependabot Bot added language: javascript Work involving JavaScript code, tooling, or dependencies. type: dependencies Dependency additions, removals, and version updates. labels Oct 7, 2026
Bumps [sharp](https://github.com/lovell/sharp) from 0.34.5 to 0.35.5.
- [Release notes](https://github.com/lovell/sharp/releases)
- [Commits](lovell/sharp@v0.34.5...v0.35.5)

---
updated-dependencies:
- dependency-name: sharp
  dependency-version: 0.35.5
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Astro still resolves Sharp 0.34.5, so the website image pipeline is not actually upgraded.

1 open finding
What changed in this PR

Updates the website’s direct Sharp dependency from 0.34.5 to 0.35.5.

Changes:

  • Bumps the declared Sharp version.
  • Refreshes Sharp’s platform-specific lockfile dependencies.
File Description
website/​package.json Updates the direct Sharp dependency.
website/​pnpm-lock.yaml Records Sharp 0.35.5 and its transitive packages.
Files not reviewed (1)
  • website/pnpm-lock.yaml: Generated file

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread website/package.json
"@astrojs/starlight": "^0.39.2",
"astro": "^6.4.6",
"sharp": "^0.34.5"
"sharp": "^0.35.5"

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

language: javascript Work involving JavaScript code, tooling, or dependencies. type: dependencies Dependency additions, removals, and version updates.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant