fix(agentex-ui): bump sharp 0.34.3 -> 0.35.3 (GHSA-f88m-g3jw-g9cj) - #371
Merged
Conversation
sharp <0.35.0 inherits four libvips CVEs (CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591) via GHSA-f88m-g3jw-g9cj (HIGH). sharp 0.35.0+ bundles the fixed libvips 8.18.3. sharp is a transitive optionalDependency of next@15.5.18 (declared ^0.34.3). Pinned via npm overrides to ^0.35.0, which resolves to 0.35.3 (libvips 1.3.2 = 8.18.3). next 15.5.18's image-optimizer only calls sharp(buffer, { limitInputPixels, sequentialRead }); none of the APIs removed in 0.35.0 (failOnError, paletteBitDepth, format.jp2k) are used, and the app declares no direct sharp/next-image usage. npm ci and tsc --noEmit pass. Resolves GFDVR-20651 / GFDVR-20652.
scale-ballen
enabled auto-merge (squash)
July 22, 2026 16:18
deepthi-rao-scale
approved these changes
Jul 28, 2026
danielmillerp
approved these changes
Jul 28, 2026
scale-ballen
disabled auto-merge
July 28, 2026 18:29
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Remediates GHSA-f88m-g3jw-g9cj (HIGH) in
sharp, reported by Trivy against theagentex-uiimage.sharp< 0.35.0 inherits four libvips vulnerabilities:sharp0.35.0+ bundles the fixed libvips 8.18.3.sharp@img/sharp-libvips-*)Change
sharpis a transitiveoptionalDependencyofnext@15.5.18(declared^0.34.3, which caps at<0.35.0). It is not a direct dependency and is not imported by application code. It is pinned via the existing npmoverridesblock inagentex-ui/package.json:^0.35.0resolves to the current latest0.35.3.agentex-ui/package-lock.jsonwas regenerated with npm 10 (matching CI's Node 20 toolchain); the diff is strictly thesharptransitive closure (the@img/sharp-*platform binaries,@img/sharp-libvips-*,@img/colourreplacingcolor, and sharp's ownsemver/detect-libcfloor bumps). NolockfileVersion/format migration, no file-mode changes, no application-code changes.Transitive-pin safety
next@15.5.18's image optimizer instantiates sharp assharp(buffer, { limitInputPixels, sequentialRead })— neither option was removed in 0.35.0. The APIs removed in 0.35.0 (failOnErrorconstructor prop,paletteBitDepthmetadata,format.jp2krename) are not used by next 15.5.18, and the app declares no directsharpusage nornext/imageusage. sharp 0.35.0 requires Node ≥ 20.9.0, satisfied by thenode:20-trixie-slimbuild/runtime base.Validation
npm ciinagentex-ui/— passes (lockfile in sync; CI's exact install gate)npm run typecheck(tsc --noEmit) — passessharpand its closure changed;colorfamily removed cleanly (was consumed only by sharp)Linear
Resolves GFDVR-20651 — [Trivy] Remediate sharp vulnerabilities
Covers child GFDVR-20652 — GHSA-f88m-g3jw-g9cj in sharp@0.34.3
🤖 Generated with Claude Code
Greptile Summary
Remediates GHSA-f88m-g3jw-g9cj (HIGH) by bumping the transitive
sharpdependency from 0.34.3 to 0.35.3, which bundles libvips 8.18.3 and fixes four libvips CVEs (CVE-2026-33327, -33328, -35590, -35591). The pin is applied via npmoverridesinpackage.json, which is the appropriate mechanism for transitive-only dependencies.package.json: Adds"sharp": "^0.35.0"to the existingoverridesblock alongside the existingcross-spawn,postcss, andtaroverrides.package-lock.json: All@img/sharp-*platform binaries move from 0.34.3 → 0.35.3 and@img/sharp-libvips-*from 1.2.0 → 1.3.2;coloris cleanly replaced by@img/colour; minor floor bumps todetect-libcandsemver. No application code orlockfileVersionchanges.Confidence Score: 5/5
Safe to merge — this is a targeted transitive dependency pin with no application code changes and a well-scoped lockfile diff.
The change is limited to a transitive
sharpbump via npmoverrides. No application code is touched, the lockfile diff is internally consistent (all@img/sharp-*and@img/sharp-libvips-*entries move together), and the removedcolorpackage is correctly replaced by@img/colouras expected in sharp 0.35.x. The new Node ≥ 20.9.0 engine constraint is satisfied by the project's existingnode:20runtime base.Files Needing Attention: No files require special attention.
Important Files Changed
"sharp": "^0.35.0"to the existing npmoverridesblock — the correct mechanism for pinning a transitive optional dependency without declaring it as a direct dependency.sharp0.34.3 → 0.35.3 and the full transitive closure:@img/sharp-*platform binaries bumped to 0.35.3,@img/sharp-libvips-*to 1.3.2,colorreplaced by@img/colour,detect-libc2.0.4 → 2.1.2,semver7.7.2 → 7.8.5, and new platform entries added (riscv64, freebsd-wasm32, webcontainers-wasm32). Changes are internally consistent and scoped exclusively to the sharp closure.Reviews (2): Last reviewed commit: "Merge branch 'main' into scale-prodsec/g..." | Re-trigger Greptile