Skip to content

deps: bump sharp from 0.35.3 to 0.35.4 - #572

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/sharp-0.35.4
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/sharp-0.35.4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

Bumps sharp from 0.35.3 to 0.35.4.

Release notes

Sourced from sharp's releases.

v0.35.4

https://github.com/lovell/sharp-libvips/releases/tag/v1.3.3

v0.35.4-rc.0

Commits
  • 7f1a0a2 Release v0.35.4
  • f927818 Upgrade to sharp-libvips v1.3.3
  • e802092 Prerelease v0.35.4-rc.0
  • e13eb2f CI: Fix wasm32 build (#4589)
  • a82a0b3 Upgrade to libvips v8.18.6
  • 8044fe4 Bound resize dimensions to coordinate limit
  • 147f859 Docs: changelog entries for #4578 #4584
  • ee5bfb8 Tests: use yauzl directly rather than via extract-zip wrapper
  • 7a77889 Bump uraimo/run-on-arch-action from 3.1.0 to 3.2.0 (#4588)
  • ea5bef2 Improve support for input Streams finishing before output is requested (#4584)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [sharp](https://github.com/lovell/sharp) from 0.35.3 to 0.35.4.
- [Release notes](https://github.com/lovell/sharp/releases)
- [Commits](lovell/sharp@v0.35.3...v0.35.4)

---
updated-dependencies:
- dependency-name: sharp
  dependency-version: 0.35.4
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 8, 2026
@dependabot
dependabot Bot requested review from a team and EricAndrechek September 8, 2026 23:56
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 8, 2026
@dependabot dependabot Bot added the javascript Pull requests that update javascript code label Sep 8, 2026
@github-actions github-actions Bot added documentation Improvements or additions to documentation area/docs Documentation, site/, README labels Sep 8, 2026
@github-code-quality

Copy link
Copy Markdown
Contributor

Code Coverage Overview

Languages: Go

Go

The overall line coverage in commit 2f7e2f1 in the dependabot/npm_and_y... branch remains at 91%, unchanged from commit 4f05b18 in the main branch.

@dependabot @github

dependabot Bot commented on behalf of github Sep 9, 2026

Copy link
Copy Markdown
Contributor Author

Looks like sharp is no longer updatable, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 9, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/sharp-0.35.4 branch September 9, 2026 12:58
@github-project-automation github-project-automation Bot moved this from Backlog to Done in WaveHouse Task Board Sep 9, 2026
EricAndrechek added a commit that referenced this pull request Sep 9, 2026
## Summary

Replaces Dependabot's #571 (`astro` 7.1.6 → 7.2.8), whose generated
lockfile cannot be installed under this repo's supply-chain policy.
Bumps to **astro 7.2.10** with a lockfile resolved by pnpm itself, so it
satisfies `minimumReleaseAge`.

Supersedes #571 — once `main` carries astro 7.2.10, Dependabot closes
that PR itself (its 7.2.8 target is already satisfied). No manual close
needed.

## Why #571 could not be rebased

`pnpm install --frozen-lockfile` — the install every Node-touching CI
job runs — rejected #571's lockfile outright:

```
✗ Lockfile failed supply-chain policy check (1126 entries in 2.1s)
[ERR_PNPM_MINIMUM_RELEASE_AGE_VIOLATION] 21 lockfile entries failed verification:
  @clack/core@1.5.0 was published at 2026-09-07T20:12:19.000Z, within the minimumReleaseAge cutoff
  rolldown@1.2.7 ... postcss@8.5.28 ... tinyexec@1.3.1 ... undici@8.10.2 ...
```

That one `pnpm-install` target — reached via `make verify` (Lint), `make
build-docs` → check-docs (Docs build), `make test-ts` (Unit tests),
`make test-e2e` → build-ts (E2E tests), and invoked directly by the
workflow (Coverage) — failed all five at once, printing no reason for
any of them (#578). Integration tests, the one suite that never
installs, stayed green on the same lockfile.

`@dependabot rebase` / `recreate` cannot fix it: Dependabot resolves
with a resolver that does not read `minimumReleaseAge` from
`pnpm-workspace.yaml`, so it regenerates the same violating tree. This
is #441.

Note `astro@7.2.8` itself was **not** the problem — published
2026-08-26, 14 days old and well past the 7-day cooldown. All 21
violations were transitive: `rolldown@1.2.7` plus its 15 platform
bindings (09-02), `postcss@8.5.28` / `tinyexec@1.3.1` (09-03),
`undici@8.10.2` (09-04), `@clack/core` + `@clack/prompts` (09-07). A
Dependabot `cooldown:` setting would not have prevented it, since that
gates only the direct dependency.

## What this does instead

Bump the manifest and let pnpm resolve. Its resolver *does* honor
`minimumReleaseAge`, so it backs off to age-eligible versions on its
own:

```
docs/package.json:  "astro": "^7.1.1"  ->  "^7.2.10"
pnpm install
```

Resolves `astro@7.2.10` (published 2026-08-31, already past cooldown)
with `rolldown@1.2.2`, `postcss@8.5.25`, `undici@8.10.1`, `vite@8.2.0`.

One further manifest change rides along, surfaced by pre-push review:

- **Declare `@astrojs/markdown-remark` `^7.3.0`.** astro 7.1.6 pinned it
to exactly 7.2.2 (an *optional* peer even then, so an unmet one is
dropped silently rather than erroring); 7.2.10 widens the range to
`^7.3.0`, which the tree's 7.2.2 — a hard dep of `@astrojs/mdx` —
doesn't satisfy, so pnpm dropped it from astro's peer set. That's
load-bearing: `docs/astro.config.mjs` sets
`markdown.remarkPlugins`/`rehypePlugins`, and astro's
`coerceLegacyMarkdownPlugins()` does `await
import("@astrojs/markdown-remark")` and **throws** if it can't resolve.
It only worked via pnpm's hoisted fallback copy — an undeclared edge a
narrower `hoist-pattern`, or a starlight/mdx bump dropping that
dependency, would break.

A `sharp` bump to `^0.35.4` was also part of this branch originally
(astro 7.2.8 raised its own optional sharp floor, and the stale 0.35.3
pin had stopped sharing a copy with astro). That change reached `main`
first via #574, so it no longer appears in this diff — and #572, the
dedicated sharp PR, was superseded by #574 and is already closed.

## Synced with main

`origin/main` advanced while this was in review (#570 go-deps, #573
actions-deps, #574 npm-deps all merged). `origin/main` is merged in here
— never rebased, per §Branch Maintenance.

`pnpm-lock.yaml` conflicted. Resolved by taking main's post-#574
lockfile (`git checkout --theirs pnpm-lock.yaml`) and re-running a
targeted `pnpm install` against the merged manifests, rather than
hand-merging conflicting YAML. That is deliberate: a lockfile's
peer-suffixed keys encode a whole resolution graph, and hand-merging
them yields a tree that installs but matches neither side's actual
resolution. Re-resolving lets pnpm rebuild the graph under policy.

The result keeps both sides intact — #574's catalog `@types/node@26.4.1`
and `tsx@4.23.13` are preserved, alongside this branch's `astro@7.2.10`
and `@astrojs/markdown-remark@7.3.0`. Net diff vs `main` is now
`docs/package.json` (2 lines) plus 281+/136− in `pnpm-lock.yaml`, with
zero downgrades. One package drops out entirely —
`@rollup/pluginutils@5.4.0`, correct because astro 7.2.x drops its
`rollup` optional peer.

## Verification

- `pnpm install --frozen-lockfile` — clean, no policy violation (this is
what #571 failed), and leaves the lockfile byte-identical. Every entry
in the resulting tree is past the 7-day cooldown; the newest is
`@types/node@26.4.1` at 7d 17h.
- `make build-docs` — 22 pages, all internal links valid, mermaid
patched, 68 diagram PNGs rendered.
- `make ci` — green on the merged tree.

## Related

- #571 — the Dependabot PR this replaces.
- #441 — the underlying Dependabot/pnpm cooldown mismatch. [Commented
there](#441 (comment))
with the updated failure mode: the repo pinned pnpm 11.1.3 until #490
moved it to 11.21.0, which *does* enforce the policy under
`--frozen-lockfile` — so this now fails loudly in CI rather than merging
silently as #441 originally described.
- #578 — filed from this PR's review: `pnpm-install`'s
`--reporter=silent` swallowed the diagnostic entirely, which is why five
red jobs stated no reason.
- #572 — superseded by #574 (identical sharp bump); closed.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01CbyVditEujZabgu3R11VAm

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/docs Documentation, site/, README dependencies Pull requests that update a dependency file documentation Improvements or additions to documentation javascript Pull requests that update javascript code

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

0 participants