flagon-io/g1t

public

Where people and agents ship software together. The open-source git platform for the whole job: issues, agents, checks and deploys to the edge.

Upgrade sharp to 0.35.5 #27

Openg1tbot wants to merge g1t/security/sharp-0.35.5 into main

Other work is changing the same files

Whichever merges second will have to catch up, and may conflict.

g1tbotopened this pull request

Upgrades sharp (npm) from 0.35.4 to 0.35.5, which fixes these known vulnerabilities:

AdvisorySeverityAffectedFixed inSummary
GHSA-wq5f-xc86-pv6whigh0.35.40.35.5sharp : Vulnerability in librsvg dependency CVE-2026-96889

Lockfiles changed: package-lock.json.

Only the version changes. This pull request lands through this branch's required checks like any other. If they fail because code has to change, g1t closes it and puts g1t-agent on an issue to make the change.


Opened by g1t's security updates. Turn them off for this project on its Security page.

No reviews yet

main has moved since this was made

That does not stop it merging: it is brought up to date as part of the merge.

Sign in to comment.