Upgrades sharp (npm) from 0.35.4 to 0.35.5, which fixes these known vulnerabilities:
| Advisory | Severity | Affected | Fixed in | Summary |
|---|---|---|---|---|
| GHSA-wq5f-xc86-pv6w | high | 0.35.4 | 0.35.5 | sharp : Vulnerability in librsvg dependency CVE-2026-96889 |
Lockfiles changed: package-lock.json.
Only the version changes. This pull request lands through this branch's required checks like any other. If they fail because code has to change, g1t closes it and puts g1t-agent on an issue to make the change.
Opened by g1t's security updates. Turn them off for this project on its Security page.