fix(agentex-ui): bump sharp 0.34.3 -> 0.35.3 (GHSA-f88m-g3jw-g9cj)#371
Open
scale-prodsec[bot] wants to merge 1 commit into
Open
fix(agentex-ui): bump sharp 0.34.3 -> 0.35.3 (GHSA-f88m-g3jw-g9cj)#371scale-prodsec[bot] wants to merge 1 commit into
scale-prodsec[bot] wants to merge 1 commit into
Conversation
sharp <0.35.0 inherits four libvips CVEs (CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591) via GHSA-f88m-g3jw-g9cj (HIGH). sharp 0.35.0+ bundles the fixed libvips 8.18.3. sharp is a transitive optionalDependency of next@15.5.18 (declared ^0.34.3). Pinned via npm overrides to ^0.35.0, which resolves to 0.35.3 (libvips 1.3.2 = 8.18.3). next 15.5.18's image-optimizer only calls sharp(buffer, { limitInputPixels, sequentialRead }); none of the APIs removed in 0.35.0 (failOnError, paletteBitDepth, format.jp2k) are used, and the app declares no direct sharp/next-image usage. npm ci and tsc --noEmit pass. Resolves GFDVR-20651 / GFDVR-20652.
scale-ballen
enabled auto-merge (squash)
July 22, 2026 16:18
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Remediates GHSA-f88m-g3jw-g9cj (HIGH) in
sharp, reported by Trivy against theagentex-uiimage.sharp< 0.35.0 inherits four libvips vulnerabilities:sharp0.35.0+ bundles the fixed libvips 8.18.3.sharp@img/sharp-libvips-*)Change
sharpis a transitiveoptionalDependencyofnext@15.5.18(declared^0.34.3, which caps at<0.35.0). It is not a direct dependency and is not imported by application code. It is pinned via the existing npmoverridesblock inagentex-ui/package.json:^0.35.0resolves to the current latest0.35.3.agentex-ui/package-lock.jsonwas regenerated with npm 10 (matching CI's Node 20 toolchain); the diff is strictly thesharptransitive closure (the@img/sharp-*platform binaries,@img/sharp-libvips-*,@img/colourreplacingcolor, and sharp's ownsemver/detect-libcfloor bumps). NolockfileVersion/format migration, no file-mode changes, no application-code changes.Transitive-pin safety
next@15.5.18's image optimizer instantiates sharp assharp(buffer, { limitInputPixels, sequentialRead })— neither option was removed in 0.35.0. The APIs removed in 0.35.0 (failOnErrorconstructor prop,paletteBitDepthmetadata,format.jp2krename) are not used by next 15.5.18, and the app declares no directsharpusage nornext/imageusage. sharp 0.35.0 requires Node ≥ 20.9.0, satisfied by thenode:20-trixie-slimbuild/runtime base.Validation
npm ciinagentex-ui/— passes (lockfile in sync; CI's exact install gate)npm run typecheck(tsc --noEmit) — passessharpand its closure changed;colorfamily removed cleanly (was consumed only by sharp)Linear
Resolves GFDVR-20651 — [Trivy] Remediate sharp vulnerabilities
Covers child GFDVR-20652 — GHSA-f88m-g3jw-g9cj in sharp@0.34.3
🤖 Generated with Claude Code
Greptile Summary
Remediates GHSA-f88m-g3jw-g9cj by pinning the transitive
sharpdependency from0.34.3to^0.35.0(resolved to0.35.3) via npmoverridesinpackage.json. The regenerated lockfile is cleanly scoped to the sharp transitive closure with no changes outside it.package.json: Adds\"sharp\": \"^0.35.0\"to the existingoverridesblock alongside the existingcross-spawn,postcss, andtarpins.package-lock.json: Updatessharpto 0.35.3, all@img/sharp-*platform binaries to 0.35.3, and all@img/sharp-libvips-*packages to 1.3.2 (bundling the fixed libvips 8.18.3). Thecolorpackage and its dependents (simple-swizzle,is-arrayish) are removed and replaced by@img/colour. New platform targets (freebsd-wasm32,linux-riscv64,webcontainers-wasm32) are added as expected for the new minor.Confidence Score: 5/5
Safe to merge — a targeted security override with no application code changes and a lockfile diff cleanly scoped to the sharp transitive closure.
The override correctly targets the vulnerable transitive dependency, resolves to the latest patched release, and the lockfile regeneration introduced no unrelated package changes. The removed color subtree and added platform targets are all expected consequences of the sharp 0.35.x minor. No application code, types, or other runtime paths were touched.
No files require special attention.
Important Files Changed
"sharp": "^0.35.0"to the existingoverridesblock, pinning the transitive sharp dependency to the patched version that bundles libvips 8.18.3.colorwith@img/colour; removessimple-swizzle/is-arrayish; adds new platform targets (freebsd-wasm32, linux-riscv64, webcontainers-wasm32). All changes are strictly within the sharp transitive closure.Flowchart
%%{init: {'theme': 'neutral'}}%% flowchart TD A["agentex-ui/package.json\noverrides: sharp ^0.35.0"] -->|"npm ci resolves override"| B["sharp@0.35.3"] B --> C["@img/sharp-libvips-linux-x64@1.3.2\n(libvips 8.18.3 — patched)"] B --> D["@img/colour@1.1.0\n(replaces color@4.x)"] B --> E["detect-libc@^2.1.2\nsemver@^7.8.5"] F["next@15.5.18\noptionalDependency: sharp ^0.34.3"] -.->|"overridden by npm overrides"| B C -->|"bundles fixed libvips resolving"| G["CVE-2026-33327\nCVE-2026-33328\nCVE-2026-35590\nCVE-2026-35591"] style G fill:#d4edda,stroke:#28a745,color:#155724 style A fill:#cce5ff,stroke:#004085,color:#004085 style B fill:#fff3cd,stroke:#856404,color:#856404Reviews (1): Last reviewed commit: "fix(agentex-ui): bump sharp 0.34.3 -> 0...." | Re-trigger Greptile