Skip to content

fix(deps): patch sharp and qs vulnerabilities - #429

Merged
dytsou merged 2 commits into
mainfrom
fix/sharp-libheif
Sep 12, 2026
Merged

dytsou merged 2 commits into
mainfrom
fix/sharp-libheif

Conversation

@dytsou

@dytsou dytsou commented Sep 12, 2026 •

Copy link
Copy Markdown
Owner

Type of changes

  • Fix

Purpose

  • Patch the transitive sharp dependency used by Wrangler and Miniflare to remove the vulnerable libheif release.
  • Patch the transitive qs dependency used by Express and body-parser to remove the reported denial-of-service advisories.

Additional Information

  • The lockfile now resolves sharp@0.35.4 (libvips@1.3.3) and qs@6.16.0.
  • Validation passed: pnpm install --frozen-lockfile --ignore-scripts, pnpm test (35 files, 310 tests), pnpm lint, and git diff --check.
  • pnpm audit --json reports zero known vulnerabilities.

Post-Deploy Monitoring & Validation

No additional operational monitoring required. These changes update development and request-parsing dependencies; application runtime code is unchanged.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 12, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
github-readme-stats a444560 Commit Preview URL

Branch Preview URL
Sep 12 2026, 06:09 AM

@dytsou dytsou changed the title fix(deps): patch transitive sharp vulnerability fix(deps): patch sharp and qs vulnerabilities Sep 12, 2026
@sonarqubecloud

Copy link
Copy Markdown

@dytsou
dytsou merged commit 32a8e2a into main Sep 12, 2026
14 checks passed
@dytsou
dytsou deleted the fix/sharp-libheif branch September 12, 2026 06:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant