Skip to content

fix(dev-1696): bump sharp to 0.35.4 - #62

Open
spur-vuln-author[bot] wants to merge 1 commit into
mainfrom
fix/dev-1696
Open

spur-vuln-author[bot] wants to merge 1 commit into
mainfrom
fix/dev-1696

Conversation

@spur-vuln-author

Copy link
Copy Markdown

Context

Batched group (ticket_group_key tg:sharp:pnpm-lock.yaml, 2 advisories) against sharp, all in pnpm-lock.yaml:

Transitive dependency (not declared in any package.json), resolved via pnpm-lock.yaml. No Dependabot PR exists for either advisory, so this PR was constructed directly from the highest first_patched_version across the group (0.35.4).

Test evidence

No Dependabot PR existed; constructed from first_patched_version 0.35.4 (highest across the batch). Added a pnpm.overrides entry and regenerated the lockfile with pnpm install --lockfile-only. Confirmed via lockfile inspection that sharp now resolves to 0.35.5 (previously 0.34.1), satisfying >= 0.35.4 for both advisories. Companion-file scan (Dockerfiles, .nvmrc, go.mod, CI workflow YAML, etc. hardcoding 0.34.1) found no hits.

Risk

Low. Lockfile-only transitive dependency bump, resolves both batched advisories at once. Group max severity high; Tier 1 / 90-day SLA.


@spur-vuln-author spur-vuln-author Bot added the spur-vuln Security vulnerability remediation PR label Sep 30, 2026
@spur-vuln-reviewer

Copy link
Copy Markdown

Escalating: Gate 3 (diff equivalence) mechanically FAILed. gate3-check.sh: GATE3 FAIL target=sharp manifest=pnpm-lock.yaml pr_version=? required=0.35.4 alerts=87,119 extra_files=1 state=open. Detail: the helper has no extraction rule for ecosystem=npm manifest basename=pnpm-lock.yaml, so it could not extract the new sharp version from the diff, and flagged package.json as a file outside {manifest, lockfile} (which is actually the expected direct-dependency file for an npm/pnpm version bump). This looks like a tooling gap in gate3-check.sh (no pnpm-lock.yaml parser) rather than a real diff deviation, but per the review contract a mechanical Gate 3 FAIL is never re-derived or second-guessed by the reviewer. Required version per max open Dependabot alert(s) 87,119: 0.35.4. Not merged. A human must review this. This reviewer will not act on this PR again. [[spur-vuln-reviewer: escalated diff-mismatch-constructed]]

@spur-vuln-reviewer spur-vuln-reviewer Bot added the hitl Needs human review — automated vuln remediation escalated this label Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

hitl Needs human review — automated vuln remediation escalated this spur-vuln Security vulnerability remediation PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants