Repository navigation
chore(deps): bump sharp, @astrojs/node and astro in /tests/resources/sites/astro - #14248
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [sharp](https://github.com/lovell/sharp) to 0.35.5 and updates ancestor dependencies [sharp](https://github.com/lovell/sharp), [@astrojs/node](https://github.com/withastro/astro/tree/HEAD/packages/integrations/node) and [astro](https://github.com/withastro/astro/tree/HEAD/packages/astro). These dependencies need to be updated together. Updates `sharp` from 0.34.5 to 0.35.5 - [Release notes](https://github.com/lovell/sharp/releases) - [Commits](lovell/sharp@v0.34.5...v0.35.5) Updates `@astrojs/node` from 10.1.3 to 11.1.7 - [Release notes](https://github.com/withastro/astro/releases) - [Changelog](https://github.com/withastro/astro/blob/main/packages/integrations/node/CHANGELOG.md) - [Commits](https://github.com/withastro/astro/commits/@astrojs/node@11.1.7/packages/integrations/node) Updates `astro` from 6.4.4 to 7.3.7 - [Release notes](https://github.com/withastro/astro/releases) - [Changelog](https://github.com/withastro/astro/blob/main/packages/astro/CHANGELOG-v6.md) - [Commits](https://github.com/withastro/astro/commits/astro@7.3.7/packages/astro) --- updated-dependencies: - dependency-name: sharp dependency-version: 0.35.5 dependency-type: indirect - dependency-name: "@astrojs/node" dependency-version: 11.1.7 dependency-type: direct:production - dependency-name: astro dependency-version: 7.3.7 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
|
Review complete. No issues found — approved ✅. This PR updates only the
No other files changed; the sibling Astro fixtures ( Reviewed commit: 4cf9fd0 |
🟢 Tier S · Ready to merge
Updates the Astro site test fixture to Astro 7.3.7 and the matching Node adapter 11.1.7. Its lockfile resolves sharp 0.35.5 and the updated transitive dependencies.
Note @dependabot[bot] does not have write access to this repository, so Hansi does not approve automatically. A maintainer can review and approve. 📂 Walkthrough · 2
Reviewed |
Security rulesNo new WARNING or ERROR findings from security rules. 32 existing findings tracked in
|
✨ Benchmark resultsComparing
Per-scenario breakdown & investigation detailsMetrics below reflect the current branch (after). Δ P95 compares against the base.
Top API waits (after)
|
Bumps sharp to 0.35.5 and updates ancestor dependencies sharp, @astrojs/node and astro. These dependencies need to be updated together.
Updates
sharpfrom 0.34.5 to 0.35.5Release notes
Sourced from sharp's releases.
... (truncated)
Commits
51a990fRelease v0.35.596de105Upgrade to sharp-libvips v1.3.43a61390CI: Configure Dependabot with all package.json locations4940c50Improve gain map support for rotate/flip/flop ops20654aaPrerelease v0.35.5-rc.1ef4f934CI: Upgrade to Ubuntu 26.04358df95Upgrade to libvips v8.18.749f4903Improve gain map support for rotate-then-extract #46060e2e55eSilence a couple of compiler/static analysis warningscef3b8cImprove gain map support for extract operation #4606Updates
@astrojs/nodefrom 10.1.3 to 11.1.7Release notes
Sourced from @astrojs/node's releases.
Changelog
Sourced from @astrojs/node's changelog.
... (truncated)
Commits
e4f8f46[ci] release (#18120)1d9e910Merge commit from forkaef4652Update@astrojs/node(#18080)b98bd2cUpdate@astrojs/node(#17988)8a3106e[ci] release (#17939)0037c1aStop aborted request bodies from logging duplicate unhandled rejections in@a...d5b3ffaUpdate dependency@fastify/staticto v10 [SECURITY] (#17513)01395b8Fix trailing-slash redirect truncating query strings that contain a second `?...2fdf731[ci] release (#17849)d4894e1Update@astrojs/node(#17805)Updates
astrofrom 6.4.4 to 7.3.7Release notes
Sourced from astro's releases.
... (truncated)
Changelog
Sourced from astro's changelog.
... (truncated)
Commits
25c19fa[ci] release (#18272)38f6793fix(astro): approve workerd builds inastro add cloudflarefor pnpm v11+ an...547b572Restore content-type gate in security.checkOrigin so JSON requests are not bl...fcf6ed6fix(assets): return requested format from Sharp transform (#18222)bec7d18Ignorelayoutfrontmatter in Markdown content collection entries with `defe...71b154fRegister cache provider before handleCache runs in composable cache() handler...05225actest(content): cover Markdown content entry query in propagated asset wrappercba76ccIgnorelayoutfrontmatter for deferred Markdown content collection entriese4f8f46[ci] release (#18120)95d5d16Fix emptyDir EPERM fallback to use rmSync instead of rmdirSync for Node 25+ c...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.