Skip to content

build(deps): patch sharp and mysql2 vulnerabilities - #98

Merged
Ryson-32 merged 8 commits into
mainfrom
ryan/dependency-security-updates
Sep 24, 2026
Merged

Ryson-32 merged 8 commits into
mainfrom
ryan/dependency-security-updates

Conversation

@Ryson-32

@Ryson-32 Ryson-32 commented Sep 24, 2026 •

Copy link
Copy Markdown
Member

Updates sharp to 0.35.4 and overrides Prisma's pinned mysql2 dependency with 3.23.1, fixing the three remaining dependency security alerts. Also retains baseline-browser-mapping 2.11.22 from the earlier Dependabot update.

Validation: clean npm ci, npm audit (0 vulnerabilities), lint, coverage (1,665 tests; all four metrics at least 97%), application type checking and production build, and an AVIF encode/decode smoke test on Windows. Linux/ARM container runtime validation has not been performed.

No application version change.

dependabot Bot and others added 7 commits September 11, 2026 00:56
Bumps [baseline-browser-mapping](https://github.com/web-platform-dx/baseline-browser-mapping) from 2.10.33 to 2.11.22.
- [Release notes](https://github.com/web-platform-dx/baseline-browser-mapping/releases)
- [Commits](web-platform-dx/baseline-browser-mapping@v2.10.33...v2.11.22)

---
updated-dependencies:
- dependency-name: baseline-browser-mapping
  dependency-version: 2.11.22
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
…list-4.28.9' into ryan/dependency-security-updates
….1.11' into ryan/dependency-security-updates
…4.3.2' into ryan/dependency-security-updates
Copilot AI lite review requested due to automatic review settings September 24, 2026 06:14
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-24T06:18:35.572796Z e338cc1 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Align eslint-config-next with Next.js 16.3.4 and regenerate the lockfile.

Review effort: Lite
Findings: None

What changed in this PR

Updates security-sensitive dependencies to patched versions and refreshes the workspace lockfile.

Changes:

  • Upgrades Next.js, js-yaml, Vitest, sharp, and mysql2.
  • Refreshes native and transitive dependencies.
  • Updates workspace manifests and lockfile resolutions.
File Summary
packages/​ui/​package.json Upgrades Next.js.
packages/​core/​package.json Upgrades js-yaml.
package.json Updates dependencies and overrides; eslint-config-next remains outdated.
package-lock.json Records patched dependency resolutions but retains the older ESLint Next configuration.
local/​package.json Updates Next.js, but its ESLint configuration remains on 16.2.12.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@Ryson-32 Ryson-32 changed the title build(deps): complete security dependency updates build(deps): patch sharp and mysql2 vulnerabilities Sep 24, 2026
@Ryson-32
Ryson-32 merged commit 9372e01 into main Sep 24, 2026
5 checks passed
@Ryson-32
Ryson-32 deleted the ryan/dependency-security-updates branch September 24, 2026 06:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants