Bump sharp and next - #9
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [sharp](https://github.com/lovell/sharp) to 0.35.4 and updates ancestor dependency [next](https://github.com/vercel/next.js). These dependencies need to be updated together. Updates `sharp` from 0.34.5 to 0.35.4 - [Release notes](https://github.com/lovell/sharp/releases) - [Commits](lovell/sharp@v0.34.5...v0.35.4) Updates `next` from 16.2.7 to 16.3.5 - [Release notes](https://github.com/vercel/next.js/releases) - [Commits](vercel/next.js@v16.2.7...v16.3.5) --- updated-dependencies: - dependency-name: sharp dependency-version: 0.35.4 dependency-type: indirect - dependency-name: next dependency-version: 16.3.5 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Superseded by Next.js 16.3.5 on main, which also clears the sharp advisory. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps sharp to 0.35.4 and updates ancestor dependency next. These dependencies need to be updated together.
Updates
sharpfrom 0.34.5 to 0.35.4Release notes
Sourced from sharp's releases.
... (truncated)
Commits
7f1a0a2Release v0.35.4f927818Upgrade to sharp-libvips v1.3.3e802092Prerelease v0.35.4-rc.0e13eb2fCI: Fix wasm32 build (#4589)a82a0b3Upgrade to libvips v8.18.68044fe4Bound resize dimensions to coordinate limit147f859Docs: changelog entries for #4578 #4584ee5bfb8Tests: use yauzl directly rather than via extract-zip wrapper7a77889Bump uraimo/run-on-arch-action from 3.1.0 to 3.2.0 (#4588)ea5bef2Improve support for input Streams finishing before output is requested (#4584)Updates
nextfrom 16.2.7 to 16.3.5Release notes
Sourced from next's releases.
... (truncated)
Commits
ca2c75ev16.3.514fb290[backport] Fix use cache prerender signal retention (#98448)2b1f28d[16.3.x] Add CSP nonce to script tags of loading and template files (#98403)4b56cee[16.3.x] Backport docs fixes (#98317)5568a02[backport] docs: local development: Rewrite docker section, add Windows Dev D...93249ab[16.3.X] Emit whole-app server NFTs whenoutput: 'standalone'is used with ...6549fd7[16.3.x] next/image: reject empty image on read/write to disk cache (#98186)d9eac96[16.3.x] next/image: skip 0-byte entries when initializing disk LRU cache (#9...84b35fe[test] Fix 16.3 deploy test assertions (#98133)14f9c1a[16.3.x][ci] Run flake detection and new deploy tests when merged and on back...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.