Skip to content

fix(computer-use): patch image renderer and audit locked dependencies - #12

Merged
Hmbown merged 1 commit into
mainfrom
fix/win32-native-fixture-origin
Oct 7, 2026
Merged

Hmbown merged 1 commit into
mainfrom
fix/win32-native-fixture-origin

Conversation

@Hmbown

@Hmbown Hmbown commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

The computer-use branding renderer pinned sharp 0.35.4, affected by GHSA-wq5f-xc86-pv6w. Upgrade to 0.35.5 (librsvg 2.63.2) and add a full locked dependency audit to the existing Linux/macOS/Windows verification lanes.

Local validation: clean npm ci; dependency audit 0 vulnerabilities; tests 438 passed, 0 failed, 18 platform-specific skipped; receipt check clean; native SVG render/resize to a 24x16 PNG passed. Three-OS verification must pass before merge. No app publication or signing is performed.


Devin Review

Upgrade sharp 0.35.4 to 0.35.5 with librsvg 2.63.2 for GHSA-wq5f-xc86-pv6w. Audit the full committed dependency lock on all three existing OS lanes, including build dependencies.

Validation: clean npm ci; npm audit 0 vulnerabilities; npm test 438 passed, 0 failed, 18 platform-specific skipped; receipt check clean; native SVG render and PNG resize 24x16 passed. Hosted three-OS and signed packaging are separate gates.
Copilot AI balanced review requested due to automatic review settings October 7, 2026 00:25

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Devin Review: No Issues Found

Devin Review analyzed this PR and found no bugs or issues to report.

Devin Review

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No blocking issues remain, and the required Linux, macOS, and Windows verification checks have now passed.

Review effort: Balanced
Findings: None

What changed in this PR

Updates the computer-use branding renderer’s dependency to address the reported vulnerability and adds dependency auditing to cross-platform verification.

Changes:

  • Pins sharp to 0.35.5 and refreshes its locked platform dependencies.
  • Adds npm audit --audit-level=low to Linux, macOS, and Windows verification.
File Description
package.json Updates the sharp version pin.
package-lock.json Refreshes sharp dependencies and synchronizes executable metadata.
.github/​workflows/​verify.yml Adds a dependency audit step.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@Hmbown
Hmbown merged commit f585fbd into main Oct 7, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants