Repository navigation
fix(computer-use): patch image renderer and audit locked dependencies - #12
Merged
Merged
Conversation
Upgrade sharp 0.35.4 to 0.35.5 with librsvg 2.63.2 for GHSA-wq5f-xc86-pv6w. Audit the full committed dependency lock on all three existing OS lanes, including build dependencies. Validation: clean npm ci; npm audit 0 vulnerabilities; npm test 438 passed, 0 failed, 18 platform-specific skipped; receipt check clean; native SVG render and PNG resize 24x16 passed. Hosted three-OS and signed packaging are separate gates.
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
No blocking issues remain, and the required Linux, macOS, and Windows verification checks have now passed.
Review effort: Balanced
Findings: None
What changed in this PR
Updates the computer-use branding renderer’s dependency to address the reported vulnerability and adds dependency auditing to cross-platform verification.
Changes:
- Pins sharp to 0.35.5 and refreshes its locked platform dependencies.
- Adds
npm audit --audit-level=lowto Linux, macOS, and Windows verification.
| File | Description |
|---|---|
| package.json | Updates the sharp version pin. |
| package-lock.json | Refreshes sharp dependencies and synchronizes executable metadata. |
| .github/workflows/verify.yml | Adds a dependency audit step. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The computer-use branding renderer pinned sharp 0.35.4, affected by GHSA-wq5f-xc86-pv6w. Upgrade to 0.35.5 (librsvg 2.63.2) and add a full locked dependency audit to the existing Linux/macOS/Windows verification lanes.
Local validation: clean npm ci; dependency audit 0 vulnerabilities; tests 438 passed, 0 failed, 18 platform-specific skipped; receipt check clean; native SVG render/resize to a 24x16 PNG passed. Three-OS verification must pass before merge. No app publication or signing is performed.