Skip to content

chore(deps): update dependency sharp to v0.32.6 [security]#1238

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/npm-sharp-vulnerability
Open

chore(deps): update dependency sharp to v0.32.6 [security]#1238
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/npm-sharp-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Nov 16, 2023

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
sharp (source, changelog) 0.32.00.32.6 age confidence

sharp vulnerability in libwebp dependency CVE-2023-4863

GHSA-54xq-cgqr-rpm3

More information

Details

Overview

sharp uses libwebp to decode WebP images and versions prior to the latest 0.32.6 are vulnerable to the high severity GHSA-j7hp-h8jx-5ppr.

Who does this affect?

Almost anyone processing untrusted input with versions of sharp prior to 0.32.6.

How to resolve this?
Using prebuilt binaries provided by sharp?

Most people rely on the prebuilt binaries provided by sharp.

Please upgrade sharp to the latest 0.32.6, which provides libwebp 1.3.2.

Using a globally-installed libvips?

Please ensure you are using the latest libwebp 1.3.2.

Possible workaround

Add the following to your code to prevent sharp from decoding WebP images.

sharp.block({ operation: ["VipsForeignLoadWebp"] });

Severity

  • CVSS Score: 7.8 / 10 (High)
  • Vector String: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

lovell/sharp (sharp)

v0.32.6

Compare Source

v0.32.5

Compare Source

v0.32.4

Compare Source

v0.32.3

Compare Source

v0.32.2

Compare Source

v0.32.1

Compare Source


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Nov 16, 2023

Copy link
Copy Markdown

Deploying daim with  Cloudflare Pages  Cloudflare Pages

Latest commit: 24f3a7a
Status: ✅  Deploy successful!
Preview URL: https://a6ef45d2.daim.pages.dev
Branch Preview URL: https://renovate-npm-sharp-vulnerabi.daim.pages.dev

View logs

@vercel

vercel Bot commented Nov 16, 2023

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
daim Error Error Mar 30, 2026 9:02pm

@renovate
renovate Bot force-pushed the renovate/npm-sharp-vulnerability branch from 26b056f to 8bf4033 Compare December 7, 2023 07:41
@renovate
renovate Bot force-pushed the renovate/npm-sharp-vulnerability branch from 8bf4033 to 70bc2b1 Compare December 7, 2023 11:13
@renovate
renovate Bot force-pushed the renovate/npm-sharp-vulnerability branch from 70bc2b1 to d05bf7e Compare December 7, 2023 13:39
@renovate
renovate Bot force-pushed the renovate/npm-sharp-vulnerability branch from d05bf7e to a8c1dc8 Compare December 9, 2023 05:21
@renovate
renovate Bot force-pushed the renovate/npm-sharp-vulnerability branch from a8c1dc8 to c9daee7 Compare December 11, 2023 07:40
@renovate
renovate Bot force-pushed the renovate/npm-sharp-vulnerability branch from c9daee7 to 6402870 Compare December 13, 2023 03:50
@renovate
renovate Bot force-pushed the renovate/npm-sharp-vulnerability branch from 6402870 to 29a0d05 Compare January 16, 2024 00:52
@renovate
renovate Bot force-pushed the renovate/npm-sharp-vulnerability branch from 29a0d05 to 162d330 Compare January 23, 2024 00:15
@renovate
renovate Bot force-pushed the renovate/npm-sharp-vulnerability branch from 162d330 to f810013 Compare January 23, 2024 01:00
@renovate
renovate Bot force-pushed the renovate/npm-sharp-vulnerability branch from f810013 to ea41a64 Compare January 23, 2024 05:06
@renovate
renovate Bot force-pushed the renovate/npm-sharp-vulnerability branch from ea41a64 to 7274c79 Compare January 25, 2024 01:24
@renovate renovate Bot changed the title chore(deps): update dependency sharp to v0.32.6 [security] chore(deps): update dependency sharp to v0.32.6 [security] - autoclosed Feb 24, 2024
@renovate renovate Bot closed this Feb 24, 2024
@renovate
renovate Bot deleted the renovate/npm-sharp-vulnerability branch February 24, 2024 01:42
@renovate
renovate Bot restored the renovate/npm-sharp-vulnerability branch February 24, 2024 05:32
@renovate renovate Bot changed the title chore(deps): update dependency sharp to v0.32.6 [security] - autoclosed chore(deps): update dependency sharp to v0.32.6 [security] Feb 24, 2024
@renovate renovate Bot reopened this Feb 24, 2024
@renovate
renovate Bot force-pushed the renovate/npm-sharp-vulnerability branch from 7274c79 to 1e79bf4 Compare February 24, 2024 05:34
@renovate
renovate Bot force-pushed the renovate/npm-sharp-vulnerability branch from 1e79bf4 to 7e26aaf Compare March 28, 2024 04:53
@renovate
renovate Bot force-pushed the renovate/npm-sharp-vulnerability branch from 7e26aaf to 638da3b Compare November 18, 2025 13:08
@renovate
renovate Bot force-pushed the renovate/npm-sharp-vulnerability branch from 638da3b to f5e07e7 Compare December 3, 2025 14:39
@renovate renovate Bot changed the title chore(deps): update dependency sharp to v0.32.6 [security] chore(deps): update dependency sharp to v0.32.6 [security] - autoclosed Mar 27, 2026
@renovate renovate Bot closed this Mar 27, 2026
@renovate
renovate Bot deleted the renovate/npm-sharp-vulnerability branch March 27, 2026 01:17
@renovate renovate Bot changed the title chore(deps): update dependency sharp to v0.32.6 [security] - autoclosed chore(deps): update dependency sharp to v0.32.6 [security] Mar 30, 2026
@renovate renovate Bot reopened this Mar 30, 2026
@renovate
renovate Bot force-pushed the renovate/npm-sharp-vulnerability branch 2 times, most recently from f5e07e7 to 24f3a7a Compare March 30, 2026 20:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants