Skip to content

chore(deps): bump sharp and wrangler in /cloudflare-og-worker - #2424

Merged
JSv4 merged 1 commit into
mainfrom
dependabot/npm_and_yarn/cloudflare-og-worker/multi-52d952c776
Oct 9, 2026
Merged

JSv4 merged 1 commit into
mainfrom
dependabot/npm_and_yarn/cloudflare-og-worker/multi-52d952c776

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor

Bumps sharp to 0.35.5 and updates ancestor dependency wrangler. These dependencies need to be updated together.

Updates sharp from 0.35.2 to 0.35.5

Release notes

Sourced from sharp's releases.

v0.35.5

https://github.com/lovell/sharp-libvips/releases/tag/v1.3.4

  • Add upper bounds check on length of linear and GIF delay arrays.

  • Improve error handing when WebAssembly fallback also fails. #4593 @​lazerg

  • TypeScript: Allow multi-frame options for JXL output. #4602 @​ramin-010

  • TypeScript: Remove non-existent named export. #4604

  • Increase accepted dimensions when extending an image. #4605

  • Improve gain map support for extract and rotate operations. #4606

  • Tests: Ensure composite tests pass on big endian platforms. #4609

v0.35.5-rc.1

https://github.com/lovell/sharp-libvips/releases/tag/v1.3.4-rc.1

  • Add upper bounds check on length of linear and GIF delay arrays.

  • Improve error handing when WebAssembly fallback also fails. #4593 @​lazerg

  • TypeScript: Allow multi-frame options for JXL output. #4602 @​ramin-010

  • TypeScript: Remove non-existent named export. #4604

  • Increase accepted dimensions when extending an image. #4605

  • Improve gain map support for extract operation. #4606

... (truncated)

Commits
  • 51a990f Release v0.35.5
  • 96de105 Upgrade to sharp-libvips v1.3.4
  • 3a61390 CI: Configure Dependabot with all package.json locations
  • 4940c50 Improve gain map support for rotate/flip/flop ops
  • 20654aa Prerelease v0.35.5-rc.1
  • ef4f934 CI: Upgrade to Ubuntu 26.04
  • 358df95 Upgrade to libvips v8.18.7
  • 49f4903 Improve gain map support for rotate-then-extract #4606
  • 0e2e55e Silence a couple of compiler/static analysis warnings
  • cef3b8c Improve gain map support for extract operation #4606
  • Additional commits viewable in compare view

Updates wrangler from 4.114.0 to 4.149.0

Release notes

Sourced from wrangler's releases.

wrangler@4.149.0

Minor Changes

  • #16036 9a58244 Thanks @​edevil! - Support temporary event accounts in R2 and Containers commands

    wrangler r2 and wrangler containers commands now accept the hidden --temporary flag, so accounts created for an event can manage buckets, objects and containers directly. Every command that supports --temporary now also accepts a hidden --event-code flag, so the first command a participant runs can create the event account:

    wrangler r2 bucket create my-bucket --temporary --event-code <code>

    R2 and Containers are only available on event accounts. R2 custom domains, Sippy, external container registries and wrangler cloudchamber commands still require a logged-in account.

Patch Changes

  • #16139 2d1d563 Thanks @​cpojer! - Update esbuild to 0.28.2

    Align esbuild dependency with tooling using the latest 0.28 patch so package managers can share one installation instead of downloading a second native binary.

  • #15632 85b14e7 Thanks @​petebacondarwin! - Honor Retry-After directives during static asset uploads

    Static asset uploads now pause retries and pending uploads until the latest outstanding deadline requested by the API. A per-request limiter also keeps gateway retries at the reduced concurrency after the pause ends, preventing a deployment from immediately overloading a constrained asset service again.

  • #16098 fe607f9 Thanks @​dependabot! - Update dependencies of "miniflare", "wrangler"

    The following dependency versions have been updated:

    Dependency From To
    sharp 0.35.4 0.35.5
  • #16093 ad7ff45 Thanks @​DiogoSantoss! - Document that addresses catch-all entries must use the zone apex

    A *@domain entry in addresses must use the zone apex, such as *@example.com. The zone catch-all also receives mail for every subdomain in the zone that has no literal rule.

  • #16102 757faa6 Thanks @​tlq5l! - Keep Preview secrets when deploying to an existing Preview

    Secrets added to a Preview with wrangler preview secret put or wrangler preview secret bulk were lost the next time wrangler preview ran, because each new deployment was created from the Wrangler config, --var and --secrets-file values only.

    wrangler preview now carries over the secrets of the Preview's latest deployment. A value passed in this deployment (--secrets-file, --var or a previews binding with the same name) still replaces the existing secret, and wrangler preview secret delete removes one.

  • #15617 93c1069 Thanks @​jpatel3! - Stop the update check from recommending deprecated versions

    Previously, the "update available" notice shown by wrangler and @cloudflare/vite-plugin always pointed at whichever version was tagged latest on npm, even after that version had been deprecated for shipping a bug. Deprecated versions are now never recommended: if the latest release has been deprecated, the newest non-deprecated stable release below it is suggested instead, or nothing at all if you are already on it.

    The check now reads the npm registry directly instead of going through the update-check package, which discarded the deprecation information. The on-disk cache location and one-hour refresh interval are unchanged.

  • #16003 6947df3 Thanks @​oddharsh! - Ship using and await using declarations to the runtime as written, for smaller Worker bundles

    Workers and Pages Functions that use explicit resource management no longer carry about 1 KB of bundled helper code to emulate it. workerd supports using and await using natively at every compatibility date, so wrangler deploy, wrangler versions upload and Pages Functions builds now leave these declarations untouched.

  • #15958 82acf3c Thanks @​breken-ai! - Apply each action's own condition in wrangler r2 bucket lifecycle add

... (truncated)

Commits
  • 84c4e95 Version Packages (#16099)
  • 82acf3c [wrangler] Apply each action's own condition in r2 bucket lifecycle add (#1...
  • 757faa6 [wrangler] Keep Preview secrets when deploying to an existing Preview (#16102)
  • 85b14e7 [deploy-helpers] respect Retry-After during asset uploads (#15632)
  • 6947df3 [wrangler][vite-plugin] Preserve using declarations when bundling (#16003)
  • 9a58244 [wrangler] Support temporary event accounts in R2 and Containers commands (#1...
  • 540f084 Version Packages (#16034)
  • 42c7219 [wrangler] Fix r2 object put and r2 bulk put storing a different key in local...
  • 2dde890 [wrangler] Clarify secret version errors and support versions bulk deletions ...
  • b4e1299 [wrangler] Add --source-namespace and --source-repo-name for artifacts.repo q...
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [sharp](https://github.com/lovell/sharp) to 0.35.5 and updates ancestor dependency [wrangler](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/wrangler). These dependencies need to be updated together.


Updates `sharp` from 0.35.2 to 0.35.5
- [Release notes](https://github.com/lovell/sharp/releases)
- [Commits](lovell/sharp@v0.35.2...v0.35.5)

Updates `wrangler` from 4.114.0 to 4.149.0
- [Release notes](https://github.com/cloudflare/workers-sdk/releases)
- [Commits](https://github.com/cloudflare/workers-sdk/commits/wrangler@4.149.0/packages/wrangler)

---
updated-dependencies:
- dependency-name: sharp
  dependency-version: 0.35.5
  dependency-type: indirect
- dependency-name: wrangler
  dependency-version: 4.149.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 9, 2026
@claude

claude Bot commented Oct 9, 2026

Copy link
Copy Markdown

Review: Dependabot bump (wrangler ^4.114.0 → ^4.149.0, sharp 0.35.2 → 0.35.5)

The change is confined to cloudflare-og-worker/package.json and its lockfile. It doesn't touch application code, the backend or the frontend app.

  • Code quality: The lockfile changes match the manifest change. The new @emnapi/runtime entry is optional and dev-only. It is the usual WASM fallback pulled in by sharp. The workerd binaries move from 1.20260722.1 to 1.20261006.1, which fits the wrangler bump.
  • Bugs: None found by reading the diff. I did not run it. The sharp release notes list only a bounds check, error-handling and TypeScript fixes. wrangler is a minor-range bump inside 4.x.
  • Performance: Nothing notable.
  • Security: The bump adds input bounds checks in sharp and picks up newer workerd builds. The lockfile resolved URLs all point at registry.npmjs.org, and each version change comes with a changed integrity hash.
  • Tests: The repo has no test for the worker. Before merging, run npx wrangler deploy --dry-run in cloudflare-og-worker, or wrangler dev, and check that OG image generation still works.
  • Changelog: This is a routine dependency update, so a changelog.d/ fragment seems unnecessary.

Looks good to merge once CI is green.

@JSv4
JSv4 merged commit f684e45 into main Oct 9, 2026
7 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/cloudflare-og-worker/multi-52d952c776 branch October 9, 2026 13:58
@github-actions github-actions Bot locked and limited conversation to collaborators Oct 9, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant