Skip to content

chore(deps): bump sharp, @astrojs/cloudflare and astro - #97

Closed
dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/npm_and_yarn/multi-d7962404c7
Closed

dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/npm_and_yarn/multi-d7962404c7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps sharp to 0.35.5 and updates ancestor dependencies sharp, @astrojs/cloudflare and astro. These dependencies need to be updated together.

Updates sharp from 0.34.5 to 0.35.5

Release notes

Sourced from sharp's releases.

v0.35.5

https://github.com/lovell/sharp-libvips/releases/tag/v1.3.4

  • Add upper bounds check on length of linear and GIF delay arrays.

  • Improve error handing when WebAssembly fallback also fails. #4593 @​lazerg

  • TypeScript: Allow multi-frame options for JXL output. #4602 @​ramin-010

  • TypeScript: Remove non-existent named export. #4604

  • Increase accepted dimensions when extending an image. #4605

  • Improve gain map support for extract and rotate operations. #4606

  • Tests: Ensure composite tests pass on big endian platforms. #4609

v0.35.5-rc.1

https://github.com/lovell/sharp-libvips/releases/tag/v1.3.4-rc.1

  • Add upper bounds check on length of linear and GIF delay arrays.

  • Improve error handing when WebAssembly fallback also fails. #4593 @​lazerg

  • TypeScript: Allow multi-frame options for JXL output. #4602 @​ramin-010

  • TypeScript: Remove non-existent named export. #4604

  • Increase accepted dimensions when extending an image. #4605

  • Improve gain map support for extract operation. #4606

... (truncated)

Commits
  • 51a990f Release v0.35.5
  • 96de105 Upgrade to sharp-libvips v1.3.4
  • 3a61390 CI: Configure Dependabot with all package.json locations
  • 4940c50 Improve gain map support for rotate/flip/flop ops
  • 20654aa Prerelease v0.35.5-rc.1
  • ef4f934 CI: Upgrade to Ubuntu 26.04
  • 358df95 Upgrade to libvips v8.18.7
  • 49f4903 Improve gain map support for rotate-then-extract #4606
  • 0e2e55e Silence a couple of compiler/static analysis warnings
  • cef3b8c Improve gain map support for extract operation #4606
  • Additional commits viewable in compare view

Updates @astrojs/cloudflare from 12.6.13 to 14.3.3

Release notes

Sourced from @​astrojs/cloudflare's releases.

@​astrojs/cloudflare@​14.3.3

Patch Changes

  • #18059 30cb32e Thanks @​Princesseuh! - Fixes image transforms without a specified quality outputting an higher quality than expected on certain formats

  • #18091 28d59a9 Thanks @​astro-factory! - Fixes optimizeDeps.include glob astro/runtime/** matching .d.ts files, which caused 83 unnecessary optimizer entries and empty output chunks per environment during dev

  • #18032 f7dbc6a Thanks @​adamchal! - Fixes image requests when using imageService: 'compile' with passthroughImageService().

  • Updated dependencies []:

    • @​astrojs/underscore-redirects@​1.0.4

@​astrojs/cloudflare@​14.3.2

Patch Changes

  • #17958 b95c574 Thanks @​astro-factory! - Fixes a build failure when the wrangler config uses the exports field to declare Durable Object classes

  • #18022 24946f7 Thanks @​matthewp! - Fixes cold astro dev crashes when using the passthrough image service

  • #17842 d68db73 Thanks @​adamchal! - Fixes broken images on static sites by transforming prerendered images at build time with the default Cloudflare Images binding

  • #17945 750b4db Thanks @​matthewp! - Pre-bundles renderer server entrypoints and the default console logger during dev so they are included in the initial optimization pass, preventing a mid-request re-optimization that could crash the dev server on Cloudflare (workerd).

  • Updated dependencies []:

    • @​astrojs/underscore-redirects@​1.0.4

@​astrojs/cloudflare@​14.3.1

Patch Changes

  • #17914 a400504 Thanks @​astro-factory! - Fixes a build crash when a custom worker entrypoint exports Durable Object classes alongside prerendered pages. The prerender worker no longer inherits durable_objects, migrations, or workflows from the entry worker config.

  • Updated dependencies []:

    • @​astrojs/underscore-redirects@​1.0.4

@​astrojs/cloudflare@​14.3.0

Minor Changes

  • #17795 15e2deb Thanks @​matthewp! - Adds concurrent rendering support for experimental.incrementalBuild, including when using @astrojs/cloudflare

    Incremental builds no longer disable caching when build.concurrency is greater than 1. Projects that set build.concurrency: 1 to keep the cache enabled can remove that workaround. Cloudflare builds also reduce serialization overhead for large prerendered pages.

  • #17887 35aa62e Thanks @​matthewp! - Adds a Cloudflare finalize() response handler for custom request handlers

    Call finalize() to apply cookies and Cloudflare CDN cache defaults to the response from an astro/fetch pipeline:

    import { astro, FetchState } from 'astro/fetch';
    import { cf, finalize } from '@astrojs/cloudflare/fetch';
    export default {
    async fetch(request: Request, env: Env, context: ExecutionContext) {
    const state = new FetchState(request);

... (truncated)

Changelog

Sourced from @​astrojs/cloudflare's changelog.

14.3.3

Patch Changes

  • #18059 30cb32e Thanks @​Princesseuh! - Fixes image transforms without a specified quality outputting an higher quality than expected on certain formats

  • #18091 28d59a9 Thanks @​astro-factory! - Fixes optimizeDeps.include glob astro/runtime/** matching .d.ts files, which caused 83 unnecessary optimizer entries and empty output chunks per environment during dev

  • #18032 f7dbc6a Thanks @​adamchal! - Fixes image requests when using imageService: 'compile' with passthroughImageService().

  • Updated dependencies []:

    • @​astrojs/underscore-redirects@​1.0.4

14.3.2

Patch Changes

  • #17958 b95c574 Thanks @​astro-factory! - Fixes a build failure when the wrangler config uses the exports field to declare Durable Object classes

  • #18022 24946f7 Thanks @​matthewp! - Fixes cold astro dev crashes when using the passthrough image service

  • #17842 d68db73 Thanks @​adamchal! - Fixes broken images on static sites by transforming prerendered images at build time with the default Cloudflare Images binding

  • #17945 750b4db Thanks @​matthewp! - Pre-bundles renderer server entrypoints and the default console logger during dev so they are included in the initial optimization pass, preventing a mid-request re-optimization that could crash the dev server on Cloudflare (workerd).

  • Updated dependencies []:

    • @​astrojs/underscore-redirects@​1.0.4

14.3.1

Patch Changes

  • #17914 a400504 Thanks @​astro-factory! - Fixes a build crash when a custom worker entrypoint exports Durable Object classes alongside prerendered pages. The prerender worker no longer inherits durable_objects, migrations, or workflows from the entry worker config.

  • Updated dependencies []:

    • @​astrojs/underscore-redirects@​1.0.4

14.3.0

Minor Changes

  • #17795 15e2deb Thanks @​matthewp! - Adds concurrent rendering support for experimental.incrementalBuild, including when using @astrojs/cloudflare

    Incremental builds no longer disable caching when build.concurrency is greater than 1. Projects that set build.concurrency: 1 to keep the cache enabled can remove that workaround. Cloudflare builds also reduce serialization overhead for large prerendered pages.

  • #17887 35aa62e Thanks @​matthewp! - Adds a Cloudflare finalize() response handler for custom request handlers

    Call finalize() to apply cookies and Cloudflare CDN cache defaults to the response from an astro/fetch pipeline:

    import { astro, FetchState } from 'astro/fetch';
    import { cf, finalize } from '@astrojs/cloudflare/fetch';

... (truncated)

Commits
  • 790c6f7 [ci] release (#18035)
  • 00393ff Update dependency vitest [SECURITY] (#18026)
  • 28d59a9 fix(cloudflare): restrict optimizeDeps glob to .js files to exclude .d.ts (#1...
  • 40378cc [ci] format
  • 30cb32e fix(cloudflare): set default image transformation quality (#18059)
  • 1e66b14 Update dependency svelte to v5.55.7 [SECURITY] (#18021)
  • 24f63d3 Update dependency hono to v4.13.5 [SECURITY] (#18020)
  • 2245837 fix(astro): stop the head-metadata plugin invalidating its own virtual module...
  • f7dbc6a fix(cloudflare): respect passthrough image service in compile mode (#18032)
  • 8a3106e [ci] release (#17939)
  • Additional commits viewable in compare view

Updates astro from 5.18.0 to 7.3.5

Release notes

Sourced from astro's releases.

astro@7.3.5

Patch Changes

  • #17736 2b8b2e8 Thanks @​ematipico! - Adds a new container function called renderComponent(), which renders Astro components with inlined styles and scripts.

    Users must import the component with the new ?container query string:

    import { experimental_AstroContainer } from "astro/container";
    import TodoList from "../components/TodoList.astro?container";
    const container = await experimental_AstroContainer.create();
    const _string = container.renderComponent(TodoList);

astro@7.3.4

Patch Changes

  • #18063 40896ac Thanks @​adamchal! - Fixes incremental builds repeatedly rendering unchanged pages when modules or compiled CSS reference bundled assets.

  • #18053 cf5d72f Thanks @​Princesseuh! - Improves the astro check error shown for TypeScript 7. The command now explains that TypeScript 7 is not currently supported and provides instructions for experimentally type-checking Astro files with TypeScript 7.1 and @astrojs/ts-content-mapper.

  • #18086 795a7e4 Thanks @​ump45nose! - Fix double-escaped ampersands in Markdown image alt and title attributes. The __ASTRO_IMAGE_ round-trip now decodes the numeric (&) and named (&) character references the Markdown processors emit, so an & in an alt or title is escaped exactly once in the final HTML instead of twice.

  • #18074 0429805 Thanks @​SurefireStudios! - Fix three error names that did not match their documented reference. MissingLocale, MissingIndexForInternationalization and NoManifestAvailable reported names ending in Error in the dev overlay, while their error reference pages are published under the unsuffixed names, so the name shown to users could not be found in the docs.

  • #18007 2245837 Thanks @​L4XB! - Fixes the dev server re-evaluating the whole server module graph on every request. The astro:head-metadata plugin invalidated its component metadata virtual module from its own transform hook, so each evaluation of that module scheduled the next one. Adapters that run requests outside Vite's module runner, such as @astrojs/cloudflare, paid for a full re-evaluation of the server graph on every request for the lifetime of the process.

  • #18096 43657c4 Thanks @​matthewp! - Fixes domain-based i18n routing to respect security.allowedDomains when selecting a locale from request host headers

  • #18043 8a53a8b Thanks @​astro-factory! - Fixes image.responsiveStyles emitting invalid object-position CSS values for same-axis keyword pairs (top bottom, left right, etc.)

  • #18029 c08252d Thanks @​matthewp! - Runs astro dev and astro preview in the foreground when an AI agent is detected on Windows, allowing the agent to manage the process lifetime. Pass --background explicitly to request an Astro-managed background process. Agent-inferred backgrounding remains enabled on other platforms.

  • Updated dependencies [3fd16ee, 8358d59]:

    • @​astrojs/markdown-satteri@​0.4.2

astro@7.3.3

Patch Changes

  • #17651 504333c Thanks @​sxzz! - Refactors internal version handling to use a smaller, ESM-native dependency

  • #17942 0bc5715 Thanks @​matthewp! - Returns appropriate 400 and 404 responses from the image endpoint for invalid and missing local image paths

  • #17700 b2222fc Thanks @​winklemad! - Fixes Astro.preferredLocaleList returning an empty list when a locale is configured with the object form ({ path, codes }) and the browser sends the code with different casing or an underscore, such as en-US matching a configured en-us

  • #17941 394ff79 Thanks @​matthewp! - Fixes astro preview --ignore-lock (and astro dev --ignore-lock) being refused when run from an AI agent environment. The flag now starts the server in the foreground instead of erroring, since agent detection only inferred background mode and was never explicitly requested. An explicit --background combined with --ignore-lock still errors.

  • #17928 3277927 Thanks @​ArmandPhilippot! - Fixes TypeScript autocompletion for getImage() to suggest all available predefined options.

... (truncated)

Changelog

Sourced from astro's changelog.

7.3.5

Patch Changes

  • #17736 2b8b2e8 Thanks @​ematipico! - Adds a new container function called renderComponent(), which renders Astro components with inlined styles and scripts.

    Users must import the component with the new ?container query string:

    import { experimental_AstroContainer } from "astro/container";
    import TodoList from "../components/TodoList.astro?container";
    const container = await experimental_AstroContainer.create();
    const _string = container.renderComponent(TodoList);

7.3.4

Patch Changes

  • #18063 40896ac Thanks @​adamchal! - Fixes incremental builds repeatedly rendering unchanged pages when modules or compiled CSS reference bundled assets.

  • #18053 cf5d72f Thanks @​Princesseuh! - Improves the astro check error shown for TypeScript 7. The command now explains that TypeScript 7 is not currently supported and provides instructions for experimentally type-checking Astro files with TypeScript 7.1 and @astrojs/ts-content-mapper.

  • #18086 795a7e4 Thanks @​ump45nose! - Fix double-escaped ampersands in Markdown image alt and title attributes. The __ASTRO_IMAGE_ round-trip now decodes the numeric (&) and named (&) character references the Markdown processors emit, so an & in an alt or title is escaped exactly once in the final HTML instead of twice.

  • #18074 0429805 Thanks @​SurefireStudios! - Fix three error names that did not match their documented reference. MissingLocale, MissingIndexForInternationalization and NoManifestAvailable reported names ending in Error in the dev overlay, while their error reference pages are published under the unsuffixed names, so the name shown to users could not be found in the docs.

  • #18007 2245837 Thanks @​L4XB! - Fixes the dev server re-evaluating the whole server module graph on every request. The astro:head-metadata plugin invalidated its component metadata virtual module from its own transform hook, so each evaluation of that module scheduled the next one. Adapters that run requests outside Vite's module runner, such as @astrojs/cloudflare, paid for a full re-evaluation of the server graph on every request for the lifetime of the process.

  • #18096 43657c4 Thanks @​matthewp! - Fixes domain-based i18n routing to respect security.allowedDomains when selecting a locale from request host headers

  • #18043 8a53a8b Thanks @​astro-factory! - Fixes image.responsiveStyles emitting invalid object-position CSS values for same-axis keyword pairs (top bottom, left right, etc.)

  • #18029 c08252d Thanks @​matthewp! - Runs astro dev and astro preview in the foreground when an AI agent is detected on Windows, allowing the agent to manage the process lifetime. Pass --background explicitly to request an Astro-managed background process. Agent-inferred backgrounding remains enabled on other platforms.

  • Updated dependencies [3fd16ee, 8358d59]:

    • @​astrojs/markdown-satteri@​0.4.2

7.3.3

Patch Changes

  • #17651 504333c Thanks @​sxzz! - Refactors internal version handling to use a smaller, ESM-native dependency

  • #17942 0bc5715 Thanks @​matthewp! - Returns appropriate 400 and 404 responses from the image endpoint for invalid and missing local image paths

  • #17700 b2222fc Thanks @​winklemad! - Fixes Astro.preferredLocaleList returning an empty list when a locale is configured with the object form ({ path, codes }) and the browser sends the code with different casing or an underscore, such as en-US matching a configured en-us

  • #17941 394ff79 Thanks @​matthewp! - Fixes astro preview --ignore-lock (and astro dev --ignore-lock) being refused when run from an AI agent environment. The flag now starts the server in the foreground instead of erroring, since agent detection only inferred background mode and was never explicitly requested. An explicit --background combined with --ignore-lock still errors.

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [sharp](https://github.com/lovell/sharp) to 0.35.5 and updates ancestor dependencies [sharp](https://github.com/lovell/sharp), [@astrojs/cloudflare](https://github.com/withastro/astro/tree/HEAD/packages/integrations/cloudflare) and [astro](https://github.com/withastro/astro/tree/HEAD/packages/astro). These dependencies need to be updated together.


Updates `sharp` from 0.34.5 to 0.35.5
- [Release notes](https://github.com/lovell/sharp/releases)
- [Commits](lovell/sharp@v0.34.5...v0.35.5)

Updates `@astrojs/cloudflare` from 12.6.13 to 14.3.3
- [Release notes](https://github.com/withastro/astro/releases)
- [Changelog](https://github.com/withastro/astro/blob/main/packages/integrations/cloudflare/CHANGELOG.md)
- [Commits](https://github.com/withastro/astro/commits/@astrojs/cloudflare@14.3.3/packages/integrations/cloudflare)

Updates `astro` from 5.18.0 to 7.3.5
- [Release notes](https://github.com/withastro/astro/releases)
- [Changelog](https://github.com/withastro/astro/blob/main/packages/astro/CHANGELOG.md)
- [Commits](https://github.com/withastro/astro/commits/astro@7.3.5/packages/astro)

---
updated-dependencies:
- dependency-name: sharp
  dependency-version: 0.35.5
  dependency-type: indirect
- dependency-name: "@astrojs/cloudflare"
  dependency-version: 14.3.3
  dependency-type: direct:production
- dependency-name: astro
  dependency-version: 7.3.5
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 1, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 1, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/multi-d7962404c7 branch October 1, 2026 12:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants