Skip to content

chore(deps): bump sharp, next and @gitlawb/openclaude in /web - #318

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/web/multi-91f82b3a4f
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/web/multi-91f82b3a4f

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 11, 2026

Copy link
Copy Markdown
Contributor

Bumps sharp to 0.35.4 and updates ancestor dependencies sharp, next and @gitlawb/openclaude. These dependencies need to be updated together.

Updates sharp from 0.34.5 to 0.35.4

Release notes

Sourced from sharp's releases.

v0.35.4

https://github.com/lovell/sharp-libvips/releases/tag/v1.3.3

v0.35.4-rc.0

... (truncated)

Commits
  • 7f1a0a2 Release v0.35.4
  • f927818 Upgrade to sharp-libvips v1.3.3
  • e802092 Prerelease v0.35.4-rc.0
  • e13eb2f CI: Fix wasm32 build (#4589)
  • a82a0b3 Upgrade to libvips v8.18.6
  • 8044fe4 Bound resize dimensions to coordinate limit
  • 147f859 Docs: changelog entries for #4578 #4584
  • ee5bfb8 Tests: use yauzl directly rather than via extract-zip wrapper
  • 7a77889 Bump uraimo/run-on-arch-action from 3.1.0 to 3.2.0 (#4588)
  • ea5bef2 Improve support for input Streams finishing before output is requested (#4584)
  • Additional commits viewable in compare view

Updates next from 16.2.9 to 16.3.4

Release notes

Sourced from next's releases.

v16.3.4

Follow-up release to v16.3.3 re-enabling AVIF Image Optimization (#97949).

The following bug fixes have been backported. It does not include all pending features/changes on canary.

  • testmode: Fix infinite recursion in testmode passthrough fetch (#97691)
  • Fix build error when aliasing typescript to @​typescript/typescript6 (#97997)
  • Fix unset crossOrigin in Turbopack manifests (#97930)

Credits

Huge thanks to @​eps1lon, @​mischnic, and @​timneutkens for helping!

v16.3.3

This release contains security fixes for the following advisories:

Critical:

v16.3.2

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes

  • [backport] Scope app-entry export validation to files inside the app directory (#97357)
  • [backport] Fix catch-all index page being served for every other slug (#97416)
  • [16.3] Turbopack: don't trace embedded WASM loader helpers (#97353) (#97463)
  • [16.3] Turbopack: retain conditions when replacing resolve request keys (#97453)
  • [16.3.x] Fix Turbopack worker chunk loading with asset prefix (#97419)
  • [16.3.x] Authenticate Turborepo remote caching with OIDC instead of a static PAT (#97603)

Credits

Huge thanks to @​lubieowoce, @​unstubbable, @​timneutkens, @​mischnic, and @​eps1lon for helping!

v16.3.1

What's Changed

... (truncated)

Commits
  • 299180d v16.3.4
  • 12e173d [16.3.x] Re-enable AVIF image optimization and require sharp 0.35.4 (#97949)
  • 5d9022e [backport] Fix unset crossOrigin in Turbopack manifests (#97930)
  • d8f4560 [16.3.x] Fix build error when aliasing typescript to @​typescript/typescript6 ...
  • 656aebf [16.3] testmode: Fix infinite recursion in testmode passthrough fetch (#97691)
  • f37c1d6 [16.3.x] ci: remove pull_request_stats workflow (#97975)
  • a9a1cb7 v16.3.3
  • 968b9fc [16.3.x] Fix ISR misses with backslashes in segments when deployed on Windows
  • 3a15b4a [16.3.x] [next/image]: disable avif image optimization
  • 7378b51 Backport/docs fixes 16.3 (#97649)
  • Additional commits viewable in compare view

Updates @gitlawb/openclaude from 0.20.1 to 0.30.0

Release notes

Sourced from @​gitlawb/openclaude's releases.

v0.30.0

0.30.0 (2026-08-31)

Features

  • providers: add focused LLMTR hybrid gateway (#2150) (1e56d4e)
  • providers: live model lists for OpenRouter and OpenGateway (#2084) (bb6d66f)

Bug Fixes

  • api: scope Anthropic attribution to compatible request paths (#2147) (30090c7)
  • bg: identify sessions with persisted process markers (#2163) (ca7c3ef)
  • effort: preserve known model exclusions when force-enabled (#2148) (69aca78)
  • integrations: keep managed AIMLAPI attribution over caller headers (#2179) (aaccb57)
  • openai-shim: drop synthetic tool-results marker and guard echoes (#2039) (#2153) (54f963d)
  • plugins: anchor marketplace hostPattern against lookalike hosts (#2177) (5f1ab9b)
  • settings: preserve concurrent updates (#2137) (34536c6)
  • settings: stop proto-named permission rules from aborting validation (#2170) (8db8830)
  • tui: proper Unicode/IME input handling for composed sequences (#2018) (#2154) (e802626)

v0.29.1

0.29.1 (2026-08-19)

Performance Improvements

  • stop busting the prompt cache and slim per-turn context (#2142) (31ac8a6)

v0.29.0

0.29.0 (2026-08-19)

Features

  • aimlapi: passwordless onboarding and resumable card top-up (3/3) (#2032) (fb9102c)
  • cost: support exact custom model pricing (#2131) (09eba26)
  • gateway: add Concentrate AI provider with dynamic model discovery (#2140) (084bc53)
  • merge knowledge graph + conversation arc into memdir (#1811) (c461a03)
  • partners: add ApiSmart, refresh Novita AI logo (#2121) (575b407)
  • partners: add Concentrate and Exa to partner roster (#2141) (6e35903)
  • xai: add Grok 4.6/4.5 to catalog, xAI provider, and gateways (#2117) (7cae408)
  • zai: expand Coding Plan catalog support (#2127) (ea65516)

Bug Fixes

  • api: resolve swarm-field tool names by own-property (#2123) (f553d08)
  • bg: preserve detached session terminal outcomes (#2133) (108a413)

... (truncated)

Changelog

Sourced from @​gitlawb/openclaude's changelog.

0.30.0 (2026-08-31)

Features

  • providers: add focused LLMTR hybrid gateway (#2150) (1e56d4e)
  • providers: live model lists for OpenRouter and OpenGateway (#2084) (bb6d66f)

Bug Fixes

  • api: scope Anthropic attribution to compatible request paths (#2147) (30090c7)
  • bg: identify sessions with persisted process markers (#2163) (ca7c3ef)
  • effort: preserve known model exclusions when force-enabled (#2148) (69aca78)
  • integrations: keep managed AIMLAPI attribution over caller headers (#2179) (aaccb57)
  • openai-shim: drop synthetic tool-results marker and guard echoes (#2039) (#2153) (54f963d)
  • plugins: anchor marketplace hostPattern against lookalike hosts (#2177) (5f1ab9b)
  • settings: preserve concurrent updates (#2137) (34536c6)
  • settings: stop proto-named permission rules from aborting validation (#2170) (8db8830)
  • tui: proper Unicode/IME input handling for composed sequences (#2018) (#2154) (e802626)

0.29.1 (2026-08-19)

Performance Improvements

  • stop busting the prompt cache and slim per-turn context (#2142) (31ac8a6)

0.29.0 (2026-08-19)

Features

  • aimlapi: passwordless onboarding and resumable card top-up (3/3) (#2032) (fb9102c)
  • cost: support exact custom model pricing (#2131) (09eba26)
  • gateway: add Concentrate AI provider with dynamic model discovery (#2140) (084bc53)
  • merge knowledge graph + conversation arc into memdir (#1811) (c461a03)
  • partners: add ApiSmart, refresh Novita AI logo (#2121) (575b407)
  • partners: add Concentrate and Exa to partner roster (#2141) (6e35903)
  • xai: add Grok 4.6/4.5 to catalog, xAI provider, and gateways (#2117) (7cae408)
  • zai: expand Coding Plan catalog support (#2127) (ea65516)

Bug Fixes

  • api: resolve swarm-field tool names by own-property (#2123) (f553d08)
  • bg: preserve detached session terminal outcomes (#2133) (108a413)
  • code-reviewer: require inline diff input and preserve read-only search in embedded-search builds (#2102) (645d596)
  • extend Ling 3.0 Tiny :free availability window to Aug 17 (ee64d80)
  • Ling 3.0 Tiny :free window back to Aug 13 (official promo end) (6277bfa)

... (truncated)

Commits
  • 6c7efde chore(main): release 0.30.0 (#2165)
  • b4af6f1 test(settings): unit-test the multi-source merge customizer (#2176)
  • aaccb57 fix(integrations): keep managed AIMLAPI attribution over caller headers (#2179)
  • 5f1ab9b fix(plugins): anchor marketplace hostPattern against lookalike hosts (#2177)
  • 8db8830 fix(settings): stop proto-named permission rules from aborting validation (#2...
  • 30090c7 fix(api): scope Anthropic attribution to compatible request paths (#2147)
  • ca7c3ef fix(bg): identify sessions with persisted process markers (#2163)
  • e802626 fix(tui): proper Unicode/IME input handling for composed sequences (#2018) (#...
  • 54f963d fix(openai-shim): drop synthetic tool-results marker and guard echoes (#2039)...
  • 39c3850 docs: tighten PR review expectations in CONTRIBUTING and AGENTS guides (#2151)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [sharp](https://github.com/lovell/sharp) to 0.35.4 and updates ancestor dependencies [sharp](https://github.com/lovell/sharp), [next](https://github.com/vercel/next.js) and [@gitlawb/openclaude](https://github.com/Gitlawb/openclaude). These dependencies need to be updated together.


Updates `sharp` from 0.34.5 to 0.35.4
- [Release notes](https://github.com/lovell/sharp/releases)
- [Commits](lovell/sharp@v0.34.5...v0.35.4)

Updates `next` from 16.2.9 to 16.3.4
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v16.2.9...v16.3.4)

Updates `@gitlawb/openclaude` from 0.20.1 to 0.30.0
- [Release notes](https://github.com/Gitlawb/openclaude/releases)
- [Changelog](https://github.com/Gitlawb/openclaude/blob/main/CHANGELOG.md)
- [Commits](Gitlawb/openclaude@v0.20.1...v0.30.0)

---
updated-dependencies:
- dependency-name: sharp
  dependency-version: 0.35.4
  dependency-type: indirect
- dependency-name: next
  dependency-version: 16.3.4
  dependency-type: direct:production
- dependency-name: "@gitlawb/openclaude"
  dependency-version: 0.30.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 11, 2026
@ecc-tools

ecc-tools Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor

ECC Tools / Security Evidence

Commit: 6fc508a39e4b145d5dedc040a06f2694afcda4e6

Security evidence gate passed (success)

No security-sensitive scanner-evidence gap detected.

Mode: enforce

Scanned 2 changed file(s). No missing scanner-evidence signal was detected.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor

ECC Tools / PR Risk Taxonomy

Commit: 6fc508a39e4b145d5dedc040a06f2694afcda4e6

PR taxonomy review recommended (neutral)

Detected 2 PR taxonomy bucket(s): Install Manifest Integrity, CI/CD Recommendation.

Scanned 2 changed file(s).

Roadmap taxonomy buckets:

Install Manifest Integrity

Install manifests, plugin metadata, and shipped skills should stay synchronized with user-facing setup guidance.

Signals:

  • 1 install or manifest path(s) changed

Paths:

  • web/package-lock.json

CI/CD Recommendation

CI, dependency, coverage, and contract signals should be routed into follow-up checks or verification work.

Signals:

  • 1 CI or workflow path(s) changed

Paths:

  • web/package-lock.json

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor

ECC Tools / Reference Set Readiness

Commit: 6fc508a39e4b145d5dedc040a06f2694afcda4e6

Reference set readiness gaps detected (neutral)

Reference evidence present for 0/7 areas (0%) across 2 changed file(s).

This check is based on files changed in this PR. Repository-level readiness is still reported by /ecc-tools analyze comments and generated manifests.

Area Status Evidence / Next Step
Deep analyzer corpus Missing Add analyzer fixture, golden, benchmark, or reference-set files that can catch analyzer regressions.
RAG/evaluator comparison Missing Add retrieval or evaluator reference-set comparison fixtures with expected ranking behavior.
PR salvage/review corpus Missing Add stale-PR, review-thread, reopen-flow, or salvage reference cases for queue cleanup automation.
Discussion triage corpus Missing Add public discussion triage fixtures, golden cases, or reference sets for informational, answered, and no-response classifications.
Harness compatibility Missing Add cross-harness, adapter-compliance, or harness-audit evidence for Claude, Codex, OpenCode, Zed, dmux, and agent surfaces.
Security evidence Missing Attach security evidence such as SBOMs, SARIF, audit reports, or AgentShield evidence packs.
CI failure-mode evidence Missing Add captured CI failure logs, dry-run fixtures, or troubleshooting docs for common workflow failure modes.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor

ECC Tools / Hosted Promotion Readiness

Commit: 6fc508a39e4b145d5dedc040a06f2694afcda4e6

Hosted promotion readiness passed (success)

No hosted promotion evidence gaps detected across 2 changed file(s); 0 corpus scenarios had matching evidence.

This check compares PR file changes against the evaluator/RAG promotion corpus in src/analyzers/fixtures/evaluator-rag-corpus.ts.
Hosted output scoring inspected 0 completed cached hosted job results.

No evaluator corpus scenarios matched this PR.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@coderabbitai

coderabbitai Bot commented Sep 11, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 08b65803-b508-48b9-80a3-bd177ff997e1

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants