Severity: high
CVE: (none)
Package: sharp @ 0.34.5
Vulnerable range: <0.35.0
Patched in: >=0.35.0
Dep paths:
artifacts__void-client>sharp
sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591
Reference: GHSA-f88m-g3jw-g9cj
Filed automatically by .github/workflows/pnpm-audit.yml. The fix
work for this CVE belongs in its own task; see
docs/security-audit-public-2026-04.md §11 limitation 4 for the
policy. Either bump the affected dep (closes this issue on the next
scheduled run) or add an entry to scripts/audit/ignore-list.json
with a written reachability rationale and a re-evaluation date.
Severity: high
CVE: (none)
Package:
sharp@0.34.5Vulnerable range:
<0.35.0Patched in:
>=0.35.0Dep paths:
artifacts__void-client>sharpReference: GHSA-f88m-g3jw-g9cj
Filed automatically by
.github/workflows/pnpm-audit.yml. The fixwork for this CVE belongs in its own task; see
docs/security-audit-public-2026-04.md§11 limitation 4 for thepolicy. Either bump the affected dep (closes this issue on the next
scheduled run) or add an entry to
scripts/audit/ignore-list.jsonwith a written reachability rationale and a re-evaluation date.