Severity: high
CVE: (none)
Package: sharp @ 0.35.3
Vulnerable range: <0.35.4
Patched in: >=0.35.4
Dep paths:
artifacts__void-client>sharp
sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545
Reference: GHSA-rgj7-g3m4-5g8c
Filed automatically by .github/workflows/pnpm-audit.yml. The fix
work for this CVE belongs in its own task; see
docs/security-audit-public-2026-04.md §11 limitation 4 for the
policy. Either bump the affected dep (closes this issue on the next
scheduled run) or add an entry to scripts/audit/ignore-list.json
with a written reachability rationale and a re-evaluation date.
Severity: high
CVE: (none)
Package:
sharp@0.35.3Vulnerable range:
<0.35.4Patched in:
>=0.35.4Dep paths:
artifacts__void-client>sharpReference: GHSA-rgj7-g3m4-5g8c
Filed automatically by
.github/workflows/pnpm-audit.yml. The fixwork for this CVE belongs in its own task; see
docs/security-audit-public-2026-04.md§11 limitation 4 for thepolicy. Either bump the affected dep (closes this issue on the next
scheduled run) or add an entry to
scripts/audit/ignore-list.jsonwith a written reachability rationale and a re-evaluation date.