Skip to content

fix(functions-v2-imagemagick): upgrade sharp to fix inherited libvips vulnerabilities - #4395

Merged
angelcaamal merged 1 commit into
mainfrom
fix/upgrade-sharp-functions-v2-imagemagick
Jul 31, 2026
Merged

fix(functions-v2-imagemagick): upgrade sharp to fix inherited libvips vulnerabilities#4395
angelcaamal merged 1 commit into
mainfrom
fix/upgrade-sharp-functions-v2-imagemagick

Conversation

@angelcaamal

@angelcaamal angelcaamal commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

Description

Upgrades the sharp dependency in functions/v2/imagemagick/package.json to resolve high-severity security vulnerabilities inherited from the transitive libvips library.

Security CVEs Fixed

  • CVE-2026-33327
  • CVE-2026-33328
  • CVE-2026-35590
  • CVE-2026-35591

Changes Made

  • Updated sharp dependency in functions/v2/imagemagick/package.json.
  • Regenerated package-lock.json to pull patched libvips binaries.

Fixes Internal: b/541283569

Note: Before submitting a pull request, please open an issue for discussion if you are not associated with Google.

Checklist

  • I have followed guidelines from CONTRIBUTING.MD and Samples Style Guide
  • Tests pass: npm test (see Testing)
  • Lint pass: npm run lint (see Style)
  • Required CI tests pass (see CI testing)
  • These samples need a new API enabled in testing projects to pass (let us know which ones)
  • These samples need a new/updated env vars in testing projects set to pass (let us know which ones)
  • This pull request is from a branch created directly off of GoogleCloudPlatform/nodejs-docs-samples. Not a fork.
  • This sample adds a new sample directory, and I updated the CODEOWNERS file with the codeowners for this sample
  • This sample adds a new sample directory, and I created GitHub Actions workflow for this sample
  • This sample adds a new Product API, and I updated the Blunderbuss issue/PR auto-assigner with the codeowners for this sample
  • Please merge this PR for me once it is approved

Note: Any check with (dev), (experimental), or (legacy) can be ignored and should not block your PR from merging (see CI testing).

@product-auto-label product-auto-label Bot added samples Issues that are directly related to samples. api: cloudfunctions Issues related to the Cloud Run functions API. asset: pattern DEE Asset tagging - Pattern. labels Jul 31, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the sharp dependency in functions/v2/imagemagick/package.json from version ^0.34.5 to ^0.35.3. There are no review comments, and I have no feedback to provide.

@angelcaamal
angelcaamal marked this pull request as ready for review July 31, 2026 18:02
@angelcaamal
angelcaamal requested review from a team as code owners July 31, 2026 18:02

@amcolin amcolin left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@angelcaamal
angelcaamal merged commit 793a616 into main Jul 31, 2026
22 checks passed
@angelcaamal
angelcaamal deleted the fix/upgrade-sharp-functions-v2-imagemagick branch July 31, 2026 18:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

api: cloudfunctions Issues related to the Cloud Run functions API. asset: pattern DEE Asset tagging - Pattern. samples Issues that are directly related to samples.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants