Repository navigation
build(deps): refresh clients and patch Sharp - #1202
Conversation
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: needs maintainer review before merge. What this changesThis PR refreshes Go clients and worker tooling, including Sharp 0.35.5 for a published security fix. Example: Install the tracking worker’s locked dependencies.
Review scores
ProductKind: Maintenance · Worth it: Yes · Fix scope: Complete Merge readiness✅ Ready for maintainer review Keep open: this collaborator-authored PR provides a useful dependency and security refresh absent from current main; no actionable introduced defect was found. Priority: P2 Before mergeNone. FindingsNone. Tests
Agent review detailsHow this fits togetherGo dependencies support the CLI’s Google API and MCP operations; worker dependencies build, test, and deploy the email-tracking worker. flowchart LR
A[CLI commands] --> B[Go clients]
B --> C[Google APIs and MCP]
D[Worker package and lockfile] --> E[Wrangler and Vite]
E --> F[Tracking worker]
E --> G[Miniflare and Sharp]
Technical reviewBest possible solution: Land the focused dependency refresh through the existing validation gates while preserving the current toolchain and worker install policy. Do we have a high-confidence way to reproduce the issue? This is dependency maintenance; the affected Sharp version and patched replacement are established by the lockfile and published advisory. Is this the best way to solve the issue? The manifest and lockfile refresh is appropriately scoped and retains existing compatibility and install-policy choices. AGENTS.md: found and applied where relevant. Codex review notes: model internal, reasoning medium; reviewed against 9762a448e120. Provenance checked
TestingProof path: in-process harness. SecurityNone. EvidenceWhat I checked:
Likely related people:
LabelsLabel changes:
Label justifications:
Rating scale6/6 🦀 challenger crab · 5/6 🦞 diamond lobster · 4/6 🐚 platinum hermit · 3/6 🦐 gold shrimp · 2/6 🦪 silver shellfish · 1/6 🧂 unranked krab. Overall follows the weaker of proof and patch quality; ✨ marks media proof (a screenshot, video, or linked artifact) that directly shows the changed behavior. WorkflowClawSweeper edits this one comment on every review. Comment Reviewed October 10, 2026, 1:30 AM ET / 05:30 UTC. |
Refresh the Google API/auth, MCP, and Go networking/cryptography modules while retaining the Go 1.26 floor. Update Wrangler to 4.149.0, Workers types to 5.20261009.1, and Vite to 8.3.4 using pnpm 11 and the existing 24-hour release cooldown.
The refreshed lockfile also selects Sharp 0.35.5, fixing GHSA-wq5f-xc86-pv6w (librsvg CVE-2026-96889). Sharp install scripts remain disabled. No application version changes.
Validation: module metadata confirms Go 1.26 compatibility; full make ci and frozen-lockfile make worker-ci on AWS Crabbox; independent review through P2.