Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump sharp from 0.32.1 to 0.32.2 #326

Merged
merged 1 commit into from
Jul 14, 2023

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jul 12, 2023

Bumps sharp from 0.32.1 to 0.32.2.

Changelog

Sourced from sharp's changelog.

v0.32.2 - 11th July 2023

  • Limit HEIF output dimensions to 16384x16384, matches libvips.

  • Ensure exceptions are not thrown when terminating. #3569

  • Ensure the same access method is used for all inputs (regression in 0.32.0). #3669

  • Improve detection of jp2 filename extensions. #3674 @​bianjunjie1981

  • Guard use of smartcrop premultiplied option to prevent warning (regression in 0.32.1). #3710

  • Prevent over-compute in affine-based rotate before resize. #3722

  • Allow sequential read for EXIF-based auto-orientation. #3725

Commits
  • 16ea04f Release v0.32.2
  • 9c547dc Use copy rather than cache to prevent affine overcompute
  • 5522060 Limit HEIF output dimensions to 16384x16384
  • d2f0fa8 Tests: loosen threshold for affine rotate then extract
  • 2bb3ea8 Bump deps
  • 3434eef Guard use of smartcrop premultiplied option #3710
  • 2f67823 Allow seq read for EXIF-based auto-orient #3725
  • 38c760c Update to latest (temporary) prebuild patch
  • 14c3346 Prevent over-compute in affine rotate #3722
  • 0da55ba Tests: remove unused dependency
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [sharp](https://github.com/lovell/sharp) from 0.32.1 to 0.32.2.
- [Release notes](https://github.com/lovell/sharp/releases)
- [Changelog](https://github.com/lovell/sharp/blob/main/docs/changelog.md)
- [Commits](lovell/sharp@v0.32.1...v0.32.2)

---
updated-dependencies:
- dependency-name: sharp
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
@what-the-diff
Copy link

what-the-diff bot commented Jul 12, 2023

PR Summary

  • Updated Dependency Version
    The version of a critical underlying component, sharp, was updated in the project's package.json file. This update takes us from version 0.32.1 to 0.32.2, enabling us to take advantage of the latest bug fixes, security patches, and performance improvements from this newer version.

@github-actions github-actions bot merged commit a50a5fd into main Jul 14, 2023
12 checks passed
@github-actions github-actions bot deleted the dependabot/npm_and_yarn/sharp-0.32.2 branch July 14, 2023 01:17
@github-actions
Copy link

This Pull Request is closed by a GitHub Action

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant