Skip to content

build(deps): bump sharp and @haxtheweb/haxcms-nodejs - #626

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/multi-681fd813e6
Closed

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/multi-681fd813e6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

Bumps sharp and @haxtheweb/haxcms-nodejs. These dependencies needed to be updated together.
Updates sharp from 0.32.6 to 0.35.4

Release notes

Sourced from sharp's releases.

v0.35.4

https://github.com/lovell/sharp-libvips/releases/tag/v1.3.3

v0.35.4-rc.0

... (truncated)

Commits
  • 7f1a0a2 Release v0.35.4
  • f927818 Upgrade to sharp-libvips v1.3.3
  • e802092 Prerelease v0.35.4-rc.0
  • e13eb2f CI: Fix wasm32 build (#4589)
  • a82a0b3 Upgrade to libvips v8.18.6
  • 8044fe4 Bound resize dimensions to coordinate limit
  • 147f859 Docs: changelog entries for #4578 #4584
  • ee5bfb8 Tests: use yauzl directly rather than via extract-zip wrapper
  • 7a77889 Bump uraimo/run-on-arch-action from 3.1.0 to 3.2.0 (#4588)
  • ea5bef2 Improve support for input Streams finishing before output is requested (#4584)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for sharp since your current version.


Updates @haxtheweb/haxcms-nodejs from 26.0.1 to 26.8.1

Release notes

Sourced from @​haxtheweb/haxcms-nodejs's releases.

26.8.1

What's new in 26.8.0 On-premises API migration HAX moved off open-api.hax.cloud entirely. Document conversion, the file list, and site operations now run locally, and both backends converged on a v1 REST API — PHP routes refactored to mirror NodeJS, haxcms-php implementing the new v1 surface, with legacy blox, v0, and screenshot endpoints removed.

Issues: #2903, #2852, #2856, #2857, #2867, #2825, #2833, #2828, #2860

Import, export, and document conversion Docx import reliability and hierarchy dialog improvements, no more double-encoded ampersands in titles, outline-from-file presentation, EPUB page export, PDF download review, direct embedding from the file admin panel, and CLI skeleton import/export with a better site-creation skeleton selector.

Issues: #2794, #2915, #2916, #2922, #2924, #2925, #2937, #2902, #2798, #2799, #2921

Media and image handling media-playlist and image-gallery blocks folded in, MP3 and MP4 UX improvements, transcript-gap detection for videos, in-place image rotation that reflects changes instantly, and a JPEG quality setting.

Issues: #2893, #2901, #2800, #2815, #2836, #2816

Themes and design system Two new themes — a twenty-six (2015-inspired) theme and a link-tree theme — plus palette-default respect, a system-level style guide, site-level block management, normalized .3s/.6s transitions, and a unified user menu across app-hax and hax sites.

Issues: #2823, #2822, #2796, #2846, #2844, #2917, #2905

Performance and security cleanup Removed legacy polyfills, Polymer references, wiredjs, and the shoelace carousel (replaced in-house); CLS fixes, a Chrome first-load hang fix, a lighthouse audit pass, cache-expiration review, .well-known and SECURITY.txt rollout, and VERSION.txt access removed for hardening.

Issues: #2875, #2882, #2890, #2895, #2897, #2909, #2850, #2840, #2878, #2859, #2839, #2838, #2866, #2864

Developer experience and Skills The Skills framework was incorporated into PRAW (and split intentionally between PRAW and create), an OpenStax-to-HAX plugin for Claude, a tutorial-producing skill, an audio skill bridge, NodeJS live-reload with local assets, custom ports, JSON CLI output, and project scorecards for every core repo.

Issues: #2832, #2908, #2932, #2911, #2943, #2931, #2855, #2847, #2812, #2948, #2808, #2809, #2810, #2811

Reports and revision history The reports dashboard was redesigned as table-based information, and revision history now accounts for the .json variant of each item.

Issues: #2829, #2830, #2827

Publishing resilience Windows PowerShell publish-to-surge/netlify/vercel fix, symlink-publish errors, undefined-domain and custom-theme publishing hardening, and server-port respect.

Issues: #2862, #2870, #2868, #2874, #2873

Community pillars reflected this cycle HAX development is evaluated against seven community pillars. Here is how the 26.8.0 work maps onto them:

Accessible: WCAG 2.0 AA components, a11y-media-player transcript support, and video transcript-gap detection so uncaptioned media gets surfaced. Efficient: webcomponents shrank net 8,127 lines through polyfill, Polymer, and wiredjs removal; CLS fixes and lazy loading keep it fast. Free and Open: The on-premises API migration keeps content and calls on your own infrastructure, and OpenStax-to-HAX import extends the 5Rs of OER. Extensible: The Skills framework and an app-store editor make HAX stretch further without forking. Platform Agnostic: PHP and NodeJS backends converged on one v1 REST API, and publish-to-surge, netlify, and vercel reach anywhere.

... (truncated)

Changelog

Sourced from @​haxtheweb/haxcms-nodejs's changelog.

26.8.1 (2026-08-14)

Bug Fixes

  • api-conformance: align spec, tests, and media settings reads (6642abf)
  • pptx: exclude pptx-in-html-out vendor package from babel transpilation (6227e66)

26.0.0 (2026-08-14)

Bug Fixes

  • api-conformance: align spec, tests, and media settings reads (6642abf)
  • pptx: exclude pptx-in-html-out vendor package from babel transpilation (6227e66)
Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code minor labels Sep 9, 2026
@dependabot
dependabot Bot requested a review from btopro as a code owner September 9, 2026 01:44
@dependabot dependabot Bot added minor dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 9, 2026
Bumps [sharp](https://github.com/lovell/sharp) and [@haxtheweb/haxcms-nodejs](https://github.com/haxtheweb/haxcms-nodejs). These dependencies needed to be updated together.

Updates `sharp` from 0.32.6 to 0.35.4
- [Release notes](https://github.com/lovell/sharp/releases)
- [Commits](lovell/sharp@v0.32.6...v0.35.4)

Updates `@haxtheweb/haxcms-nodejs` from 26.0.1 to 26.8.1
- [Release notes](https://github.com/haxtheweb/haxcms-nodejs/releases)
- [Changelog](https://github.com/haxtheweb/haxcms-nodejs/blob/main/CHANGELOG.md)
- [Commits](haxtheweb/haxcms-nodejs@v26.0.1...26.8.1)

---
updated-dependencies:
- dependency-name: "@haxtheweb/haxcms-nodejs"
  dependency-version: 26.8.1
  dependency-type: direct:production
- dependency-name: sharp
  dependency-version: 0.35.4
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/multi-681fd813e6 branch from fa39d74 to da31bc4 Compare September 15, 2026 18:07
@btopro btopro closed this Sep 15, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 15, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@github-actions github-actions Bot locked and limited conversation to collaborators Sep 15, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/multi-681fd813e6 branch September 15, 2026 18:08
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code minor

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant