From e798e124ce566767d24fe3588bec06fb7961cb1f Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 1 Jul 2026 19:53:55 +0000 Subject: [PATCH 1/4] chore(deps): bump @vercel/og from 0.6.2 to 0.11.1 Bumps @vercel/og from 0.6.2 to 0.11.1. --- updated-dependencies: - dependency-name: "@vercel/og" dependency-version: 0.11.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] --- package.json | 2 +- pnpm-lock.yaml | 54 ++++++++++++++++++++++++++++++++------------------ 2 files changed, 36 insertions(+), 20 deletions(-) diff --git a/package.json b/package.json index aba16e4..d11271e 100644 --- a/package.json +++ b/package.json @@ -33,7 +33,7 @@ "@tailwindcss/postcss": "4.3.1", "@types/react": "^19.2.17", "@types/unist": "^3.0.3", - "@vercel/og": "^0.6.2", + "@vercel/og": "^0.11.1", "astro": "^6.4.6", "estree-util-value-to-estree": "^3.5.0", "gray-matter": "4.0.3", diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index 7e56afa..6dd25c8 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -47,8 +47,8 @@ importers: specifier: ^3.0.3 version: 3.0.3 '@vercel/og': - specifier: ^0.6.2 - version: 0.6.2 + specifier: ^0.11.1 + version: 0.11.1 astro: specifier: ^6.4.6 version: 6.4.6(@types/node@22.19.21)(@vercel/blob@2.3.0)(jiti@2.7.0)(lightningcss@1.32.0)(rollup@4.57.1)(tsx@4.21.0)(yaml@2.4.2) @@ -2031,8 +2031,8 @@ packages: '@vercel/node@5.7.11': resolution: {integrity: sha512-U2y8YOeSFdSNBQA1VwChy0yPVIDPNPJiNuAx2fuj1ZljAUZYL85/hYM/S6JHtZZ77ZaqM+qtGdvXlvLvoVRgfQ==} - '@vercel/og@0.6.2': - resolution: {integrity: sha512-OTe0KE37F5Y2eTys6eMnfopC+P4qr2ooXUTFyFPTplYSPwowmFk/HLD1FXtbKLjqsIH0SgekcJWad+C5uX4nkg==} + '@vercel/og@0.11.1': + resolution: {integrity: sha512-02rXXRABFq1B03w3aNhcVfxkY+8Ba5QFi4ax0zS0oOiD/LL9WUd/LA7BjVPakrQmVhIBjuo2oBM5U25R9IuXMg==} engines: {node: '>=16'} '@vercel/oidc@3.2.0': @@ -2532,6 +2532,10 @@ packages: peerDependencies: postcss: ^8.0.9 + css-gradient-parser@0.0.17: + resolution: {integrity: sha512-w2Xy9UMMwlKtou0vlRnXvWglPAceXCTtcmVSo8ZBUvqCV5aXEFP/PC6d+I464810I9FT++UACwTD5511bmGPUg==} + engines: {node: '>=16'} + css-select@5.2.2: resolution: {integrity: sha512-TizTzUddG/xYLA3NXodFM0fSbNizXjOKhqiQQwvhlspadZokn1KDy0NZFS0wuEubIYAV5/c1/lAr0TaaFXEXzw==} @@ -2731,6 +2735,10 @@ packages: electron-to-chromium@1.5.340: resolution: {integrity: sha512-908qahOGocRMinT2nM3ajCEM99H4iPdv84eagPP3FfZy/1ZGeOy2CZYzjhms81ckOPCXPlW7LkY4XpxD8r1DrA==} + emoji-regex-xs@2.0.1: + resolution: {integrity: sha512-1QFuh8l7LqUcKe24LsPUNzjrzJQ7pgRwp1QMcZ5MX6mFplk2zQ08NVCM84++1cveaUUYtcCYHmeFEuNg16sU4g==} + engines: {node: '>=10.0.0'} + emoji-regex@10.3.0: resolution: {integrity: sha512-QpLs9D9v9kArv4lfDEgg1X/gN5XLnf/A6l9cs8SPZLRZR3ZkY9+kwIQTxm+fsSej5UMYGE8fdoaZVIBlqG0XTw==} @@ -5047,8 +5055,9 @@ packages: resolution: {integrity: sha512-OcXjMsGdhL4XnbShKpAcSqPMzQoYkYyhbEaeSko47MjRP9NfEQMhZkXL1DoFlt9LWQn4YttrdnV6X2OiyzBi+A==} engines: {node: '>=10'} - resolve@1.22.8: - resolution: {integrity: sha512-oKWePCxqpd6FlLvGV1VU0x7bkPmmCNolxzjMf4NczoDnQcIWrAF+cPtZn5i6n+RfD2d9i0tzpKnG6Yk168yIyw==} + resolve@1.22.12: + resolution: {integrity: sha512-TyeJ1zif53BPfHootBGwPRYT1RUt6oGWsaQr8UyZW/eAm9bKoijtvruSDEmZHm92CwS9nj7/fWttqPCgzep8CA==} + engines: {node: '>= 0.4'} hasBin: true resolve@2.0.0-next.5: @@ -5132,8 +5141,8 @@ packages: sass-formatter@0.7.9: resolution: {integrity: sha512-CWZ8XiSim+fJVG0cFLStwDvft1VI7uvXdCNJYXhDvowiv+DsbD1nXLiQ4zrE5UBvj5DWZJ93cwN0NX5PMsr1Pw==} - satori@0.10.9: - resolution: {integrity: sha512-XU9EELUEZuioT4acLIpCXxHcFzrsC8muvg0MY28d+TlqwxbkTzBmWbw+3+hnCzXT7YZ0Qm8k3eXktDaEu+qmEw==} + satori@0.25.0: + resolution: {integrity: sha512-utINfLxrYrmSnLvxFT4ZwgwWa8KOjrz7ans32V5wItgHVmzESl/9i33nE38uG0miycab8hUqQtDlOpqrIpB/iw==} engines: {node: '>=16'} sax@1.6.0: @@ -6100,8 +6109,8 @@ packages: resolution: {integrity: sha512-4LCcse/U2MHZ63HAJVE+v71o7yOdIe4cZ70Wpf8D/IyjDKYQLV5GD46B+hSTjJsvV5PztjvHoU580EftxjDZFQ==} engines: {node: '>=12.20'} - yoga-wasm-web@0.3.3: - resolution: {integrity: sha512-N+d4UJSJbt/R3wqY7Coqs5pcV0aUj2j9IaQ3rNj9bVCLld8tTGKRa2USARjnvZJWVx1NDmQev8EknoczaOQDOA==} + yoga-layout@3.2.1: + resolution: {integrity: sha512-0LPOt3AxKqMdFBZA3HBAt/t/8vIKq7VaQYbuA8WxCgung+p9TVyKRYdpvCb80HcdTN2NkbIKbhNwKUfm3tQywQ==} zod-validation-error@4.0.2: resolution: {integrity: sha512-Q6/nZLe6jxuU80qb/4uJ4t5v2VEZ44lzQjPDhYJNztRQ4wyWc6VF3D3Kb/fAuPetZQnhS3hnajCf9CsWesghLQ==} @@ -7910,11 +7919,12 @@ snapshots: - rollup - supports-color - '@vercel/og@0.6.2': + '@vercel/og@0.11.1': dependencies: '@resvg/resvg-wasm': 2.4.0 - satori: 0.10.9 - yoga-wasm-web: 0.3.3 + satori: 0.25.0 + optionalDependencies: + sharp: 0.34.5 '@vercel/oidc@3.2.0': {} @@ -8537,6 +8547,8 @@ snapshots: dependencies: postcss: 8.5.10 + css-gradient-parser@0.0.17: {} + css-select@5.2.2: dependencies: boolbase: 1.0.0 @@ -8752,6 +8764,8 @@ snapshots: electron-to-chromium@1.5.340: {} + emoji-regex-xs@2.0.1: {} + emoji-regex@10.3.0: {} emoji-regex@8.0.0: {} @@ -9013,7 +9027,7 @@ snapshots: dependencies: debug: 3.2.7 is-core-module: 2.16.2 - resolve: 1.22.8 + resolve: 1.22.12 transitivePeerDependencies: - supports-color optional: true @@ -11638,8 +11652,9 @@ snapshots: resolve.exports@2.0.3: {} - resolve@1.22.8: + resolve@1.22.12: dependencies: + es-errors: 1.3.0 is-core-module: 2.16.2 path-parse: 1.0.7 supports-preserve-symlinks-flag: 1.0.0 @@ -11807,18 +11822,19 @@ snapshots: dependencies: suf-log: 2.5.3 - satori@0.10.9: + satori@0.25.0: dependencies: '@shuding/opentype.js': 1.4.0-beta.0 css-background-parser: 0.1.0 css-box-shadow: 1.0.0-3 + css-gradient-parser: 0.0.17 css-to-react-native: 3.2.0 - emoji-regex: 10.3.0 + emoji-regex-xs: 2.0.1 escape-html: 1.0.3 linebreak: 1.1.0 parse-css-color: 0.2.1 postcss-value-parser: 4.2.0 - yoga-wasm-web: 0.3.3 + yoga-layout: 3.2.1 sax@1.6.0: {} @@ -12912,7 +12928,7 @@ snapshots: yocto-queue@1.2.2: {} - yoga-wasm-web@0.3.3: {} + yoga-layout@3.2.1: {} zod-validation-error@4.0.2(zod@4.3.6): dependencies: From aa8efe96c402ef0e7b19a348a2ebdd5498ee3c39 Mon Sep 17 00:00:00 2001 From: Claude Date: Thu, 2 Jul 2026 10:14:34 +0000 Subject: [PATCH 2/4] ci: skip Vercel preview deploy for Dependabot PRs (no secrets access) Dependabot PRs run from the same repo (not a fork), so the deploy step's fork-only guard let it through even though GitHub withholds repository secrets from dependabot-actor runs. That caused deploy.mjs to fail with 'missing --token'. Treat dependabot[bot] runs the same as fork PRs: build/lint/typecheck/test still run, but preview deploy and lighthouse are skipped until a maintainer adds the 'trusted' label. Co-Authored-By: Claude Sonnet 5 --- .github/workflows/ci.yml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index ee676d3..4072a65 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -96,7 +96,7 @@ jobs: - name: Deploy Preview to Vercel if: ${{ github.event_name != 'push' && github.event_name != 'workflow_dispatch' && - (!github.event.pull_request.head.repo.fork || + ((!github.event.pull_request.head.repo.fork && github.actor != 'dependabot[bot]') || (github.event_name == 'pull_request_target' && contains(github.event.pull_request.labels.*.name, 'trusted'))) }} run: node .github/scripts/deploy.mjs --token=${{ secrets.VERCEL_TOKEN }} @@ -104,7 +104,7 @@ jobs: - name: Create GitHub Preview Deployment if: ${{ github.event_name != 'push' && github.event_name != 'workflow_dispatch' && - (!github.event.pull_request.head.repo.fork || + ((!github.event.pull_request.head.repo.fork && github.actor != 'dependabot[bot]') || (github.event_name == 'pull_request_target' && contains(github.event.pull_request.labels.*.name, 'trusted'))) }} uses: chrnorm/deployment-action@500aa6a23c81ffa1acf71072aee3cfa2cc2e556a @@ -132,7 +132,7 @@ jobs: needs: build-and-deploy runs-on: ubuntu-latest if: - ${{ !github.event.pull_request.head.repo.fork || + ${{ (!github.event.pull_request.head.repo.fork && github.actor != 'dependabot[bot]') || (github.event_name == 'pull_request_target' && contains(github.event.pull_request.labels.*.name, 'trusted')) }} steps: From 7b0f7e031758b63a69acb2a2fb44af535552287b Mon Sep 17 00:00:00 2001 From: Piotr Monwid-Olechnowicz Date: Tue, 7 Jul 2026 12:15:14 +0200 Subject: [PATCH 3/4] fix(og): run api/og on nodejs runtime, not edge MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit @vercel/og 0.11.1 added sharp as an optional dependency (it wasn't present in 0.6.2), which pushes the edge-bundled api/og function to 1.04 MB — over Vercel's 1 MB Edge Function size limit on this plan. The Node.js runtime has a far higher size ceiling and this handler only uses standard Web APIs (Request/Response, fetch, crypto.subtle) that Node 22+ supports natively, so no other code changes are needed. Co-Authored-By: Claude Sonnet 5 --- api/og.ts | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/api/og.ts b/api/og.ts index 5e5ab17..765c715 100644 --- a/api/og.ts +++ b/api/og.ts @@ -14,7 +14,7 @@ const author = { type Author = typeof author; -export const config = { runtime: "edge" }; +export const config = { runtime: "nodejs" }; const interRegular = fetchFont( new URL("../assets/og/Inter-Regular.ttf", import.meta.url) From 86096927ffb5b986b9474638c78eb9ae87a94ace Mon Sep 17 00:00:00 2001 From: Claude Date: Tue, 7 Jul 2026 10:34:03 +0000 Subject: [PATCH 4/4] ci: retrigger workflow run The previous commit was pushed via the GitHub API, which does not trigger a new Actions run. Empty commit to kick off CI on the nodejs-runtime fix. Co-Authored-By: Claude Sonnet 5