← Package details

Runtime evidence / smoke tested

sharp0.35.5

Observed 2026-10-09 11:12 UTC · Linux amd64 / glibc

Download JSON
Immutable loading evidence badge for sharp
Passed

All applicable planned loading observations completed.

This is loading evidence. It does not establish functional correctness or package safety.

Runtime matrix

4 pinned runtimes · production_ab51508deb208994caf81cb80f14b800

Import uses ESM; require uses CommonJS. Root modes use fresh sandboxes. Subpath batches share module caches and globals. Select a result to inspect its evidence.

Does sharp work in Node.js, Bun and Deno?

All applicable planned loading checks completed. The runtimes used the same installed dependency snapshot. Test environment: Linux amd64 / glibc, with install scripts and execution networking disabled. Successful import or require does not prove that package functions, native features or your application work.

Does sharp work with Node.js?

sharp@0.35.5 passed the applicable loading checks in Node.js 24.21.0. 2 passed · 0 failed.

sharp@0.35.5 passed the applicable loading checks in Node.js 26.10.0. 2 passed · 0 failed.

Does sharp work with Bun?

sharp@0.35.5 passed the applicable loading checks in Bun 1.4.2. 2 passed · 0 failed.

Does sharp work with Deno?

sharp@0.35.5 passed the applicable loading checks in Deno 2.9.7. 2 passed · 0 failed.

Compare npm package compatibility across Node.js, Bun and Deno · Browse observed runtime loading failures

Shared preparation

Passed

6 installed packages · 26 optional dependencies omitted · lifecycle scripts disabled

The omitted count covers locked optional dependencies. Optional peers are separate and are not automatically installed.

Static manifest, native and script observations

Static indicators are context; their presence alone does not establish a prerequisite or failure.

Coverage and evidence

Node.js 24.21.0 · Root · ESM importPassed

1 passed · 0 failed · 1 observed of 1 planned

Evidence JSON
Node.js 24.21.0 · Root · CommonJS requirePassed

1 passed · 0 failed · 1 observed of 1 planned

Evidence JSON
Node.js 24.21.0 · Subpaths · ESM importNot applicable

0 passed · 0 failed · 0 observed of 0 planned

Evidence JSON
Node.js 24.21.0 · Subpaths · CommonJS requireNot applicable

0 passed · 0 failed · 0 observed of 0 planned

Evidence JSON
Node.js 26.10.0 · Root · ESM importPassed

1 passed · 0 failed · 1 observed of 1 planned

Evidence JSON
Node.js 26.10.0 · Root · CommonJS requirePassed

1 passed · 0 failed · 1 observed of 1 planned

Evidence JSON
Node.js 26.10.0 · Subpaths · ESM importNot applicable

0 passed · 0 failed · 0 observed of 0 planned

Evidence JSON
Node.js 26.10.0 · Subpaths · CommonJS requireNot applicable

0 passed · 0 failed · 0 observed of 0 planned

Evidence JSON
Bun 1.4.2 · Root · ESM importPassed

1 passed · 0 failed · 1 observed of 1 planned

Evidence JSON
Bun 1.4.2 · Root · CommonJS requirePassed

1 passed · 0 failed · 1 observed of 1 planned

Evidence JSON
Bun 1.4.2 · Subpaths · ESM importNot applicable

0 passed · 0 failed · 0 observed of 0 planned

Evidence JSON
Bun 1.4.2 · Subpaths · CommonJS requireNot applicable

0 passed · 0 failed · 0 observed of 0 planned

Evidence JSON
Deno 2.9.7 · Root · ESM importPassed

1 passed · 0 failed · 1 observed of 1 planned

Evidence JSON
Deno 2.9.7 · Root · CommonJS requirePassed

1 passed · 0 failed · 1 observed of 1 planned

Evidence JSON
Deno 2.9.7 · Subpaths · ESM importNot applicable

0 passed · 0 failed · 0 observed of 0 planned

Evidence JSON
Deno 2.9.7 · Subpaths · CommonJS requireNot applicable

0 passed · 0 failed · 0 observed of 0 planned

Evidence JSON
Planner omissions
pattern
0
non executable
0
not exported
0
invalid subpath
0
coverage limit
0

    Reproduce these inputs

    Download the recorded inputs and exact dependency lock. These files do not include the CLI, runtime images or installed packages.

    Local replay requires setup. The CLI currently runs from the CompatLab source repository on a qualified Linux amd64/runsc host. Hosted runtime images are not yet distributed for public download; an operator must supply the exact images named in this report. A fresh image build does not substitute for them. CLI setup and replay requirements

    Command for a configured host

    Run from the built CompatLab repository with both downloads in that directory and the exact runtime images loaded. Rebuilding creates a new snapshot generation.

    sudo "$(command -v node)" apps/cli/dist/bin.js reproduce ./a8c756bb-256c-4f5a-8a71-f0bae7fbbe17-reproduction.json --rebuild --lockfile ./package-lock.json --json

    The original worker last reported its sealed snapshot as available. Verified reuse requires those actual bytes in your local state directory.

    Exact provenance
    artifact
    sharp@0.35.5
    integrity
    sha512-Ywn4OnzGukp7CDMrp08RQ50YKmuwG47brZgIVPTvBaaAfQlRlygrRqSrxdCiL9M+LlzLBiJ68IR1QqvzHyjC7g==
    tarball
    https://registry.npmjs.org/sharp/-/sharp-0.35.5.tgz
    snapshot
    b0fc2654-3a81-409a-b2c9-7213b87d5fc3
    generation
    044ca2bf-e43e-41b3-8a19-e83746d355fb
    lockDigest
    d57829b55e2d1ddb85b3fbe1445cd345b016b69f24800538ca8809bc952424d9
    treeDigest
    89b38f9de99e901bb3409e035abafd0fe0fe446d69a9b6219bf000318275efed
    installerImage
    node:24.21.0-bookworm-slim@sha256:5cbc7caba8c2c0f0bca675d1b61b9f2857e1cf1853c6164ee9dd409501a936e7
    preparationProfile
    npm_11_19_0_linux_amd64_v2
    harness
    load_v2
    planner
    explicit_exports_v1
    policy
    runtime_limits_v2
    classifier
    classifier_v2
    classifiedAt
    2026-10-09T11:12:10.963Z

    node_24_21_0

    sha256:f2fcbb4dfbd6d5f57f4e43de97e70182d9982ac7cc0cc063dfff2cf1759a411d

    Built 2026-10-04 15:20 UTC · runtime_image_v1

    node_26_10_0

    sha256:9c1c93cc35d1408d26a61c4efccbde37c35425e362a2e723b885c3333d2be073

    Built 2026-10-04 15:20 UTC · runtime_image_v1

    bun_1_4_2

    sha256:2343363679fb92d59a395ff081b783b5514f06295b1bc6d61baaeef17e793789

    Built 2026-10-04 15:21 UTC · runtime_image_v1

    deno_2_9_7

    sha256:4292bb23555f98fb9dfc30fb447daa1c301686d89264fd8643ccb86bc0d53c29

    Built 2026-10-04 15:21 UTC · runtime_image_v1

    Evidence limitations

    • Only installation and loading were observed; functional correctness and package safety are not established.
    • Subpath batches share module caches and globals; root modes use separate fresh sandboxes.
    • Package-visible harness observations can be tampered with. They are not adversarial attestation.
    • Evidence applies to these exact artifacts, dependency snapshot, runtime images and Linux amd64/glibc policy.
    • Runtime error codes are captured observations and can also be thrown by package code.
    sharp@0.35.5: Node.js, Bun & Deno test report | CompatLab