Source: npx @rafinery/cli audit --json (rafa.audit/v1, run 2026-07-26), dependency tier.
Machine-sourced from the envelope.
Both packages are transitive under next (chain.direct: false; paths
next@15.5.15 -> postcss@8.4.31 and next@15.5.15 -> sharp@0.34.5). Neither is dev:true.
Priority is the mechanical map on the highest severity present: . Grouped into
one row because they share one fix action (a block, or the parent
bump).
>= 8.5.18 covers all three postcss advisories; >= 0.35.0 covers sharp.
Reachability — brain-grounded annotation (priority-neutral)
Both annotations argue the practical risk is well below the CVSS headline. Neither downgrades the row — annotate, never downgrade. The reason to take it anyway is that it is genuinely cheap: an overrides block and a reinstall, no code change, no API surface moved.
Sequencing with the major
If next-dependency-cves (the 15 -> 16 major) is scheduled soon, upgrading next pulls fresh
postcss and sharp on its own and this row closes for free — do not do both. If the major is
deferred, take the override now: it retires 4 of the 28 findings for ~15 minutes of work.