fix(deps): update @astrojs packages#1591
Conversation
|
🚀 Preview deployment ready! ✅ Preview URL: https://pr-1591---web-njpdbbjcea-an.a.run.app This comment was automatically generated by the deploy-preview workflow. |
69eb03e to
6ac22bf
Compare
Renovate PR Review Results⚖️ Safety Assessment: ✅ Safe🔍 Release Content AnalysisThis PR updates three Astro packages with patch-level security and stability fixes: 1. astro: 6.1.8 → 6.1.9 Security Hardening (4 PRs merged):
Dependency Updates:
Bug Fix:
2. @astrojs/react: 5.0.3 → 5.0.4
3. @astrojs/node: 10.0.5 → 10.0.6
Breaking Changes: None 🎯 Impact Scope InvestigationPackage Usage Analysis:
i18n Configuration Check:
Security Hardening Relevance:
Dependency Chain Impact:
💡 Recommended ActionsImmediate Action: Merge without manual migration This is a patch-level security release with:
Pre-merge Validation: # Run full test suite
pnpm test
# Verify build succeeds
pnpm build
# Check linting/formatting
pnpm lint
pnpm format:checkPost-merge Verification (via CI):
No Code Changes Required: All security fixes are internal framework improvements with no user-facing API changes. 🔗 Reference Links
Generated by koki-develop/claude-renovate-review 🚫 Permission Denied Tool ExecutionsThe following tool executions that Claude Code attempted were blocked due to insufficient permissions. Run #25024997465 - 1 tool denied
Generated by koki-develop/claude-denied-tools |
This PR contains the following updates:
10.0.5→10.0.65.0.3→5.0.46.1.8→6.1.9Release Notes
withastro/astro (@astrojs/node)
v10.0.6Compare Source
Patch Changes
99464ed,f3485c3]:withastro/astro (@astrojs/react)
v5.0.4Compare Source
Patch Changes
99464ed,f3485c3]:withastro/astro (astro)
v6.1.9Compare Source
Patch Changes
#16448
99464edThanks @matthewp! - Updates vite, picomatch, and unstorage to latest patch versions#16422
a3951d7Thanks @matthewp! - Hardensastro-islandexport resolution and hydration error handling for malformed component metadata#16420
e21de1dThanks @matthewp! - Hardens Astro's error overlay and server logging paths to avoid unsafe HTML insertion and format-string interpolation#16419
f3485c3Thanks @matthewp! - Hardens nested object and package metadata lookups to ignore prototype keys in content handling and project scaffolding#16022
a002540Thanks @mathieumaf! - Fixes an issue where i18n domains would return 404 whentrailingSlashis set tonever.Updated dependencies [
99464ed,f3485c3]:Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.