Skip to content

⬆️ Update dependency astro to v7.3.6 - #460

Merged
frenck merged 1 commit into
mainfrom
renovate/astro-7.x
Oct 6, 2026
Merged

frenck merged 1 commit into
mainfrom
renovate/astro-7.x

Conversation

@renovate

@renovate renovate Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
astro (source) 7.3.5 → 7.3.6 age adoption passing confidence

Release Notes

withastro/astro (astro)

v7.3.6

Compare Source

Patch Changes
  • #​18166 5134d0f Thanks @​astro-factory! - Fixes an intermittent dev server crash when using astro:actions inside a server island with adapters that use a pre-bundled SSR environment (e.g. @astrojs/cloudflare)

  • #​18076 8a2df66 Thanks @​astro-factory! - Fixes stale scoped styles during HMR when both markup and <style> are changed in a single save

  • #​18252 2d29e7e Thanks @​astro-factory! - Fixes CSS from other pages leaking into a page's <head> in dev when the page imports a module such as astro:config/server.

  • #​18000 6724575 Thanks @​barclayd! - Fixes a bug where server islands containing framework components rendered empty in the dev server when using a custom src/fetch.ts

  • #​18241 7c5fd6f Thanks @​astro-factory! - Fixes the composable i18n() handler from astro/fetch and astro/hono returning an empty 404 for paths without a locale prefix. It now renders the custom 404 page, matching astro().

  • #​18164 1a6997f Thanks @​astro-factory! - Fixes CSS Module HMR in dev when a component is rendered both with and without hydration on the same page. Astro now uses path-based class name hashing in dev mode so that editing CSS declarations no longer changes the generated selectors, allowing Vite's CSS HMR to update styles without a full page reload.

  • #​18243 dd29d62 Thanks @​astro-factory! - Fixes context.props being null in middleware and endpoints when the composable astro/hono or astro/fetch actions() handler runs before middleware(), or when pages() runs without middleware()

  • #​18193 95d5d16 Thanks @​astro-factory! - Fixes astro build failing on Windows with Node.js 25+ with ERR_INVALID_ARG_VALUE when clearing the output directory hits a transient EPERM error

  • #​18220 d6c13a4 Thanks @​astro-factory! - Fixes type errors reported in Astro's built-in <Picture /> and <Font /> components when type-checking a project with tsc and @astrojs/ts-content-mapper

  • #​18133 faac481 Thanks @​astro-factory! - Fixes lost request state when Vite discovers server dependencies during a request in Cloudflare dev mode

  • #​18146 2af4516 Thanks @​astro-factory! - Fixes CSS imported from an injectScript('page') script being dropped during build

  • #​18159 e5f8fe0 Thanks @​astro-factory! - Fixes a hang when a server:defer component is inside a slot of another component in an MDX content collection entry

  • #​18246 c3b42ad Thanks @​astro-factory! - Fixes the glob() loader skipping content files whose paths contain # or ?

  • #​18248 b97184e Thanks @​astro-factory! - Fixes a bug where page routes added with injectRoute() returned a 404 when i18n.routing.prefixDefaultLocale was true and the route path had no locale prefix

  • #​18251 3415263 Thanks @​astro-factory! - Fixes content collection changes being ignored in astro dev after the dev server restarts because of a config change

  • #​18226 ad54af0 Thanks @​imharjot! - Fixes Astro.cookies.get() returning undefined for request cookies with empty values

  • #​18155 37ab0e4 Thanks @​astro-factory! - Fixes nondeterministic ordering of the server manifest's assets array, ensuring builds with identical inputs produce byte-identical output

  • #​18099 6987261 Thanks @​renovate! - Adds YAML parsing with timestamp and merge key support, and formats YAML errors consistently across Astro, Markdown, MDX, and Markdoc.

  • #​15595 64e4039 Thanks @​qzio! - Improves CSRF protection by taking modern browsers headers into account

  • #​18215 941bd5e Thanks @​ump45nose! - Fixes a runtime ReferenceError for inlined scripts that import a URL with /* @vite-ignore */.

    Astro now inlines scripts after Vite replaces its preload markers, so ignored dynamic imports can remain inline without shipping an unresolved __VITE_PRELOAD__ reference.

  • #​18179 6caa659 Thanks @​matthewp! - Fixes custom View Transition direction names that are not valid CSS identifiers, such as names starting with a digit or containing spaces. These directions now match their animations correctly.

  • #​18250 7eae39b Thanks @​astro-factory! - Fixes a 404 for a CSS file that a dynamic import preloads when the imported module uses a component that is also a hydrated island on the same page

  • #​18176 7c9d00d Thanks @​astro-factory! - Fixes duplicate CSS in production builds when a component is both server-rendered and used with client:only on the same page

  • #​18245 492e95f Thanks @​astro-factory! - Fixes the composable astro/fetch and astro/hono handlers (trailingSlash(), redirects(), actions(), middleware(), and pages()) so they reject over-encoded request paths with a 400 Bad Request, matching astro(). For these requests, redirects() and actions() return the 400 response instead of undefined, so no redirect is issued and no action runs.

  • #​18078 0a2ab10 Thanks @​manuelgruber! - Fixes Astro.rewrite() and context.rewrite() selecting the wrong route in astro dev when two dynamic routes match the same path

  • #​18210 62b13ba Thanks @​edmundhung! - Allows Astro CLI commands to install tagged package versions

  • #​18069 d39eb97 Thanks @​astro-factory! - Fixes a dev server dependency scan failure when an .astro file contains a literal <script in frontmatter or a template expression

  • #​18114 c17d920 Thanks @​matthewp! - Fixes Astro on StackBlitz and other WebContainer environments

  • #​18088 cb767f9 Thanks @​astro-factory! - Fixes a MODULE_LEVEL_DIRECTIVE warning during build caused by a stale "use astro:head-inject" directive in content collection propagated asset modules

  • #​18247 2b3f73d Thanks @​astro-factory! - Fixes actions returning 500 for malformed JSON request bodies and undecodable action names. A SyntaxError from invalid JSON now returns 400 (BAD_REQUEST), and a URIError from a malformed percent-encoded action name now returns 404 (NOT_FOUND).

  • 1d9e910 Thanks @​matthewp! - Validates the Host header against security.allowedDomains when using the Node adapter

  • #​18249 c7799a4 Thanks @​astro-factory! - Fixes the fontsource font provider to resolve variable fonts when using the "Variable" suffix in the font name (e.g. "Inter Variable")

  • #​18163 e48da9d Thanks @​astro-factory! - Fixes <video muted> losing its muted state after a ClientRouter navigation in Chrome

  • #​18244 f67e7f7 Thanks @​astro-factory! - Fixes localized error pages such as src/pages/pt/404.astro returning a 200 status when rendered through the pages() handler from astro/fetch or astro/hono

  • #​18242 c5275e3 Thanks @​astro-factory! - Fixes experimental_AstroContainer output including dev toolbar data-astro-source-file and data-astro-source-loc attributes when rendering components under Vitest

  • Updated dependencies [6987261, 62b13ba]:


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added dependencies Upgrade or downgrade of project dependencies. javascript no-stale This issue or PR is exempted from the stable bot. labels Oct 6, 2026
@renovate
renovate Bot enabled auto-merge (squash) October 6, 2026 16:39
@coderabbitai

coderabbitai Bot commented Oct 6, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 8b9348c8-0c97-4984-9a39-bf63e77f0475

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codspeed

codspeed Bot commented Oct 6, 2026

Copy link
Copy Markdown

Merging this PR will not alter performance

✅ 16 untouched benchmarks


Comparing renovate/astro-7.x (1b65114) with main (b22a7f7)

Open in CodSpeed

@frenck
frenck disabled auto-merge October 6, 2026 17:06
@frenck
frenck merged commit 8c2c0c0 into main Oct 6, 2026
75 of 76 checks passed
@frenck
frenck deleted the renovate/astro-7.x branch October 6, 2026 17:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Upgrade or downgrade of project dependencies. javascript no-stale This issue or PR is exempted from the stable bot.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant