Visitar URL original
chore(deps): bump sharp, @astrojs/node and astro in /tests/resources/sites/astro by dependabot[bot] · Pull Request #14248 · appwrite/appwrite · GitHub
Skip to content

chore(deps): bump sharp, @astrojs/node and astro in /tests/resources/sites/astro - #14248

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/tests/resources/sites/astro/multi-71a1e3bc20
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/tests/resources/sites/astro/multi-71a1e3bc20

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor

Bumps sharp to 0.35.5 and updates ancestor dependencies sharp, @astrojs/node and astro. These dependencies need to be updated together.

Updates sharp from 0.34.5 to 0.35.5

Release notes

Sourced from sharp's releases.

v0.35.5

https://github.com/lovell/sharp-libvips/releases/tag/v1.3.4

  • Add upper bounds check on length of linear and GIF delay arrays.

  • Improve error handing when WebAssembly fallback also fails. #4593 @​lazerg

  • TypeScript: Allow multi-frame options for JXL output. #4602 @​ramin-010

  • TypeScript: Remove non-existent named export. #4604

  • Increase accepted dimensions when extending an image. #4605

  • Improve gain map support for extract and rotate operations. #4606

  • Tests: Ensure composite tests pass on big endian platforms. #4609

v0.35.5-rc.1

https://github.com/lovell/sharp-libvips/releases/tag/v1.3.4-rc.1

  • Add upper bounds check on length of linear and GIF delay arrays.

  • Improve error handing when WebAssembly fallback also fails. #4593 @​lazerg

  • TypeScript: Allow multi-frame options for JXL output. #4602 @​ramin-010

  • TypeScript: Remove non-existent named export. #4604

  • Increase accepted dimensions when extending an image. #4605

  • Improve gain map support for extract operation. #4606

... (truncated)

Commits
  • 51a990f Release v0.35.5
  • 96de105 Upgrade to sharp-libvips v1.3.4
  • 3a61390 CI: Configure Dependabot with all package.json locations
  • 4940c50 Improve gain map support for rotate/flip/flop ops
  • 20654aa Prerelease v0.35.5-rc.1
  • ef4f934 CI: Upgrade to Ubuntu 26.04
  • 358df95 Upgrade to libvips v8.18.7
  • 49f4903 Improve gain map support for rotate-then-extract #4606
  • 0e2e55e Silence a couple of compiler/static analysis warnings
  • cef3b8c Improve gain map support for extract operation #4606
  • Additional commits viewable in compare view

Updates @astrojs/node from 10.1.3 to 11.1.7

Release notes

Sourced from @​astrojs/node's releases.

@​astrojs/node@​11.1.7

Patch Changes

  • 1d9e910 Thanks @​matthewp! - Validates the Host header against security.allowedDomains when using the Node adapter
  • Updated dependencies [6987261, 62b13ba]:
    • @​astrojs/internal-helpers@​0.12.0

@​astrojs/node@​11.1.7-beta.0

Patch Changes

@​astrojs/node@​11.1.6

Patch Changes

  • #17971 0037c1a Thanks @​matthewp! - Fixes aborted request bodies causing duplicate unhandled rejection logs in standalone mode when using src/fetch.ts

  • #17964 01395b8 Thanks @​astro-factory! - Fixes trailing-slash redirects truncating query strings that contain a second ? character

@​astrojs/node@​11.1.5

Patch Changes

  • Updated dependencies [f8e9458]:
    • @​astrojs/internal-helpers@​0.11.0

@​astrojs/node@​11.1.4

Patch Changes

  • Updated dependencies [05763a0]:
    • @​astrojs/internal-helpers@​0.10.4
Changelog

Sourced from @​astrojs/node's changelog.

11.1.7

Patch Changes

  • 1d9e910 Thanks @​matthewp! - Validates the Host header against security.allowedDomains when using the Node adapter
  • Updated dependencies [6987261, 62b13ba]:
    • @​astrojs/internal-helpers@​0.12.0

11.1.6

Patch Changes

  • #17971 0037c1a Thanks @​matthewp! - Fixes aborted request bodies causing duplicate unhandled rejection logs in standalone mode when using src/fetch.ts

  • #17964 01395b8 Thanks @​astro-factory! - Fixes trailing-slash redirects truncating query strings that contain a second ? character

11.1.5

Patch Changes

  • Updated dependencies [f8e9458]:
    • @​astrojs/internal-helpers@​0.11.0

11.1.4

Patch Changes

  • Updated dependencies [05763a0]:
    • @​astrojs/internal-helpers@​0.10.4

11.1.3

Patch Changes

  • #17636 51723b1 Thanks @​matthewp! - Updates the adapter to wait for the configured log destination through Astro's new app.getLogger() API. This release requires Astro 7.2.1 or later.

  • Updated dependencies [8c193f6]:

    • @​astrojs/internal-helpers@​0.10.3

11.1.2

Patch Changes

  • #17400 c1cf110 Thanks @​tianrking! - Return a 404 instead of a 500 for unknown parameters that match a prerendered dynamic endpoint.

11.1.1

Patch Changes

  • #17658 8b211a5 Thanks @​astrobot-houston! - Fixes an EventEmitter memory leak when serving static pages over keep-alive connections with staticHeaders enabled and CSP (security.csp) active

... (truncated)

Commits

Updates astro from 6.4.4 to 7.3.7

Release notes

Sourced from astro's releases.

astro@7.3.7

Patch Changes

  • #18266 cba76cc Thanks @​astro-factory! - Fixes a build error when a Markdown content collection entry loaded with glob({ deferRender: true }) has a layout frontmatter property. layout is now ignored for content collection entries, as documented.

  • #18287 38f6793 Thanks @​astro-factory! - Fixes astro add cloudflare failing to install dependencies with pnpm v11+ by approving the workerd build script, and shows the package manager's error output when astro add fails to install dependencies

  • #18222 fcf6ed6 Thanks @​mingjunlu! - Fixes an issue where AVIF images were served as image/heif instead of image/avif in the dev server.

  • #18240 de4df06 Thanks @​astro-factory! - Fixes the cache() handler from astro/hono and astro/fetch throwing a TypeError when a cache provider is configured. It now registers the cache provider before rendering, so Astro.cache is available to downstream handlers like pages().

  • #18268 547b572 Thanks @​astro-factory! - Fixes security.checkOrigin rejecting cross-origin requests with non-form content types such as application/json. As documented, the check only applies to unsafe requests that have no content-type header or one of application/x-www-form-urlencoded, multipart/form-data, or text/plain.

astro@7.3.6

Patch Changes

  • #18166 5134d0f Thanks @​astro-factory! - Fixes an intermittent dev server crash when using astro:actions inside a server island with adapters that use a pre-bundled SSR environment (e.g. @astrojs/cloudflare)

  • #18076 8a2df66 Thanks @​astro-factory! - Fixes stale scoped styles during HMR when both markup and <style> are changed in a single save

  • #18252 2d29e7e Thanks @​astro-factory! - Fixes CSS from other pages leaking into a page's <head> in dev when the page imports a module such as astro:config/server.

  • #18000 6724575 Thanks @​barclayd! - Fixes a bug where server islands containing framework components rendered empty in the dev server when using a custom src/fetch.ts

  • #18241 7c5fd6f Thanks @​astro-factory! - Fixes the composable i18n() handler from astro/fetch and astro/hono returning an empty 404 for paths without a locale prefix. It now renders the custom 404 page, matching astro().

  • #18164 1a6997f Thanks @​astro-factory! - Fixes CSS Module HMR in dev when a component is rendered both with and without hydration on the same page. Astro now uses path-based class name hashing in dev mode so that editing CSS declarations no longer changes the generated selectors, allowing Vite's CSS HMR to update styles without a full page reload.

  • #18243 dd29d62 Thanks @​astro-factory! - Fixes context.props being null in middleware and endpoints when the composable astro/hono or astro/fetch actions() handler runs before middleware(), or when pages() runs without middleware()

  • #18193 95d5d16 Thanks @​astro-factory! - Fixes astro build failing on Windows with Node.js 25+ with ERR_INVALID_ARG_VALUE when clearing the output directory hits a transient EPERM error

  • #18220 d6c13a4 Thanks @​astro-factory! - Fixes type errors reported in Astro's built-in <Picture /> and <Font /> components when type-checking a project with tsc and @astrojs/ts-content-mapper

  • #18133 faac481 Thanks @​astro-factory! - Fixes lost request state when Vite discovers server dependencies during a request in Cloudflare dev mode

  • #18146 2af4516 Thanks @​astro-factory! - Fixes CSS imported from an injectScript('page') script being dropped during build

  • #18159 e5f8fe0 Thanks @​astro-factory! - Fixes a hang when a server:defer component is inside a slot of another component in an MDX content collection entry

  • #18246 c3b42ad Thanks @​astro-factory! - Fixes the glob() loader skipping content files whose paths contain # or ?

  • #18248 b97184e Thanks @​astro-factory! - Fixes a bug where page routes added with injectRoute() returned a 404 when i18n.routing.prefixDefaultLocale was true and the route path had no locale prefix

  • #18251 3415263 Thanks @​astro-factory! - Fixes content collection changes being ignored in astro dev after the dev server restarts because of a config change

  • #18226 ad54af0 Thanks @​imharjot! - Fixes Astro.cookies.get() returning undefined for request cookies with empty values

  • #18155 37ab0e4 Thanks @​astro-factory! - Fixes nondeterministic ordering of the server manifest's assets array, ensuring builds with identical inputs produce byte-identical output

... (truncated)

Changelog

Sourced from astro's changelog.

6.4.7

Patch Changes

  • #17035 197e50e Thanks @​astrobot-houston! - Fixes getRelativeLocaleUrl, getAbsoluteLocaleUrl, and getAbsoluteLocaleUrlList to strip trailing slashes when trailingSlash: 'never' is configured

  • #16967 3719765 Thanks @​astrobot-houston! - Fixes double URL-encoded paths returning 400 Bad Request on on-demand routes

    Previously, any URL containing a double-encoded character (like %255B, which is [ encoded twice) was unconditionally rejected with a 400 Bad Request before middleware or route handlers could run. This broke embedded tools like Sanity Studio whose client-side router legitimately produces double-encoded URLs.

    The fix replaces the rejection approach with iterative decoding — multi-level percent-encoding is now fully resolved to its canonical form before being passed to middleware and route matching. This preserves the security fix for CVE-2025-66202 (middleware authorization bypass via double encoding) because middleware now always sees the fully decoded path, making bypass impossible. For example, /api/%2561dmin is decoded to /api/admin, which middleware can correctly block.

  • #17066 2f4d92a Thanks @​matthewp! - Fixes prerendered redirect targets being incorrectly bundled into the SSR function in hybrid mode, causing massive bundle size inflation

  • #16882 621beb7 Thanks @​jettwayio! - fix(render): honour compressHTML when joining head elements

  • #16892 8d753b0 Thanks @​astrobot-houston! - Fixes custom elements in MDX having their children's slot attribute stripped by the JSX runtime

    When custom elements (tags with hyphens like <my-element>) are used in MDX files, the slot HTML attribute on their children is now correctly preserved. Previously, the shared JSX runtime would treat slot as an Astro slot assignment and remove it from the output, breaking Shadow DOM named slot distribution for web components.

  • #16957 544ee76 Thanks @​thelazylamaGit! - Fixes stale inline CSS in server-rendered HTML after CSS file edits during dev

    When editing a CSS file (.css, .scss, etc.) during development, the inline <style> tags in server-rendered HTML would retain old CSS content instead of updating. This caused a brief flash of old CSS (FOUC) on fresh page loads before Vite's client-side HMR corrected the styles.

    The fix ensures that Astro's per-route dev CSS virtual modules are invalidated in both the SSR module graph and the module runner's evaluation cache when a style file changes, so the next page render picks up the fresh CSS.

  • #17044 2220d22 Thanks @​astrobot-houston! - Fixes CSS from client:only islands leaking to unrelated pages when Rollup bundles non-CSS-importing modules into the same chunk as CSS-importing modules

  • #17040 7c4763d Thanks @​astrobot-houston! - Fixes HMR not triggering for files inside the src/middleware/ directory during dev

  • #16672 52fc862 Thanks @​martinheidegger! - Fixes support for numeric IDs in YAML frontmatter when using content collection references

  • #16762 9de80ae Thanks @​alexanderdombroski! - Adds a JSON schema to the Wrangler configuration file generated when running astro add cloudflare

  • #17046 ef771ec Thanks @​ematipico! - Improves the diagnostics emitted when Astro parses incorrect .astro files.

6.4.6

Patch Changes

  • #16765 b10e86e Thanks @​fkatsuhiro! - Fixes an issue where renaming an image file while the dev server is running triggers a build error. Now Astro correctly hot-reloads the image without crashing.

  • #17026 add3df1 Thanks @​matthewp! - Hardens addAttribute to drop attribute names containing characters that are invalid per the HTML spec (", ', >, /, =, whitespace)

  • #17033 ffda27b Thanks @​matthewp! - Validates the request origin against allowedDomains before fetching prerendered error pages. When allowedDomains is configured and the Host header matches, the original origin is used. Otherwise, the fetch falls back to localhost.

6.4.5

Patch Changes

... (truncated)

Commits
  • 25c19fa [ci] release (#18272)
  • 38f6793 fix(astro): approve workerd builds in astro add cloudflare for pnpm v11+ an...
  • 547b572 Restore content-type gate in security.checkOrigin so JSON requests are not bl...
  • fcf6ed6 fix(assets): return requested format from Sharp transform (#18222)
  • bec7d18 Ignore layout frontmatter in Markdown content collection entries with `defe...
  • 71b154f Register cache provider before handleCache runs in composable cache() handler...
  • 05225ac test(content): cover Markdown content entry query in propagated asset wrapper
  • cba76cc Ignore layout frontmatter for deferred Markdown content collection entries
  • e4f8f46 [ci] release (#18120)
  • 95d5d16 Fix emptyDir EPERM fallback to use rmSync instead of rmdirSync for Node 25+ c...
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [sharp](https://github.com/lovell/sharp) to 0.35.5 and updates ancestor dependencies [sharp](https://github.com/lovell/sharp), [@astrojs/node](https://github.com/withastro/astro/tree/HEAD/packages/integrations/node) and [astro](https://github.com/withastro/astro/tree/HEAD/packages/astro). These dependencies need to be updated together.


Updates `sharp` from 0.34.5 to 0.35.5
- [Release notes](https://github.com/lovell/sharp/releases)
- [Commits](lovell/sharp@v0.34.5...v0.35.5)

Updates `@astrojs/node` from 10.1.3 to 11.1.7
- [Release notes](https://github.com/withastro/astro/releases)
- [Changelog](https://github.com/withastro/astro/blob/main/packages/integrations/node/CHANGELOG.md)
- [Commits](https://github.com/withastro/astro/commits/@astrojs/node@11.1.7/packages/integrations/node)

Updates `astro` from 6.4.4 to 7.3.7
- [Release notes](https://github.com/withastro/astro/releases)
- [Changelog](https://github.com/withastro/astro/blob/main/packages/astro/CHANGELOG-v6.md)
- [Commits](https://github.com/withastro/astro/commits/astro@7.3.7/packages/astro)

---
updated-dependencies:
- dependency-name: sharp
  dependency-version: 0.35.5
  dependency-type: indirect
- dependency-name: "@astrojs/node"
  dependency-version: 11.1.7
  dependency-type: direct:production
- dependency-name: astro
  dependency-version: 7.3.7
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 8, 2026
@tenki-reviewer

tenki-reviewer Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Review complete. No issues found — approved ✅.


This PR updates only the tests/sites/astro fixture's dependency versions, moving the Astro site template used in e2e build/deploy tests to the latest major of Astro and its Node adapter.

Files Change
tests/resources/sites/astro/package.json Bump astro from ^6.4.4 to ^7.3.7 and @astrojs/node from ^10.1.3 to ^11.1.7 in the test fixture.

No other files changed; the sibling Astro fixtures (astro-custom-start-command, astro-static) remain on the previous major, which is a minor consistency note rather than a defect.

Reviewed commit: 4cf9fd0

@hansi-codes

hansi-codes Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

🟢 Tier S · Ready to merge

The dependency versions and lockfile are consistent, and the existing Astro site E2E coverage exercises this fixture.

Updates the Astro site test fixture to Astro 7.3.7 and the matching Node adapter 11.1.7. Its lockfile resolves sharp 0.35.5 and the updated transitive dependencies.

Verdict New comments Fixed Still open
💬 Commented 0 0 0

Note

@dependabot[bot] does not have write access to this repository, so Hansi does not approve automatically. A maintainer can review and approve.

📂 Walkthrough · 2
File Change
tests/resources/sites/astro/package.json Bumps the fixture's Astro and Node adapter dependencies.
tests/resources/sites/astro/package-lock.json Refreshes the fixture lockfile for the new dependency versions, including sharp 0.35.5.

Reviewed 4cf9fd0 · Details · Comment @hansi-codes review to re-run, or mention @hansi-codes with a question.

@hansi-codes hansi-codes Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Tier S · Looks good to merge. Summary

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

Security rules

No new WARNING or ERROR findings from security rules.

32 existing findings tracked in .semgrep/baseline.json
  • php.appwrite.guest-write-without-abuse-limit (17)
  • php.appwrite.permissive-write-permission (8)
  • php.appwrite.secret-compare-timing (5)
  • php.appwrite.weak-secret-env-default (2)

Posted by Checks / Rules. Re-runs update this comment in place. Rule details and baseline: .semgrep/README.md.

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

✨ Benchmark results

Comparing main (before) → dependabot/npm_and_yarn/tests/resources/sites/astro/multi-71a1e3bc20 (after).

Metric Before After Change
🚀 Requests/sec 202.72 208.15 ⚪ +2.7%
⏱️ Latency P50 84.26 ms 83.75 ms ⚪ -0.6%
⏱️ Latency P95 205.71 ms 193.07 ms 🟢 -6.1%
Per-scenario breakdown & investigation details

Metrics below reflect the current branch (after). Δ P95 compares against the base.

Scenario P50 (ms) P95 (ms) Requests RPS Δ P95 (ms)
API total 83.75 193.07 12,996 208.15 -12.64
Account 158.2 280.14 684 11.33 -25.76
TablesDB 80.14 151.93 7,068 115.68 -13.3
Storage 78.37 174.96 3,420 57.92 +7.88
Functions 117.06 220.15 1,824 31.58 -15.25

Top API waits (after)

API request Max wait (ms)
functions.create 444.09
storage.files.preview 386.77
account.name.update 374.81
account.prefs.update 362.21
storage.files.create 341.68

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants