Skip to content

chore(deps): Bump the production-dependencies group across 1 directory with 2 updates - #349

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/website/production-dependencies-c4afd95db7
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/website/production-dependencies-c4afd95db7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor

Bumps the production-dependencies group with 2 updates in the /website directory: astro and marked.

Updates astro from 7.3.5 to 7.3.6

Release notes

Sourced from astro's releases.

astro@7.3.6

Patch Changes

  • #18166 5134d0f Thanks @​astro-factory! - Fixes an intermittent dev server crash when using astro:actions inside a server island with adapters that use a pre-bundled SSR environment (e.g. @astrojs/cloudflare)

  • #18076 8a2df66 Thanks @​astro-factory! - Fixes stale scoped styles during HMR when both markup and <style> are changed in a single save

  • #18252 2d29e7e Thanks @​astro-factory! - Fixes CSS from other pages leaking into a page's <head> in dev when the page imports a module such as astro:config/server.

  • #18000 6724575 Thanks @​barclayd! - Fixes a bug where server islands containing framework components rendered empty in the dev server when using a custom src/fetch.ts

  • #18241 7c5fd6f Thanks @​astro-factory! - Fixes the composable i18n() handler from astro/fetch and astro/hono returning an empty 404 for paths without a locale prefix. It now renders the custom 404 page, matching astro().

  • #18164 1a6997f Thanks @​astro-factory! - Fixes CSS Module HMR in dev when a component is rendered both with and without hydration on the same page. Astro now uses path-based class name hashing in dev mode so that editing CSS declarations no longer changes the generated selectors, allowing Vite's CSS HMR to update styles without a full page reload.

  • #18243 dd29d62 Thanks @​astro-factory! - Fixes context.props being null in middleware and endpoints when the composable astro/hono or astro/fetch actions() handler runs before middleware(), or when pages() runs without middleware()

  • #18193 95d5d16 Thanks @​astro-factory! - Fixes astro build failing on Windows with Node.js 25+ with ERR_INVALID_ARG_VALUE when clearing the output directory hits a transient EPERM error

  • #18220 d6c13a4 Thanks @​astro-factory! - Fixes type errors reported in Astro's built-in <Picture /> and <Font /> components when type-checking a project with tsc and @astrojs/ts-content-mapper

  • #18133 faac481 Thanks @​astro-factory! - Fixes lost request state when Vite discovers server dependencies during a request in Cloudflare dev mode

  • #18146 2af4516 Thanks @​astro-factory! - Fixes CSS imported from an injectScript('page') script being dropped during build

  • #18159 e5f8fe0 Thanks @​astro-factory! - Fixes a hang when a server:defer component is inside a slot of another component in an MDX content collection entry

  • #18246 c3b42ad Thanks @​astro-factory! - Fixes the glob() loader skipping content files whose paths contain # or ?

  • #18248 b97184e Thanks @​astro-factory! - Fixes a bug where page routes added with injectRoute() returned a 404 when i18n.routing.prefixDefaultLocale was true and the route path had no locale prefix

  • #18251 3415263 Thanks @​astro-factory! - Fixes content collection changes being ignored in astro dev after the dev server restarts because of a config change

  • #18226 ad54af0 Thanks @​imharjot! - Fixes Astro.cookies.get() returning undefined for request cookies with empty values

  • #18155 37ab0e4 Thanks @​astro-factory! - Fixes nondeterministic ordering of the server manifest's assets array, ensuring builds with identical inputs produce byte-identical output

  • #18099 6987261 Thanks @​renovate! - Adds YAML parsing with timestamp and merge key support, and formats YAML errors consistently across Astro, Markdown, MDX, and Markdoc.

  • #15595 64e4039 Thanks @​qzio! - Improves CSRF protection by taking modern browsers headers into account

  • #18215 941bd5e Thanks @​ump45nose! - Fixes a runtime ReferenceError for inlined scripts that import a URL with /* @vite-ignore */.

    Astro now inlines scripts after Vite replaces its preload markers, so ignored dynamic imports can remain inline without shipping an unresolved __VITE_PRELOAD__ reference.

  • #18179 6caa659 Thanks @​matthewp! - Fixes custom View Transition direction names that are not valid CSS identifiers, such as names starting with a digit or containing spaces. These directions now match their animations correctly.

  • #18250 7eae39b Thanks @​astro-factory! - Fixes a 404 for a CSS file that a dynamic import preloads when the imported module uses a component that is also a hydrated island on the same page

  • #18176 7c9d00d Thanks @​astro-factory! - Fixes duplicate CSS in production builds when a component is both server-rendered and used with client:only on the same page

... (truncated)

Changelog

Sourced from astro's changelog.

7.3.6

Patch Changes

  • #18166 5134d0f Thanks @​astro-factory! - Fixes an intermittent dev server crash when using astro:actions inside a server island with adapters that use a pre-bundled SSR environment (e.g. @astrojs/cloudflare)

  • #18076 8a2df66 Thanks @​astro-factory! - Fixes stale scoped styles during HMR when both markup and <style> are changed in a single save

  • #18252 2d29e7e Thanks @​astro-factory! - Fixes CSS from other pages leaking into a page's <head> in dev when the page imports a module such as astro:config/server.

  • #18000 6724575 Thanks @​barclayd! - Fixes a bug where server islands containing framework components rendered empty in the dev server when using a custom src/fetch.ts

  • #18241 7c5fd6f Thanks @​astro-factory! - Fixes the composable i18n() handler from astro/fetch and astro/hono returning an empty 404 for paths without a locale prefix. It now renders the custom 404 page, matching astro().

  • #18164 1a6997f Thanks @​astro-factory! - Fixes CSS Module HMR in dev when a component is rendered both with and without hydration on the same page. Astro now uses path-based class name hashing in dev mode so that editing CSS declarations no longer changes the generated selectors, allowing Vite's CSS HMR to update styles without a full page reload.

  • #18243 dd29d62 Thanks @​astro-factory! - Fixes context.props being null in middleware and endpoints when the composable astro/hono or astro/fetch actions() handler runs before middleware(), or when pages() runs without middleware()

  • #18193 95d5d16 Thanks @​astro-factory! - Fixes astro build failing on Windows with Node.js 25+ with ERR_INVALID_ARG_VALUE when clearing the output directory hits a transient EPERM error

  • #18220 d6c13a4 Thanks @​astro-factory! - Fixes type errors reported in Astro's built-in <Picture /> and <Font /> components when type-checking a project with tsc and @astrojs/ts-content-mapper

  • #18133 faac481 Thanks @​astro-factory! - Fixes lost request state when Vite discovers server dependencies during a request in Cloudflare dev mode

  • #18146 2af4516 Thanks @​astro-factory! - Fixes CSS imported from an injectScript('page') script being dropped during build

  • #18159 e5f8fe0 Thanks @​astro-factory! - Fixes a hang when a server:defer component is inside a slot of another component in an MDX content collection entry

  • #18246 c3b42ad Thanks @​astro-factory! - Fixes the glob() loader skipping content files whose paths contain # or ?

  • #18248 b97184e Thanks @​astro-factory! - Fixes a bug where page routes added with injectRoute() returned a 404 when i18n.routing.prefixDefaultLocale was true and the route path had no locale prefix

  • #18251 3415263 Thanks @​astro-factory! - Fixes content collection changes being ignored in astro dev after the dev server restarts because of a config change

  • #18226 ad54af0 Thanks @​imharjot! - Fixes Astro.cookies.get() returning undefined for request cookies with empty values

  • #18155 37ab0e4 Thanks @​astro-factory! - Fixes nondeterministic ordering of the server manifest's assets array, ensuring builds with identical inputs produce byte-identical output

  • #18099 6987261 Thanks @​renovate! - Adds YAML parsing with timestamp and merge key support, and formats YAML errors consistently across Astro, Markdown, MDX, and Markdoc.

  • #15595 64e4039 Thanks @​qzio! - Improves CSRF protection by taking modern browsers headers into account

  • #18215 941bd5e Thanks @​ump45nose! - Fixes a runtime ReferenceError for inlined scripts that import a URL with /* @vite-ignore */.

    Astro now inlines scripts after Vite replaces its preload markers, so ignored dynamic imports can remain inline without shipping an unresolved __VITE_PRELOAD__ reference.

  • #18179 6caa659 Thanks @​matthewp! - Fixes custom View Transition direction names that are not valid CSS identifiers, such as names starting with a digit or containing spaces. These directions now match their animations correctly.

  • #18250 7eae39b Thanks @​astro-factory! - Fixes a 404 for a CSS file that a dynamic import preloads when the imported module uses a component that is also a hydrated island on the same page

... (truncated)

Commits
  • e4f8f46 [ci] release (#18120)
  • 95d5d16 Fix emptyDir EPERM fallback to use rmSync instead of rmdirSync for Node 25+ c...
  • c5275e3 Skip dev toolbar source annotations when compiling in Vite test mode (#18162)...
  • cb767f9 Remove dead use astro:head-inject directive that caused rolldown MODULE_LEV...
  • 8a2df66 Clear stale compile metadata in HMR when markup and style change together (#1...
  • c7799a4 Support "Variable" suffix in fontsource font family names (#18249)
  • 2b3f73d Return proper action errors for malformed JSON bodies and undecodable action ...
  • 2d29e7e Stop dev-mode CSS collector from crossing page boundaries via `virtual:astro:...
  • c3b42ad fix(content): handle # and ? in glob() loader file paths (#18246)
  • 3415263 Re-initialize content layer after in-place dev server restart (#18251)
  • Additional commits viewable in compare view

Updates marked from 18.0.14 to 18.1.0

Release notes

Sourced from marked's releases.

v18.1.0

18.1.0 (2026-10-05)

Bug Fixes

  • avoid cubic backtracking on unicode whitespace in a link destination (#4106) (0d20220)
  • load CLI configs with top-level await (#4100) (c61543e)
  • reject unbalanced parentheses in link destinations (#4107) (3363c99)

Features

  • add linkParenPossible to lexer state to fail fast for link token generation (#4070) (4ee44f7)
Commits
  • e809386 chore(release): 18.1.0 [skip ci]
  • 3363c99 fix: reject unbalanced parentheses in link destinations (#4107)
  • 0d20220 fix: avoid cubic backtracking on unicode whitespace in a link destination (#4...
  • c18a64f chore(deps): bump undici (#4122)
  • 4ee44f7 feat: add linkParenPossible to lexer state to fail fast for link token genera...
  • c61543e fix: load CLI configs with top-level await (#4100)
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…y with 2 updates

Bumps the production-dependencies group with 2 updates in the /website directory: [astro](https://github.com/withastro/astro/tree/HEAD/packages/astro) and [marked](https://github.com/markedjs/marked).


Updates `astro` from 7.3.5 to 7.3.6
- [Release notes](https://github.com/withastro/astro/releases)
- [Changelog](https://github.com/withastro/astro/blob/main/packages/astro/CHANGELOG.md)
- [Commits](https://github.com/withastro/astro/commits/astro@7.3.6/packages/astro)

Updates `marked` from 18.0.14 to 18.1.0
- [Release notes](https://github.com/markedjs/marked/releases)
- [Commits](markedjs/marked@v18.0.14...v18.1.0)

---
updated-dependencies:
- dependency-name: astro
  dependency-version: 7.3.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: marked
  dependency-version: 18.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from a team as a code owner October 9, 2026 20:49
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 9, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants