Skip to content

chore(website): upgrade to Astro 7, Starlight 0.42 and @astrojs/cloudflare 14 - #85

Merged
anurag629 merged 1 commit into
devfrom
security/astro-7
Oct 1, 2026
Merged

anurag629 merged 1 commit into
devfrom
security/astro-7

Conversation

@anurag629

Copy link
Copy Markdown
Member

Fixes the open Astro security alerts on the docs site, including the critical image optimization RCE (fixed in 7.2.8). Replaces #82, which didn't build. Website only, no package changes.

  • astro 7.3.5, @astrojs/starlight 0.42.5, @astrojs/cloudflare 14.3.3, @astrojs/react 7, @astrojs/sitemap 3.7.4, tailwindcss 4.3.3, wrangler ^4.146 (needed by the adapter)
  • wrangler.jsonc main now points at @astrojs/cloudflare/entrypoints/server. The build writes dist/server/wrangler.json with the same routes, observability and assets settings.
  • imageService: 'compile' keeps build-time image handling. The v14 default would switch to the Cloudflare Images binding.
  • Starlight's Markdown pipeline (satteri) resolves to its wasm build inside the Worker bundle, so the root package.json tells pnpm to also install wasm32 builds, and the docs prerender in Node (prerenderEnvironment: 'node') like the old adapter did.
  • compressHTML: true keeps the HTML output the same, and session: false stops the adapter from adding a SESSION KV namespace.

Checked on Node 22 with pnpm 9.15: frozen install, pnpm -r build, typecheck and 156 tests pass. Ran the built Worker with wrangler dev: all 19 docs pages and the 404 are there (matches the live sitemap), status codes match production, /api/chat streams and answers the CORS preflight, and getSecret still reads Worker secrets (checked /api/visitors against a local stand-in for Upstash). Landing page and docs look the same as production, with no console errors. Worker bundle is about 660 KB gzipped.

…flare 14

Fixes the open Astro security alerts on the docs site, including the
critical image optimization RCE (fixed in 7.2.8).

- wrangler main points at @astrojs/cloudflare/entrypoints/server
- imageService 'compile' keeps build-time image handling (the v14
  default would switch to the Cloudflare Images binding)
- prerenderEnvironment 'node' and wasm32 installs for Starlight's
  Markdown pipeline (satteri), which resolves to its wasm build in the
  Worker bundle
- compressHTML stays true, session: false (no SESSION KV namespace)
- wrangler ^4.146 for the new adapter
@anurag629
anurag629 merged commit 2c68beb into dev Oct 1, 2026
1 check passed
@anurag629
anurag629 deleted the security/astro-7 branch October 1, 2026 18:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant