chore(website): upgrade to Astro 7, Starlight 0.42 and @astrojs/cloudflare 14 - #85
Merged
Merged
Conversation
…flare 14 Fixes the open Astro security alerts on the docs site, including the critical image optimization RCE (fixed in 7.2.8). - wrangler main points at @astrojs/cloudflare/entrypoints/server - imageService 'compile' keeps build-time image handling (the v14 default would switch to the Cloudflare Images binding) - prerenderEnvironment 'node' and wasm32 installs for Starlight's Markdown pipeline (satteri), which resolves to its wasm build in the Worker bundle - compressHTML stays true, session: false (no SESSION KV namespace) - wrangler ^4.146 for the new adapter
This was referenced Oct 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes the open Astro security alerts on the docs site, including the critical image optimization RCE (fixed in 7.2.8). Replaces #82, which didn't build. Website only, no package changes.
wrangler.jsoncmainnow points at@astrojs/cloudflare/entrypoints/server. The build writesdist/server/wrangler.jsonwith the same routes, observability and assets settings.imageService: 'compile'keeps build-time image handling. The v14 default would switch to the Cloudflare Images binding.package.jsontells pnpm to also install wasm32 builds, and the docs prerender in Node (prerenderEnvironment: 'node') like the old adapter did.compressHTML: truekeeps the HTML output the same, andsession: falsestops the adapter from adding aSESSIONKV namespace.Checked on Node 22 with pnpm 9.15: frozen install,
pnpm -r build, typecheck and 156 tests pass. Ran the built Worker withwrangler dev: all 19 docs pages and the 404 are there (matches the live sitemap), status codes match production,/api/chatstreams and answers the CORS preflight, andgetSecretstill reads Worker secrets (checked/api/visitorsagainst a local stand-in for Upstash). Landing page and docs look the same as production, with no console errors. Worker bundle is about 660 KB gzipped.