deps: upgrade to Astro 7 and Starlight 0.42; fix quickstart go.sum - #463
Merged
Merged
Conversation
The quickstart program imports echo/v5/middleware, which needs golang.org/x/time. `go get` of the root package does not record it, so `go run main.go` failed on a clean machine with a missing go.sum entry.
Clears all 21 open Dependabot alerts on site/package-lock.json, including the critical astro advisory (fixed in 7.2.8) and high-severity js-yaml, nanoid, postcss, sharp, smol-toml and svgo advisories. `npm audit` reports 0 vulnerabilities. - astro 6.4.7 -> 7.3.5, @astrojs/starlight 0.40.0 -> 0.42.4 (requires astro 7.2.10+), @astrojs/markdown-remark 7.2.0 -> 7.3.1, sharp 0.35.1 -> 0.35.5. - The lockfile is regenerated: npm could not resolve the Astro 7 peer range from the old tree. No site code changes were needed. Starlight 0.42's new mobile menu markup does not affect our CSS or component overrides (Banner, Footer, Search).
This was referenced Oct 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #462, which merged before these two commits were pushed to its branch.
Dependencies: astro 6.4.7 -> 7.3.5, @astrojs/starlight 0.40.0 -> 0.42.4 (requires astro 7.2.10+), @astrojs/markdown-remark 7.2.0 -> 7.3.1, sharp 0.35.1 -> 0.35.5. The lockfile is regenerated because npm could not resolve the Astro 7 peer range from the old tree. This clears all 21 open Dependabot alerts on
site/package-lock.json(1 critical astro advisory fixed in 7.2.8, plus high-severity js-yaml, nanoid, postcss, sharp, smol-toml and svgo advisories);npm auditreports 0 vulnerabilities. No site code changes were needed: Starlight 0.42's new mobile menu markup does not affect our CSS or component overrides (Banner, Footer, Search).Quickstart: run
go mod tidybeforego run main.goin all five locales. The program importsecho/v5/middleware, which needsgolang.org/x/time;go getof the root package does not record it, so the quickstart failed on a clean machine with a missing go.sum entry (the homepage steps got the same fix in #462).Validation:
go vet ./...andgo test -race ./...; stable/next production builds, source/translation checks, all routes and internal links/assets, and performance checks pass. Page sizes stay within the recorded baseline.MODULE_LEVEL_DIRECTIVEwarnings for MDX pages and an emptyi18ncollection warning; they do not affect output. Defining an emptyi18ncollection only adds a second warning, so it is left out.