Skip to content

deps: upgrade to Astro 7 and Starlight 0.42; fix quickstart go.sum - #463

Merged
vishr merged 2 commits into
masterfrom
deps/astro7-quickstart
Oct 1, 2026
Merged

vishr merged 2 commits into
masterfrom
deps/astro7-quickstart

Conversation

@vishr

@vishr vishr commented Oct 1, 2026

Copy link
Copy Markdown
Member

Follow-up to #462, which merged before these two commits were pushed to its branch.

Dependencies: astro 6.4.7 -> 7.3.5, @astrojs/starlight 0.40.0 -> 0.42.4 (requires astro 7.2.10+), @astrojs/markdown-remark 7.2.0 -> 7.3.1, sharp 0.35.1 -> 0.35.5. The lockfile is regenerated because npm could not resolve the Astro 7 peer range from the old tree. This clears all 21 open Dependabot alerts on site/package-lock.json (1 critical astro advisory fixed in 7.2.8, plus high-severity js-yaml, nanoid, postcss, sharp, smol-toml and svgo advisories); npm audit reports 0 vulnerabilities. No site code changes were needed: Starlight 0.42's new mobile menu markup does not affect our CSS or component overrides (Banner, Footer, Search).

Quickstart: run go mod tidy before go run main.go in all five locales. The program imports echo/v5/middleware, which needs golang.org/x/time; go get of the root package does not record it, so the quickstart failed on a clean machine with a missing go.sum entry (the homepage steps got the same fix in #462).

Validation:

  • 37 Node tests; go vet ./... and go test -race ./...; stable/next production builds, source/translation checks, all routes and internal links/assets, and performance checks pass. Page sizes stay within the recorded baseline.
  • Quickstart program builds in an empty module with the documented steps.
  • Local browser checks: homepage (feature cards, steps, hero terminal, buttons), Pagefind search results and quick links, and the mobile menu at 390px with no horizontal scroll.
  • Astro 7 prints new upstream MODULE_LEVEL_DIRECTIVE warnings for MDX pages and an empty i18n collection warning; they do not affect output. Defining an empty i18n collection only adds a second warning, so it is left out.

The quickstart program imports echo/v5/middleware, which needs
golang.org/x/time. `go get` of the root package does not record it, so
`go run main.go` failed on a clean machine with a missing go.sum entry.
Clears all 21 open Dependabot alerts on site/package-lock.json, including
the critical astro advisory (fixed in 7.2.8) and high-severity js-yaml,
nanoid, postcss, sharp, smol-toml and svgo advisories. `npm audit` reports
0 vulnerabilities.

- astro 6.4.7 -> 7.3.5, @astrojs/starlight 0.40.0 -> 0.42.4 (requires
  astro 7.2.10+), @astrojs/markdown-remark 7.2.0 -> 7.3.1, sharp
  0.35.1 -> 0.35.5.
- The lockfile is regenerated: npm could not resolve the Astro 7 peer
  range from the old tree.

No site code changes were needed. Starlight 0.42's new mobile menu markup
does not affect our CSS or component overrides (Banner, Footer, Search).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant