Skip to content

[ci] release - #18120

Merged
matthewp merged 1 commit into
mainfrom
changeset-release/main
Oct 6, 2026
Merged

matthewp merged 1 commit into
mainfrom
changeset-release/main

Conversation

@astrobot-houston

@astrobot-houston astrobot-houston commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@astrojs/internal-helpers@0.12.0

Minor Changes

  • #18099 6987261 Thanks @renovate! - Adds YAML parsing with timestamp and merge key support, and formats YAML errors consistently across Astro, Markdown, MDX, and Markdoc.

Patch Changes

astro@7.3.6

Patch Changes

  • #18166 5134d0f Thanks @astro-factory! - Fixes an intermittent dev server crash when using astro:actions inside a server island with adapters that use a pre-bundled SSR environment (e.g. @astrojs/cloudflare)

  • #18076 8a2df66 Thanks @astro-factory! - Fixes stale scoped styles during HMR when both markup and <style> are changed in a single save

  • #18252 2d29e7e Thanks @astro-factory! - Fixes CSS from other pages leaking into a page's <head> in dev when the page imports a module such as astro:config/server.

  • #18000 6724575 Thanks @barclayd! - Fixes a bug where server islands containing framework components rendered empty in the dev server when using a custom src/fetch.ts

  • #18241 7c5fd6f Thanks @astro-factory! - Fixes the composable i18n() handler from astro/fetch and astro/hono returning an empty 404 for paths without a locale prefix. It now renders the custom 404 page, matching astro().

  • #18164 1a6997f Thanks @astro-factory! - Fixes CSS Module HMR in dev when a component is rendered both with and without hydration on the same page. Astro now uses path-based class name hashing in dev mode so that editing CSS declarations no longer changes the generated selectors, allowing Vite's CSS HMR to update styles without a full page reload.

  • #18243 dd29d62 Thanks @astro-factory! - Fixes context.props being null in middleware and endpoints when the composable astro/hono or astro/fetch actions() handler runs before middleware(), or when pages() runs without middleware()

  • #18193 95d5d16 Thanks @astro-factory! - Fixes astro build failing on Windows with Node.js 25+ with ERR_INVALID_ARG_VALUE when clearing the output directory hits a transient EPERM error

  • #18220 d6c13a4 Thanks @astro-factory! - Fixes type errors reported in Astro's built-in <Picture /> and <Font /> components when type-checking a project with tsc and @astrojs/ts-content-mapper

  • #18133 faac481 Thanks @astro-factory! - Fixes lost request state when Vite discovers server dependencies during a request in Cloudflare dev mode

  • #18146 2af4516 Thanks @astro-factory! - Fixes CSS imported from an injectScript('page') script being dropped during build

  • #18159 e5f8fe0 Thanks @astro-factory! - Fixes a hang when a server:defer component is inside a slot of another component in an MDX content collection entry

  • #18246 c3b42ad Thanks @astro-factory! - Fixes the glob() loader skipping content files whose paths contain # or ?

  • #18248 b97184e Thanks @astro-factory! - Fixes a bug where page routes added with injectRoute() returned a 404 when i18n.routing.prefixDefaultLocale was true and the route path had no locale prefix

  • #18251 3415263 Thanks @astro-factory! - Fixes content collection changes being ignored in astro dev after the dev server restarts because of a config change

  • #18226 ad54af0 Thanks @imharjot! - Fixes Astro.cookies.get() returning undefined for request cookies with empty values

  • #18155 37ab0e4 Thanks @astro-factory! - Fixes nondeterministic ordering of the server manifest's assets array, ensuring builds with identical inputs produce byte-identical output

  • #18099 6987261 Thanks @renovate! - Adds YAML parsing with timestamp and merge key support, and formats YAML errors consistently across Astro, Markdown, MDX, and Markdoc.

  • #15595 64e4039 Thanks @qzio! - Improves CSRF protection by taking modern browsers headers into account

  • #18215 941bd5e Thanks @ump45nose! - Fixes a runtime ReferenceError for inlined scripts that import a URL with /* @vite-ignore */.

    Astro now inlines scripts after Vite replaces its preload markers, so ignored dynamic imports can remain inline without shipping an unresolved __VITE_PRELOAD__ reference.

  • #18179 6caa659 Thanks @matthewp! - Fixes custom View Transition direction names that are not valid CSS identifiers, such as names starting with a digit or containing spaces. These directions now match their animations correctly.

  • #18250 7eae39b Thanks @astro-factory! - Fixes a 404 for a CSS file that a dynamic import preloads when the imported module uses a component that is also a hydrated island on the same page

  • #18176 7c9d00d Thanks @astro-factory! - Fixes duplicate CSS in production builds when a component is both server-rendered and used with client:only on the same page

  • #18245 492e95f Thanks @astro-factory! - Fixes the composable astro/fetch and astro/hono handlers (trailingSlash(), redirects(), actions(), middleware(), and pages()) so they reject over-encoded request paths with a 400 Bad Request, matching astro(). For these requests, redirects() and actions() return the 400 response instead of undefined, so no redirect is issued and no action runs.

  • #18078 0a2ab10 Thanks @manuelgruber! - Fixes Astro.rewrite() and context.rewrite() selecting the wrong route in astro dev when two dynamic routes match the same path

  • #18210 62b13ba Thanks @edmundhung! - Allows Astro CLI commands to install tagged package versions

  • #18069 d39eb97 Thanks @astro-factory! - Fixes a dev server dependency scan failure when an .astro file contains a literal <script in frontmatter or a template expression

  • #18114 c17d920 Thanks @matthewp! - Fixes Astro on StackBlitz and other WebContainer environments

  • #18088 cb767f9 Thanks @astro-factory! - Fixes a MODULE_LEVEL_DIRECTIVE warning during build caused by a stale "use astro:head-inject" directive in content collection propagated asset modules

  • #18247 2b3f73d Thanks @astro-factory! - Fixes actions returning 500 for malformed JSON request bodies and undecodable action names. A SyntaxError from invalid JSON now returns 400 (BAD_REQUEST), and a URIError from a malformed percent-encoded action name now returns 404 (NOT_FOUND).

  • 1d9e910 Thanks @matthewp! - Validates the Host header against security.allowedDomains when using the Node adapter

  • #18249 c7799a4 Thanks @astro-factory! - Fixes the fontsource font provider to resolve variable fonts when using the "Variable" suffix in the font name (e.g. "Inter Variable")

  • #18163 e48da9d Thanks @astro-factory! - Fixes <video muted> losing its muted state after a ClientRouter navigation in Chrome

  • #18244 f67e7f7 Thanks @astro-factory! - Fixes localized error pages such as src/pages/pt/404.astro returning a 200 status when rendered through the pages() handler from astro/fetch or astro/hono

  • #18242 c5275e3 Thanks @astro-factory! - Fixes experimental_AstroContainer output including dev toolbar data-astro-source-file and data-astro-source-loc attributes when rendering components under Vitest

  • Updated dependencies [6987261, 62b13ba]:

    • @astrojs/internal-helpers@0.12.0
    • @astrojs/markdown-satteri@0.4.3

create-astro@5.2.5

Patch Changes

@astrojs/cloudflare@14.3.4

Patch Changes

  • #18213 1e5523d Thanks @astro-factory! - Fixes the globalThis.process shim being prepended to client-side scripts. The shim is now only added to the server output.

  • #18253 78dca00 Thanks @astro-factory! - Fixes the @astrojs/cloudflare/hono usage example so i18n() is mounted before pages(). In the old order, i18n() never ran, so locale redirects and fallbacks were skipped.

  • #18145 02246c9 Thanks @astro-factory! - Fixes dev dependency scan failing when a frontmatter line starts with import.meta or import(

  • #17677 4f85749 Thanks @andreialba! - Fixes remote images without a file extension failing with 400 Unsupported format: null when using the cloudflare-binding image service

    Astro only adds the f (format) parameter to /_image URLs when it can infer a format from the source, and otherwise leaves it off so the image service resolves the format from the source itself. Extensionless remote images, such as GitHub avatars like https://avatars.githubusercontent.com/u/1234, take that path. The image transform endpoint now falls back to the source's media type when f is absent, passing SVG sources through unchanged and encoding everything else as WebP. This also fixes SVG images, which are requested as f=svg and previously failed the same way.

  • #18057 8db3024 Thanks @asqar! - Fixes astro build failing with fetch failed / connect ECONNREFUSED 127.0.0.1:<port> during prerendering on hosts where localhost resolves to IPv6

    The prerenderer started its Vite preview server with host: 'localhost' and then built the fetch URL by re-stating that same hostname. localhost was therefore resolved twice, independently — once by listen() to pick a bind address and once by fetch() to pick a connect address — with nothing making the two agree. On hosts where those resolutions land on different families, the preview server listens on ::1 while fetch dials 127.0.0.1, and every prerender request is refused. The URL is now derived from the address actually bound, so bind and connect agree by construction.

  • Updated dependencies [6987261, 62b13ba]:

    • @astrojs/internal-helpers@0.12.0
    • @astrojs/underscore-redirects@1.0.4

@astrojs/markdoc@2.0.10

Patch Changes

  • #18099 6987261 Thanks @renovate! - Adds YAML parsing with timestamp and merge key support, and formats YAML errors consistently across Astro, Markdown, MDX, and Markdoc.
  • Updated dependencies [6987261, 62b13ba]:
    • @astrojs/internal-helpers@0.12.0

@astrojs/mdx@8.0.3

Patch Changes

  • #18099 6987261 Thanks @renovate! - Adds YAML parsing with timestamp and merge key support, and formats YAML errors consistently across Astro, Markdown, MDX, and Markdoc.
  • Updated dependencies [6987261, 62b13ba]:
    • @astrojs/internal-helpers@0.12.0
    • @astrojs/markdown-satteri@0.4.3

@astrojs/netlify@8.2.7

Patch Changes

  • Updated dependencies [6987261, 62b13ba]:
    • @astrojs/internal-helpers@0.12.0
    • @astrojs/underscore-redirects@1.0.4

@astrojs/node@11.1.7

Patch Changes

  • 1d9e910 Thanks @matthewp! - Validates the Host header against security.allowedDomains when using the Node adapter
  • Updated dependencies [6987261, 62b13ba]:
    • @astrojs/internal-helpers@0.12.0

@astrojs/preact@6.0.6

Patch Changes

  • Updated dependencies [6987261, 62b13ba]:
    • @astrojs/internal-helpers@0.12.0

@astrojs/react@7.0.1

Patch Changes

  • Updated dependencies [6987261, 62b13ba]:
    • @astrojs/internal-helpers@0.12.0

@astrojs/vercel@11.0.12

Patch Changes

  • #18254 36f3a0c Thanks @astro-factory! - Fixes middleware rewrites returning 404 instead of 200 when the 404 page is server-rendered
  • Updated dependencies [6987261, 62b13ba]:
    • @astrojs/internal-helpers@0.12.0

astro-vscode@2.17.1

Patch Changes

@astrojs/markdown-remark@7.3.2

Patch Changes

  • #18099 6987261 Thanks @renovate! - Adds YAML parsing with timestamp and merge key support, and formats YAML errors consistently across Astro, Markdown, MDX, and Markdoc.

  • #18139 d047b5c Thanks @breken-ai! - Fixes Markdown code blocks with languages ending in a symbol, such as c#, c++, and f#, being highlighted as c or f

  • Updated dependencies [6987261, 62b13ba]:

    • @astrojs/internal-helpers@0.12.0

@astrojs/markdown-satteri@0.4.3

Patch Changes

  • Updated dependencies [6987261, 62b13ba]:
    • @astrojs/internal-helpers@0.12.0

@github-actions github-actions Bot added pkg: example Related to an example package (scope) pkg: astro Related to the core `astro` package (scope) labels Sep 24, 2026
@astro-factory

astro-factory Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Release security review

Passed

No release-blocking vulnerabilities were found.

Reviewed commit: b9dbbb8

@astrobot-houston
astrobot-houston force-pushed the changeset-release/main branch 6 times, most recently from e0bff7d to c017265 Compare September 26, 2026 15:37
@github-actions github-actions Bot added the pkg: integration Related to any renderer integration (scope) label Sep 26, 2026
@astrobot-houston
astrobot-houston force-pushed the changeset-release/main branch 3 times, most recently from 87f27a7 to 85f69d2 Compare September 27, 2026 18:29
@github-actions github-actions Bot added the feat: markdown Related to Markdown (scope) label Sep 27, 2026
@github-actions github-actions Bot added pkg: react Related to React (scope) pkg: preact Related to Preact (scope) labels Sep 28, 2026
@astrobot-houston
astrobot-houston force-pushed the changeset-release/main branch 13 times, most recently from 62db7d9 to b368488 Compare September 29, 2026 09:24
@astrobot-houston
astrobot-houston force-pushed the changeset-release/main branch 2 times, most recently from 6d5f83a to 4f97fb4 Compare October 2, 2026 12:11
@astrobot-houston
astrobot-houston force-pushed the changeset-release/main branch 4 times, most recently from 58a2128 to b39722f Compare October 5, 2026 12:55
@github-actions github-actions Bot added the pkg: create-astro Related to the `create-astro` package (scope) label Oct 5, 2026
@astrobot-houston
astrobot-houston force-pushed the changeset-release/main branch 16 times, most recently from 2e10b3b to ce1690f Compare October 6, 2026 00:42
@matthewp
matthewp merged commit e4f8f46 into main Oct 6, 2026
29 checks passed
@matthewp
matthewp deleted the changeset-release/main branch October 6, 2026 12:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

feat: markdown Related to Markdown (scope) pkg: astro Related to the core `astro` package (scope) pkg: create-astro Related to the `create-astro` package (scope) pkg: example Related to an example package (scope) pkg: integration Related to any renderer integration (scope) pkg: preact Related to Preact (scope) pkg: react Related to React (scope)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants