Skip to content

chore: update dependencies and GitHub Actions - #53

Merged
forzagreen merged 1 commit into
mainfrom
chore/update-dependencies
Sep 20, 2026
Merged

forzagreen merged 1 commit into
mainfrom
chore/update-dependencies

Conversation

@forzagreen

Copy link
Copy Markdown
Owner

Updates the website, Python and GitHub Actions dependencies. npm audit goes from 10 vulnerabilities (1 critical, 7 high) to 0. No data changes: arabterm.db.gz and both dumps are untouched.

Website

Package From To
astro 6.3.6 7.3.3
better-sqlite3 11.10.0 13.0.3
@types/better-sqlite3 7.6.13 9.6.0

The critical advisory is in astro itself (XSS, SSRF, RCE through AVIF optimization), and it, esbuild and sharp are only fixed in Astro 7, so the major bump was required. The other 7 advisories (js-yaml, nanoid, postcss, smol-toml, svgo, vite, devalue) cleared with npm audit fix.

Astro 7 whitespace change

Astro 7 changes the default of compressHTML to 'jsx', which drops a line break next to an element or an {expression} instead of collapsing it to a space. The templates wrap Arabic sentences across lines, so words were glued together:

  • on all 469 paginated pages: إلى 10000من أصل instead of إلى 10000 من أصل
  • on the home and about pages: spaces lost around inline links, <em> and <strong>

The build passed without a warning; this only showed up when comparing the built output. This PR sets compressHTML: true in astro.config.mjs, which is the lossless behaviour Astro 6 had. The alternative, adding {" "} in the templates, would break again the next time a sentence is wrapped.

Verification

Built the site on Astro 6.4.8 and on Astro 7.3.3 and compared all 593 pages at the DOM level:

  • same set of 678 files
  • JSON downloads byte-identical
  • no text differences in any page
  • remaining differences: scoped-style hash ids, CSS and inline-script minifier output, and extra whitespace-only nodes inside flex/grid containers or between block elements, none of which renders

A clean npm ci works on Node 24, the version the workflow uses. The site was not checked in a browser.

Python

uv lock --upgrade: sqlalchemy 2.0.49 → 2.0.54, pymysql 1.1.3 → 1.2.3, ruff 0.15.13 → 0.16.8, pip 26.1.1 → 26.2.1, plus greenlet and typing-extensions.

  • make validate passes
  • make search_mariadb term="telescope" returns results against a local MariaDB container (read-only, no dump regenerated)

GitHub Actions

actions/checkout and actions/setup-node v6 → v7. The other actions were already on their latest major.

Neither breaking change applies here: checkout v7 blocks fork-PR checkouts under pull_request_target / workflow_run, which these workflows do not use, and setup-node v7 drops a dummy NODE_AUTH_TOKEN that only matters when publishing to npm. The workflows could not be run locally; validate-db.yml runs on this PR because the workflow file changed, and gh-pages.yml first runs on merge.

Website: astro 6.3.6 -> 7.3.3, better-sqlite3 11.10.0 -> 13.0.3,
@types/better-sqlite3 7.6.13 -> 9.6.0. npm audit goes from 10
vulnerabilities (1 critical, in astro) to 0; the astro, esbuild and sharp
advisories are only fixed in astro 7.

Astro 7 defaults compressHTML to 'jsx', which drops a line break next to an
element or an {expression} instead of collapsing it to a space. That glued
Arabic words together on every paginated page ("10000من أصل") and around
links on the home and about pages, so set compressHTML: true to keep the
lossless behaviour of Astro 6.

Python: sqlalchemy 2.0.54, pymysql 1.2.3, ruff 0.16.8, pip 26.2.1, plus
greenlet and typing-extensions.

Actions: actions/checkout and actions/setup-node v6 -> v7.
@forzagreen
forzagreen merged commit 6ec0a2e into main Sep 20, 2026
1 check passed
forzagreen added a commit that referenced this pull request Sep 20, 2026
The gh-pages build failed at `npm ci` after #53:

    Missing: @emnapi/core@1.11.3 from lock file
    Missing: @emnapi/wasi-threads@1.2.3 from lock file

The lockfile was written by npm 11.5.1, which does not record the peer
dependencies of the optional @napi-rs/wasm-runtime that Astro 7 pulls in.
The runner has npm 11.19.0, which requires them. Regenerated with
npm 11.19.0; no package version changes.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant