chore: update dependencies and GitHub Actions - #53
Merged
Merged
Conversation
Website: astro 6.3.6 -> 7.3.3, better-sqlite3 11.10.0 -> 13.0.3,
@types/better-sqlite3 7.6.13 -> 9.6.0. npm audit goes from 10
vulnerabilities (1 critical, in astro) to 0; the astro, esbuild and sharp
advisories are only fixed in astro 7.
Astro 7 defaults compressHTML to 'jsx', which drops a line break next to an
element or an {expression} instead of collapsing it to a space. That glued
Arabic words together on every paginated page ("10000من أصل") and around
links on the home and about pages, so set compressHTML: true to keep the
lossless behaviour of Astro 6.
Python: sqlalchemy 2.0.54, pymysql 1.2.3, ruff 0.16.8, pip 26.2.1, plus
greenlet and typing-extensions.
Actions: actions/checkout and actions/setup-node v6 -> v7.
forzagreen
added a commit
that referenced
this pull request
Sep 20, 2026
The gh-pages build failed at `npm ci` after #53: Missing: @emnapi/core@1.11.3 from lock file Missing: @emnapi/wasi-threads@1.2.3 from lock file The lockfile was written by npm 11.5.1, which does not record the peer dependencies of the optional @napi-rs/wasm-runtime that Astro 7 pulls in. The runner has npm 11.19.0, which requires them. Regenerated with npm 11.19.0; no package version changes.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updates the website, Python and GitHub Actions dependencies.
npm auditgoes from 10 vulnerabilities (1 critical, 7 high) to 0. No data changes:arabterm.db.gzand both dumps are untouched.Website
astrobetter-sqlite3@types/better-sqlite3The critical advisory is in
astroitself (XSS, SSRF, RCE through AVIF optimization), and it,esbuildandsharpare only fixed in Astro 7, so the major bump was required. The other 7 advisories (js-yaml,nanoid,postcss,smol-toml,svgo,vite,devalue) cleared withnpm audit fix.Astro 7 whitespace change
Astro 7 changes the default of
compressHTMLto'jsx', which drops a line break next to an element or an{expression}instead of collapsing it to a space. The templates wrap Arabic sentences across lines, so words were glued together:إلى 10000من أصلinstead ofإلى 10000 من أصل<em>and<strong>The build passed without a warning; this only showed up when comparing the built output. This PR sets
compressHTML: trueinastro.config.mjs, which is the lossless behaviour Astro 6 had. The alternative, adding{" "}in the templates, would break again the next time a sentence is wrapped.Verification
Built the site on Astro 6.4.8 and on Astro 7.3.3 and compared all 593 pages at the DOM level:
A clean
npm ciworks on Node 24, the version the workflow uses. The site was not checked in a browser.Python
uv lock --upgrade:sqlalchemy2.0.49 → 2.0.54,pymysql1.1.3 → 1.2.3,ruff0.15.13 → 0.16.8,pip26.1.1 → 26.2.1, plusgreenletandtyping-extensions.make validatepassesmake search_mariadb term="telescope"returns results against a local MariaDB container (read-only, no dump regenerated)GitHub Actions
actions/checkoutandactions/setup-nodev6 → v7. The other actions were already on their latest major.Neither breaking change applies here: checkout v7 blocks fork-PR checkouts under
pull_request_target/workflow_run, which these workflows do not use, and setup-node v7 drops a dummyNODE_AUTH_TOKENthat only matters when publishing to npm. The workflows could not be run locally;validate-db.ymlruns on this PR because the workflow file changed, andgh-pages.ymlfirst runs on merge.