Skip to content

security: bump astro 5.18.2 -> 7.3.3 in docs-site (critical RCE) - #371

Merged
dawsbot merged 1 commit into
masterfrom
security/astro-7
Sep 23, 2026
Merged

dawsbot merged 1 commit into
masterfrom
security/astro-7

Conversation

@dawsbot

@dawsbot dawsbot commented Sep 23, 2026

Copy link
Copy Markdown
Owner

Closes the last critical advisory in this repo.

eeth.dev is built from docs-site/, which has its own lockfile — so an npm audit run at the repo root misses it entirely. That's how this one stayed hidden.

Advisory Severity Fixed in
GHSA-26w7-cxv4-gfx2 — Astro: remote code execution through AVIF image optimization critical 7.2.8

Same bug class as the Next.js AVIF RCE already patched in www and drain.

Versions

Package From To Why
astro 5.18.2 7.3.3 ≥ 7.2.8, patched
@astrojs/starlight 0.32.6 0.42.2 peer astro ^7.2.10
starlight-typedoc 0.21.5 0.23.1 peer starlight >=0.39.0
@astrojs/markdown-remark — 7.3.1 new, required
sharp 0.33.5 0.35.4

@astrojs/markdown-remark has to be added explicitly: astro 7 dropped it in favour of @astrojs/markdown-satteri, but starlight still declares it a peer — so nothing pulls it in and starlight resolves to undefined.

Two breaking changes — why dependabot's PR never went green

  1. Starlight 0.33 changed social from an object to an array of link items. Migrated in astro.config.mjs.
  2. typedoc got stricter: moduleResolution: node now errors (TS5107, node10 deprecated), and process was unresolved because tsconfig.docs.json put types at the top level, where tsconfig silently ignores it. Moved types into compilerOptions and switched to moduleResolution: bundler.

tsconfig.docs.json is referenced only by docs-site/astro.config.mjs, so the published library build is untouched.

Verification — against the live site, not just a green build

  • 80 pages build, exit 0
  • Homepage visible text identical to live eeth.dev: 1364 chars both
  • Sitemap route sets identical: 79 routes each
  • docs-site npm audit: 0 vulnerabilities (was 1 critical)

🤖 Generated with Claude Code

Closes the last critical advisory in this repo. eeth.dev is built from
docs-site/, which had its own lockfile and was missed by an audit run at the
repo root:

  GHSA-26w7-cxv4-gfx2  Astro: remote code execution through AVIF image
                       optimization. Fixed in 7.2.8.

Same bug class as the Next.js AVIF RCE patched in www and drain.

Coherent version set (all published before this environment's registry
cutoff, so `npm install` can actually resolve them):

  astro                     5.18.2  -> 7.3.3   (>= 7.2.8, patched)
  @astrojs/starlight        0.32.6  -> 0.42.2  (peer: astro ^7.2.10)
  starlight-typedoc         0.21.5  -> 0.23.1  (peer: starlight >= 0.39.0)
  @astrojs/markdown-remark  (new)      7.3.1   see below
  sharp                     0.33.5  -> 0.35.4

`@astrojs/markdown-remark` has to be added explicitly: astro 7 dropped it in
favour of @astrojs/markdown-satteri, but starlight still declares it as a
peer, so nothing pulls it in and starlight fails to resolve without it.

Two breaking changes had to be handled, which is why the dependabot PR for
this bump never went green:

  1. Starlight 0.33 changed `social` from an object to an array of link
     items -- migrated in astro.config.mjs.
  2. typedoc now rejects `moduleResolution: node` (TS5107, node10 is
     deprecated) and could not find `process`, because tsconfig.docs.json
     put `types` at the top level where tsconfig ignores it. Moved `types`
     into compilerOptions and switched to `moduleResolution: bundler`.
     tsconfig.docs.json is referenced only by docs-site/astro.config.mjs,
     so the published library build is untouched.

Verified against the live site rather than just a green build:
  - 80 pages build, exit 0
  - homepage visible text identical to live eeth.dev, 1364 chars both
  - sitemap route sets identical, 79 routes each
  - docs-site npm audit: 0 vulnerabilities (was 1 critical)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@vercel

vercel Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
essential-eth Ready Ready Preview Sep 23, 2026 4:16pm UTC

@dawsbot
dawsbot merged commit 2c88d5b into master Sep 23, 2026
2 of 7 checks passed
@dawsbot
dawsbot deleted the security/astro-7 branch September 23, 2026 16:17

This branch was successfully deployed

1 active deployment
Preview — 818a618e Deployed Sep 23, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant