Skip to content

fix: update astro to ^6.4.6 to resolve CVE-2026-54299, CVE-2026-50146, CVE-2026-54298#244

Open
liliwilson wants to merge 1 commit into
mainfrom
independabot/astro-CVE-2026-54299
Open

fix: update astro to ^6.4.6 to resolve CVE-2026-54299, CVE-2026-50146, CVE-2026-54298#244
liliwilson wants to merge 1 commit into
mainfrom
independabot/astro-CVE-2026-54299

Conversation

@liliwilson

Copy link
Copy Markdown
Contributor

Bumps astro from 6.1.10 to 6.4.8 (^6.4.6), resolving three Dependabot alerts:

What changed: Updated astro constraint in package.json from ^6.1.10 to ^6.4.6. Lock file resolves to 6.4.8.

Verification: npm audit after update shows zero high-severity astro vulnerabilities.

This PR was generated with Oz.

…CVE-2026-54298

Bumps astro from 6.1.10 to 6.4.8 (^6.4.6), resolving:
- CVE-2026-54299 (GHSA-2pvr-wf23-7pc7): Host header SSRF in prerendered error page fetch (high, cvss 7.5)
- CVE-2026-50146 (GHSA-8hv8-536x-4wqp): Reflected XSS via unescaped slot name (high, cvss 7.1)
- CVE-2026-54298 (GHSA-jrpj-wcv7-9fh9): XSS via Unescaped Attribute Names in Spread Props (moderate, cvss 4.2)

Co-Authored-By: Oz <oz-agent@warp.dev>
@cla-bot cla-bot Bot added the cla-signed label Jun 22, 2026
@vercel

vercel Bot commented Jun 22, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
docs Error Error Jun 22, 2026 1:06pm

Request Review

@oz-for-oss

oz-for-oss Bot commented Jun 22, 2026

Copy link
Copy Markdown
Contributor

@liliwilson

I'm starting a first review of this pull request.

You can view the conversation on Warp.

I completed the review and no human review was requested for this pull request.

Comment /oz-review on this pull request to retrigger a review (up to 3 times on the same pull request).

Powered by Oz

@oz-for-oss oz-for-oss Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Overview

This PR updates astro from 6.1.10 to ^6.4.6 and refreshes the lockfile to resolve the listed Astro CVEs. The diff is limited to dependency metadata in package.json and package-lock.json.

Concerns

  • No blocking correctness or security concerns found in the changed lines.
  • No approved or repository spec context was available, so no spec-drift findings apply.

Verdict

Found: 0 critical, 0 important, 0 suggestions

Approve

Comment /oz-review on this pull request to retrigger a review (up to 3 times on the same pull request).

Powered by Oz

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants