Skip to content

deps: bump the all-js-deps group with 3 updates - #78

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bun/all-js-deps-5f1d5c4af2
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bun/all-js-deps-5f1d5c4af2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps the all-js-deps group with 3 updates: @astrojs/mdx, astro and wrangler.

Updates @astrojs/mdx from 8.0.1 to 8.0.2

Release notes

Sourced from @​astrojs/mdx's releases.

@​astrojs/mdx@​8.0.2

Patch Changes

  • #18036 f4444eb Thanks @​astro-factory! - Fixes an incompatibility where @astrojs/mdx v8 could be installed with astro versions that bundle an older @astrojs/markdown-satteri lacking MDX support. Also improves the error message when the processor is too old to suggest updating astro itself.
  • Updated dependencies [3fd16ee, 8358d59]:
    • @​astrojs/markdown-satteri@​0.4.2
Changelog

Sourced from @​astrojs/mdx's changelog.

8.0.2

Patch Changes

  • #18036 f4444eb Thanks @​astro-factory! - Fixes an incompatibility where @astrojs/mdx v8 could be installed with astro versions that bundle an older @astrojs/markdown-satteri lacking MDX support. Also improves the error message when the processor is too old to suggest updating astro itself.
  • Updated dependencies [3fd16ee, 8358d59]:
    • @​astrojs/markdown-satteri@​0.4.2
Commits

Updates astro from 7.3.3 to 7.3.5

Release notes

Sourced from astro's releases.

astro@7.3.5

Patch Changes

  • #17736 2b8b2e8 Thanks @​ematipico! - Adds a new container function called renderComponent(), which renders Astro components with inlined styles and scripts.

    Users must import the component with the new ?container query string:

    import { experimental_AstroContainer } from "astro/container";
    import TodoList from "../components/TodoList.astro?container";
    const container = await experimental_AstroContainer.create();
    const _string = container.renderComponent(TodoList);

astro@7.3.4

Patch Changes

  • #18063 40896ac Thanks @​adamchal! - Fixes incremental builds repeatedly rendering unchanged pages when modules or compiled CSS reference bundled assets.

  • #18053 cf5d72f Thanks @​Princesseuh! - Improves the astro check error shown for TypeScript 7. The command now explains that TypeScript 7 is not currently supported and provides instructions for experimentally type-checking Astro files with TypeScript 7.1 and @astrojs/ts-content-mapper.

  • #18086 795a7e4 Thanks @​ump45nose! - Fix double-escaped ampersands in Markdown image alt and title attributes. The __ASTRO_IMAGE_ round-trip now decodes the numeric (&) and named (&) character references the Markdown processors emit, so an & in an alt or title is escaped exactly once in the final HTML instead of twice.

  • #18074 0429805 Thanks @​SurefireStudios! - Fix three error names that did not match their documented reference. MissingLocale, MissingIndexForInternationalization and NoManifestAvailable reported names ending in Error in the dev overlay, while their error reference pages are published under the unsuffixed names, so the name shown to users could not be found in the docs.

  • #18007 2245837 Thanks @​L4XB! - Fixes the dev server re-evaluating the whole server module graph on every request. The astro:head-metadata plugin invalidated its component metadata virtual module from its own transform hook, so each evaluation of that module scheduled the next one. Adapters that run requests outside Vite's module runner, such as @astrojs/cloudflare, paid for a full re-evaluation of the server graph on every request for the lifetime of the process.

  • #18096 43657c4 Thanks @​matthewp! - Fixes domain-based i18n routing to respect security.allowedDomains when selecting a locale from request host headers

  • #18043 8a53a8b Thanks @​astro-factory! - Fixes image.responsiveStyles emitting invalid object-position CSS values for same-axis keyword pairs (top bottom, left right, etc.)

  • #18029 c08252d Thanks @​matthewp! - Runs astro dev and astro preview in the foreground when an AI agent is detected on Windows, allowing the agent to manage the process lifetime. Pass --background explicitly to request an Astro-managed background process. Agent-inferred backgrounding remains enabled on other platforms.

  • Updated dependencies [3fd16ee, 8358d59]:

    • @​astrojs/markdown-satteri@​0.4.2
Changelog

Sourced from astro's changelog.

7.3.5

Patch Changes

  • #17736 2b8b2e8 Thanks @​ematipico! - Adds a new container function called renderComponent(), which renders Astro components with inlined styles and scripts.

    Users must import the component with the new ?container query string:

    import { experimental_AstroContainer } from "astro/container";
    import TodoList from "../components/TodoList.astro?container";
    const container = await experimental_AstroContainer.create();
    const _string = container.renderComponent(TodoList);

7.3.4

Patch Changes

  • #18063 40896ac Thanks @​adamchal! - Fixes incremental builds repeatedly rendering unchanged pages when modules or compiled CSS reference bundled assets.

  • #18053 cf5d72f Thanks @​Princesseuh! - Improves the astro check error shown for TypeScript 7. The command now explains that TypeScript 7 is not currently supported and provides instructions for experimentally type-checking Astro files with TypeScript 7.1 and @astrojs/ts-content-mapper.

  • #18086 795a7e4 Thanks @​ump45nose! - Fix double-escaped ampersands in Markdown image alt and title attributes. The __ASTRO_IMAGE_ round-trip now decodes the numeric (&) and named (&) character references the Markdown processors emit, so an & in an alt or title is escaped exactly once in the final HTML instead of twice.

  • #18074 0429805 Thanks @​SurefireStudios! - Fix three error names that did not match their documented reference. MissingLocale, MissingIndexForInternationalization and NoManifestAvailable reported names ending in Error in the dev overlay, while their error reference pages are published under the unsuffixed names, so the name shown to users could not be found in the docs.

  • #18007 2245837 Thanks @​L4XB! - Fixes the dev server re-evaluating the whole server module graph on every request. The astro:head-metadata plugin invalidated its component metadata virtual module from its own transform hook, so each evaluation of that module scheduled the next one. Adapters that run requests outside Vite's module runner, such as @astrojs/cloudflare, paid for a full re-evaluation of the server graph on every request for the lifetime of the process.

  • #18096 43657c4 Thanks @​matthewp! - Fixes domain-based i18n routing to respect security.allowedDomains when selecting a locale from request host headers

  • #18043 8a53a8b Thanks @​astro-factory! - Fixes image.responsiveStyles emitting invalid object-position CSS values for same-axis keyword pairs (top bottom, left right, etc.)

  • #18029 c08252d Thanks @​matthewp! - Runs astro dev and astro preview in the foreground when an AI agent is detected on Windows, allowing the agent to manage the process lifetime. Pass --background explicitly to request an Astro-managed background process. Agent-inferred backgrounding remains enabled on other platforms.

  • Updated dependencies [3fd16ee, 8358d59]:

    • @​astrojs/markdown-satteri@​0.4.2
Commits

Updates wrangler from 4.134.0 to 4.139.0

Release notes

Sourced from wrangler's releases.

wrangler@4.139.0

Minor Changes

  • #15792 479e1e8 Thanks @​flakey5! - Configure SSH for experimental Durable Object-managed Containers

    Set containers[].ssh and containers[].authorized_keys when using scheduling_policy: "durable_object". These are application-wide settings that follow the same rules as the existing Durable Object-managed Container settings: normal deployments create missing applications and update explicitly configured values, while omitted settings preserve the existing application configuration.

    // wrangler.jsonc
    {
      "containers": [
        {
          "name": "sandbox",
          "class_name": "Sandbox",
          "scheduling_policy": "durable_object",
          "ssh": { "enabled": true },
          "authorized_keys": [
            { "name": "laptop", "public_key": "ssh-ed25519 AAAA..." }
          ]
        }
      ]
    }
  • #15648 52c0e9f Thanks @​tpmmorris! - Expose configured Cron Triggers to local development consumers

    Wrangler now passes the active environment's exact Cron Trigger expressions to Miniflare so Local Explorer can display them. Headless agent sessions also advertise the Local Explorer scheduled invocation API.

  • #15786 bdda4c3 Thanks @​ThomasRubini! - Support UDP connect handlers in local development

    The experimental connect configuration now accepts protocol: "udp", with optional idle_timeout_ms and max_pending_bytes settings. UDP datagrams are delivered to the Worker's connect() handler using workerd's value-mode socket streams, and can be tested with Miniflare#dispatchConnect({ protocol: "udp" }).

  • #15779 fc3cbaa Thanks @​Naapperas! - Support workflow entries in the exports configuration map

    A Worker can now declare the Workflows it defines in exports, keyed by the WorkflowEntrypoint class name:

    {
      "exports": {
        "MyWorkflow": {
          "type": "workflow",
          "name": "my-workflow",
          "limits": { "steps": 100 },
          "schedules": "0 * * * *"
        }
      }
    }

    A workflow export accepts the same settings as a workflows binding: limits, concurrency, schedules, and default_retention. wrangler deploy and wrangler versions upload send these entries to the upload API by name, and wrangler deploy and wrangler triggers deploy provision the Workflow with its settings, just as they do for workflows bindings owned by the Worker. A Workflow may be declared both as a binding and as an export, as long as both declarations use the same class and do not set the same setting to different values. A binding to another Worker's Workflow cannot share a name with an export. @cloudflare/config adds the matching exports.workflow() helper. Local development does not yet act on these entries.

... (truncated)

Commits
  • c59dae6 Version Packages (#15828)
  • 15799d4 [wrangler] Update smol-toml to 1.9.0 (#15838)
  • 479e1e8 Allow ssh config for DO containers (#15792)
  • 52c0e9f Add backend support for cron triggers in local explorer (#15648)
  • fc3cbaa [workers-utils,miniflare,wrangler] Accept workflow entries in the exports con...
  • cd60c9c [wrangler] chore: Show --jurisdiction flag in KV Create Namespace help (#15803)
  • bdda4c3 [wrangler] Support UDP connect handlers for local development (#15786)
  • 8d7e380 Version Packages (#15813)
  • 8fade73 fix(workers-utils): standardize Zod validation errors (#15806)
  • 6e77c53 Use CLOUDFLARE_PREVIEW_BUILD environment variable for preview delegation (#15...
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the all-js-deps group with 3 updates: [@astrojs/mdx](https://github.com/withastro/astro/tree/HEAD/packages/integrations/mdx), [astro](https://github.com/withastro/astro/tree/HEAD/packages/astro) and [wrangler](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/wrangler).


Updates `@astrojs/mdx` from 8.0.1 to 8.0.2
- [Release notes](https://github.com/withastro/astro/releases)
- [Changelog](https://github.com/withastro/astro/blob/main/packages/integrations/mdx/CHANGELOG.md)
- [Commits](https://github.com/withastro/astro/commits/@astrojs/mdx@8.0.2/packages/integrations/mdx)

Updates `astro` from 7.3.3 to 7.3.5
- [Release notes](https://github.com/withastro/astro/releases)
- [Changelog](https://github.com/withastro/astro/blob/main/packages/astro/CHANGELOG.md)
- [Commits](https://github.com/withastro/astro/commits/astro@7.3.5/packages/astro)

Updates `wrangler` from 4.134.0 to 4.139.0
- [Release notes](https://github.com/cloudflare/workers-sdk/releases)
- [Commits](https://github.com/cloudflare/workers-sdk/commits/wrangler@4.139.0/packages/wrangler)

---
updated-dependencies:
- dependency-name: "@astrojs/mdx"
  dependency-version: 8.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-js-deps
- dependency-name: astro
  dependency-version: 7.3.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-js-deps
- dependency-name: wrangler
  dependency-version: 4.139.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-js-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 28, 2026
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
goceleris-docs dfcd16a Commit Preview URL

Branch Preview URL
Sep 28 2026, 01:47 AM

@coderabbitai

coderabbitai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: goceleris/docs/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 0afbb656-bb31-4525-a6c7-1db48d6de715

📥 Commits

Reviewing files that changed from the base of the PR and between 54459f9 and dfcd16a.

⛔ Files ignored due to path filters (1)
  • bun.lock is excluded by !**/*.lock
📒 Files selected for processing (1)
  • package.json
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (3)
  • GitHub Check: Workers Builds: goceleris-docs
  • GitHub Check: coverage
  • GitHub Check: build
🧰 Additional context used
🔀 Multi-repo context goceleris/probatorium, goceleris/celeris, goceleris/loadgen

Linked repositories findings

goceleris/probatorium

  • .github/dependabot.yml:117-133 defines the all-js-deps group for the benchmark adapters’ npm directories, covering major, minor, and patch updates. This is consistent with the grouped dependency-update objective. [::goceleris/probatorium::]
  • The repository’s JavaScript manifests and lockfiles contain no references to @astrojs/mdx, astro, or wrangler; these dependencies have no observed benchmark-adapter consumers. [::goceleris/probatorium::]

goceleris/celeris / goceleris/loadgen

  • No JavaScript manifests or references to the upgraded packages were found, so no cross-repository API or runtime compatibility impact was identified. [::goceleris/celeris::] [::goceleris/loadgen::]
🔇 Additional comments (1)
package.json (1)

23-23: LGTM!

Also applies to: 27-27, 37-37


📝 Summary

Summary by CodeRabbit

  • Chores
    • Updated the site’s supporting framework and publishing tools to newer patch releases. These updates keep the underlying platform components current. No changes to user-facing features are included in this release.

Walkthrough

The dependency ranges for @astrojs/mdx, Astro, and Wrangler changed in package.json.

Changes

Dependency updates

Layer / File(s) Summary
Dependency version ranges
package.json:23–27, package.json:37
Updated the version ranges for @astrojs/mdx, Astro, and Wrangler. The Wrangler development dependency range also changed.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to dfcd1

No concrete current-head failure or unresolved dependency-contract risk is established.

Architecture Summary

Architecture risk: 🔵 Low · up to dfcd1

The change affects 1 system.

Changed systems: package.json

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — package.json (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in package.json: Updated @astrojs/mdx, astro, and wrangler dependency versions; the other dependencies in this range are unchanged.
  • observed — Modified behavior in package.json: Updated the Wrangler development dependency range from ^4.134.0 to ^4.139.0.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title uses the required deps: prefix and accurately describes the three dependency updates.
Description check ✅ Passed The description clearly documents the three dependency updates and includes relevant release notes.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Benchmark Provenance ✅ Passed No benchmark figure or results file is changed. The pull request changes only dependency declarations in package.json (lines 25, 29, and 37) and the related bun.lock entries. The changed-path inventor…
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants