Files
vercel__workflow/workbench/astro/package.json
Pranay Prakash b92dfbb94d fix(deps): upgrade astro to 6.4.6 to resolve CVE-2026-54299 (#2457)
Astro <6.4.6 is vulnerable to CVE-2026-54299 (GHSA-2pvr-wf23-7pc7, host
header SSRF in prerendered error page fetch). The fix only exists in the
6.x line — there is no 5.x backport — so this bumps:

- workbench/astro: astro ^6.4.6, @astrojs/node 10.1.4, @astrojs/vercel ^10.0.8
- packages/astro: astro devDependency 6.4.6 (typecheck only, not shipped)

Removes both vulnerable astro@5.16.3 and astro@5.18.0 from the lockfile.
Verified the example app builds under both the node and vercel adapters.

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-16 14:18:36 -07:00

29 lines
794 B
JSON

{
"name": "@workflow/example-astro",
"private": true,
"type": "module",
"version": "0.0.0",
"scripts": {
"generate:workflows": "node ../scripts/generate-workflows-registry.js ./src/workflows src/lib/_workflows.ts",
"predev": "pnpm generate:workflows",
"prebuild": "pnpm generate:workflows",
"dev": "astro dev",
"build": "astro build",
"preview": "astro preview",
"astro": "astro",
"start": "node scripts/start-with-pg.mjs"
},
"dependencies": {
"@astrojs/node": "10.1.4",
"@astrojs/vercel": "^10.0.8",
"ai": "catalog:",
"astro": "^6.4.6",
"lodash.chunk": "^4.2.0",
"openai": "6.9.0",
"workflow": "workspace:*",
"@workflow/ai": "workspace:*",
"@workflow/world-postgres": "workspace:*",
"zod": "catalog:"
}
}