Skip to content

build(deps): bump astro from v7.2.10 to v7.3.5, @astrojs/react to v7 - #747

Merged
stasadev merged 2 commits into
mainfrom
dependabot/npm_and_yarn/major-deps-065c6647dd
Oct 5, 2026
Merged

stasadev merged 2 commits into
mainfrom
dependabot/npm_and_yarn/major-deps-065c6647dd

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

The Issue

Dependabot bumped @astrojs/react to v7, and the rest of the dependencies had fallen behind. npm audit reported two transitive findings, http-cache-semantics (high, GHSA-ch52-4w7c-c8xp) and fast-uri (moderate, GHSA-hrr3-gc8f-f4qj).

How This PR Solves The Issue

ddev npx @astrojs/upgrade
ddev npm update

Bumps Astro to v7.3.5 along with @astrojs/markdown-remark, @astrojs/mdx, React 19.3, sass, sharp, and other minor and patch releases in the lock file. npm audit now reports no vulnerabilities.

allowScripts is unchanged, because esbuild@0.28.2 and @parcel/watcher@2.6.0 are still the installed versions, and npm install-scripts ls reports no unreviewed install scripts.

Manual Testing Instructions

ddev start

# check for problems in:
ddev logs
ddev npm run build
ddev npm audit

Compare https://dependabot-npm-and-yarn-majo-kgcv.ddev-com-front-end.pages.dev/ against https://ddev.com/, in both desktop and mobile views:

Release/Deployment Notes

@astrojs/react v7 compiles JSX with Oxc instead of Babel and drops the babel option, which this site does not use.

Astro 7.3 records the dev server in .astro/dev.json. After ddev restart, a new process can reuse the PID stored there, so astro-dev-daemon exits once with "Another astro dev server is already running" and supervisor restarts it a few seconds later.

🤖 Developed with assistance from Claude Code

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 28, 2026
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Deploying ddev-com-front-end with  Cloudflare Pages  Cloudflare Pages

Latest commit: 347101e
Status: ✅  Deploy successful!
Preview URL: https://1e8a425b.ddev-com-front-end.pages.dev
Branch Preview URL: https://dependabot-npm-and-yarn-majo-kgcv.ddev-com-front-end.pages.dev

View logs

@dependabot dependabot Bot added the javascript Pull requests that update javascript code label Sep 28, 2026
@rfay
rfay requested a review from stasadev September 30, 2026 15:01
@rfay
rfay force-pushed the dependabot/npm_and_yarn/major-deps-065c6647dd branch from b2fd6b5 to 5d71abd Compare September 30, 2026 15:01
@stasadev

Copy link
Copy Markdown
Member

I'll bump everything next week.

dependabot Bot and others added 2 commits October 5, 2026 14:32
Bumps the major-deps group with 1 update: [@astrojs/react](https://github.com/withastro/astro/tree/HEAD/packages/integrations/react).


Updates `@astrojs/react` from 6.0.5 to 7.0.0
- [Release notes](https://github.com/withastro/astro/releases)
- [Changelog](https://github.com/withastro/astro/blob/main/packages/integrations/react/CHANGELOG.md)
- [Commits](https://github.com/withastro/astro/commits/@astrojs/react@7.0.0/packages/integrations/react)

---
updated-dependencies:
- dependency-name: "@astrojs/react"
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: major-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
## The Issue

Dependabot bumped `@astrojs/react` to v7, and the rest of the dependencies had fallen behind. `npm audit` reported two transitive findings, `http-cache-semantics` (high, GHSA-ch52-4w7c-c8xp) and `fast-uri` (moderate, GHSA-hrr3-gc8f-f4qj).

## How This PR Solves The Issue

```bash
ddev npx @astrojs/upgrade
ddev npm update
```

Bumps Astro to v7.3.5 along with `@astrojs/markdown-remark`, `@astrojs/mdx`, React 19.3, `sass`, `sharp`, and other minor and patch releases in the lock file. `npm audit` now reports no vulnerabilities.

`allowScripts` is unchanged, because `esbuild@0.28.2` and `@parcel/watcher@2.6.0` are still the installed versions, and `npm install-scripts ls` reports no unreviewed install scripts.

## Manual Testing Instructions

```bash
ddev start

# check for problems in:
ddev logs
ddev npm run build
ddev npm audit
```

Compare https://dependabot-npm-and-yarn-majo-kgcv.ddev-com-front-end.pages.dev/ against https://ddev.com/, in both desktop and mobile views:

- https://dependabot-npm-and-yarn-majo-kgcv.ddev-com-front-end.pages.dev/blog/markdown-features-demo/ vs https://ddev.com/blog/markdown-features-demo/
- https://dependabot-npm-and-yarn-majo-kgcv.ddev-com-front-end.pages.dev/get-started/ vs https://ddev.com/get-started/
- Site search and the theme toggle

## Release/Deployment Notes

`@astrojs/react` v7 compiles JSX with Oxc instead of Babel and drops the `babel` option, which this site does not use.

Astro 7.3 records the dev server in `.astro/dev.json`. After `ddev restart`, a new process can reuse the PID stored there, so `astro-dev-daemon` exits once with "Another astro dev server is already running" and supervisor restarts it a few seconds later.

🤖 Developed with assistance from [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@stasadev
stasadev force-pushed the dependabot/npm_and_yarn/major-deps-065c6647dd branch from 5d71abd to 347101e Compare October 5, 2026 11:43
@stasadev stasadev changed the title build(deps): bump @astrojs/react from 6.0.5 to 7.0.0 in the major-deps group build(deps): bump astro from v7.2.10 to v7.3.5, @astrojs/react to v7 Oct 5, 2026
stasadev added a commit to stasadev/ddev.com that referenced this pull request Oct 5, 2026
…le docs

## The Issue

`AGENTS.md` had grown to 304 lines, all loaded in every session, although most of it applies only to blog content, images, or commits. Nothing enforced its rules, and `.gitignore` ignored all of `.claude`, so no shared Claude Code configuration could be committed. `ddev textlint` passed on errors it could not fix, because `textlint --fix` exits 0 when they remain, so CI failed where the local check had passed. README.md, README_SPONSOR.md, MARKDOWN_FORMATTING.md, and FORK_PREVIEW_SETUP.md had drifted from the code.

## How This PR Solves The Issue

Follows ddev/ddev#8805 and its follow-ups. `AGENTS.md` keeps what applies to every change and links the rest:

- `.claude/rules/content.md` (blog posts, schema, links, images) and `.claude/rules/comments.md` load only for the files they cover.
- Skills: `bump-deps` documents the dependency bump from ddev#601, ddev#637, ddev#685, ddev#734, and ddev#747, including `allowScripts`. `add-sponsor` replaces README_SPONSOR.md, and only needs the sponsor's website. `ddev-commit` holds the commit and PR rules, and `blog-images` the screenshot steps, now with a shorter FEATURE_IMAGE_GUIDE.md as `feature-banner.md`.
- `.claude/settings.json` denies `git push`, allows read-only `gh` commands and the `ddev` checks, and adds two hooks. Before `git commit`, the check-only prettier and textlint run as in CI. After an edit, `ddev prettier` runs on that file, and `ddev textlint` too under `src/content/`.
- `ddev prettier` and `ddev textlint` take optional file arguments, and `ddev textlint` checks again after fixing.
- `.gitignore` ignores only the personal files the Claude Code docs list.

The docs corrections include blog categories, the dev server port, page paths, image conversion to WebP, external link behavior, feature image sizes, the unused `squareLogo`, the theme toggle, and the fork preview workflows. Prettier has no Astro plugin, so `AGENTS.md` now says nothing formats `.astro` files. README.md is shorter, with setup steps that `AGENTS.md` and the skills no longer repeat.

## Manual Testing Instructions

```bash
ddev start
ddev prettier src/lib/api.ts             # formats one file
ddev textlint                             # fixes, then reports anything left
```

Start a new Claude Code session on this branch, then confirm that `/bump-deps`, `/add-sponsor`, `/ddev-commit`, and `/blog-images` are listed, that editing a file formats it, that `git commit` runs the checks first, and that `git push` is denied.

## Automated Testing Overview

None. The hook scripts were run directly against a formatted file, an unformatted one, an unfixable textlint error, a `.prettierignore` path, a path outside the project, an empty payload, and a stopped project.

## Release/Deployment Notes

No effect on the site build. Agents other than Claude Code keep reading `AGENTS.md`, which links each rule and skill file.

🤖 Developed with assistance from [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
stasadev added a commit to stasadev/ddev.com that referenced this pull request Oct 5, 2026
…le docs

## The Issue

`AGENTS.md` had grown to 304 lines, all loaded in every session, although most of it applies only to blog content, images, or commits. Nothing enforced its rules, and `.gitignore` ignored all of `.claude`, so no shared Claude Code configuration could be committed. `ddev textlint` passed on errors it could not fix, because `textlint --fix` exits 0 when they remain, so CI failed where the local check had passed. README.md, README_SPONSOR.md, MARKDOWN_FORMATTING.md, and FORK_PREVIEW_SETUP.md had drifted from the code.

## How This PR Solves The Issue

Follows ddev/ddev#8805 and its follow-ups. `AGENTS.md` keeps what applies to every change and links the rest:

- `.claude/rules/content.md` (blog posts, their voice, schema, links, images) and `.claude/rules/comments.md` load only for the files they cover.
- Skills: `bump-deps` documents the dependency bump from ddev#601, ddev#637, ddev#685, ddev#734, and ddev#747, including `allowScripts`. `add-sponsor` replaces README_SPONSOR.md, and only needs the sponsor's website. `ddev-commit` holds the commit and PR rules, and `blog-images` the screenshot steps, now with a shorter FEATURE_IMAGE_GUIDE.md as `feature-banner.md`.
- `.claude/settings.json` denies `git push`, allows read-only `gh` commands and the `ddev` checks, and adds two hooks. Before `git commit`, the check-only prettier and textlint run as in CI. After an edit, `ddev prettier` runs on that file, and `ddev textlint` too under `src/content/`.
- `ddev prettier` and `ddev textlint` take optional file arguments, and `ddev textlint` checks again after fixing. The npm scripts call `prettier` and `textlint` by name, since `npm run` already puts `node_modules/.bin` on `PATH`.
- `.gitignore` ignores only the personal files the Claude Code docs list.

The docs corrections include blog categories, the dev server port, page paths, image conversion to WebP, external link behavior, feature image sizes, the unused `squareLogo`, the theme toggle, and the fork preview workflows and URLs. Prettier has no Astro plugin, so `AGENTS.md` now says nothing formats `.astro` files. README.md is shorter, with setup steps that `AGENTS.md` and the skills no longer repeat, and opens with the logo, badges, and links, as the ddev/ddev README does. Two posts set `modifiedData` instead of `modifiedDate`, which the content schema dropped without an error, so their modified dates now show.

## Manual Testing Instructions

```bash
ddev start
ddev prettier src/lib/api.ts             # formats one file
ddev textlint                             # fixes, then reports anything left
```

Start a new Claude Code session on this branch, then confirm that `/bump-deps`, `/add-sponsor`, `/ddev-commit`, and `/blog-images` are listed, that editing a file formats it, that `git commit` runs the checks first, and that `git push` is denied.

## Automated Testing Overview

None. The hook scripts were run directly against a formatted file, an unformatted one, an unfixable textlint error, a `.prettierignore` path, a path outside the project, an empty payload, and a stopped project. In a live session, an edit was formatted, an unfixable textlint error was reported back, and `git commit --dry-run` was blocked while that error remained.

## Release/Deployment Notes

No effect on the site build. Agents other than Claude Code keep reading `AGENTS.md`, which links each rule and skill file.

🤖 Developed with assistance from [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@stasadev
stasadev merged commit ae1a534 into main Oct 5, 2026
3 checks passed
@stasadev
stasadev deleted the dependabot/npm_and_yarn/major-deps-065c6647dd branch October 5, 2026 12:58
stasadev added a commit to stasadev/ddev.com that referenced this pull request Oct 5, 2026
…le docs

## The Issue

`AGENTS.md` had grown to 304 lines, all loaded in every session, although most of it applies only to blog content, images, or commits. Nothing enforced its rules, and `.gitignore` ignored all of `.claude`, so no shared Claude Code configuration could be committed. `ddev textlint` passed on errors it could not fix, because `textlint --fix` exits 0 when they remain, so CI failed where the local check had passed. README.md, README_SPONSOR.md, MARKDOWN_FORMATTING.md, and FORK_PREVIEW_SETUP.md had drifted from the code.

## How This PR Solves The Issue

Follows ddev/ddev#8805 and its follow-ups. `AGENTS.md` keeps what applies to every change and links the rest:

- `.claude/rules/content.md` (blog posts, their voice, schema, links, images) and `.claude/rules/comments.md` load only for the files they cover.
- Skills: `bump-deps` documents the dependency bump from ddev#601, ddev#637, ddev#685, ddev#734, and ddev#747, including `allowScripts`. `add-sponsor` replaces README_SPONSOR.md, and only needs the sponsor's website. `ddev-commit` holds the commit and PR rules, and `blog-images` the screenshot steps, now with a shorter FEATURE_IMAGE_GUIDE.md as `feature-banner.md`.
- `.claude/settings.json` denies `git push`, allows read-only `gh` commands and the `ddev` checks, and adds two hooks. Before `git commit`, the check-only prettier and textlint run as in CI. After an edit, `ddev prettier` runs on that file, and `ddev textlint` too under `src/content/`.
- `ddev prettier` and `ddev textlint` take optional file arguments, and `ddev textlint` checks again after fixing. The npm scripts call `prettier` and `textlint` by name, since `npm run` already puts `node_modules/.bin` on `PATH`.
- `.gitignore` ignores only the personal files the Claude Code docs list.

The docs corrections include blog categories, the dev server port, page paths, image conversion to WebP, external link behavior, feature image sizes, the unused `squareLogo`, the theme toggle, and the fork preview workflows and URLs. Prettier has no Astro plugin, so `AGENTS.md` now says nothing formats `.astro` files. README.md is shorter, with setup steps that `AGENTS.md` and the skills no longer repeat, and opens with the logo, badges, and links, as the ddev/ddev README does. Two posts set `modifiedData` instead of `modifiedDate`, which the content schema dropped without an error, so their modified dates now show.

## Manual Testing Instructions

```bash
ddev start
ddev prettier src/lib/api.ts             # formats one file
ddev textlint                             # fixes, then reports anything left
```

Start a new Claude Code session on this branch, then confirm that `/bump-deps`, `/add-sponsor`, `/ddev-commit`, and `/blog-images` are listed, that editing a file formats it, that `git commit` runs the checks first, and that `git push` is denied.

## Automated Testing Overview

None. The hook scripts were run directly against a formatted file, an unformatted one, an unfixable textlint error, a `.prettierignore` path, a path outside the project, an empty payload, and a stopped project. In a live session, an edit was formatted, an unfixable textlint error was reported back, and `git commit --dry-run` was blocked while that error remained.

## Release/Deployment Notes

No effect on the site build. Agents other than Claude Code keep reading `AGENTS.md`, which links each rule and skill file.

🤖 Developed with assistance from [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
stasadev added a commit to stasadev/ddev.com that referenced this pull request Oct 5, 2026
…le docs

## Short Summary (TL;DR)

Most of `AGENTS.md` moves into rules and skills that load only when needed, hooks now run the prettier and textlint checks that CI runs, and the docs that had drifted from the code are corrected.

## The Issue

`AGENTS.md` had grown to 304 lines, all loaded in every session, although most of it applies only to blog content, images, or commits. Nothing enforced its rules, and `.gitignore` ignored all of `.claude`, so no shared Claude Code configuration could be committed. `ddev textlint` passed on errors it could not fix, because `textlint --fix` exits 0 when they remain, so CI failed where the local check had passed. README.md, README_SPONSOR.md, MARKDOWN_FORMATTING.md, and FORK_PREVIEW_SETUP.md had drifted from the code.

## How This PR Solves The Issue

Follows ddev/ddev#8805 and its follow-ups. `AGENTS.md` keeps what applies to every change and links the rest:

- `.claude/rules/content.md` (blog posts, their voice, schema, links, images) and `.claude/rules/comments.md` load only for the files they cover.
- Skills: `bump-deps` documents the dependency bump from ddev#601, ddev#637, ddev#685, ddev#734, and ddev#747, including `allowScripts`. `add-sponsor` replaces README_SPONSOR.md, and only needs the sponsor's website. `ddev-commit` holds the commit and PR rules, and the PR template gains the Short Summary (TL;DR) section from the ddev/ddev template. `blog-images` holds the screenshot steps, now with a shorter FEATURE_IMAGE_GUIDE.md as `feature-banner.md`.
- `.claude/settings.json` denies `git push`, allows read-only `gh` commands and the `ddev` checks, and adds two hooks. Before `git commit`, the check-only prettier and textlint run as in CI. After an edit, `ddev prettier` runs on that file, and `ddev textlint` too under `src/content/`.
- `ddev prettier` and `ddev textlint` take optional file arguments, and `ddev textlint` checks again after fixing. The npm scripts call `prettier` and `textlint` by name, since `npm run` already puts `node_modules/.bin` on `PATH`.
- `.gitignore` ignores only the personal files the Claude Code docs list.

The docs corrections include blog categories, the dev server port, page paths, image conversion to WebP, external link behavior, feature image sizes, the unused `squareLogo`, the theme toggle, and the fork preview workflows and URLs. Prettier has no Astro plugin, so `AGENTS.md` now says nothing formats `.astro` files. README.md is shorter, with setup steps that `AGENTS.md` and the skills no longer repeat, and opens with the logo, badges, and links, as the ddev/ddev README does. Two posts set `modifiedData` instead of `modifiedDate`, which the content schema dropped without an error, so their modified dates now show.

## Manual Testing Instructions

```bash
ddev start
ddev prettier src/lib/api.ts             # formats one file
ddev textlint                             # fixes, then reports anything left
```

Start a new Claude Code session on this branch, then confirm that `/bump-deps`, `/add-sponsor`, `/ddev-commit`, and `/blog-images` are listed, that editing a file formats it, that `git commit` runs the checks first, and that `git push` is denied.

## Automated Testing Overview

None. The hook scripts were run directly against a formatted file, an unformatted one, an unfixable textlint error, a `.prettierignore` path, a path outside the project, an empty payload, and a stopped project. In a live session, an edit was formatted, an unfixable textlint error was reported back, and `git commit --dry-run` was blocked while that error remained.

## Release/Deployment Notes

No effect on the site build. Agents other than Claude Code keep reading `AGENTS.md`, which links each rule and skill file.

🤖 Developed with assistance from [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
stasadev added a commit to stasadev/ddev.com that referenced this pull request Oct 5, 2026
…le docs

## Short Summary (TL;DR)

Most of `AGENTS.md` moves into rules and skills that load only when needed, hooks now run the prettier and textlint checks that CI runs, and the docs that had drifted from the code are corrected.

## The Issue

`AGENTS.md` had grown to 304 lines, all loaded in every session, although most of it applies only to blog content, images, or commits. Nothing enforced its rules, and `.gitignore` ignored all of `.claude`, so no shared Claude Code configuration could be committed. `ddev textlint` passed on errors it could not fix, because `textlint --fix` exits 0 when they remain, so CI failed where the local check had passed. README.md, README_SPONSOR.md, MARKDOWN_FORMATTING.md, and FORK_PREVIEW_SETUP.md had drifted from the code.

## How This PR Solves The Issue

Follows ddev/ddev#8805 and its follow-ups. `AGENTS.md` keeps what applies to every change and links the rest:

- `.claude/rules/content.md` (blog posts, their voice, schema, links, images) and `.claude/rules/comments.md` load only for the files they cover.
- Skills: `bump-deps` documents the dependency bump from ddev#601, ddev#637, ddev#685, ddev#734, and ddev#747, including `allowScripts`. `add-sponsor` replaces README_SPONSOR.md, and only needs the sponsor's website. `ddev-commit` holds the commit and PR rules, and the PR template gains the Short Summary (TL;DR) section from the ddev/ddev template. `blog-images` holds the screenshot steps, now with a shorter FEATURE_IMAGE_GUIDE.md as `feature-banner.md`.
- `.claude/settings.json` denies `git push`, allows read-only `gh` commands and the `ddev` checks, and adds two hooks. Before `git commit`, the check-only prettier and textlint run as in CI. After an edit, `ddev prettier` runs on that file, and `ddev textlint` too under `src/content/`.
- `ddev prettier` and `ddev textlint` take optional file arguments, and `ddev textlint` checks again after fixing. The npm scripts call `prettier` and `textlint` by name, since `npm run` already puts `node_modules/.bin` on `PATH`.
- `.gitignore` ignores only the personal files the Claude Code docs list.

The docs corrections include blog categories, the dev server port, page paths, image conversion to WebP, external link behavior, feature image sizes, the unused `squareLogo`, the theme toggle, and the fork preview workflows and URLs. Prettier has no Astro plugin, so `AGENTS.md` now says nothing formats `.astro` files. README.md is shorter, with setup steps that `AGENTS.md` and the skills no longer repeat, and opens with the logo, badges, and links, as the ddev/ddev README does. Two posts set `modifiedData` instead of `modifiedDate`, which the content schema dropped without an error, so their modified dates now show.

## Manual Testing Instructions

```bash
ddev start
ddev prettier src/lib/api.ts             # formats one file
ddev textlint                             # fixes, then reports anything left
```

Start a new Claude Code session on this branch, then confirm that `/bump-deps`, `/add-sponsor`, `/ddev-commit`, and `/blog-images` are listed, that editing a file formats it, that `git commit` runs the checks first, and that `git push` is denied.

## Automated Testing Overview

None. The hook scripts were run directly against a formatted file, an unformatted one, an unfixable textlint error, a `.prettierignore` path, a path outside the project, an empty payload, and a stopped project. In a live session, an edit was formatted, an unfixable textlint error was reported back, and `git commit --dry-run` was blocked while that error remained.

## Release/Deployment Notes

No effect on the site build. Agents other than Claude Code, including Copilot code review, keep reading `AGENTS.md`, which links each rule and skill file.

🤖 Developed with assistance from [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant