astro
npm
pkg:npm/astro
34,430 Dependabot PRs
about 3 hours ago
7,643 repositories
523 repositories
Security Advisories
Astro's middleware authentication checks based on url.pathname can be bypassed via url encoded values
Atro CSRF Middleware Bypass (security.checkOrigin)
Astro allows unauthorized third-party images in _image endpoint
Astro: XSS in define:vars via incomplete </script> tag sanitization
Astro's `X-Forwarded-Host` is reflected without validation
Recent PRs
build(deps): bump the dependencies group across 1 directory with 10 updates
gxjansen/gxjansen.github.io #192
Bump the prod-minor-patch group across 1 directory with 4 updates
chore(deps): bump astro from 6.3.7 to 6.4.2
Hexaxia-Labs/hexaxia-labs.github.io #3
chore(deps): bump astro from 6.3.8 to 6.4.2
SecPal/secpal.app #116
deps(deps): bump the minor-and-patch group across 1 directory with 12 updates
pramodhm112/cloudnative-atlas #13
chore(deps): bump the npm_and_yarn group across 1 directory with 8 updates
build(deps): bump the minor-updates group across 1 directory with 3 updates
markd3ng/KIRARI #62
chore(deps): bump the astro group with 3 updates
ArtemioPadilla/issue-driven-web-template #74
Bump astro from 6.3.7 to 6.4.2
PlayForm/Favicon #55
chore(deps): bump astro from 6.3.6 to 6.4.2
SebitaxGod/Portafolio-astro #7
chore(deps): bump the npm_and_yarn group across 4 directories with 15 updates
danielbodnar/sandbox-agent #18
chore(deps): bump the npm_and_yarn group across 7 directories with 8 updates
chore(deps): bump the npm_and_yarn group across 1 directory with 7 updates
milliorn/portfolio #249
chore(deps)(deps-dev): bump the astro group with 3 updates
chore(deps): bump the minor-and-patch group across 1 directory with 4 updates
chore(deps): Bump astro from 6.3.3 to 6.3.6 in /docs
devantler-tech/ksail #4904
chore(deps): bump astro from 6.1.9 to 6.3.1 in /website in the website-minor-patch group across 1 directory
agent-of-empires/agent-of-empires #1537
build(deps): bump the patch-updates group across 1 directory with 11 updates
W-zeke/my_blog #10
Bump the patch-updates group across 1 directory with 3 updates
CCA8798/CCA8798_Blog_Astro_Fuwari #22
Bump astro from 6.3.1 to 6.3.8
esphome/esphome-devices #1628
deps(deps): bump the minor-and-patch group across 1 directory with 13 updates
pramodhm112/cloudnative-atlas #12
build(deps): bump the astro group across 1 directory with 2 updates
Build(deps): Bump the patch-updates group across 1 directory with 7 updates
Yamrc/RC-Blog #138
build(deps): bump the patch-updates group across 1 directory with 3 updates
naranyinyun/NalanyinyunsLibrary #87
deps(site): bump astro from 6.3.5 to 6.3.8 in /site
mcp-tool-shop-org/sovereign #13
chore(deps): bump the patch-updates group across 1 directory with 4 updates
Games55k/iBlog #47
deps: bump the production-dependencies group with 2 updates
sitcon-tw/camp2026 #137
Bump the patch-updates group across 1 directory with 8 updates
Bump the patch-updates group across 1 directory with 8 updates
build(deps): bump the patch-and-minor-dependencies group across 1 directory with 63 updates
nl-design-system/theme-wizard #776
chore(site): bump astro from 6.3.5 to 6.3.7 in /site in the astro-ecosystem group
jonathan-vella/azure-agentic-infraops #437
build(deps): bump the patch-updates group across 1 directory with 6 updates
qwc-ch/Firefly #24
chore(deps)(deps): bump the prod-minor-patch group with 11 updates
pauljohnchamberlain/pool-pals #2
yarn(deps): bump astro from 6.3.5 to 6.3.7 in the production-dependencies group
Bump astro from 6.3.5 to 6.3.7 in /docs/starlight in the docs-dependencies group
chore(deps): bump the npm-root group with 5 updates
chore(deps): bump astro from 6.3.5 to 6.3.7 in the astro group
subhan-f/personal-portfolio #10
chore(deps): bump astro from 6.3.1 to 6.3.7
javirojas988/clase-alan-turing #5
chore(dependency): bump astro from 5.18.1 to 6.3.7
qianjunakasumi/qianjunakasumi.moe #430
chore(deps): bump astro from 6.3.1 to 6.3.7
Ju4nmaFd3z/cert-dev-ops-personal-site #5
chore(deps): bump the all-npm-minor-patch group across 1 directory with 20 updates
blaudden/mtbo-sajten #154
chore(deps): Bump the minor-and-patch group across 1 directory with 14 updates
MinistrarePL/SimpleInvesting #7
Package Details
| Name: | astro |
| Ecosystem: | npm |
| PURL Type: | npm |
| Package URL: | pkg:npm/astro |
| JSON API: | View JSON |
Security Advisories
Package Information
Astro is a modern site builder with web best practices, performance, and DX front-of-mind.
| Repository: | https://github.com/withastro/astro |
| Homepage: | https://astro.build |
| Latest Release: |
4.16.16
over 1 year ago |
| Dependent Repos: | 18,705 |
| Dependent Packages: | 915 |
| Downloads: | 1,349,386 |
| Ranking: | Top 0.1941% by dependent repos Top 0.2899% by downloads Top 0.0943% by dependent pkgs |