astro
npm
pkg:npm/astro
34,429 Dependabot PRs
about 14 hours ago
7,643 repositories
523 repositories
Security Advisories
Astro's middleware authentication checks based on url.pathname can be bypassed via url encoded values
Atro CSRF Middleware Bypass (security.checkOrigin)
Astro allows unauthorized third-party images in _image endpoint
Astro: XSS in define:vars via incomplete </script> tag sanitization
Astro's `X-Forwarded-Host` is reflected without validation
Recent PRs (filtered by: Patch PRs )
chore(deps)(deps-dev): bump the astro group with 3 updates
chore(deps): bump the minor-and-patch group across 1 directory with 4 updates
chore(deps): Bump astro from 6.3.3 to 6.3.6 in /docs
devantler-tech/ksail #4904
build(deps): bump the patch-updates group across 1 directory with 11 updates
W-zeke/my_blog #10
Bump the patch-updates group across 1 directory with 3 updates
CCA8798/CCA8798_Blog_Astro_Fuwari #22
Bump astro from 6.3.1 to 6.3.8
esphome/esphome-devices #1628
build(deps): bump the astro group across 1 directory with 2 updates
Build(deps): Bump the patch-updates group across 1 directory with 7 updates
Yamrc/RC-Blog #138
build(deps): bump the patch-updates group across 1 directory with 3 updates
naranyinyun/NalanyinyunsLibrary #87
deps(site): bump astro from 6.3.5 to 6.3.8 in /site
mcp-tool-shop-org/sovereign #13
chore(deps): bump the patch-updates group across 1 directory with 4 updates
Games55k/iBlog #47
deps: bump the production-dependencies group with 2 updates
sitcon-tw/camp2026 #137
Bump the patch-updates group across 1 directory with 8 updates
Bump the patch-updates group across 1 directory with 8 updates
chore(site): bump astro from 6.3.5 to 6.3.7 in /site in the astro-ecosystem group
jonathan-vella/azure-agentic-infraops #437
build(deps): bump the patch-updates group across 1 directory with 6 updates
qwc-ch/Firefly #24
yarn(deps): bump astro from 6.3.5 to 6.3.7 in the production-dependencies group
Bump astro from 6.3.5 to 6.3.7 in /docs/starlight in the docs-dependencies group
chore(deps): bump the npm-root group with 5 updates
chore(deps): bump astro from 6.3.5 to 6.3.7 in the astro group
subhan-f/personal-portfolio #10
chore(deps): bump astro from 6.3.1 to 6.3.7
javirojas988/clase-alan-turing #5
chore(deps): bump astro from 6.3.1 to 6.3.7
Ju4nmaFd3z/cert-dev-ops-personal-site #5
chore(deps): Bump the minor-and-patch group across 1 directory with 14 updates
MinistrarePL/SimpleInvesting #7
Bump the patch-updates group across 1 directory with 4 updates
chore(deps): bump astro from 6.3.1 to 6.3.7
jruiher341/personal-site-alan-turing #4
Bump the patch-updates group across 1 directory with 9 updates
vanutama/vanutamamenulis2026 #7
chore(deps): bump the minor-and-patch group across 1 directory with 3 updates
chore(deps): bump the npm-minor-patch group with 3 updates
rbetree/menav #75
chore(deps)(deps): bump astro from 6.3.3 to 6.3.7 in the astro group
cuberhaus/PersonalPortfolio #139
設定(deps): Bump astro from 6.3.6 to 6.3.7
cho5butter/dtmf #47
chore(deps): bump the minor-and-patch group with 7 updates
fune-gaku/member-site-template-public #77
chore(deps): Bump astro from 6.3.3 to 6.3.7 in the astro-ecosystem group
chore(deps): bump astro from 6.3.3 to 6.3.7 in the astro-ecosystem group
Hayato-Isagawa/edu-evidence #215
chore(deps): bump astro from 6.1.9 to 6.1.10 in /site in the npm_and_yarn group across 1 directory
marquetools/marque #785
chore(deps): bump astro from 6.3.5 to 6.3.7 in the patch-updates group across 1 directory
build(pkg): bump astro from 6.3.3 to 6.3.7
DiscordLuau/docs #24
chore(deps): bump astro from 6.3.6 to 6.3.7
jagreehal/effect-analyzer #118
build(deps): bump astro from 6.3.3 to 6.3.7 in the all-non-major group
Bump astro from 6.3.3 to 6.3.7 in the prod-minor-patch group
build(deps): bump astro from 6.3.1 to 6.3.7
schalkneethling/schalkneethling.com #1283
build(deps): bump the astro group across 1 directory with 3 updates
navikt/sokos-utbetalingsportalen #887
npm: bump astro from 6.3.3 to 6.3.7
tresr-community/chatbot-frontend #625
build(deps): bump the npm_and_yarn group across 2 directories with 6 updates
tsukasa-u/FUSOU #182
Package Details
| Name: | astro |
| Ecosystem: | npm |
| PURL Type: | npm |
| Package URL: | pkg:npm/astro |
| JSON API: | View JSON |
Security Advisories
Package Information
Astro is a modern site builder with web best practices, performance, and DX front-of-mind.
| Repository: | https://github.com/withastro/astro |
| Homepage: | https://astro.build |
| Latest Release: |
4.16.16
over 1 year ago |
| Dependent Repos: | 18,705 |
| Dependent Packages: | 915 |
| Downloads: | 1,349,386 |
| Ranking: | Top 0.1941% by dependent repos Top 0.2899% by downloads Top 0.0943% by dependent pkgs |