Skip to content

Conversation

@mend-for-github-com
Copy link
Contributor

@mend-for-github-com mend-for-github-com bot commented Nov 19, 2025

This PR contains the following updates:

Package Type Update Change
astro (source) dependencies patch 5.15.6 -> 5.15.8

By merging this PR, the issue #69 will be automatically resolved and closed:

Severity CVSS Score Vulnerability
High High 7.1 CVE-2025-64764
Medium Medium 5.3 CVE-2025-64765

Release Notes

withastro/astro (astro)

v5.15.8

Compare Source

Patch Changes
  • #​14772 00c579a Thanks @​matthewp! - Improves the security of Server Islands slots by encrypting them before transmission to the browser, matching the security model used for props. This improves the integrity of slot content and prevents injection attacks, even when component templates don't explicitly support slots.

    Slots continue to work as expected for normal usage—this change has no breaking changes for legitimate requests.

  • #​14771 6f80081 Thanks @​matthewp! - Fix middleware pathname matching by normalizing URL-encoded paths

    Middleware now receives normalized pathname values, ensuring that encoded paths like /%61dmin are properly decoded to /admin before middleware checks. This prevents potential security issues where middleware checks might be bypassed through URL encoding.

v5.15.7

Compare Source

Patch Changes

  • If you want to rebase/retry this PR, check this box

@mend-for-github-com mend-for-github-com bot added the security fix Security fix generated by Mend label Nov 19, 2025
@mend-for-github-com mend-for-github-com bot changed the title chore(deps): update dependency astro to v5.15.8 chore(deps): update dependency astro to v5.15.8 - autoclosed Nov 19, 2025
@mend-for-github-com mend-for-github-com bot deleted the whitesource-remediate/astro-5.x-lockfile branch November 19, 2025 16:47
@mend-for-github-com mend-for-github-com bot changed the title chore(deps): update dependency astro to v5.15.8 - autoclosed chore(deps): update dependency astro to v5.15.8 Nov 20, 2025
@mend-for-github-com mend-for-github-com bot reopened this Nov 20, 2025
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/astro-5.x-lockfile branch 2 times, most recently from d935b39 to 2336ceb Compare November 20, 2025 18:05
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/astro-5.x-lockfile branch from 2336ceb to 9f7bf20 Compare November 20, 2025 20:55
@mend-for-github-com mend-for-github-com bot changed the title chore(deps): update dependency astro to v5.15.8 chore(deps): update dependency astro to v5.15.8 - autoclosed Nov 20, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fix Security fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant