#1806340896ac Thanks @adamchal! - Fixes incremental builds repeatedly rendering unchanged pages when modules or compiled CSS reference bundled assets.
#18053cf5d72f Thanks @Princesseuh! - Improves the astro check error shown for TypeScript 7. The command now explains that TypeScript 7 is not currently supported and provides instructions for experimentally type-checking Astro files with TypeScript 7.1 and @astrojs/ts-content-mapper.
#18086795a7e4 Thanks @ump45nose! - Fix double-escaped ampersands in Markdown image alt and title attributes. The __ASTRO_IMAGE_ round-trip now decodes the numeric (&) and named (&) character references the Markdown processors emit, so an & in an alt or title is escaped exactly once in the final HTML instead of twice.
#180740429805 Thanks @SurefireStudios! - Fix three error names that did not match their documented reference. MissingLocale, MissingIndexForInternationalization and NoManifestAvailable reported names ending in Error in the dev overlay, while their error reference pages are published under the unsuffixed names, so the name shown to users could not be found in the docs.
#180072245837 Thanks @L4XB! - Fixes the dev server re-evaluating the whole server module graph on every request. The astro:head-metadata plugin invalidated its component metadata virtual module from its own transform hook, so each evaluation of that module scheduled the next one. Adapters that run requests outside Vite's module runner, such as @astrojs/cloudflare, paid for a full re-evaluation of the server graph on every request for the lifetime of the process.
#1809643657c4 Thanks @matthewp! - Fixes domain-based i18n routing to respect security.allowedDomains when selecting a locale from request host headers
#180438a53a8b Thanks @astro-factory! - Fixes image.responsiveStyles emitting invalid object-position CSS values for same-axis keyword pairs (top bottom, left right, etc.)
#18029c08252d Thanks @matthewp! - Runs astro dev and astro preview in the foreground when an AI agent is detected on Windows, allowing the agent to manage the process lifetime. Pass --background explicitly to request an Astro-managed background process. Agent-inferred backgrounding remains enabled on other platforms.
Add support for first-class modules. These can be accessed using the new meta.load() and meta.get-module() functions, and may be passed as the $module argument to numerous eisting sass:meta functions.
Add the meta.css() mixin, which includes CSS from a first-class module.
JS API
Add a SassModule class and a corresponding Value.assertModule() method.
Dart API
Add a SassModule class and a corresponding Value.assertModule() method.
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [astro](https://astro.build) ([source](https://github.com/withastro/astro/tree/HEAD/packages/astro)) | [`7.3.3` → `7.3.4`](https://renovatebot.com/diffs/npm/astro/7.3.3/7.3.4) |  |  |
| [npm](https://docs.npmjs.com/) ([source](https://github.com/npm/cli)) | [`12.0.2` → `12.1.0`](https://renovatebot.com/diffs/npm/npm/12.0.2/12.1.0) |  |  |
| [sass](https://github.com/sass/dart-sass) | [`1.104.1` → `1.105.0`](https://renovatebot.com/diffs/npm/sass/1.104.1/1.105.0) |  |  |
| [satori](https://github.com/vercel/satori) | [`0.33.4` → `0.33.5`](https://renovatebot.com/diffs/npm/satori/0.33.4/0.33.5) |  |  |
---
### Release Notes
<details>
<summary>withastro/astro (astro)</summary>
### [`v7.3.4`](https://github.com/withastro/astro/blob/HEAD/packages/astro/CHANGELOG.md#734)
[Compare Source](https://github.com/withastro/astro/compare/astro@7.3.3...astro@7.3.4)
##### Patch Changes
- [#​18063](https://github.com/withastro/astro/pull/18063) [`40896ac`](https://github.com/withastro/astro/commit/40896acb744988d9d3c2015e810c57de26390b3f) Thanks [@​adamchal](https://github.com/adamchal)! - Fixes incremental builds repeatedly rendering unchanged pages when modules or compiled CSS reference bundled assets.
- [#​18053](https://github.com/withastro/astro/pull/18053) [`cf5d72f`](https://github.com/withastro/astro/commit/cf5d72f286c3c1185b7d39692b8ca8e789c16e02) Thanks [@​Princesseuh](https://github.com/Princesseuh)! - Improves the `astro check` error shown for TypeScript 7. The command now explains that TypeScript 7 is not currently supported and provides instructions for experimentally type-checking Astro files with TypeScript 7.1 and `@astrojs/ts-content-mapper`.
- [#​18086](https://github.com/withastro/astro/pull/18086) [`795a7e4`](https://github.com/withastro/astro/commit/795a7e44640e7ad513a590a362dc0d3259de7771) Thanks [@​ump45nose](https://github.com/ump45nose)! - Fix double-escaped ampersands in Markdown image `alt` and `title` attributes. The `__ASTRO_IMAGE_` round-trip now decodes the numeric (`&`) and named (`&`) character references the Markdown processors emit, so an `&` in an alt or title is escaped exactly once in the final HTML instead of twice.
- [#​18074](https://github.com/withastro/astro/pull/18074) [`0429805`](https://github.com/withastro/astro/commit/042980585a75a12f3b0d63377483af98ef80e0f9) Thanks [@​SurefireStudios](https://github.com/SurefireStudios)! - Fix three error names that did not match their documented reference. `MissingLocale`, `MissingIndexForInternationalization` and `NoManifestAvailable` reported names ending in `Error` in the dev overlay, while their error reference pages are published under the unsuffixed names, so the name shown to users could not be found in the docs.
- [#​18007](https://github.com/withastro/astro/pull/18007) [`2245837`](https://github.com/withastro/astro/commit/22458379f5f258ac1df225f5af644b98b1b8237b) Thanks [@​L4XB](https://github.com/L4XB)! - Fixes the dev server re-evaluating the whole server module graph on every request. The `astro:head-metadata` plugin invalidated its component metadata virtual module from its own `transform` hook, so each evaluation of that module scheduled the next one. Adapters that run requests outside Vite's module runner, such as `@astrojs/cloudflare`, paid for a full re-evaluation of the server graph on every request for the lifetime of the process.
- [#​18096](https://github.com/withastro/astro/pull/18096) [`43657c4`](https://github.com/withastro/astro/commit/43657c4612f04cecf6e34d288eed1811c6508b74) Thanks [@​matthewp](https://github.com/matthewp)! - Fixes domain-based i18n routing to respect `security.allowedDomains` when selecting a locale from request host headers
- [#​18043](https://github.com/withastro/astro/pull/18043) [`8a53a8b`](https://github.com/withastro/astro/commit/8a53a8b70f964e7bc127d6991cc9aca21e87750f) Thanks [@​astro-factory](https://github.com/apps/astro-factory)! - Fixes `image.responsiveStyles` emitting invalid `object-position` CSS values for same-axis keyword pairs (`top bottom`, `left right`, etc.)
- [#​18029](https://github.com/withastro/astro/pull/18029) [`c08252d`](https://github.com/withastro/astro/commit/c08252d6803d4af2890b4bd1c69e4b4fc49e2d04) Thanks [@​matthewp](https://github.com/matthewp)! - Runs `astro dev` and `astro preview` in the foreground when an AI agent is detected on Windows, allowing the agent to manage the process lifetime. Pass `--background` explicitly to request an Astro-managed background process. Agent-inferred backgrounding remains enabled on other platforms.
- Updated dependencies \[[`3fd16ee`](https://github.com/withastro/astro/commit/3fd16eeb5cd096a6ceb8cc3e70b89ed30d6fcd4d), [`8358d59`](https://github.com/withastro/astro/commit/8358d59cba754480c7d830c473837a0d7100ac7e)]:
- [@​astrojs/markdown-satteri](https://github.com/astrojs/markdown-satteri)@0.4.2
</details>
<details>
<summary>npm/cli (npm)</summary>
### [`v12.1.0`](https://github.com/npm/cli/blob/HEAD/CHANGELOG.md#1210-2026-09-21)
[Compare Source](https://github.com/npm/cli/compare/v12.0.2...v12.1.0)
##### Features
- [`6400533`](https://github.com/npm/cli/commit/6400533ab3d830716964bcf0def42b6c47f3fd70) [#​9948](https://github.com/npm/cli/pull/9948) token: support read-write-stage-only granular access tokens ([#​9948](https://github.com/npm/cli/issues/9948)) ([@​Tayvon](https://github.com/Tayvon), [@​Copilot](https://github.com/Copilot))
- [`8723f53`](https://github.com/npm/cli/commit/8723f539061eb8034a690f412ec8ccaa1529febc) [#​9898](https://github.com/npm/cli/pull/9898) stage: display staged package status ([#​9898](https://github.com/npm/cli/issues/9898)) ([@​joelverhagen](https://github.com/joelverhagen))
##### Bug Fixes
- [`c9876d7`](https://github.com/npm/cli/commit/c9876d7ea7150b0702e4151210b9fa1a8dbc7fbf) [#​9882](https://github.com/npm/cli/pull/9882) provenance-file takes precedence over OIDC auto-generated provenance ([#​9882](https://github.com/npm/cli/issues/9882)) ([@​yunseo-kim](https://github.com/yunseo-kim))
- [`b016aa2`](https://github.com/npm/cli/commit/b016aa287d01fcd688d6704222f193ce5c04bfb7) [#​9913](https://github.com/npm/cli/pull/9913) config: avoid exporting persistent allow-scripts ([#​9913](https://github.com/npm/cli/issues/9913)) ([@​Fnine59](https://github.com/Fnine59))
- [`d6c6122`](https://github.com/npm/cli/commit/d6c612258c571c71a00f496c1f8980ed13b8a4d9) [#​9914](https://github.com/npm/cli/pull/9914) arborist: match allowScripts keys for local paths ([#​9914](https://github.com/npm/cli/issues/9914)) ([@​martinrrm](https://github.com/martinrrm), [@​Copilot](https://github.com/Copilot))
- [`a8c9b2f`](https://github.com/npm/cli/commit/a8c9b2fe25342967be48eba3f792218c6becca8a) [#​9823](https://github.com/npm/cli/pull/9823) keep dry-run output valid json ([#​9823](https://github.com/npm/cli/issues/9823)) ([@​martinrrm](https://github.com/martinrrm))
- [`da50c34`](https://github.com/npm/cli/commit/da50c3479b556da74f88ff0b579d5191a7db0a24) [#​9881](https://github.com/npm/cli/pull/9881) arborist: reject uninstall args that carry a version ([#​9881](https://github.com/npm/cli/issues/9881)) ([@​lazerg](https://github.com/lazerg))
- [`71915e8`](https://github.com/npm/cli/commit/71915e8e7d6ac57f60c827274a95db786802e410) [#​9756](https://github.com/npm/cli/pull/9756) exempt explicit pack targets from allow-directory ([#​9756](https://github.com/npm/cli/issues/9756)) ([@​ychampion](https://github.com/ychampion), [@​ychampion](https://github.com/ychampion))
- [`51c2bf8`](https://github.com/npm/cli/commit/51c2bf81fa2c31547d0fec44fff2aaac3d9a9862) [#​9864](https://github.com/npm/cli/pull/9864) don't print the funding message for global installs ([#​9864](https://github.com/npm/cli/issues/9864)) ([@​lazerg](https://github.com/lazerg))
##### Documentation
- [`bea9066`](https://github.com/npm/cli/commit/bea9066c7d1fe09d6475bbe391f28116aa6a83a6) [#​9838](https://github.com/npm/cli/pull/9838) document npm 12 install script blocking ([#​9838](https://github.com/npm/cli/issues/9838)) ([@​reggi](https://github.com/reggi))
##### Dependencies
- [`6e40f73`](https://github.com/npm/cli/commit/6e40f7399cebd4f699ce5988c10b935f08f747ff) [#​9871](https://github.com/npm/cli/pull/9871) `undici@6.28.0` ([@​martinrrm](https://github.com/martinrrm), [@​Copilot](https://github.com/Copilot))
- [`05bd2a4`](https://github.com/npm/cli/commit/05bd2a49fc89ca5a4dcf8c15e69ebfbdffd32dd9) [#​9871](https://github.com/npm/cli/pull/9871) `ip-address@10.5.0` ([@​martinrrm](https://github.com/martinrrm), [@​Copilot](https://github.com/Copilot))
- [`b7c490d`](https://github.com/npm/cli/commit/b7c490d19299f15101f41a86667bd34b14717eb0) [#​9871](https://github.com/npm/cli/pull/9871) `brace-expansion@5.0.9` ([@​martinrrm](https://github.com/martinrrm), [@​Copilot](https://github.com/Copilot))
- [`75a943d`](https://github.com/npm/cli/commit/75a943ded97e8d00a484d3d64cadc9aa013bd268) [#​9843](https://github.com/npm/cli/pull/9843) `tar@7.5.22` ([#​9843](https://github.com/npm/cli/issues/9843)) ([@​martinrrm](https://github.com/martinrrm), [@​Copilot](https://github.com/Copilot))
##### Chores
- [`7b50811`](https://github.com/npm/cli/commit/7b508113d98bf9ae5ef2582b8418014dd8869ec1) [#​9961](https://github.com/npm/cli/pull/9961) pack: select workspace through config ([#​9961](https://github.com/npm/cli/issues/9961)) ([@​reggi](https://github.com/reggi))
- [`81a901c`](https://github.com/npm/cli/commit/81a901c9a5913f9bd8104e6196af3580eafa13cb) [#​9915](https://github.com/npm/cli/pull/9915) recognize prefixed Node.js PR titles ([#​9915](https://github.com/npm/cli/issues/9915)) ([@​reggi](https://github.com/reggi))
- [`4cdccea`](https://github.com/npm/cli/commit/4cdcceac047f82571d0ec734e18b87d1d130e042) [#​9836](https://github.com/npm/cli/pull/9836) update `node-integration` workflow template to latest actions ([#​9836](https://github.com/npm/cli/issues/9836)) ([@​MikeMcC399](https://github.com/MikeMcC399))
- [`278df04`](https://github.com/npm/cli/commit/278df04d3f25d391af3213a243bb9f89e1d11899) [#​9822](https://github.com/npm/cli/pull/9822) pass nodedir to node-gyp via npm\_package\_config env in node integration ([#​9822](https://github.com/npm/cli/issues/9822)) ([@​reggi](https://github.com/reggi), [@​Copilot](https://github.com/Copilot))
- [workspace](https://github.com/npm/cli/releases/tag/arborist-v10.0.3): `@npmcli/arborist@10.0.3`
- [workspace](https://github.com/npm/cli/releases/tag/config-v11.1.0): `@npmcli/config@11.1.0`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmdiff-v9.0.3): `libnpmdiff@9.0.3`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmexec-v11.0.3): `libnpmexec@11.0.3`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmfund-v8.0.3): `libnpmfund@8.0.3`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmpack-v10.0.3): `libnpmpack@10.0.3`
- [workspace](https://github.com/npm/cli/releases/tag/libnpmpublish-v12.0.1): `libnpmpublish@12.0.1`
</details>
<details>
<summary>sass/dart-sass (sass)</summary>
### [`v1.105.0`](https://github.com/sass/dart-sass/blob/HEAD/CHANGELOG.md#11050)
[Compare Source](https://github.com/sass/dart-sass/compare/1.104.1...1.105.0)
- Add support for first-class modules. These can be accessed using the new
`meta.load()` and `meta.get-module()` functions, and may be passed as the
`$module` argument to numerous eisting `sass:meta` functions.
- Add the `meta.css()` mixin, which includes CSS from a first-class module.
##### JS API
- Add a `SassModule` class and a corresponding `Value.assertModule()` method.
##### Dart API
- Add a `SassModule` class and a corresponding `Value.assertModule()` method.
</details>
<details>
<summary>vercel/satori (satori)</summary>
### [`v0.33.5`](https://github.com/vercel/satori/releases/tag/0.33.5)
[Compare Source](https://github.com/vercel/satori/compare/0.33.4...0.33.5)
##### Bug Fixes
- Harden SVG serialization ([#​814](https://github.com/vercel/satori/issues/814)) ([26a52af](https://github.com/vercel/satori/commit/26a52affc031216fee5882b6e965c8dbc7ac1782))
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://github.com/renovatebot/renovate/discussions) if that's undesired.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMDguMSIsInVwZGF0ZWRJblZlciI6IjQ0LjEwOC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImF1dG9tYXRlZCIsImRlcGVuZGVuY2llcyJdfQ==-->
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
This PR contains the following updates:
7.3.3→7.3.412.0.2→12.1.01.104.1→1.105.00.33.4→0.33.5Release Notes
withastro/astro (astro)
v7.3.4Compare Source
Patch Changes
#18063
40896acThanks @adamchal! - Fixes incremental builds repeatedly rendering unchanged pages when modules or compiled CSS reference bundled assets.#18053
cf5d72fThanks @Princesseuh! - Improves theastro checkerror shown for TypeScript 7. The command now explains that TypeScript 7 is not currently supported and provides instructions for experimentally type-checking Astro files with TypeScript 7.1 and@astrojs/ts-content-mapper.#18086
795a7e4Thanks @ump45nose! - Fix double-escaped ampersands in Markdown imagealtandtitleattributes. The__ASTRO_IMAGE_round-trip now decodes the numeric (&) and named (&) character references the Markdown processors emit, so an&in an alt or title is escaped exactly once in the final HTML instead of twice.#18074
0429805Thanks @SurefireStudios! - Fix three error names that did not match their documented reference.MissingLocale,MissingIndexForInternationalizationandNoManifestAvailablereported names ending inErrorin the dev overlay, while their error reference pages are published under the unsuffixed names, so the name shown to users could not be found in the docs.#18007
2245837Thanks @L4XB! - Fixes the dev server re-evaluating the whole server module graph on every request. Theastro:head-metadataplugin invalidated its component metadata virtual module from its owntransformhook, so each evaluation of that module scheduled the next one. Adapters that run requests outside Vite's module runner, such as@astrojs/cloudflare, paid for a full re-evaluation of the server graph on every request for the lifetime of the process.#18096
43657c4Thanks @matthewp! - Fixes domain-based i18n routing to respectsecurity.allowedDomainswhen selecting a locale from request host headers#18043
8a53a8bThanks @astro-factory! - Fixesimage.responsiveStylesemitting invalidobject-positionCSS values for same-axis keyword pairs (top bottom,left right, etc.)#18029
c08252dThanks @matthewp! - Runsastro devandastro previewin the foreground when an AI agent is detected on Windows, allowing the agent to manage the process lifetime. Pass--backgroundexplicitly to request an Astro-managed background process. Agent-inferred backgrounding remains enabled on other platforms.Updated dependencies [
3fd16ee,8358d59]:npm/cli (npm)
v12.1.0Compare Source
Features
6400533#9948 token: support read-write-stage-only granular access tokens (#9948) (@Tayvon, @Copilot)8723f53#9898 stage: display staged package status (#9898) (@joelverhagen)Bug Fixes
c9876d7#9882 provenance-file takes precedence over OIDC auto-generated provenance (#9882) (@yunseo-kim)b016aa2#9913 config: avoid exporting persistent allow-scripts (#9913) (@Fnine59)d6c6122#9914 arborist: match allowScripts keys for local paths (#9914) (@martinrrm, @Copilot)a8c9b2f#9823 keep dry-run output valid json (#9823) (@martinrrm)da50c34#9881 arborist: reject uninstall args that carry a version (#9881) (@lazerg)71915e8#9756 exempt explicit pack targets from allow-directory (#9756) (@ychampion, @ychampion)51c2bf8#9864 don't print the funding message for global installs (#9864) (@lazerg)Documentation
bea9066#9838 document npm 12 install script blocking (#9838) (@reggi)Dependencies
6e40f73#9871undici@6.28.0(@martinrrm, @Copilot)05bd2a4#9871ip-address@10.5.0(@martinrrm, @Copilot)b7c490d#9871brace-expansion@5.0.9(@martinrrm, @Copilot)75a943d#9843tar@7.5.22(#9843) (@martinrrm, @Copilot)Chores
7b50811#9961 pack: select workspace through config (#9961) (@reggi)81a901c#9915 recognize prefixed Node.js PR titles (#9915) (@reggi)4cdccea#9836 updatenode-integrationworkflow template to latest actions (#9836) (@MikeMcC399)278df04#9822 pass nodedir to node-gyp via npm_package_config env in node integration (#9822) (@reggi, @Copilot)@npmcli/arborist@10.0.3@npmcli/config@11.1.0libnpmdiff@9.0.3libnpmexec@11.0.3libnpmfund@8.0.3libnpmpack@10.0.3libnpmpublish@12.0.1sass/dart-sass (sass)
v1.105.0Compare Source
Add support for first-class modules. These can be accessed using the new
meta.load()andmeta.get-module()functions, and may be passed as the$moduleargument to numerous eistingsass:metafunctions.Add the
meta.css()mixin, which includes CSS from a first-class module.JS API
SassModuleclass and a correspondingValue.assertModule()method.Dart API
SassModuleclass and a correspondingValue.assertModule()method.vercel/satori (satori)
v0.33.5Compare Source
Bug Fixes
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate CLI.