chore(deps): update astro to 7.2.1 and drop the unused session runtime #217

Sammanfogat
supernaut sammanfogade 3 incheckningar från chore/astro-7.2 in i main 2026-08-13 07:19:02 +00:00
Ägare

Updates Astro to 7.2.1 and adopts the one change in 7.2 that applies to this repo.

Versions

Package From To
astro 7.1.6 7.2.1
@astrojs/node 11.0.3 11.1.1
@lucide/astro 1.28.0 1.31.0

Pinned exactly, matching the rest of package.json. pnpm up --latest would have written caret
ranges instead, so the pins were edited in place and installed.

Supersedes #209 and #210. Both target older releases than these: #209 wants astro 7.2.0 with
@astrojs/node 11.1.0, and #210 wants @lucide/astro 1.29.0. Close them in favour of this.

Left out on purpose. typescript 6 to 7 and pako 2 to 3 are majors and deserve their own change
with their own review. cssnano, pg, eslint and the typescript-eslint packages have patch
updates that Renovate handles on its own schedule.

What 7.2 offers, and what applies here

Four changes shipped. One is relevant.

session: false, adopted. The portal has never used Astro's session API. Sessions here are a
signed cookie of our own (src/lib/auth/session.ts): HMAC-SHA256, verified in constant time, with
the payload shape checked after the MAC. No driver was configured for Astro's own store either, so
the runtime sat in the bundle serving nothing. Before 7.2 it shipped regardless.

Measured on the built output rather than assumed. Rebased onto main after #216 landed, dist/server
goes from 2344 kB to 2304 kB, and the one file that referenced the session runtime is gone. The
saving is 40 kB either way; only the baseline moved when #216 merged.

Astro.session is now undefined, which is the honest signal. Reaching for it is a mistake in this
codebase and should fail at the call site rather than hand back a store nothing else reads. It also
means slightly less code in the bundle that has any say in who is logged in.

Incremental static builds, skipped. Experimental, and routes opt in by returning a cacheKey
from getStaticPaths. There is no getStaticPaths anywhere in this repo and output is "server",
so there is nothing for it to attach to.

astro preview --background, skipped. pnpm preview runs node ./dist/server/entry.mjs
directly, not astro preview.

Relative logger.entrypoint, skipped. Needs a custom logger. There is none.

Notes for review

The unmet eslint peer warning is not new. eslint-plugin-jsx-a11y wants eslint 9 or lower and the
repo runs 10.8.0. Verified identical before and after the upgrade, so nothing here touches it.

Version bumped 1.4.1 to 1.4.2. Patch, because a dependency upgrade and the removal of unused runtime
preserve meaning and add no content or components.

Verified

Re-run after the rebase onto main with #216 in, so these cover astro 7.2.1 sitting alongside the
new src/lib/env.ts, which reads import.meta.env.

  • pnpm test: 361 passed, unchanged from main
  • pnpm check: 0 errors, 0 warnings
  • pnpm eslint, pnpm stylelint, pnpm format:check, pnpm mdlint, pnpm lang-check: all clean
  • pnpm build: standalone server builds, sitemap and robots.txt generated
  • pnpm install --frozen-lockfile: lockfile coherent with #216's zod entry, supply-chain policies pass
Updates Astro to 7.2.1 and adopts the one change in 7.2 that applies to this repo. ## Versions | Package | From | To | | --- | --- | --- | | `astro` | 7.1.6 | 7.2.1 | | `@astrojs/node` | 11.0.3 | 11.1.1 | | `@lucide/astro` | 1.28.0 | 1.31.0 | Pinned exactly, matching the rest of `package.json`. `pnpm up --latest` would have written caret ranges instead, so the pins were edited in place and installed. **Supersedes #209 and #210.** Both target older releases than these: #209 wants astro 7.2.0 with `@astrojs/node` 11.1.0, and #210 wants `@lucide/astro` 1.29.0. Close them in favour of this. Left out on purpose. `typescript` 6 to 7 and `pako` 2 to 3 are majors and deserve their own change with their own review. `cssnano`, `pg`, `eslint` and the `typescript-eslint` packages have patch updates that Renovate handles on its own schedule. ## What 7.2 offers, and what applies here Four changes shipped. One is relevant. **`session: false`, adopted.** The portal has never used Astro's session API. Sessions here are a signed cookie of our own (`src/lib/auth/session.ts`): HMAC-SHA256, verified in constant time, with the payload shape checked after the MAC. No driver was configured for Astro's own store either, so the runtime sat in the bundle serving nothing. Before 7.2 it shipped regardless. Measured on the built output rather than assumed. Rebased onto `main` after #216 landed, `dist/server` goes from 2344 kB to 2304 kB, and the one file that referenced the session runtime is gone. The saving is 40 kB either way; only the baseline moved when #216 merged. `Astro.session` is now undefined, which is the honest signal. Reaching for it is a mistake in this codebase and should fail at the call site rather than hand back a store nothing else reads. It also means slightly less code in the bundle that has any say in who is logged in. **Incremental static builds, skipped.** Experimental, and routes opt in by returning a `cacheKey` from `getStaticPaths`. There is no `getStaticPaths` anywhere in this repo and `output` is `"server"`, so there is nothing for it to attach to. **`astro preview --background`, skipped.** `pnpm preview` runs `node ./dist/server/entry.mjs` directly, not `astro preview`. **Relative `logger.entrypoint`, skipped.** Needs a custom logger. There is none. ## Notes for review The unmet eslint peer warning is not new. `eslint-plugin-jsx-a11y` wants eslint 9 or lower and the repo runs 10.8.0. Verified identical before and after the upgrade, so nothing here touches it. Version bumped 1.4.1 to 1.4.2. Patch, because a dependency upgrade and the removal of unused runtime preserve meaning and add no content or components. ## Verified Re-run after the rebase onto `main` with #216 in, so these cover astro 7.2.1 sitting alongside the new `src/lib/env.ts`, which reads `import.meta.env`. - `pnpm test`: 361 passed, unchanged from main - `pnpm check`: 0 errors, 0 warnings - `pnpm eslint`, `pnpm stylelint`, `pnpm format:check`, `pnpm mdlint`, `pnpm lang-check`: all clean - `pnpm build`: standalone server builds, sitemap and robots.txt generated - `pnpm install --frozen-lockfile`: lockfile coherent with #216's zod entry, supply-chain policies pass
supernaut lade till 2 incheckningar 2026-08-12 19:39:25 +00:00
astro 7.1.6 to 7.2.1, @astrojs/node 11.0.3 to 11.1.1, @lucide/astro 1.28.0 to 1.31.0.

Pinned exactly, matching the rest of package.json. `pnpm up --latest` would have written caret
ranges instead, so the versions were edited in place and installed.

This supersedes two Renovate pull requests, both of which target older releases than these:
astro 7.2.0 with @astrojs/node 11.1.0 in #209, and @lucide/astro 1.29.0 in #210.

The unmet eslint peer warning is not new. eslint-plugin-jsx-a11y wants eslint 9 or lower and the
repo runs 10.8.0. Verified identical before and after the upgrade, so it is untouched here.

Left out on purpose: typescript 6 to 7 and pako 2 to 3 are majors and want their own change with
their own review. cssnano, pg, eslint and the typescript-eslint packages have patch updates that
Renovate handles on its own schedule.

Gates: 305 tests, astro check with 0 errors, eslint, stylelint, prettier, markdownlint and the
content style check all clean. The standalone server builds.
perf(build): drop astro's unused session runtime from the ssr bundle
Väntande kontroller
ci / ci (pull_request) Has started running
9fe087c2b1
The portal has never used Astro's session API. Sessions here are a signed cookie of our own
(src/lib/auth/session.ts): HMAC-SHA256, verified in constant time, with the payload shape checked
after the MAC. No driver was configured for Astro's own store either, so the runtime sat in the
bundle serving nothing.

Before 7.2 it shipped regardless. `session: false` is new in 7.2 and tree-shakes it out.

Measured on the built output rather than assumed: dist/server goes from 2456 kB to 2416 kB, and the
one file that referenced the session runtime is gone. `Astro.session` is now undefined. That is the
honest signal, because reaching for it is a mistake in this codebase and should fail at the call
site instead of handing back a store nothing else reads. It also means slightly less code in the
bundle that has any say in who is logged in.

Of the four changes in 7.2, this is the only one that applies to this repo:

- Incremental static builds are experimental and opt in per route through a `cacheKey` returned from
  `getStaticPaths`. There is no `getStaticPaths` anywhere here, and `output` is "server".
- `astro preview --background` does not apply. `pnpm preview` runs the built node entry directly.
- Relative `logger.entrypoint` paths need a custom logger. There is none.
supernaut tvångsskickade chore/astro-7.2 från 9fe087c2b1
Väntande kontroller
ci / ci (pull_request) Has started running
till 91b771a174
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m25s
2026-08-12 19:40:00 +00:00
Jämför
supernaut lade till 1 incheckning 2026-08-13 06:52:15 +00:00
build: bump packages
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m21s
7657075efe
supernaut sammanfogade incheckning c0fae64c82 till main 2026-08-13 07:19:02 +00:00
supernaut tog bort grenen chore/astro-7.2 2026-08-13 07:19:03 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-web!217
Ingen beskrivning angiven.