Update dependency @astrojs/starlight to ^0.32.0 - #3

Open
dev-mend-for-github-com[bot] wants to merge 1 commit into
masterfrom
whitesource-remediate/astrojs-starlight-0.x
Open

Update dependency @astrojs/starlight to ^0.32.0#3
dev-mend-for-github-com[bot] wants to merge 1 commit into
masterfrom
whitesource-remediate/astrojs-starlight-0.x

Conversation

@dev-mend-for-github-com

@dev-mend-for-github-comdev-mend-for-github-comBot commented Feb 10, 2026

Copy link
Copy Markdown

This PR contains the following updates:

PackageTypeUpdateChange
@astrojs/starlight (source)dependenciesminor^0.31.1^0.32.0

By merging this PR, the below vulnerabilities will be automatically resolved:

Severity CVSS ScoreVulnerability
Medium Medium6.9CVE-2025-27789
Medium Medium5.3CVE-2026-41305
Low Low2.3CVE-2024-53382

Release Notes

withastro/starlight (@​astrojs/starlight)

v0.32.0

Compare Source

Minor Changes
  • #​2390f493361 Thanks @​delucis! - Moves route data to Astro.locals instead of passing it down via component props

    ⚠️Breaking change:
    Previously, all of Starlight’s templating components, including user or plugin overrides, had access to a data object for the current route via Astro.props.
    This data is now available as Astro.locals.starlightRoute instead.

    To update, refactor any component overrides you have:

    • Remove imports of @astrojs/starlight/props, which is now deprecated.
    • Update code that accesses Astro.props to use Astro.locals.starlightRoute instead.
    • Remove any spreading of {...Astro.props} into child components, which is no longer required.

    In the following example, a custom override for Starlight’s LastUpdated component is updated for the new style:

    ---
    import Default from '@​astrojs/starlight/components/LastUpdated.astro';
    - import type { Props } from '@​astrojs/starlight/props';- const { lastUpdated } = Astro.props;+ const { lastUpdated } = Astro.locals.starlightRoute;
    const updatedThisYear = lastUpdated?.getFullYear() === new Date().getFullYear();
    ---
    {updatedThisYear && (
    - <Default {...Astro.props}><slot /></Default>+ <Default><slot /></Default>
    )}

    Community Starlight plugins may also need to be manually updated to work with Starlight 0.32. If you encounter any issues, please reach out to the plugin author to see if it is a known issue or if an updated version is being worked on.

  • #​2578f895f75 Thanks @​HiDeoo! - Deprecates the Starlight plugin setup hook in favor of the new config:setup hook which provides the same functionality.

    ⚠️BREAKING CHANGE:

    The Starlight plugin setup hook is now deprecated and will be removed in a future release. Please update your plugins to use the new config:setup hook instead.

    export default {
    name: 'plugin-with-translations',
    hooks: {
    - 'setup'({ config }) {+ 'config:setup'({ config }) {
    // Your plugin configuration setup code
    },
    },
    };
  • #​2578f895f75 Thanks @​HiDeoo! - Exposes the built-in localization system in the Starlight plugin config:setup hook.

    ⚠️BREAKING CHANGE:

    This addition changes how Starlight plugins add or update translation strings used in Starlight’s localization APIs.
    Plugins previously using the injectTranslations() callback function from the plugin config:setup hook should now use the same function available in the i18n:setup hook.

    export default {
    name: 'plugin-with-translations',
    hooks: {
    - 'config:setup'({ injectTranslations }) {+ 'i18n:setup'({ injectTranslations }) {
    injectTranslations({
    en: {
    'myPlugin.doThing': 'Do the thing',
    },
    fr: {
    'myPlugin.doThing': 'Faire le truc',
    },
    });
    },
    },
    };
  • #​28582df9d05 Thanks @​XREvo! - Adds support for Pagefind’s multisite search features

  • #​2578f895f75 Thanks @​HiDeoo! - Adds a new HookParameters utility type to get the type of a plugin hook’s arguments.

  • #​2578f895f75 Thanks @​HiDeoo! - Adds a new useTranslations() callback function to the Starlight plugin config:setup hook to generate a utility function to access UI strings for a given language.

  • #​2578f895f75 Thanks @​HiDeoo! - Adds a new absolutePathToLang() callback function to the Starlight plugin config:setup to get the language for a given absolute file path.

Patch Changes

  • If you want to rebase/retry this PR, check this box

@dev-mend-for-github-comdev-mend-for-github-comBot added the security fix Security fix generated by Mend label Feb 10, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fixSecurity fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Update dependency @astrojs/starlight to ^0.32.0 - #3

Open
dev-mend-for-github-com[bot] wants to merge 1 commit into
masterfrom
whitesource-remediate/astrojs-starlight-0.x
Open

Update dependency @astrojs/starlight to ^0.32.0#3
dev-mend-for-github-com[bot] wants to merge 1 commit into
masterfrom
whitesource-remediate/astrojs-starlight-0.x

Conversation

@dev-mend-for-github-com

@dev-mend-for-github-comdev-mend-for-github-comBot commented Feb 10, 2026

Copy link
Copy Markdown

This PR contains the following updates:

PackageTypeUpdateChange
@astrojs/starlight (source)dependenciesminor^0.31.1^0.32.0

By merging this PR, the below vulnerabilities will be automatically resolved:

Severity CVSS ScoreVulnerability
Medium Medium6.9CVE-2025-27789
Medium Medium5.3CVE-2026-41305
Low Low2.3CVE-2024-53382

Release Notes

withastro/starlight (@​astrojs/starlight)

v0.32.0

Compare Source

Minor Changes
  • #​2390f493361 Thanks @​delucis! - Moves route data to Astro.locals instead of passing it down via component props

    ⚠️Breaking change:
    Previously, all of Starlight’s templating components, including user or plugin overrides, had access to a data object for the current route via Astro.props.
    This data is now available as Astro.locals.starlightRoute instead.

    To update, refactor any component overrides you have:

    • Remove imports of @astrojs/starlight/props, which is now deprecated.
    • Update code that accesses Astro.props to use Astro.locals.starlightRoute instead.
    • Remove any spreading of {...Astro.props} into child components, which is no longer required.

    In the following example, a custom override for Starlight’s LastUpdated component is updated for the new style:

    ---
    import Default from '@&#8203;astrojs/starlight/components/LastUpdated.astro';
    - import type { Props } from '@&#8203;astrojs/starlight/props';- const { lastUpdated } = Astro.props;+ const { lastUpdated } = Astro.locals.starlightRoute;
    const updatedThisYear = lastUpdated?.getFullYear() === new Date().getFullYear();
    ---
    {updatedThisYear && (
    - <Default {...Astro.props}><slot /></Default>+ <Default><slot /></Default>
    )}

    Community Starlight plugins may also need to be manually updated to work with Starlight 0.32. If you encounter any issues, please reach out to the plugin author to see if it is a known issue or if an updated version is being worked on.

  • #​2578f895f75 Thanks @​HiDeoo! - Deprecates the Starlight plugin setup hook in favor of the new config:setup hook which provides the same functionality.

    ⚠️BREAKING CHANGE:

    The Starlight plugin setup hook is now deprecated and will be removed in a future release. Please update your plugins to use the new config:setup hook instead.

    export default {
    name: 'plugin-with-translations',
    hooks: {
    - 'setup'({ config }) {+ 'config:setup'({ config }) {
    // Your plugin configuration setup code
    },
    },
    };
  • #​2578f895f75 Thanks @​HiDeoo! - Exposes the built-in localization system in the Starlight plugin config:setup hook.

    ⚠️BREAKING CHANGE:

    This addition changes how Starlight plugins add or update translation strings used in Starlight’s localization APIs.
    Plugins previously using the injectTranslations() callback function from the plugin config:setup hook should now use the same function available in the i18n:setup hook.

    export default {
    name: 'plugin-with-translations',
    hooks: {
    - 'config:setup'({ injectTranslations }) {+ 'i18n:setup'({ injectTranslations }) {
    injectTranslations({
    en: {
    'myPlugin.doThing': 'Do the thing',
    },
    fr: {
    'myPlugin.doThing': 'Faire le truc',
    },
    });
    },
    },
    };
  • #​28582df9d05 Thanks @​XREvo! - Adds support for Pagefind’s multisite search features

  • #​2578f895f75 Thanks @​HiDeoo! - Adds a new HookParameters utility type to get the type of a plugin hook’s arguments.

  • #​2578f895f75 Thanks @​HiDeoo! - Adds a new useTranslations() callback function to the Starlight plugin config:setup hook to generate a utility function to access UI strings for a given language.

  • #​2578f895f75 Thanks @​HiDeoo! - Adds a new absolutePathToLang() callback function to the Starlight plugin config:setup to get the language for a given absolute file path.

Patch Changes

  • If you want to rebase/retry this PR, check this box

@dev-mend-for-github-comdev-mend-for-github-comBot added the security fix Security fix generated by Mend label Feb 10, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fixSecurity fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Update dependency @astrojs/starlight to ^0.32.0 - #3

Open
dev-mend-for-github-com[bot] wants to merge 1 commit into
masterfrom
whitesource-remediate/astrojs-starlight-0.x
Open

Update dependency @astrojs/starlight to ^0.32.0#3
dev-mend-for-github-com[bot] wants to merge 1 commit into
masterfrom
whitesource-remediate/astrojs-starlight-0.x

Conversation

@dev-mend-for-github-com

@dev-mend-for-github-comdev-mend-for-github-comBot commented Feb 10, 2026

Copy link
Copy Markdown

This PR contains the following updates:

PackageTypeUpdateChange
@astrojs/starlight (source)dependenciesminor^0.31.1^0.32.0

By merging this PR, the below vulnerabilities will be automatically resolved:

Severity CVSS ScoreVulnerability
Medium Medium6.9CVE-2025-27789
Medium Medium5.3CVE-2026-41305
Low Low2.3CVE-2024-53382

Release Notes

withastro/starlight (@​astrojs/starlight)

v0.32.0

Compare Source

Minor Changes
  • #​2390f493361 Thanks @​delucis! - Moves route data to Astro.locals instead of passing it down via component props

    ⚠️Breaking change:
    Previously, all of Starlight’s templating components, including user or plugin overrides, had access to a data object for the current route via Astro.props.
    This data is now available as Astro.locals.starlightRoute instead.

    To update, refactor any component overrides you have:

    • Remove imports of @astrojs/starlight/props, which is now deprecated.
    • Update code that accesses Astro.props to use Astro.locals.starlightRoute instead.
    • Remove any spreading of {...Astro.props} into child components, which is no longer required.

    In the following example, a custom override for Starlight’s LastUpdated component is updated for the new style:

    ---
    import Default from '@&#8203;astrojs/starlight/components/LastUpdated.astro';
    - import type { Props } from '@&#8203;astrojs/starlight/props';- const { lastUpdated } = Astro.props;+ const { lastUpdated } = Astro.locals.starlightRoute;
    const updatedThisYear = lastUpdated?.getFullYear() === new Date().getFullYear();
    ---
    {updatedThisYear && (
    - <Default {...Astro.props}><slot /></Default>+ <Default><slot /></Default>
    )}

    Community Starlight plugins may also need to be manually updated to work with Starlight 0.32. If you encounter any issues, please reach out to the plugin author to see if it is a known issue or if an updated version is being worked on.

  • #​2578f895f75 Thanks @​HiDeoo! - Deprecates the Starlight plugin setup hook in favor of the new config:setup hook which provides the same functionality.

    ⚠️BREAKING CHANGE:

    The Starlight plugin setup hook is now deprecated and will be removed in a future release. Please update your plugins to use the new config:setup hook instead.

    export default {
    name: 'plugin-with-translations',
    hooks: {
    - 'setup'({ config }) {+ 'config:setup'({ config }) {
    // Your plugin configuration setup code
    },
    },
    };
  • #​2578f895f75 Thanks @​HiDeoo! - Exposes the built-in localization system in the Starlight plugin config:setup hook.

    ⚠️BREAKING CHANGE:

    This addition changes how Starlight plugins add or update translation strings used in Starlight’s localization APIs.
    Plugins previously using the injectTranslations() callback function from the plugin config:setup hook should now use the same function available in the i18n:setup hook.

    export default {
    name: 'plugin-with-translations',
    hooks: {
    - 'config:setup'({ injectTranslations }) {+ 'i18n:setup'({ injectTranslations }) {
    injectTranslations({
    en: {
    'myPlugin.doThing': 'Do the thing',
    },
    fr: {
    'myPlugin.doThing': 'Faire le truc',
    },
    });
    },
    },
    };
  • #​28582df9d05 Thanks @​XREvo! - Adds support for Pagefind’s multisite search features

  • #​2578f895f75 Thanks @​HiDeoo! - Adds a new HookParameters utility type to get the type of a plugin hook’s arguments.

  • #​2578f895f75 Thanks @​HiDeoo! - Adds a new useTranslations() callback function to the Starlight plugin config:setup hook to generate a utility function to access UI strings for a given language.

  • #​2578f895f75 Thanks @​HiDeoo! - Adds a new absolutePathToLang() callback function to the Starlight plugin config:setup to get the language for a given absolute file path.

Patch Changes

  • If you want to rebase/retry this PR, check this box

@dev-mend-for-github-comdev-mend-for-github-comBot added the security fix Security fix generated by Mend label Feb 10, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fixSecurity fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Update dependency @astrojs/starlight to ^0.32.0 - #3

Open
dev-mend-for-github-com[bot] wants to merge 1 commit into
masterfrom
whitesource-remediate/astrojs-starlight-0.x
Open

Update dependency @astrojs/starlight to ^0.32.0#3
dev-mend-for-github-com[bot] wants to merge 1 commit into
masterfrom
whitesource-remediate/astrojs-starlight-0.x

Conversation

@dev-mend-for-github-com

@dev-mend-for-github-comdev-mend-for-github-comBot commented Feb 10, 2026

Copy link
Copy Markdown

This PR contains the following updates:

PackageTypeUpdateChange
@astrojs/starlight (source)dependenciesminor^0.31.1^0.32.0

By merging this PR, the below vulnerabilities will be automatically resolved:

Severity CVSS ScoreVulnerability
Medium Medium6.9CVE-2025-27789
Medium Medium5.3CVE-2026-41305
Low Low2.3CVE-2024-53382

Release Notes

withastro/starlight (@​astrojs/starlight)

v0.32.0

Compare Source

Minor Changes
  • #​2390f493361 Thanks @​delucis! - Moves route data to Astro.locals instead of passing it down via component props

    ⚠️Breaking change:
    Previously, all of Starlight’s templating components, including user or plugin overrides, had access to a data object for the current route via Astro.props.
    This data is now available as Astro.locals.starlightRoute instead.

    To update, refactor any component overrides you have:

    • Remove imports of @astrojs/starlight/props, which is now deprecated.
    • Update code that accesses Astro.props to use Astro.locals.starlightRoute instead.
    • Remove any spreading of {...Astro.props} into child components, which is no longer required.

    In the following example, a custom override for Starlight’s LastUpdated component is updated for the new style:

    ---
    import Default from '@&#8203;astrojs/starlight/components/LastUpdated.astro';
    - import type { Props } from '@&#8203;astrojs/starlight/props';- const { lastUpdated } = Astro.props;+ const { lastUpdated } = Astro.locals.starlightRoute;
    const updatedThisYear = lastUpdated?.getFullYear() === new Date().getFullYear();
    ---
    {updatedThisYear && (
    - <Default {...Astro.props}><slot /></Default>+ <Default><slot /></Default>
    )}

    Community Starlight plugins may also need to be manually updated to work with Starlight 0.32. If you encounter any issues, please reach out to the plugin author to see if it is a known issue or if an updated version is being worked on.

  • #​2578f895f75 Thanks @​HiDeoo! - Deprecates the Starlight plugin setup hook in favor of the new config:setup hook which provides the same functionality.

    ⚠️BREAKING CHANGE:

    The Starlight plugin setup hook is now deprecated and will be removed in a future release. Please update your plugins to use the new config:setup hook instead.

    export default {
    name: 'plugin-with-translations',
    hooks: {
    - 'setup'({ config }) {+ 'config:setup'({ config }) {
    // Your plugin configuration setup code
    },
    },
    };
  • #​2578f895f75 Thanks @​HiDeoo! - Exposes the built-in localization system in the Starlight plugin config:setup hook.

    ⚠️BREAKING CHANGE:

    This addition changes how Starlight plugins add or update translation strings used in Starlight’s localization APIs.
    Plugins previously using the injectTranslations() callback function from the plugin config:setup hook should now use the same function available in the i18n:setup hook.

    export default {
    name: 'plugin-with-translations',
    hooks: {
    - 'config:setup'({ injectTranslations }) {+ 'i18n:setup'({ injectTranslations }) {
    injectTranslations({
    en: {
    'myPlugin.doThing': 'Do the thing',
    },
    fr: {
    'myPlugin.doThing': 'Faire le truc',
    },
    });
    },
    },
    };
  • #​28582df9d05 Thanks @​XREvo! - Adds support for Pagefind’s multisite search features

  • #​2578f895f75 Thanks @​HiDeoo! - Adds a new HookParameters utility type to get the type of a plugin hook’s arguments.

  • #​2578f895f75 Thanks @​HiDeoo! - Adds a new useTranslations() callback function to the Starlight plugin config:setup hook to generate a utility function to access UI strings for a given language.

  • #​2578f895f75 Thanks @​HiDeoo! - Adds a new absolutePathToLang() callback function to the Starlight plugin config:setup to get the language for a given absolute file path.

Patch Changes

  • If you want to rebase/retry this PR, check this box

@dev-mend-for-github-comdev-mend-for-github-comBot added the security fix Security fix generated by Mend label Feb 10, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fixSecurity fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Update dependency @astrojs/starlight to ^0.32.0 - #3

Open
dev-mend-for-github-com[bot] wants to merge 1 commit into
masterfrom
whitesource-remediate/astrojs-starlight-0.x
Open

Update dependency @astrojs/starlight to ^0.32.0#3
dev-mend-for-github-com[bot] wants to merge 1 commit into
masterfrom
whitesource-remediate/astrojs-starlight-0.x

Conversation

@dev-mend-for-github-com

@dev-mend-for-github-comdev-mend-for-github-comBot commented Feb 10, 2026

Copy link
Copy Markdown

This PR contains the following updates:

PackageTypeUpdateChange
@astrojs/starlight (source)dependenciesminor^0.31.1^0.32.0

By merging this PR, the below vulnerabilities will be automatically resolved:

Severity CVSS ScoreVulnerability
Medium Medium6.9CVE-2025-27789
Medium Medium5.3CVE-2026-41305
Low Low2.3CVE-2024-53382

Release Notes

withastro/starlight (@​astrojs/starlight)

v0.32.0

Compare Source

Minor Changes
  • #​2390f493361 Thanks @​delucis! - Moves route data to Astro.locals instead of passing it down via component props

    ⚠️Breaking change:
    Previously, all of Starlight’s templating components, including user or plugin overrides, had access to a data object for the current route via Astro.props.
    This data is now available as Astro.locals.starlightRoute instead.

    To update, refactor any component overrides you have:

    • Remove imports of @astrojs/starlight/props, which is now deprecated.
    • Update code that accesses Astro.props to use Astro.locals.starlightRoute instead.
    • Remove any spreading of {...Astro.props} into child components, which is no longer required.

    In the following example, a custom override for Starlight’s LastUpdated component is updated for the new style:

    ---
    import Default from '@&#8203;astrojs/starlight/components/LastUpdated.astro';
    - import type { Props } from '@&#8203;astrojs/starlight/props';- const { lastUpdated } = Astro.props;+ const { lastUpdated } = Astro.locals.starlightRoute;
    const updatedThisYear = lastUpdated?.getFullYear() === new Date().getFullYear();
    ---
    {updatedThisYear && (
    - <Default {...Astro.props}><slot /></Default>+ <Default><slot /></Default>
    )}

    Community Starlight plugins may also need to be manually updated to work with Starlight 0.32. If you encounter any issues, please reach out to the plugin author to see if it is a known issue or if an updated version is being worked on.

  • #​2578f895f75 Thanks @​HiDeoo! - Deprecates the Starlight plugin setup hook in favor of the new config:setup hook which provides the same functionality.

    ⚠️BREAKING CHANGE:

    The Starlight plugin setup hook is now deprecated and will be removed in a future release. Please update your plugins to use the new config:setup hook instead.

    export default {
    name: 'plugin-with-translations',
    hooks: {
    - 'setup'({ config }) {+ 'config:setup'({ config }) {
    // Your plugin configuration setup code
    },
    },
    };
  • #​2578f895f75 Thanks @​HiDeoo! - Exposes the built-in localization system in the Starlight plugin config:setup hook.

    ⚠️BREAKING CHANGE:

    This addition changes how Starlight plugins add or update translation strings used in Starlight’s localization APIs.
    Plugins previously using the injectTranslations() callback function from the plugin config:setup hook should now use the same function available in the i18n:setup hook.

    export default {
    name: 'plugin-with-translations',
    hooks: {
    - 'config:setup'({ injectTranslations }) {+ 'i18n:setup'({ injectTranslations }) {
    injectTranslations({
    en: {
    'myPlugin.doThing': 'Do the thing',
    },
    fr: {
    'myPlugin.doThing': 'Faire le truc',
    },
    });
    },
    },
    };
  • #​28582df9d05 Thanks @​XREvo! - Adds support for Pagefind’s multisite search features

  • #​2578f895f75 Thanks @​HiDeoo! - Adds a new HookParameters utility type to get the type of a plugin hook’s arguments.

  • #​2578f895f75 Thanks @​HiDeoo! - Adds a new useTranslations() callback function to the Starlight plugin config:setup hook to generate a utility function to access UI strings for a given language.

  • #​2578f895f75 Thanks @​HiDeoo! - Adds a new absolutePathToLang() callback function to the Starlight plugin config:setup to get the language for a given absolute file path.

Patch Changes

  • If you want to rebase/retry this PR, check this box

@dev-mend-for-github-comdev-mend-for-github-comBot added the security fix Security fix generated by Mend label Feb 10, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fixSecurity fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Update dependency @astrojs/starlight to ^0.32.0 - #3

Open
dev-mend-for-github-com[bot] wants to merge 1 commit into
masterfrom
whitesource-remediate/astrojs-starlight-0.x
Open

Update dependency @astrojs/starlight to ^0.32.0#3
dev-mend-for-github-com[bot] wants to merge 1 commit into
masterfrom
whitesource-remediate/astrojs-starlight-0.x

Conversation

@dev-mend-for-github-com

@dev-mend-for-github-comdev-mend-for-github-comBot commented Feb 10, 2026

Copy link
Copy Markdown

This PR contains the following updates:

PackageTypeUpdateChange
@astrojs/starlight (source)dependenciesminor^0.31.1^0.32.0

By merging this PR, the below vulnerabilities will be automatically resolved:

Severity CVSS ScoreVulnerability
Medium Medium6.9CVE-2025-27789
Medium Medium5.3CVE-2026-41305
Low Low2.3CVE-2024-53382

Release Notes

withastro/starlight (@​astrojs/starlight)

v0.32.0

Compare Source

Minor Changes
  • #​2390f493361 Thanks @​delucis! - Moves route data to Astro.locals instead of passing it down via component props

    ⚠️Breaking change:
    Previously, all of Starlight’s templating components, including user or plugin overrides, had access to a data object for the current route via Astro.props.
    This data is now available as Astro.locals.starlightRoute instead.

    To update, refactor any component overrides you have:

    • Remove imports of @astrojs/starlight/props, which is now deprecated.
    • Update code that accesses Astro.props to use Astro.locals.starlightRoute instead.
    • Remove any spreading of {...Astro.props} into child components, which is no longer required.

    In the following example, a custom override for Starlight’s LastUpdated component is updated for the new style:

    ---
    import Default from '@&#8203;astrojs/starlight/components/LastUpdated.astro';
    - import type { Props } from '@&#8203;astrojs/starlight/props';- const { lastUpdated } = Astro.props;+ const { lastUpdated } = Astro.locals.starlightRoute;
    const updatedThisYear = lastUpdated?.getFullYear() === new Date().getFullYear();
    ---
    {updatedThisYear && (
    - <Default {...Astro.props}><slot /></Default>+ <Default><slot /></Default>
    )}

    Community Starlight plugins may also need to be manually updated to work with Starlight 0.32. If you encounter any issues, please reach out to the plugin author to see if it is a known issue or if an updated version is being worked on.

  • #​2578f895f75 Thanks @​HiDeoo! - Deprecates the Starlight plugin setup hook in favor of the new config:setup hook which provides the same functionality.

    ⚠️BREAKING CHANGE:

    The Starlight plugin setup hook is now deprecated and will be removed in a future release. Please update your plugins to use the new config:setup hook instead.

    export default {
    name: 'plugin-with-translations',
    hooks: {
    - 'setup'({ config }) {+ 'config:setup'({ config }) {
    // Your plugin configuration setup code
    },
    },
    };
  • #​2578f895f75 Thanks @​HiDeoo! - Exposes the built-in localization system in the Starlight plugin config:setup hook.

    ⚠️BREAKING CHANGE:

    This addition changes how Starlight plugins add or update translation strings used in Starlight’s localization APIs.
    Plugins previously using the injectTranslations() callback function from the plugin config:setup hook should now use the same function available in the i18n:setup hook.

    export default {
    name: 'plugin-with-translations',
    hooks: {
    - 'config:setup'({ injectTranslations }) {+ 'i18n:setup'({ injectTranslations }) {
    injectTranslations({
    en: {
    'myPlugin.doThing': 'Do the thing',
    },
    fr: {
    'myPlugin.doThing': 'Faire le truc',
    },
    });
    },
    },
    };
  • #​28582df9d05 Thanks @​XREvo! - Adds support for Pagefind’s multisite search features

  • #​2578f895f75 Thanks @​HiDeoo! - Adds a new HookParameters utility type to get the type of a plugin hook’s arguments.

  • #​2578f895f75 Thanks @​HiDeoo! - Adds a new useTranslations() callback function to the Starlight plugin config:setup hook to generate a utility function to access UI strings for a given language.

  • #​2578f895f75 Thanks @​HiDeoo! - Adds a new absolutePathToLang() callback function to the Starlight plugin config:setup to get the language for a given absolute file path.

Patch Changes

  • If you want to rebase/retry this PR, check this box

@dev-mend-for-github-comdev-mend-for-github-comBot added the security fix Security fix generated by Mend label Feb 10, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fixSecurity fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Update dependency @astrojs/starlight to ^0.32.0 - #3

Open
dev-mend-for-github-com[bot] wants to merge 1 commit into
masterfrom
whitesource-remediate/astrojs-starlight-0.x
Open

Update dependency @astrojs/starlight to ^0.32.0#3
dev-mend-for-github-com[bot] wants to merge 1 commit into
masterfrom
whitesource-remediate/astrojs-starlight-0.x

Conversation

@dev-mend-for-github-com

@dev-mend-for-github-comdev-mend-for-github-comBot commented Feb 10, 2026

Copy link
Copy Markdown

This PR contains the following updates:

PackageTypeUpdateChange
@astrojs/starlight (source)dependenciesminor^0.31.1^0.32.0

By merging this PR, the below vulnerabilities will be automatically resolved:

Severity CVSS ScoreVulnerability
Medium Medium6.9CVE-2025-27789
Medium Medium5.3CVE-2026-41305
Low Low2.3CVE-2024-53382

Release Notes

withastro/starlight (@​astrojs/starlight)

v0.32.0

Compare Source

Minor Changes
  • #​2390f493361 Thanks @​delucis! - Moves route data to Astro.locals instead of passing it down via component props

    ⚠️Breaking change:
    Previously, all of Starlight’s templating components, including user or plugin overrides, had access to a data object for the current route via Astro.props.
    This data is now available as Astro.locals.starlightRoute instead.

    To update, refactor any component overrides you have:

    • Remove imports of @astrojs/starlight/props, which is now deprecated.
    • Update code that accesses Astro.props to use Astro.locals.starlightRoute instead.
    • Remove any spreading of {...Astro.props} into child components, which is no longer required.

    In the following example, a custom override for Starlight’s LastUpdated component is updated for the new style:

    ---
    import Default from '@&#8203;astrojs/starlight/components/LastUpdated.astro';
    - import type { Props } from '@&#8203;astrojs/starlight/props';- const { lastUpdated } = Astro.props;+ const { lastUpdated } = Astro.locals.starlightRoute;
    const updatedThisYear = lastUpdated?.getFullYear() === new Date().getFullYear();
    ---
    {updatedThisYear && (
    - <Default {...Astro.props}><slot /></Default>+ <Default><slot /></Default>
    )}

    Community Starlight plugins may also need to be manually updated to work with Starlight 0.32. If you encounter any issues, please reach out to the plugin author to see if it is a known issue or if an updated version is being worked on.

  • #​2578f895f75 Thanks @​HiDeoo! - Deprecates the Starlight plugin setup hook in favor of the new config:setup hook which provides the same functionality.

    ⚠️BREAKING CHANGE:

    The Starlight plugin setup hook is now deprecated and will be removed in a future release. Please update your plugins to use the new config:setup hook instead.

    export default {
    name: 'plugin-with-translations',
    hooks: {
    - 'setup'({ config }) {+ 'config:setup'({ config }) {
    // Your plugin configuration setup code
    },
    },
    };
  • #​2578f895f75 Thanks @​HiDeoo! - Exposes the built-in localization system in the Starlight plugin config:setup hook.

    ⚠️BREAKING CHANGE:

    This addition changes how Starlight plugins add or update translation strings used in Starlight’s localization APIs.
    Plugins previously using the injectTranslations() callback function from the plugin config:setup hook should now use the same function available in the i18n:setup hook.

    export default {
    name: 'plugin-with-translations',
    hooks: {
    - 'config:setup'({ injectTranslations }) {+ 'i18n:setup'({ injectTranslations }) {
    injectTranslations({
    en: {
    'myPlugin.doThing': 'Do the thing',
    },
    fr: {
    'myPlugin.doThing': 'Faire le truc',
    },
    });
    },
    },
    };
  • #​28582df9d05 Thanks @​XREvo! - Adds support for Pagefind’s multisite search features

  • #​2578f895f75 Thanks @​HiDeoo! - Adds a new HookParameters utility type to get the type of a plugin hook’s arguments.

  • #​2578f895f75 Thanks @​HiDeoo! - Adds a new useTranslations() callback function to the Starlight plugin config:setup hook to generate a utility function to access UI strings for a given language.

  • #​2578f895f75 Thanks @​HiDeoo! - Adds a new absolutePathToLang() callback function to the Starlight plugin config:setup to get the language for a given absolute file path.

Patch Changes

  • If you want to rebase/retry this PR, check this box

@dev-mend-for-github-comdev-mend-for-github-comBot added the security fix Security fix generated by Mend label Feb 10, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fixSecurity fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Update dependency @astrojs/starlight to ^0.32.0 - #3

Open
dev-mend-for-github-com[bot] wants to merge 1 commit into
masterfrom
whitesource-remediate/astrojs-starlight-0.x
Open

Update dependency @astrojs/starlight to ^0.32.0#3
dev-mend-for-github-com[bot] wants to merge 1 commit into
masterfrom
whitesource-remediate/astrojs-starlight-0.x

Conversation

@dev-mend-for-github-com

@dev-mend-for-github-comdev-mend-for-github-comBot commented Feb 10, 2026

Copy link
Copy Markdown

This PR contains the following updates:

PackageTypeUpdateChange
@astrojs/starlight (source)dependenciesminor^0.31.1^0.32.0

By merging this PR, the below vulnerabilities will be automatically resolved:

Severity CVSS ScoreVulnerability
Medium Medium6.9CVE-2025-27789
Medium Medium5.3CVE-2026-41305
Low Low2.3CVE-2024-53382

Release Notes

withastro/starlight (@​astrojs/starlight)

v0.32.0

Compare Source

Minor Changes
  • #​2390f493361 Thanks @​delucis! - Moves route data to Astro.locals instead of passing it down via component props

    ⚠️Breaking change:
    Previously, all of Starlight’s templating components, including user or plugin overrides, had access to a data object for the current route via Astro.props.
    This data is now available as Astro.locals.starlightRoute instead.

    To update, refactor any component overrides you have:

    • Remove imports of @astrojs/starlight/props, which is now deprecated.
    • Update code that accesses Astro.props to use Astro.locals.starlightRoute instead.
    • Remove any spreading of {...Astro.props} into child components, which is no longer required.

    In the following example, a custom override for Starlight’s LastUpdated component is updated for the new style:

    ---
    import Default from '@&#8203;astrojs/starlight/components/LastUpdated.astro';
    - import type { Props } from '@&#8203;astrojs/starlight/props';- const { lastUpdated } = Astro.props;+ const { lastUpdated } = Astro.locals.starlightRoute;
    const updatedThisYear = lastUpdated?.getFullYear() === new Date().getFullYear();
    ---
    {updatedThisYear && (
    - <Default {...Astro.props}><slot /></Default>+ <Default><slot /></Default>
    )}

    Community Starlight plugins may also need to be manually updated to work with Starlight 0.32. If you encounter any issues, please reach out to the plugin author to see if it is a known issue or if an updated version is being worked on.

  • #​2578f895f75 Thanks @​HiDeoo! - Deprecates the Starlight plugin setup hook in favor of the new config:setup hook which provides the same functionality.

    ⚠️BREAKING CHANGE:

    The Starlight plugin setup hook is now deprecated and will be removed in a future release. Please update your plugins to use the new config:setup hook instead.

    export default {
    name: 'plugin-with-translations',
    hooks: {
    - 'setup'({ config }) {+ 'config:setup'({ config }) {
    // Your plugin configuration setup code
    },
    },
    };
  • #​2578f895f75 Thanks @​HiDeoo! - Exposes the built-in localization system in the Starlight plugin config:setup hook.

    ⚠️BREAKING CHANGE:

    This addition changes how Starlight plugins add or update translation strings used in Starlight’s localization APIs.
    Plugins previously using the injectTranslations() callback function from the plugin config:setup hook should now use the same function available in the i18n:setup hook.

    export default {
    name: 'plugin-with-translations',
    hooks: {
    - 'config:setup'({ injectTranslations }) {+ 'i18n:setup'({ injectTranslations }) {
    injectTranslations({
    en: {
    'myPlugin.doThing': 'Do the thing',
    },
    fr: {
    'myPlugin.doThing': 'Faire le truc',
    },
    });
    },
    },
    };
  • #​28582df9d05 Thanks @​XREvo! - Adds support for Pagefind’s multisite search features

  • #​2578f895f75 Thanks @​HiDeoo! - Adds a new HookParameters utility type to get the type of a plugin hook’s arguments.

  • #​2578f895f75 Thanks @​HiDeoo! - Adds a new useTranslations() callback function to the Starlight plugin config:setup hook to generate a utility function to access UI strings for a given language.

  • #​2578f895f75 Thanks @​HiDeoo! - Adds a new absolutePathToLang() callback function to the Starlight plugin config:setup to get the language for a given absolute file path.

Patch Changes

  • If you want to rebase/retry this PR, check this box

@dev-mend-for-github-comdev-mend-for-github-comBot added the security fix Security fix generated by Mend label Feb 10, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fixSecurity fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants