Backport #2457: fix(deps): upgrade astro to 6.4.6 to resolve CVE-2026-54299 - #2461

Merged
TooTallNate merged 1 commit into
stablefrom
backport/pr-2457-to-stable
Jun 16, 2026
Merged

Backport #2457: fix(deps): upgrade astro to 6.4.6 to resolve CVE-2026-54299#2461
TooTallNate merged 1 commit into
stablefrom
backport/pr-2457-to-stable

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Automated backport of #2457 to stable (backport job run).

AI recommendation: This is a security fix (CVE-2026-54299) bumping astro in packages/astro and workbench/astro, both of which exist on stable with the same vulnerable astro@5.18.0 devDependency. The fix is a self-contained dependency bump that does not build on any main-only API, so the vulnerability applies to stable as well and should be backported.

Astro <6.4.6 is vulnerable to CVE-2026-54299 (GHSA-2pvr-wf23-7pc7, host
header SSRF in prerendered error page fetch). The fix only exists in the
6.x line — there is no 5.x backport — so this bumps:
- workbench/astro: astro ^6.4.6, @astrojs/node 10.1.4, @astrojs/vercel ^10.0.8
- packages/astro: astro devDependency 6.4.6 (typecheck only, not shipped)
Removes both vulnerable astro@5.16.3 and astro@5.18.0 from the lockfile.
Verified the example app builds under both the node and vercel adapters.
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Pranay Prakash <pranay.gp@gmail.com>
@changeset-bot

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: bd4e4da

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 16 packages
NameType
@workflow/astroPatch
workflowPatch
@workflow/world-testingPatch
@workflow/corePatch
@workflow/buildersPatch
@workflow/cliPatch
@workflow/nextPatch
@workflow/nitroPatch
@workflow/vitestPatch
@workflow/web-sharedPatch
@workflow/webPatch
@workflow/nestPatch
@workflow/rollupPatch
@workflow/sveltekitPatch
@workflow/vitePatch
@workflow/nuxtPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Jun 16, 2026

Copy link
Copy Markdown
Contributor

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

DiffPackageSupply Chain
Security
VulnerabilityQualityMaintenanceLicense
Addednpm/​@​astrojs/​node@​10.1.41001008297100
Addednpm/​@​astrojs/​vercel@​10.0.81001008397100
Addednpm/​astro@​6.4.6881008898100

View full report

@TooTallNate
TooTallNate enabled auto-merge (squash) June 16, 2026 22:23
@github-actions

github-actionsBot commented Jun 16, 2026

Copy link
Copy Markdown
ContributorAuthor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
✅ ▲ Vercel Production10440671111
✅ 💻 Local Development11260861212
✅ 📦 Local Production11260861212
✅ 🐘 Local Postgres11140981212
✅ 🪟 Windows10100101
❌ 🌍 Community Worlds75986179
✅ 📋 Other568038606
Total5154983815633

❌ Failed Tests

🌍 Community Worlds (98 failed)

redis (19 failed):

  • hookWorkflow | wrun_01KV98N0R2MXQD8YSGR4BENY8P
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KV98N91GVT38AV2PYN4TYBNV
  • parallelStepsThenWebhookWorkflow - no hook_conflict from same-tick replay race | wrun_01KV98NMYQVCH6XYR4ZQ2016MM
  • sleepingWorkflow | wrun_01KV98Q46BDRXMZWGW75NWCTGC
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KV98YWQ3000CWG9RP8TN59CH
  • hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload | wrun_01KV98Z8XR51ZFQM9P012YECEQ
  • hookGetConflictThenStepParallelWorkflow - hook.getConflict() continuation step runs alongside other steps | wrun_01KV98ZGRE0PP2WG3TNFGJ1Y2E
  • hookGetConflictWorkflow - hook.getConflict() resolves with the conflicting run when token is already registered | wrun_01KV98ZZKDNP25VY06WQG1D6PT
  • hookClaimOnlyMutexWorkflow - hook works as a pure run mutex without payload data | wrun_01KV990TBH99XVBCCXW29WBNSM
  • hookAdoptOwnerResultWorkflow - duplicate adopts the owner result via conflict.returnValue | wrun_01KV990YNAH14VCA65PX4EW3N9
  • hookSignalOwnerWorkflow - duplicate forwards its payload to the owner via resumeHook | wrun_01KV9914PKN1BPEQ4WMP8YW0X0
  • hookSupersedeOwnerWorkflow - duplicate cancels the owner and claims the released token | wrun_01KV991AMMFXEQMQ91826GP029
  • resume-or-start route pattern - resumeHook retried after start() reaches the new run | wrun_01KV991MJZX32941PFHEMVVG7K
  • pages router sleepingWorkflow via pages router
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KV997R4Y3RXWNH6N2ZQZQR8A

turso (79 failed):

  • addTenWorkflow | wrun_01KV98M31H4Q3JSGN6HV5BVCZJ
  • addTenWorkflow | wrun_01KV98M31H4Q3JSGN6HV5BVCZJ
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KV98KVZC8YPZPWKJZ5K908BN
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KV98MAA50K1XAMV7C5RZP6PZ
  • promiseRaceWorkflow | wrun_01KV98MF22V7D4C4BX5FPEH4VA
  • promiseAnyWorkflow | wrun_01KV98MH96F5PWMSBHR6WJE554
  • importedStepOnlyWorkflow | wrun_01KV98MB2A66MJD5W7311FMHNF
  • readableStreamWorkflow | wrun_01KV98MKVE6FYFR3YFK3JREHJ9
  • hookWorkflow | wrun_01KV98N0R2MXQD8YSGR4BENY8P
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KV98N91GVT38AV2PYN4TYBNV
  • webhookWorkflow | wrun_01KV98NE45N76N2XXM0FRA26QF
  • parallelStepsThenWebhookWorkflow - no hook_conflict from same-tick replay race | wrun_01KV98NMYQVCH6XYR4ZQ2016MM
  • sleepingWorkflow | wrun_01KV98Q46BDRXMZWGW75NWCTGC
  • parallelSleepWorkflow | wrun_01KV98QMH679XQF9201BE678JN
  • nullByteWorkflow | wrun_01KV98QR6VNY8250G0FYKT7Q2Y
  • workflowAndStepMetadataWorkflow | wrun_01KV98QTCX4WSQBPM72VPXXG1K
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KV98T2JC8FZFVKQDAB5JA8K1
  • writableForwardedFromWorkflowWorkflow | wrun_01KV98TJPJT9DWSRVG8JJ898VG
  • writableForwardedFromStepWorkflow | wrun_01KV98TR1E9DEQN4EEZR442TTC
  • fetchWorkflow | wrun_01KV98TVNER9T1JEWTZ9KFF2DF
  • promiseRaceStressTestWorkflow | wrun_01KV98TZ1TYWNKGEZZJWRRT18R
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KV98YGG1TJ1BQWV2XJ3AT7QZ
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KV98YWQ3000CWG9RP8TN59CH
  • hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload | wrun_01KV98Z8XR51ZFQM9P012YECEQ
  • 'hookGetConflictWithPriorStepWorkflow' - hook.getConflict() does not block step execution | wrun_01KV98ZBD71VG7SC257M48MF1G
  • 'hookGetConflictWithParallelStepWorkfl…' - hook.getConflict() does not block step execution | wrun_01KV98ZE0NDYCAGFTJE5JPE3EK
  • hookGetConflictThenStepParallelWorkflow - hook.getConflict() continuation step runs alongside other steps | wrun_01KV98ZGRE0PP2WG3TNFGJ1Y2E
  • hookGetConflictWorkflow - hook.getConflict() resolves with the conflicting run when token is already registered | wrun_01KV98ZZKDNP25VY06WQG1D6PT
  • hookClaimOnlyMutexWorkflow - hook works as a pure run mutex without payload data | wrun_01KV990TBH99XVBCCXW29WBNSM
  • hookAdoptOwnerResultWorkflow - duplicate adopts the owner result via conflict.returnValue | wrun_01KV990YNAH14VCA65PX4EW3N9
  • hookSignalOwnerWorkflow - duplicate forwards its payload to the owner via resumeHook | wrun_01KV9914PKN1BPEQ4WMP8YW0X0
  • hookSupersedeOwnerWorkflow - duplicate cancels the owner and claims the released token | wrun_01KV991AMMFXEQMQ91826GP029
  • resume-or-start route pattern - resumeHook retried after start() reaches the new run | wrun_01KV991MJZX32941PFHEMVVG7K
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KV991WC53780NZNEE4YW52ZJ
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KV992CVJ6F2HBSRT8VDCXPDC
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KV992PCS9RJTZX7RR8MPY8GX
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KV992W6N0FAVHG8AAXGHF8SC
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KV992YHDR5S1K70PT7WN4AYV
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KV993F0VPKW6FB3ZN3SJ2MS7
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KV993P3F5G5M92GWFGS99V84
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KV993WBZ67WF575B6CW4WK5Q
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KV9943BE4ST811CGN2JS7RBN
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KV994A9CZCKJPGHVCP8QF5WA
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KV994JMM62VCA5J3GYTVF0D8
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KV994TW16C69PXHC518XTRXV
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KV99586QT9JYHAA44FARKKHM
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KV995J44NCP6WXJT5TARXER6
  • cancelRun - cancelling a running workflow | wrun_01KV995S4Q6A0WTMZ6HVM2D3EK
  • cancelRun via CLI - cancelling a running workflow | wrun_01KV9963CXFPF1PZD8BPEX8PTV
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KV996FZKE08Q1TW28CYCX633
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KV9970QJ4PZJYKAWYNW3XQGE
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KV997BP7C5HG0AMV6RJKPZJJ
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KV997K2A69TJN7ZTSHE7542R
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KV997NBK942J5VVW30ZT4RCS
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KV997R4Y3RXWNH6N2ZQZQR8A

Details by Category

✅ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro9407
✅ example9407
✅ express9407
✅ fastify9407
✅ hono9407
✅ nextjs-turbopack9902
✅ nextjs-webpack9902
✅ nitro9407
✅ nuxt9407
✅ sveltekit9407
✅ vite9407
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable9506
✅ express-stable9506
✅ fastify-stable9506
✅ hono-stable9506
✅ nextjs-turbopack-canary82019
✅ nextjs-turbopack-stable10100
✅ nextjs-webpack-canary82019
✅ nextjs-webpack-stable10100
✅ nitro-stable9506
✅ nuxt-stable9506
✅ sveltekit-stable9506
✅ vite-stable9506
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable9506
✅ express-stable9506
✅ fastify-stable9506
✅ hono-stable9506
✅ nextjs-turbopack-canary82019
✅ nextjs-turbopack-stable10100
✅ nextjs-webpack-canary82019
✅ nextjs-webpack-stable10100
✅ nitro-stable9506
✅ nuxt-stable9506
✅ sveltekit-stable9506
✅ vite-stable9506
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable9407
✅ express-stable9407
✅ fastify-stable9407
✅ hono-stable9407
✅ nextjs-turbopack-canary81020
✅ nextjs-turbopack-stable10001
✅ nextjs-webpack-canary81020
✅ nextjs-webpack-stable10001
✅ nitro-stable9407
✅ nuxt-stable9407
✅ sveltekit-stable9407
✅ vite-stable9407
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack10100
❌ 🌍 Community Worlds
AppPassedFailedSkipped
✅ mongodb-dev302
✅ redis-dev302
❌ redis63190
✅ turso-dev302
❌ turso3790
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable9506
✅ e2e-local-dev-tanstack-start-stable9506
✅ e2e-local-postgres-nest-stable9407
✅ e2e-local-postgres-tanstack-start-stable9407
✅ e2e-local-prod-nest-stable9506
✅ e2e-local-prod-tanstack-start-stable9506

📋 View full workflow run

@TooTallNate
TooTallNate merged commit c4ed84f into stableJun 16, 2026
92 of 95 checks passed
@TooTallNate
TooTallNate deleted the backport/pr-2457-to-stable branch June 16, 2026 22:39
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@TooTallNate
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Backport #2457: fix(deps): upgrade astro to 6.4.6 to resolve CVE-2026-54299 - #2461

Merged
TooTallNate merged 1 commit into
stablefrom
backport/pr-2457-to-stable
Jun 16, 2026
Merged

Backport #2457: fix(deps): upgrade astro to 6.4.6 to resolve CVE-2026-54299#2461
TooTallNate merged 1 commit into
stablefrom
backport/pr-2457-to-stable

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Automated backport of #2457 to stable (backport job run).

AI recommendation: This is a security fix (CVE-2026-54299) bumping astro in packages/astro and workbench/astro, both of which exist on stable with the same vulnerable astro@5.18.0 devDependency. The fix is a self-contained dependency bump that does not build on any main-only API, so the vulnerability applies to stable as well and should be backported.

Astro <6.4.6 is vulnerable to CVE-2026-54299 (GHSA-2pvr-wf23-7pc7, host
header SSRF in prerendered error page fetch). The fix only exists in the
6.x line — there is no 5.x backport — so this bumps:
- workbench/astro: astro ^6.4.6, @astrojs/node 10.1.4, @astrojs/vercel ^10.0.8
- packages/astro: astro devDependency 6.4.6 (typecheck only, not shipped)
Removes both vulnerable astro@5.16.3 and astro@5.18.0 from the lockfile.
Verified the example app builds under both the node and vercel adapters.
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Pranay Prakash <pranay.gp@gmail.com>
@changeset-bot

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: bd4e4da

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 16 packages
NameType
@workflow/astroPatch
workflowPatch
@workflow/world-testingPatch
@workflow/corePatch
@workflow/buildersPatch
@workflow/cliPatch
@workflow/nextPatch
@workflow/nitroPatch
@workflow/vitestPatch
@workflow/web-sharedPatch
@workflow/webPatch
@workflow/nestPatch
@workflow/rollupPatch
@workflow/sveltekitPatch
@workflow/vitePatch
@workflow/nuxtPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Jun 16, 2026

Copy link
Copy Markdown
Contributor

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

DiffPackageSupply Chain
Security
VulnerabilityQualityMaintenanceLicense
Addednpm/​@​astrojs/​node@​10.1.41001008297100
Addednpm/​@​astrojs/​vercel@​10.0.81001008397100
Addednpm/​astro@​6.4.6881008898100

View full report

@TooTallNate
TooTallNate enabled auto-merge (squash) June 16, 2026 22:23
@github-actions

github-actionsBot commented Jun 16, 2026

Copy link
Copy Markdown
ContributorAuthor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
✅ ▲ Vercel Production10440671111
✅ 💻 Local Development11260861212
✅ 📦 Local Production11260861212
✅ 🐘 Local Postgres11140981212
✅ 🪟 Windows10100101
❌ 🌍 Community Worlds75986179
✅ 📋 Other568038606
Total5154983815633

❌ Failed Tests

🌍 Community Worlds (98 failed)

redis (19 failed):

  • hookWorkflow | wrun_01KV98N0R2MXQD8YSGR4BENY8P
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KV98N91GVT38AV2PYN4TYBNV
  • parallelStepsThenWebhookWorkflow - no hook_conflict from same-tick replay race | wrun_01KV98NMYQVCH6XYR4ZQ2016MM
  • sleepingWorkflow | wrun_01KV98Q46BDRXMZWGW75NWCTGC
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KV98YWQ3000CWG9RP8TN59CH
  • hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload | wrun_01KV98Z8XR51ZFQM9P012YECEQ
  • hookGetConflictThenStepParallelWorkflow - hook.getConflict() continuation step runs alongside other steps | wrun_01KV98ZGRE0PP2WG3TNFGJ1Y2E
  • hookGetConflictWorkflow - hook.getConflict() resolves with the conflicting run when token is already registered | wrun_01KV98ZZKDNP25VY06WQG1D6PT
  • hookClaimOnlyMutexWorkflow - hook works as a pure run mutex without payload data | wrun_01KV990TBH99XVBCCXW29WBNSM
  • hookAdoptOwnerResultWorkflow - duplicate adopts the owner result via conflict.returnValue | wrun_01KV990YNAH14VCA65PX4EW3N9
  • hookSignalOwnerWorkflow - duplicate forwards its payload to the owner via resumeHook | wrun_01KV9914PKN1BPEQ4WMP8YW0X0
  • hookSupersedeOwnerWorkflow - duplicate cancels the owner and claims the released token | wrun_01KV991AMMFXEQMQ91826GP029
  • resume-or-start route pattern - resumeHook retried after start() reaches the new run | wrun_01KV991MJZX32941PFHEMVVG7K
  • pages router sleepingWorkflow via pages router
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KV997R4Y3RXWNH6N2ZQZQR8A

turso (79 failed):

  • addTenWorkflow | wrun_01KV98M31H4Q3JSGN6HV5BVCZJ
  • addTenWorkflow | wrun_01KV98M31H4Q3JSGN6HV5BVCZJ
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KV98KVZC8YPZPWKJZ5K908BN
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KV98MAA50K1XAMV7C5RZP6PZ
  • promiseRaceWorkflow | wrun_01KV98MF22V7D4C4BX5FPEH4VA
  • promiseAnyWorkflow | wrun_01KV98MH96F5PWMSBHR6WJE554
  • importedStepOnlyWorkflow | wrun_01KV98MB2A66MJD5W7311FMHNF
  • readableStreamWorkflow | wrun_01KV98MKVE6FYFR3YFK3JREHJ9
  • hookWorkflow | wrun_01KV98N0R2MXQD8YSGR4BENY8P
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KV98N91GVT38AV2PYN4TYBNV
  • webhookWorkflow | wrun_01KV98NE45N76N2XXM0FRA26QF
  • parallelStepsThenWebhookWorkflow - no hook_conflict from same-tick replay race | wrun_01KV98NMYQVCH6XYR4ZQ2016MM
  • sleepingWorkflow | wrun_01KV98Q46BDRXMZWGW75NWCTGC
  • parallelSleepWorkflow | wrun_01KV98QMH679XQF9201BE678JN
  • nullByteWorkflow | wrun_01KV98QR6VNY8250G0FYKT7Q2Y
  • workflowAndStepMetadataWorkflow | wrun_01KV98QTCX4WSQBPM72VPXXG1K
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KV98T2JC8FZFVKQDAB5JA8K1
  • writableForwardedFromWorkflowWorkflow | wrun_01KV98TJPJT9DWSRVG8JJ898VG
  • writableForwardedFromStepWorkflow | wrun_01KV98TR1E9DEQN4EEZR442TTC
  • fetchWorkflow | wrun_01KV98TVNER9T1JEWTZ9KFF2DF
  • promiseRaceStressTestWorkflow | wrun_01KV98TZ1TYWNKGEZZJWRRT18R
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KV98YGG1TJ1BQWV2XJ3AT7QZ
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KV98YWQ3000CWG9RP8TN59CH
  • hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload | wrun_01KV98Z8XR51ZFQM9P012YECEQ
  • 'hookGetConflictWithPriorStepWorkflow' - hook.getConflict() does not block step execution | wrun_01KV98ZBD71VG7SC257M48MF1G
  • 'hookGetConflictWithParallelStepWorkfl…' - hook.getConflict() does not block step execution | wrun_01KV98ZE0NDYCAGFTJE5JPE3EK
  • hookGetConflictThenStepParallelWorkflow - hook.getConflict() continuation step runs alongside other steps | wrun_01KV98ZGRE0PP2WG3TNFGJ1Y2E
  • hookGetConflictWorkflow - hook.getConflict() resolves with the conflicting run when token is already registered | wrun_01KV98ZZKDNP25VY06WQG1D6PT
  • hookClaimOnlyMutexWorkflow - hook works as a pure run mutex without payload data | wrun_01KV990TBH99XVBCCXW29WBNSM
  • hookAdoptOwnerResultWorkflow - duplicate adopts the owner result via conflict.returnValue | wrun_01KV990YNAH14VCA65PX4EW3N9
  • hookSignalOwnerWorkflow - duplicate forwards its payload to the owner via resumeHook | wrun_01KV9914PKN1BPEQ4WMP8YW0X0
  • hookSupersedeOwnerWorkflow - duplicate cancels the owner and claims the released token | wrun_01KV991AMMFXEQMQ91826GP029
  • resume-or-start route pattern - resumeHook retried after start() reaches the new run | wrun_01KV991MJZX32941PFHEMVVG7K
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KV991WC53780NZNEE4YW52ZJ
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KV992CVJ6F2HBSRT8VDCXPDC
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KV992PCS9RJTZX7RR8MPY8GX
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KV992W6N0FAVHG8AAXGHF8SC
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KV992YHDR5S1K70PT7WN4AYV
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KV993F0VPKW6FB3ZN3SJ2MS7
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KV993P3F5G5M92GWFGS99V84
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KV993WBZ67WF575B6CW4WK5Q
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KV9943BE4ST811CGN2JS7RBN
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KV994A9CZCKJPGHVCP8QF5WA
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KV994JMM62VCA5J3GYTVF0D8
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KV994TW16C69PXHC518XTRXV
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KV99586QT9JYHAA44FARKKHM
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KV995J44NCP6WXJT5TARXER6
  • cancelRun - cancelling a running workflow | wrun_01KV995S4Q6A0WTMZ6HVM2D3EK
  • cancelRun via CLI - cancelling a running workflow | wrun_01KV9963CXFPF1PZD8BPEX8PTV
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KV996FZKE08Q1TW28CYCX633
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KV9970QJ4PZJYKAWYNW3XQGE
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KV997BP7C5HG0AMV6RJKPZJJ
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KV997K2A69TJN7ZTSHE7542R
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KV997NBK942J5VVW30ZT4RCS
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KV997R4Y3RXWNH6N2ZQZQR8A

Details by Category

✅ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro9407
✅ example9407
✅ express9407
✅ fastify9407
✅ hono9407
✅ nextjs-turbopack9902
✅ nextjs-webpack9902
✅ nitro9407
✅ nuxt9407
✅ sveltekit9407
✅ vite9407
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable9506
✅ express-stable9506
✅ fastify-stable9506
✅ hono-stable9506
✅ nextjs-turbopack-canary82019
✅ nextjs-turbopack-stable10100
✅ nextjs-webpack-canary82019
✅ nextjs-webpack-stable10100
✅ nitro-stable9506
✅ nuxt-stable9506
✅ sveltekit-stable9506
✅ vite-stable9506
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable9506
✅ express-stable9506
✅ fastify-stable9506
✅ hono-stable9506
✅ nextjs-turbopack-canary82019
✅ nextjs-turbopack-stable10100
✅ nextjs-webpack-canary82019
✅ nextjs-webpack-stable10100
✅ nitro-stable9506
✅ nuxt-stable9506
✅ sveltekit-stable9506
✅ vite-stable9506
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable9407
✅ express-stable9407
✅ fastify-stable9407
✅ hono-stable9407
✅ nextjs-turbopack-canary81020
✅ nextjs-turbopack-stable10001
✅ nextjs-webpack-canary81020
✅ nextjs-webpack-stable10001
✅ nitro-stable9407
✅ nuxt-stable9407
✅ sveltekit-stable9407
✅ vite-stable9407
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack10100
❌ 🌍 Community Worlds
AppPassedFailedSkipped
✅ mongodb-dev302
✅ redis-dev302
❌ redis63190
✅ turso-dev302
❌ turso3790
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable9506
✅ e2e-local-dev-tanstack-start-stable9506
✅ e2e-local-postgres-nest-stable9407
✅ e2e-local-postgres-tanstack-start-stable9407
✅ e2e-local-prod-nest-stable9506
✅ e2e-local-prod-tanstack-start-stable9506

📋 View full workflow run

@TooTallNate
TooTallNate merged commit c4ed84f into stableJun 16, 2026
92 of 95 checks passed
@TooTallNate
TooTallNate deleted the backport/pr-2457-to-stable branch June 16, 2026 22:39
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@TooTallNate
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Backport #2457: fix(deps): upgrade astro to 6.4.6 to resolve CVE-2026-54299 - #2461

Merged
TooTallNate merged 1 commit into
stablefrom
backport/pr-2457-to-stable
Jun 16, 2026
Merged

Backport #2457: fix(deps): upgrade astro to 6.4.6 to resolve CVE-2026-54299#2461
TooTallNate merged 1 commit into
stablefrom
backport/pr-2457-to-stable

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Automated backport of #2457 to stable (backport job run).

AI recommendation: This is a security fix (CVE-2026-54299) bumping astro in packages/astro and workbench/astro, both of which exist on stable with the same vulnerable astro@5.18.0 devDependency. The fix is a self-contained dependency bump that does not build on any main-only API, so the vulnerability applies to stable as well and should be backported.

Astro <6.4.6 is vulnerable to CVE-2026-54299 (GHSA-2pvr-wf23-7pc7, host
header SSRF in prerendered error page fetch). The fix only exists in the
6.x line — there is no 5.x backport — so this bumps:
- workbench/astro: astro ^6.4.6, @astrojs/node 10.1.4, @astrojs/vercel ^10.0.8
- packages/astro: astro devDependency 6.4.6 (typecheck only, not shipped)
Removes both vulnerable astro@5.16.3 and astro@5.18.0 from the lockfile.
Verified the example app builds under both the node and vercel adapters.
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Pranay Prakash <pranay.gp@gmail.com>
@changeset-bot

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: bd4e4da

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 16 packages
NameType
@workflow/astroPatch
workflowPatch
@workflow/world-testingPatch
@workflow/corePatch
@workflow/buildersPatch
@workflow/cliPatch
@workflow/nextPatch
@workflow/nitroPatch
@workflow/vitestPatch
@workflow/web-sharedPatch
@workflow/webPatch
@workflow/nestPatch
@workflow/rollupPatch
@workflow/sveltekitPatch
@workflow/vitePatch
@workflow/nuxtPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Jun 16, 2026

Copy link
Copy Markdown
Contributor

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

DiffPackageSupply Chain
Security
VulnerabilityQualityMaintenanceLicense
Addednpm/​@​astrojs/​node@​10.1.41001008297100
Addednpm/​@​astrojs/​vercel@​10.0.81001008397100
Addednpm/​astro@​6.4.6881008898100

View full report

@TooTallNate
TooTallNate enabled auto-merge (squash) June 16, 2026 22:23
@github-actions

github-actionsBot commented Jun 16, 2026

Copy link
Copy Markdown
ContributorAuthor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
✅ ▲ Vercel Production10440671111
✅ 💻 Local Development11260861212
✅ 📦 Local Production11260861212
✅ 🐘 Local Postgres11140981212
✅ 🪟 Windows10100101
❌ 🌍 Community Worlds75986179
✅ 📋 Other568038606
Total5154983815633

❌ Failed Tests

🌍 Community Worlds (98 failed)

redis (19 failed):

  • hookWorkflow | wrun_01KV98N0R2MXQD8YSGR4BENY8P
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KV98N91GVT38AV2PYN4TYBNV
  • parallelStepsThenWebhookWorkflow - no hook_conflict from same-tick replay race | wrun_01KV98NMYQVCH6XYR4ZQ2016MM
  • sleepingWorkflow | wrun_01KV98Q46BDRXMZWGW75NWCTGC
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KV98YWQ3000CWG9RP8TN59CH
  • hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload | wrun_01KV98Z8XR51ZFQM9P012YECEQ
  • hookGetConflictThenStepParallelWorkflow - hook.getConflict() continuation step runs alongside other steps | wrun_01KV98ZGRE0PP2WG3TNFGJ1Y2E
  • hookGetConflictWorkflow - hook.getConflict() resolves with the conflicting run when token is already registered | wrun_01KV98ZZKDNP25VY06WQG1D6PT
  • hookClaimOnlyMutexWorkflow - hook works as a pure run mutex without payload data | wrun_01KV990TBH99XVBCCXW29WBNSM
  • hookAdoptOwnerResultWorkflow - duplicate adopts the owner result via conflict.returnValue | wrun_01KV990YNAH14VCA65PX4EW3N9
  • hookSignalOwnerWorkflow - duplicate forwards its payload to the owner via resumeHook | wrun_01KV9914PKN1BPEQ4WMP8YW0X0
  • hookSupersedeOwnerWorkflow - duplicate cancels the owner and claims the released token | wrun_01KV991AMMFXEQMQ91826GP029
  • resume-or-start route pattern - resumeHook retried after start() reaches the new run | wrun_01KV991MJZX32941PFHEMVVG7K
  • pages router sleepingWorkflow via pages router
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KV997R4Y3RXWNH6N2ZQZQR8A

turso (79 failed):

  • addTenWorkflow | wrun_01KV98M31H4Q3JSGN6HV5BVCZJ
  • addTenWorkflow | wrun_01KV98M31H4Q3JSGN6HV5BVCZJ
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KV98KVZC8YPZPWKJZ5K908BN
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KV98MAA50K1XAMV7C5RZP6PZ
  • promiseRaceWorkflow | wrun_01KV98MF22V7D4C4BX5FPEH4VA
  • promiseAnyWorkflow | wrun_01KV98MH96F5PWMSBHR6WJE554
  • importedStepOnlyWorkflow | wrun_01KV98MB2A66MJD5W7311FMHNF
  • readableStreamWorkflow | wrun_01KV98MKVE6FYFR3YFK3JREHJ9
  • hookWorkflow | wrun_01KV98N0R2MXQD8YSGR4BENY8P
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KV98N91GVT38AV2PYN4TYBNV
  • webhookWorkflow | wrun_01KV98NE45N76N2XXM0FRA26QF
  • parallelStepsThenWebhookWorkflow - no hook_conflict from same-tick replay race | wrun_01KV98NMYQVCH6XYR4ZQ2016MM
  • sleepingWorkflow | wrun_01KV98Q46BDRXMZWGW75NWCTGC
  • parallelSleepWorkflow | wrun_01KV98QMH679XQF9201BE678JN
  • nullByteWorkflow | wrun_01KV98QR6VNY8250G0FYKT7Q2Y
  • workflowAndStepMetadataWorkflow | wrun_01KV98QTCX4WSQBPM72VPXXG1K
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KV98T2JC8FZFVKQDAB5JA8K1
  • writableForwardedFromWorkflowWorkflow | wrun_01KV98TJPJT9DWSRVG8JJ898VG
  • writableForwardedFromStepWorkflow | wrun_01KV98TR1E9DEQN4EEZR442TTC
  • fetchWorkflow | wrun_01KV98TVNER9T1JEWTZ9KFF2DF
  • promiseRaceStressTestWorkflow | wrun_01KV98TZ1TYWNKGEZZJWRRT18R
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KV98YGG1TJ1BQWV2XJ3AT7QZ
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KV98YWQ3000CWG9RP8TN59CH
  • hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload | wrun_01KV98Z8XR51ZFQM9P012YECEQ
  • 'hookGetConflictWithPriorStepWorkflow' - hook.getConflict() does not block step execution | wrun_01KV98ZBD71VG7SC257M48MF1G
  • 'hookGetConflictWithParallelStepWorkfl…' - hook.getConflict() does not block step execution | wrun_01KV98ZE0NDYCAGFTJE5JPE3EK
  • hookGetConflictThenStepParallelWorkflow - hook.getConflict() continuation step runs alongside other steps | wrun_01KV98ZGRE0PP2WG3TNFGJ1Y2E
  • hookGetConflictWorkflow - hook.getConflict() resolves with the conflicting run when token is already registered | wrun_01KV98ZZKDNP25VY06WQG1D6PT
  • hookClaimOnlyMutexWorkflow - hook works as a pure run mutex without payload data | wrun_01KV990TBH99XVBCCXW29WBNSM
  • hookAdoptOwnerResultWorkflow - duplicate adopts the owner result via conflict.returnValue | wrun_01KV990YNAH14VCA65PX4EW3N9
  • hookSignalOwnerWorkflow - duplicate forwards its payload to the owner via resumeHook | wrun_01KV9914PKN1BPEQ4WMP8YW0X0
  • hookSupersedeOwnerWorkflow - duplicate cancels the owner and claims the released token | wrun_01KV991AMMFXEQMQ91826GP029
  • resume-or-start route pattern - resumeHook retried after start() reaches the new run | wrun_01KV991MJZX32941PFHEMVVG7K
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KV991WC53780NZNEE4YW52ZJ
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KV992CVJ6F2HBSRT8VDCXPDC
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KV992PCS9RJTZX7RR8MPY8GX
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KV992W6N0FAVHG8AAXGHF8SC
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KV992YHDR5S1K70PT7WN4AYV
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KV993F0VPKW6FB3ZN3SJ2MS7
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KV993P3F5G5M92GWFGS99V84
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KV993WBZ67WF575B6CW4WK5Q
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KV9943BE4ST811CGN2JS7RBN
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KV994A9CZCKJPGHVCP8QF5WA
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KV994JMM62VCA5J3GYTVF0D8
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KV994TW16C69PXHC518XTRXV
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KV99586QT9JYHAA44FARKKHM
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KV995J44NCP6WXJT5TARXER6
  • cancelRun - cancelling a running workflow | wrun_01KV995S4Q6A0WTMZ6HVM2D3EK
  • cancelRun via CLI - cancelling a running workflow | wrun_01KV9963CXFPF1PZD8BPEX8PTV
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KV996FZKE08Q1TW28CYCX633
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KV9970QJ4PZJYKAWYNW3XQGE
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KV997BP7C5HG0AMV6RJKPZJJ
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KV997K2A69TJN7ZTSHE7542R
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KV997NBK942J5VVW30ZT4RCS
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KV997R4Y3RXWNH6N2ZQZQR8A

Details by Category

✅ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro9407
✅ example9407
✅ express9407
✅ fastify9407
✅ hono9407
✅ nextjs-turbopack9902
✅ nextjs-webpack9902
✅ nitro9407
✅ nuxt9407
✅ sveltekit9407
✅ vite9407
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable9506
✅ express-stable9506
✅ fastify-stable9506
✅ hono-stable9506
✅ nextjs-turbopack-canary82019
✅ nextjs-turbopack-stable10100
✅ nextjs-webpack-canary82019
✅ nextjs-webpack-stable10100
✅ nitro-stable9506
✅ nuxt-stable9506
✅ sveltekit-stable9506
✅ vite-stable9506
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable9506
✅ express-stable9506
✅ fastify-stable9506
✅ hono-stable9506
✅ nextjs-turbopack-canary82019
✅ nextjs-turbopack-stable10100
✅ nextjs-webpack-canary82019
✅ nextjs-webpack-stable10100
✅ nitro-stable9506
✅ nuxt-stable9506
✅ sveltekit-stable9506
✅ vite-stable9506
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable9407
✅ express-stable9407
✅ fastify-stable9407
✅ hono-stable9407
✅ nextjs-turbopack-canary81020
✅ nextjs-turbopack-stable10001
✅ nextjs-webpack-canary81020
✅ nextjs-webpack-stable10001
✅ nitro-stable9407
✅ nuxt-stable9407
✅ sveltekit-stable9407
✅ vite-stable9407
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack10100
❌ 🌍 Community Worlds
AppPassedFailedSkipped
✅ mongodb-dev302
✅ redis-dev302
❌ redis63190
✅ turso-dev302
❌ turso3790
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable9506
✅ e2e-local-dev-tanstack-start-stable9506
✅ e2e-local-postgres-nest-stable9407
✅ e2e-local-postgres-tanstack-start-stable9407
✅ e2e-local-prod-nest-stable9506
✅ e2e-local-prod-tanstack-start-stable9506

📋 View full workflow run

@TooTallNate
TooTallNate merged commit c4ed84f into stableJun 16, 2026
92 of 95 checks passed
@TooTallNate
TooTallNate deleted the backport/pr-2457-to-stable branch June 16, 2026 22:39
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@TooTallNate
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Backport #2457: fix(deps): upgrade astro to 6.4.6 to resolve CVE-2026-54299 - #2461

Merged
TooTallNate merged 1 commit into
stablefrom
backport/pr-2457-to-stable
Jun 16, 2026
Merged

Backport #2457: fix(deps): upgrade astro to 6.4.6 to resolve CVE-2026-54299#2461
TooTallNate merged 1 commit into
stablefrom
backport/pr-2457-to-stable

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Automated backport of #2457 to stable (backport job run).

AI recommendation: This is a security fix (CVE-2026-54299) bumping astro in packages/astro and workbench/astro, both of which exist on stable with the same vulnerable astro@5.18.0 devDependency. The fix is a self-contained dependency bump that does not build on any main-only API, so the vulnerability applies to stable as well and should be backported.

Astro <6.4.6 is vulnerable to CVE-2026-54299 (GHSA-2pvr-wf23-7pc7, host
header SSRF in prerendered error page fetch). The fix only exists in the
6.x line — there is no 5.x backport — so this bumps:
- workbench/astro: astro ^6.4.6, @astrojs/node 10.1.4, @astrojs/vercel ^10.0.8
- packages/astro: astro devDependency 6.4.6 (typecheck only, not shipped)
Removes both vulnerable astro@5.16.3 and astro@5.18.0 from the lockfile.
Verified the example app builds under both the node and vercel adapters.
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Pranay Prakash <pranay.gp@gmail.com>
@changeset-bot

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: bd4e4da

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 16 packages
NameType
@workflow/astroPatch
workflowPatch
@workflow/world-testingPatch
@workflow/corePatch
@workflow/buildersPatch
@workflow/cliPatch
@workflow/nextPatch
@workflow/nitroPatch
@workflow/vitestPatch
@workflow/web-sharedPatch
@workflow/webPatch
@workflow/nestPatch
@workflow/rollupPatch
@workflow/sveltekitPatch
@workflow/vitePatch
@workflow/nuxtPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Jun 16, 2026

Copy link
Copy Markdown
Contributor

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

DiffPackageSupply Chain
Security
VulnerabilityQualityMaintenanceLicense
Addednpm/​@​astrojs/​node@​10.1.41001008297100
Addednpm/​@​astrojs/​vercel@​10.0.81001008397100
Addednpm/​astro@​6.4.6881008898100

View full report

@TooTallNate
TooTallNate enabled auto-merge (squash) June 16, 2026 22:23
@github-actions

github-actionsBot commented Jun 16, 2026

Copy link
Copy Markdown
ContributorAuthor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
✅ ▲ Vercel Production10440671111
✅ 💻 Local Development11260861212
✅ 📦 Local Production11260861212
✅ 🐘 Local Postgres11140981212
✅ 🪟 Windows10100101
❌ 🌍 Community Worlds75986179
✅ 📋 Other568038606
Total5154983815633

❌ Failed Tests

🌍 Community Worlds (98 failed)

redis (19 failed):

  • hookWorkflow | wrun_01KV98N0R2MXQD8YSGR4BENY8P
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KV98N91GVT38AV2PYN4TYBNV
  • parallelStepsThenWebhookWorkflow - no hook_conflict from same-tick replay race | wrun_01KV98NMYQVCH6XYR4ZQ2016MM
  • sleepingWorkflow | wrun_01KV98Q46BDRXMZWGW75NWCTGC
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KV98YWQ3000CWG9RP8TN59CH
  • hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload | wrun_01KV98Z8XR51ZFQM9P012YECEQ
  • hookGetConflictThenStepParallelWorkflow - hook.getConflict() continuation step runs alongside other steps | wrun_01KV98ZGRE0PP2WG3TNFGJ1Y2E
  • hookGetConflictWorkflow - hook.getConflict() resolves with the conflicting run when token is already registered | wrun_01KV98ZZKDNP25VY06WQG1D6PT
  • hookClaimOnlyMutexWorkflow - hook works as a pure run mutex without payload data | wrun_01KV990TBH99XVBCCXW29WBNSM
  • hookAdoptOwnerResultWorkflow - duplicate adopts the owner result via conflict.returnValue | wrun_01KV990YNAH14VCA65PX4EW3N9
  • hookSignalOwnerWorkflow - duplicate forwards its payload to the owner via resumeHook | wrun_01KV9914PKN1BPEQ4WMP8YW0X0
  • hookSupersedeOwnerWorkflow - duplicate cancels the owner and claims the released token | wrun_01KV991AMMFXEQMQ91826GP029
  • resume-or-start route pattern - resumeHook retried after start() reaches the new run | wrun_01KV991MJZX32941PFHEMVVG7K
  • pages router sleepingWorkflow via pages router
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KV997R4Y3RXWNH6N2ZQZQR8A

turso (79 failed):

  • addTenWorkflow | wrun_01KV98M31H4Q3JSGN6HV5BVCZJ
  • addTenWorkflow | wrun_01KV98M31H4Q3JSGN6HV5BVCZJ
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KV98KVZC8YPZPWKJZ5K908BN
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KV98MAA50K1XAMV7C5RZP6PZ
  • promiseRaceWorkflow | wrun_01KV98MF22V7D4C4BX5FPEH4VA
  • promiseAnyWorkflow | wrun_01KV98MH96F5PWMSBHR6WJE554
  • importedStepOnlyWorkflow | wrun_01KV98MB2A66MJD5W7311FMHNF
  • readableStreamWorkflow | wrun_01KV98MKVE6FYFR3YFK3JREHJ9
  • hookWorkflow | wrun_01KV98N0R2MXQD8YSGR4BENY8P
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KV98N91GVT38AV2PYN4TYBNV
  • webhookWorkflow | wrun_01KV98NE45N76N2XXM0FRA26QF
  • parallelStepsThenWebhookWorkflow - no hook_conflict from same-tick replay race | wrun_01KV98NMYQVCH6XYR4ZQ2016MM
  • sleepingWorkflow | wrun_01KV98Q46BDRXMZWGW75NWCTGC
  • parallelSleepWorkflow | wrun_01KV98QMH679XQF9201BE678JN
  • nullByteWorkflow | wrun_01KV98QR6VNY8250G0FYKT7Q2Y
  • workflowAndStepMetadataWorkflow | wrun_01KV98QTCX4WSQBPM72VPXXG1K
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KV98T2JC8FZFVKQDAB5JA8K1
  • writableForwardedFromWorkflowWorkflow | wrun_01KV98TJPJT9DWSRVG8JJ898VG
  • writableForwardedFromStepWorkflow | wrun_01KV98TR1E9DEQN4EEZR442TTC
  • fetchWorkflow | wrun_01KV98TVNER9T1JEWTZ9KFF2DF
  • promiseRaceStressTestWorkflow | wrun_01KV98TZ1TYWNKGEZZJWRRT18R
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KV98YGG1TJ1BQWV2XJ3AT7QZ
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KV98YWQ3000CWG9RP8TN59CH
  • hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload | wrun_01KV98Z8XR51ZFQM9P012YECEQ
  • 'hookGetConflictWithPriorStepWorkflow' - hook.getConflict() does not block step execution | wrun_01KV98ZBD71VG7SC257M48MF1G
  • 'hookGetConflictWithParallelStepWorkfl…' - hook.getConflict() does not block step execution | wrun_01KV98ZE0NDYCAGFTJE5JPE3EK
  • hookGetConflictThenStepParallelWorkflow - hook.getConflict() continuation step runs alongside other steps | wrun_01KV98ZGRE0PP2WG3TNFGJ1Y2E
  • hookGetConflictWorkflow - hook.getConflict() resolves with the conflicting run when token is already registered | wrun_01KV98ZZKDNP25VY06WQG1D6PT
  • hookClaimOnlyMutexWorkflow - hook works as a pure run mutex without payload data | wrun_01KV990TBH99XVBCCXW29WBNSM
  • hookAdoptOwnerResultWorkflow - duplicate adopts the owner result via conflict.returnValue | wrun_01KV990YNAH14VCA65PX4EW3N9
  • hookSignalOwnerWorkflow - duplicate forwards its payload to the owner via resumeHook | wrun_01KV9914PKN1BPEQ4WMP8YW0X0
  • hookSupersedeOwnerWorkflow - duplicate cancels the owner and claims the released token | wrun_01KV991AMMFXEQMQ91826GP029
  • resume-or-start route pattern - resumeHook retried after start() reaches the new run | wrun_01KV991MJZX32941PFHEMVVG7K
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KV991WC53780NZNEE4YW52ZJ
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KV992CVJ6F2HBSRT8VDCXPDC
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KV992PCS9RJTZX7RR8MPY8GX
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KV992W6N0FAVHG8AAXGHF8SC
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KV992YHDR5S1K70PT7WN4AYV
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KV993F0VPKW6FB3ZN3SJ2MS7
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KV993P3F5G5M92GWFGS99V84
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KV993WBZ67WF575B6CW4WK5Q
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KV9943BE4ST811CGN2JS7RBN
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KV994A9CZCKJPGHVCP8QF5WA
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KV994JMM62VCA5J3GYTVF0D8
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KV994TW16C69PXHC518XTRXV
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KV99586QT9JYHAA44FARKKHM
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KV995J44NCP6WXJT5TARXER6
  • cancelRun - cancelling a running workflow | wrun_01KV995S4Q6A0WTMZ6HVM2D3EK
  • cancelRun via CLI - cancelling a running workflow | wrun_01KV9963CXFPF1PZD8BPEX8PTV
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KV996FZKE08Q1TW28CYCX633
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KV9970QJ4PZJYKAWYNW3XQGE
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KV997BP7C5HG0AMV6RJKPZJJ
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KV997K2A69TJN7ZTSHE7542R
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KV997NBK942J5VVW30ZT4RCS
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KV997R4Y3RXWNH6N2ZQZQR8A

Details by Category

✅ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro9407
✅ example9407
✅ express9407
✅ fastify9407
✅ hono9407
✅ nextjs-turbopack9902
✅ nextjs-webpack9902
✅ nitro9407
✅ nuxt9407
✅ sveltekit9407
✅ vite9407
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable9506
✅ express-stable9506
✅ fastify-stable9506
✅ hono-stable9506
✅ nextjs-turbopack-canary82019
✅ nextjs-turbopack-stable10100
✅ nextjs-webpack-canary82019
✅ nextjs-webpack-stable10100
✅ nitro-stable9506
✅ nuxt-stable9506
✅ sveltekit-stable9506
✅ vite-stable9506
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable9506
✅ express-stable9506
✅ fastify-stable9506
✅ hono-stable9506
✅ nextjs-turbopack-canary82019
✅ nextjs-turbopack-stable10100
✅ nextjs-webpack-canary82019
✅ nextjs-webpack-stable10100
✅ nitro-stable9506
✅ nuxt-stable9506
✅ sveltekit-stable9506
✅ vite-stable9506
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable9407
✅ express-stable9407
✅ fastify-stable9407
✅ hono-stable9407
✅ nextjs-turbopack-canary81020
✅ nextjs-turbopack-stable10001
✅ nextjs-webpack-canary81020
✅ nextjs-webpack-stable10001
✅ nitro-stable9407
✅ nuxt-stable9407
✅ sveltekit-stable9407
✅ vite-stable9407
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack10100
❌ 🌍 Community Worlds
AppPassedFailedSkipped
✅ mongodb-dev302
✅ redis-dev302
❌ redis63190
✅ turso-dev302
❌ turso3790
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable9506
✅ e2e-local-dev-tanstack-start-stable9506
✅ e2e-local-postgres-nest-stable9407
✅ e2e-local-postgres-tanstack-start-stable9407
✅ e2e-local-prod-nest-stable9506
✅ e2e-local-prod-tanstack-start-stable9506

📋 View full workflow run

@TooTallNate
TooTallNate merged commit c4ed84f into stableJun 16, 2026
92 of 95 checks passed
@TooTallNate
TooTallNate deleted the backport/pr-2457-to-stable branch June 16, 2026 22:39
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@TooTallNate
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Backport #2457: fix(deps): upgrade astro to 6.4.6 to resolve CVE-2026-54299 - #2461

Merged
TooTallNate merged 1 commit into
stablefrom
backport/pr-2457-to-stable
Jun 16, 2026
Merged

Backport #2457: fix(deps): upgrade astro to 6.4.6 to resolve CVE-2026-54299#2461
TooTallNate merged 1 commit into
stablefrom
backport/pr-2457-to-stable

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Automated backport of #2457 to stable (backport job run).

AI recommendation: This is a security fix (CVE-2026-54299) bumping astro in packages/astro and workbench/astro, both of which exist on stable with the same vulnerable astro@5.18.0 devDependency. The fix is a self-contained dependency bump that does not build on any main-only API, so the vulnerability applies to stable as well and should be backported.

Astro <6.4.6 is vulnerable to CVE-2026-54299 (GHSA-2pvr-wf23-7pc7, host
header SSRF in prerendered error page fetch). The fix only exists in the
6.x line — there is no 5.x backport — so this bumps:
- workbench/astro: astro ^6.4.6, @astrojs/node 10.1.4, @astrojs/vercel ^10.0.8
- packages/astro: astro devDependency 6.4.6 (typecheck only, not shipped)
Removes both vulnerable astro@5.16.3 and astro@5.18.0 from the lockfile.
Verified the example app builds under both the node and vercel adapters.
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Pranay Prakash <pranay.gp@gmail.com>
@changeset-bot

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: bd4e4da

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 16 packages
NameType
@workflow/astroPatch
workflowPatch
@workflow/world-testingPatch
@workflow/corePatch
@workflow/buildersPatch
@workflow/cliPatch
@workflow/nextPatch
@workflow/nitroPatch
@workflow/vitestPatch
@workflow/web-sharedPatch
@workflow/webPatch
@workflow/nestPatch
@workflow/rollupPatch
@workflow/sveltekitPatch
@workflow/vitePatch
@workflow/nuxtPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Jun 16, 2026

Copy link
Copy Markdown
Contributor

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

DiffPackageSupply Chain
Security
VulnerabilityQualityMaintenanceLicense
Addednpm/​@​astrojs/​node@​10.1.41001008297100
Addednpm/​@​astrojs/​vercel@​10.0.81001008397100
Addednpm/​astro@​6.4.6881008898100

View full report

@TooTallNate
TooTallNate enabled auto-merge (squash) June 16, 2026 22:23
@github-actions

github-actionsBot commented Jun 16, 2026

Copy link
Copy Markdown
ContributorAuthor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
✅ ▲ Vercel Production10440671111
✅ 💻 Local Development11260861212
✅ 📦 Local Production11260861212
✅ 🐘 Local Postgres11140981212
✅ 🪟 Windows10100101
❌ 🌍 Community Worlds75986179
✅ 📋 Other568038606
Total5154983815633

❌ Failed Tests

🌍 Community Worlds (98 failed)

redis (19 failed):

  • hookWorkflow | wrun_01KV98N0R2MXQD8YSGR4BENY8P
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KV98N91GVT38AV2PYN4TYBNV
  • parallelStepsThenWebhookWorkflow - no hook_conflict from same-tick replay race | wrun_01KV98NMYQVCH6XYR4ZQ2016MM
  • sleepingWorkflow | wrun_01KV98Q46BDRXMZWGW75NWCTGC
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KV98YWQ3000CWG9RP8TN59CH
  • hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload | wrun_01KV98Z8XR51ZFQM9P012YECEQ
  • hookGetConflictThenStepParallelWorkflow - hook.getConflict() continuation step runs alongside other steps | wrun_01KV98ZGRE0PP2WG3TNFGJ1Y2E
  • hookGetConflictWorkflow - hook.getConflict() resolves with the conflicting run when token is already registered | wrun_01KV98ZZKDNP25VY06WQG1D6PT
  • hookClaimOnlyMutexWorkflow - hook works as a pure run mutex without payload data | wrun_01KV990TBH99XVBCCXW29WBNSM
  • hookAdoptOwnerResultWorkflow - duplicate adopts the owner result via conflict.returnValue | wrun_01KV990YNAH14VCA65PX4EW3N9
  • hookSignalOwnerWorkflow - duplicate forwards its payload to the owner via resumeHook | wrun_01KV9914PKN1BPEQ4WMP8YW0X0
  • hookSupersedeOwnerWorkflow - duplicate cancels the owner and claims the released token | wrun_01KV991AMMFXEQMQ91826GP029
  • resume-or-start route pattern - resumeHook retried after start() reaches the new run | wrun_01KV991MJZX32941PFHEMVVG7K
  • pages router sleepingWorkflow via pages router
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KV997R4Y3RXWNH6N2ZQZQR8A

turso (79 failed):

  • addTenWorkflow | wrun_01KV98M31H4Q3JSGN6HV5BVCZJ
  • addTenWorkflow | wrun_01KV98M31H4Q3JSGN6HV5BVCZJ
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KV98KVZC8YPZPWKJZ5K908BN
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KV98MAA50K1XAMV7C5RZP6PZ
  • promiseRaceWorkflow | wrun_01KV98MF22V7D4C4BX5FPEH4VA
  • promiseAnyWorkflow | wrun_01KV98MH96F5PWMSBHR6WJE554
  • importedStepOnlyWorkflow | wrun_01KV98MB2A66MJD5W7311FMHNF
  • readableStreamWorkflow | wrun_01KV98MKVE6FYFR3YFK3JREHJ9
  • hookWorkflow | wrun_01KV98N0R2MXQD8YSGR4BENY8P
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KV98N91GVT38AV2PYN4TYBNV
  • webhookWorkflow | wrun_01KV98NE45N76N2XXM0FRA26QF
  • parallelStepsThenWebhookWorkflow - no hook_conflict from same-tick replay race | wrun_01KV98NMYQVCH6XYR4ZQ2016MM
  • sleepingWorkflow | wrun_01KV98Q46BDRXMZWGW75NWCTGC
  • parallelSleepWorkflow | wrun_01KV98QMH679XQF9201BE678JN
  • nullByteWorkflow | wrun_01KV98QR6VNY8250G0FYKT7Q2Y
  • workflowAndStepMetadataWorkflow | wrun_01KV98QTCX4WSQBPM72VPXXG1K
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KV98T2JC8FZFVKQDAB5JA8K1
  • writableForwardedFromWorkflowWorkflow | wrun_01KV98TJPJT9DWSRVG8JJ898VG
  • writableForwardedFromStepWorkflow | wrun_01KV98TR1E9DEQN4EEZR442TTC
  • fetchWorkflow | wrun_01KV98TVNER9T1JEWTZ9KFF2DF
  • promiseRaceStressTestWorkflow | wrun_01KV98TZ1TYWNKGEZZJWRRT18R
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KV98YGG1TJ1BQWV2XJ3AT7QZ
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KV98YWQ3000CWG9RP8TN59CH
  • hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload | wrun_01KV98Z8XR51ZFQM9P012YECEQ
  • 'hookGetConflictWithPriorStepWorkflow' - hook.getConflict() does not block step execution | wrun_01KV98ZBD71VG7SC257M48MF1G
  • 'hookGetConflictWithParallelStepWorkfl…' - hook.getConflict() does not block step execution | wrun_01KV98ZE0NDYCAGFTJE5JPE3EK
  • hookGetConflictThenStepParallelWorkflow - hook.getConflict() continuation step runs alongside other steps | wrun_01KV98ZGRE0PP2WG3TNFGJ1Y2E
  • hookGetConflictWorkflow - hook.getConflict() resolves with the conflicting run when token is already registered | wrun_01KV98ZZKDNP25VY06WQG1D6PT
  • hookClaimOnlyMutexWorkflow - hook works as a pure run mutex without payload data | wrun_01KV990TBH99XVBCCXW29WBNSM
  • hookAdoptOwnerResultWorkflow - duplicate adopts the owner result via conflict.returnValue | wrun_01KV990YNAH14VCA65PX4EW3N9
  • hookSignalOwnerWorkflow - duplicate forwards its payload to the owner via resumeHook | wrun_01KV9914PKN1BPEQ4WMP8YW0X0
  • hookSupersedeOwnerWorkflow - duplicate cancels the owner and claims the released token | wrun_01KV991AMMFXEQMQ91826GP029
  • resume-or-start route pattern - resumeHook retried after start() reaches the new run | wrun_01KV991MJZX32941PFHEMVVG7K
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KV991WC53780NZNEE4YW52ZJ
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KV992CVJ6F2HBSRT8VDCXPDC
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KV992PCS9RJTZX7RR8MPY8GX
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KV992W6N0FAVHG8AAXGHF8SC
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KV992YHDR5S1K70PT7WN4AYV
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KV993F0VPKW6FB3ZN3SJ2MS7
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KV993P3F5G5M92GWFGS99V84
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KV993WBZ67WF575B6CW4WK5Q
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KV9943BE4ST811CGN2JS7RBN
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KV994A9CZCKJPGHVCP8QF5WA
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KV994JMM62VCA5J3GYTVF0D8
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KV994TW16C69PXHC518XTRXV
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KV99586QT9JYHAA44FARKKHM
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KV995J44NCP6WXJT5TARXER6
  • cancelRun - cancelling a running workflow | wrun_01KV995S4Q6A0WTMZ6HVM2D3EK
  • cancelRun via CLI - cancelling a running workflow | wrun_01KV9963CXFPF1PZD8BPEX8PTV
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KV996FZKE08Q1TW28CYCX633
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KV9970QJ4PZJYKAWYNW3XQGE
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KV997BP7C5HG0AMV6RJKPZJJ
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KV997K2A69TJN7ZTSHE7542R
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KV997NBK942J5VVW30ZT4RCS
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KV997R4Y3RXWNH6N2ZQZQR8A

Details by Category

✅ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro9407
✅ example9407
✅ express9407
✅ fastify9407
✅ hono9407
✅ nextjs-turbopack9902
✅ nextjs-webpack9902
✅ nitro9407
✅ nuxt9407
✅ sveltekit9407
✅ vite9407
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable9506
✅ express-stable9506
✅ fastify-stable9506
✅ hono-stable9506
✅ nextjs-turbopack-canary82019
✅ nextjs-turbopack-stable10100
✅ nextjs-webpack-canary82019
✅ nextjs-webpack-stable10100
✅ nitro-stable9506
✅ nuxt-stable9506
✅ sveltekit-stable9506
✅ vite-stable9506
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable9506
✅ express-stable9506
✅ fastify-stable9506
✅ hono-stable9506
✅ nextjs-turbopack-canary82019
✅ nextjs-turbopack-stable10100
✅ nextjs-webpack-canary82019
✅ nextjs-webpack-stable10100
✅ nitro-stable9506
✅ nuxt-stable9506
✅ sveltekit-stable9506
✅ vite-stable9506
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable9407
✅ express-stable9407
✅ fastify-stable9407
✅ hono-stable9407
✅ nextjs-turbopack-canary81020
✅ nextjs-turbopack-stable10001
✅ nextjs-webpack-canary81020
✅ nextjs-webpack-stable10001
✅ nitro-stable9407
✅ nuxt-stable9407
✅ sveltekit-stable9407
✅ vite-stable9407
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack10100
❌ 🌍 Community Worlds
AppPassedFailedSkipped
✅ mongodb-dev302
✅ redis-dev302
❌ redis63190
✅ turso-dev302
❌ turso3790
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable9506
✅ e2e-local-dev-tanstack-start-stable9506
✅ e2e-local-postgres-nest-stable9407
✅ e2e-local-postgres-tanstack-start-stable9407
✅ e2e-local-prod-nest-stable9506
✅ e2e-local-prod-tanstack-start-stable9506

📋 View full workflow run

@TooTallNate
TooTallNate merged commit c4ed84f into stableJun 16, 2026
92 of 95 checks passed
@TooTallNate
TooTallNate deleted the backport/pr-2457-to-stable branch June 16, 2026 22:39
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@TooTallNate
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Backport #2457: fix(deps): upgrade astro to 6.4.6 to resolve CVE-2026-54299 - #2461

Merged
TooTallNate merged 1 commit into
stablefrom
backport/pr-2457-to-stable
Jun 16, 2026
Merged

Backport #2457: fix(deps): upgrade astro to 6.4.6 to resolve CVE-2026-54299#2461
TooTallNate merged 1 commit into
stablefrom
backport/pr-2457-to-stable

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Automated backport of #2457 to stable (backport job run).

AI recommendation: This is a security fix (CVE-2026-54299) bumping astro in packages/astro and workbench/astro, both of which exist on stable with the same vulnerable astro@5.18.0 devDependency. The fix is a self-contained dependency bump that does not build on any main-only API, so the vulnerability applies to stable as well and should be backported.

Astro <6.4.6 is vulnerable to CVE-2026-54299 (GHSA-2pvr-wf23-7pc7, host
header SSRF in prerendered error page fetch). The fix only exists in the
6.x line — there is no 5.x backport — so this bumps:
- workbench/astro: astro ^6.4.6, @astrojs/node 10.1.4, @astrojs/vercel ^10.0.8
- packages/astro: astro devDependency 6.4.6 (typecheck only, not shipped)
Removes both vulnerable astro@5.16.3 and astro@5.18.0 from the lockfile.
Verified the example app builds under both the node and vercel adapters.
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Pranay Prakash <pranay.gp@gmail.com>
@changeset-bot

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: bd4e4da

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 16 packages
NameType
@workflow/astroPatch
workflowPatch
@workflow/world-testingPatch
@workflow/corePatch
@workflow/buildersPatch
@workflow/cliPatch
@workflow/nextPatch
@workflow/nitroPatch
@workflow/vitestPatch
@workflow/web-sharedPatch
@workflow/webPatch
@workflow/nestPatch
@workflow/rollupPatch
@workflow/sveltekitPatch
@workflow/vitePatch
@workflow/nuxtPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Jun 16, 2026

Copy link
Copy Markdown
Contributor

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

DiffPackageSupply Chain
Security
VulnerabilityQualityMaintenanceLicense
Addednpm/​@​astrojs/​node@​10.1.41001008297100
Addednpm/​@​astrojs/​vercel@​10.0.81001008397100
Addednpm/​astro@​6.4.6881008898100

View full report

@TooTallNate
TooTallNate enabled auto-merge (squash) June 16, 2026 22:23
@github-actions

github-actionsBot commented Jun 16, 2026

Copy link
Copy Markdown
ContributorAuthor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
✅ ▲ Vercel Production10440671111
✅ 💻 Local Development11260861212
✅ 📦 Local Production11260861212
✅ 🐘 Local Postgres11140981212
✅ 🪟 Windows10100101
❌ 🌍 Community Worlds75986179
✅ 📋 Other568038606
Total5154983815633

❌ Failed Tests

🌍 Community Worlds (98 failed)

redis (19 failed):

  • hookWorkflow | wrun_01KV98N0R2MXQD8YSGR4BENY8P
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KV98N91GVT38AV2PYN4TYBNV
  • parallelStepsThenWebhookWorkflow - no hook_conflict from same-tick replay race | wrun_01KV98NMYQVCH6XYR4ZQ2016MM
  • sleepingWorkflow | wrun_01KV98Q46BDRXMZWGW75NWCTGC
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KV98YWQ3000CWG9RP8TN59CH
  • hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload | wrun_01KV98Z8XR51ZFQM9P012YECEQ
  • hookGetConflictThenStepParallelWorkflow - hook.getConflict() continuation step runs alongside other steps | wrun_01KV98ZGRE0PP2WG3TNFGJ1Y2E
  • hookGetConflictWorkflow - hook.getConflict() resolves with the conflicting run when token is already registered | wrun_01KV98ZZKDNP25VY06WQG1D6PT
  • hookClaimOnlyMutexWorkflow - hook works as a pure run mutex without payload data | wrun_01KV990TBH99XVBCCXW29WBNSM
  • hookAdoptOwnerResultWorkflow - duplicate adopts the owner result via conflict.returnValue | wrun_01KV990YNAH14VCA65PX4EW3N9
  • hookSignalOwnerWorkflow - duplicate forwards its payload to the owner via resumeHook | wrun_01KV9914PKN1BPEQ4WMP8YW0X0
  • hookSupersedeOwnerWorkflow - duplicate cancels the owner and claims the released token | wrun_01KV991AMMFXEQMQ91826GP029
  • resume-or-start route pattern - resumeHook retried after start() reaches the new run | wrun_01KV991MJZX32941PFHEMVVG7K
  • pages router sleepingWorkflow via pages router
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KV997R4Y3RXWNH6N2ZQZQR8A

turso (79 failed):

  • addTenWorkflow | wrun_01KV98M31H4Q3JSGN6HV5BVCZJ
  • addTenWorkflow | wrun_01KV98M31H4Q3JSGN6HV5BVCZJ
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KV98KVZC8YPZPWKJZ5K908BN
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KV98MAA50K1XAMV7C5RZP6PZ
  • promiseRaceWorkflow | wrun_01KV98MF22V7D4C4BX5FPEH4VA
  • promiseAnyWorkflow | wrun_01KV98MH96F5PWMSBHR6WJE554
  • importedStepOnlyWorkflow | wrun_01KV98MB2A66MJD5W7311FMHNF
  • readableStreamWorkflow | wrun_01KV98MKVE6FYFR3YFK3JREHJ9
  • hookWorkflow | wrun_01KV98N0R2MXQD8YSGR4BENY8P
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KV98N91GVT38AV2PYN4TYBNV
  • webhookWorkflow | wrun_01KV98NE45N76N2XXM0FRA26QF
  • parallelStepsThenWebhookWorkflow - no hook_conflict from same-tick replay race | wrun_01KV98NMYQVCH6XYR4ZQ2016MM
  • sleepingWorkflow | wrun_01KV98Q46BDRXMZWGW75NWCTGC
  • parallelSleepWorkflow | wrun_01KV98QMH679XQF9201BE678JN
  • nullByteWorkflow | wrun_01KV98QR6VNY8250G0FYKT7Q2Y
  • workflowAndStepMetadataWorkflow | wrun_01KV98QTCX4WSQBPM72VPXXG1K
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KV98T2JC8FZFVKQDAB5JA8K1
  • writableForwardedFromWorkflowWorkflow | wrun_01KV98TJPJT9DWSRVG8JJ898VG
  • writableForwardedFromStepWorkflow | wrun_01KV98TR1E9DEQN4EEZR442TTC
  • fetchWorkflow | wrun_01KV98TVNER9T1JEWTZ9KFF2DF
  • promiseRaceStressTestWorkflow | wrun_01KV98TZ1TYWNKGEZZJWRRT18R
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KV98YGG1TJ1BQWV2XJ3AT7QZ
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KV98YWQ3000CWG9RP8TN59CH
  • hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload | wrun_01KV98Z8XR51ZFQM9P012YECEQ
  • 'hookGetConflictWithPriorStepWorkflow' - hook.getConflict() does not block step execution | wrun_01KV98ZBD71VG7SC257M48MF1G
  • 'hookGetConflictWithParallelStepWorkfl…' - hook.getConflict() does not block step execution | wrun_01KV98ZE0NDYCAGFTJE5JPE3EK
  • hookGetConflictThenStepParallelWorkflow - hook.getConflict() continuation step runs alongside other steps | wrun_01KV98ZGRE0PP2WG3TNFGJ1Y2E
  • hookGetConflictWorkflow - hook.getConflict() resolves with the conflicting run when token is already registered | wrun_01KV98ZZKDNP25VY06WQG1D6PT
  • hookClaimOnlyMutexWorkflow - hook works as a pure run mutex without payload data | wrun_01KV990TBH99XVBCCXW29WBNSM
  • hookAdoptOwnerResultWorkflow - duplicate adopts the owner result via conflict.returnValue | wrun_01KV990YNAH14VCA65PX4EW3N9
  • hookSignalOwnerWorkflow - duplicate forwards its payload to the owner via resumeHook | wrun_01KV9914PKN1BPEQ4WMP8YW0X0
  • hookSupersedeOwnerWorkflow - duplicate cancels the owner and claims the released token | wrun_01KV991AMMFXEQMQ91826GP029
  • resume-or-start route pattern - resumeHook retried after start() reaches the new run | wrun_01KV991MJZX32941PFHEMVVG7K
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KV991WC53780NZNEE4YW52ZJ
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KV992CVJ6F2HBSRT8VDCXPDC
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KV992PCS9RJTZX7RR8MPY8GX
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KV992W6N0FAVHG8AAXGHF8SC
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KV992YHDR5S1K70PT7WN4AYV
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KV993F0VPKW6FB3ZN3SJ2MS7
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KV993P3F5G5M92GWFGS99V84
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KV993WBZ67WF575B6CW4WK5Q
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KV9943BE4ST811CGN2JS7RBN
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KV994A9CZCKJPGHVCP8QF5WA
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KV994JMM62VCA5J3GYTVF0D8
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KV994TW16C69PXHC518XTRXV
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KV99586QT9JYHAA44FARKKHM
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KV995J44NCP6WXJT5TARXER6
  • cancelRun - cancelling a running workflow | wrun_01KV995S4Q6A0WTMZ6HVM2D3EK
  • cancelRun via CLI - cancelling a running workflow | wrun_01KV9963CXFPF1PZD8BPEX8PTV
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KV996FZKE08Q1TW28CYCX633
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KV9970QJ4PZJYKAWYNW3XQGE
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KV997BP7C5HG0AMV6RJKPZJJ
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KV997K2A69TJN7ZTSHE7542R
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KV997NBK942J5VVW30ZT4RCS
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KV997R4Y3RXWNH6N2ZQZQR8A

Details by Category

✅ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro9407
✅ example9407
✅ express9407
✅ fastify9407
✅ hono9407
✅ nextjs-turbopack9902
✅ nextjs-webpack9902
✅ nitro9407
✅ nuxt9407
✅ sveltekit9407
✅ vite9407
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable9506
✅ express-stable9506
✅ fastify-stable9506
✅ hono-stable9506
✅ nextjs-turbopack-canary82019
✅ nextjs-turbopack-stable10100
✅ nextjs-webpack-canary82019
✅ nextjs-webpack-stable10100
✅ nitro-stable9506
✅ nuxt-stable9506
✅ sveltekit-stable9506
✅ vite-stable9506
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable9506
✅ express-stable9506
✅ fastify-stable9506
✅ hono-stable9506
✅ nextjs-turbopack-canary82019
✅ nextjs-turbopack-stable10100
✅ nextjs-webpack-canary82019
✅ nextjs-webpack-stable10100
✅ nitro-stable9506
✅ nuxt-stable9506
✅ sveltekit-stable9506
✅ vite-stable9506
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable9407
✅ express-stable9407
✅ fastify-stable9407
✅ hono-stable9407
✅ nextjs-turbopack-canary81020
✅ nextjs-turbopack-stable10001
✅ nextjs-webpack-canary81020
✅ nextjs-webpack-stable10001
✅ nitro-stable9407
✅ nuxt-stable9407
✅ sveltekit-stable9407
✅ vite-stable9407
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack10100
❌ 🌍 Community Worlds
AppPassedFailedSkipped
✅ mongodb-dev302
✅ redis-dev302
❌ redis63190
✅ turso-dev302
❌ turso3790
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable9506
✅ e2e-local-dev-tanstack-start-stable9506
✅ e2e-local-postgres-nest-stable9407
✅ e2e-local-postgres-tanstack-start-stable9407
✅ e2e-local-prod-nest-stable9506
✅ e2e-local-prod-tanstack-start-stable9506

📋 View full workflow run

@TooTallNate
TooTallNate merged commit c4ed84f into stableJun 16, 2026
92 of 95 checks passed
@TooTallNate
TooTallNate deleted the backport/pr-2457-to-stable branch June 16, 2026 22:39
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@TooTallNate
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Backport #2457: fix(deps): upgrade astro to 6.4.6 to resolve CVE-2026-54299 - #2461

Merged
TooTallNate merged 1 commit into
stablefrom
backport/pr-2457-to-stable
Jun 16, 2026
Merged

Backport #2457: fix(deps): upgrade astro to 6.4.6 to resolve CVE-2026-54299#2461
TooTallNate merged 1 commit into
stablefrom
backport/pr-2457-to-stable

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Automated backport of #2457 to stable (backport job run).

AI recommendation: This is a security fix (CVE-2026-54299) bumping astro in packages/astro and workbench/astro, both of which exist on stable with the same vulnerable astro@5.18.0 devDependency. The fix is a self-contained dependency bump that does not build on any main-only API, so the vulnerability applies to stable as well and should be backported.

Astro <6.4.6 is vulnerable to CVE-2026-54299 (GHSA-2pvr-wf23-7pc7, host
header SSRF in prerendered error page fetch). The fix only exists in the
6.x line — there is no 5.x backport — so this bumps:
- workbench/astro: astro ^6.4.6, @astrojs/node 10.1.4, @astrojs/vercel ^10.0.8
- packages/astro: astro devDependency 6.4.6 (typecheck only, not shipped)
Removes both vulnerable astro@5.16.3 and astro@5.18.0 from the lockfile.
Verified the example app builds under both the node and vercel adapters.
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Pranay Prakash <pranay.gp@gmail.com>
@changeset-bot

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: bd4e4da

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 16 packages
NameType
@workflow/astroPatch
workflowPatch
@workflow/world-testingPatch
@workflow/corePatch
@workflow/buildersPatch
@workflow/cliPatch
@workflow/nextPatch
@workflow/nitroPatch
@workflow/vitestPatch
@workflow/web-sharedPatch
@workflow/webPatch
@workflow/nestPatch
@workflow/rollupPatch
@workflow/sveltekitPatch
@workflow/vitePatch
@workflow/nuxtPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Jun 16, 2026

Copy link
Copy Markdown
Contributor

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

DiffPackageSupply Chain
Security
VulnerabilityQualityMaintenanceLicense
Addednpm/​@​astrojs/​node@​10.1.41001008297100
Addednpm/​@​astrojs/​vercel@​10.0.81001008397100
Addednpm/​astro@​6.4.6881008898100

View full report

@TooTallNate
TooTallNate enabled auto-merge (squash) June 16, 2026 22:23
@github-actions

github-actionsBot commented Jun 16, 2026

Copy link
Copy Markdown
ContributorAuthor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
✅ ▲ Vercel Production10440671111
✅ 💻 Local Development11260861212
✅ 📦 Local Production11260861212
✅ 🐘 Local Postgres11140981212
✅ 🪟 Windows10100101
❌ 🌍 Community Worlds75986179
✅ 📋 Other568038606
Total5154983815633

❌ Failed Tests

🌍 Community Worlds (98 failed)

redis (19 failed):

  • hookWorkflow | wrun_01KV98N0R2MXQD8YSGR4BENY8P
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KV98N91GVT38AV2PYN4TYBNV
  • parallelStepsThenWebhookWorkflow - no hook_conflict from same-tick replay race | wrun_01KV98NMYQVCH6XYR4ZQ2016MM
  • sleepingWorkflow | wrun_01KV98Q46BDRXMZWGW75NWCTGC
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KV98YWQ3000CWG9RP8TN59CH
  • hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload | wrun_01KV98Z8XR51ZFQM9P012YECEQ
  • hookGetConflictThenStepParallelWorkflow - hook.getConflict() continuation step runs alongside other steps | wrun_01KV98ZGRE0PP2WG3TNFGJ1Y2E
  • hookGetConflictWorkflow - hook.getConflict() resolves with the conflicting run when token is already registered | wrun_01KV98ZZKDNP25VY06WQG1D6PT
  • hookClaimOnlyMutexWorkflow - hook works as a pure run mutex without payload data | wrun_01KV990TBH99XVBCCXW29WBNSM
  • hookAdoptOwnerResultWorkflow - duplicate adopts the owner result via conflict.returnValue | wrun_01KV990YNAH14VCA65PX4EW3N9
  • hookSignalOwnerWorkflow - duplicate forwards its payload to the owner via resumeHook | wrun_01KV9914PKN1BPEQ4WMP8YW0X0
  • hookSupersedeOwnerWorkflow - duplicate cancels the owner and claims the released token | wrun_01KV991AMMFXEQMQ91826GP029
  • resume-or-start route pattern - resumeHook retried after start() reaches the new run | wrun_01KV991MJZX32941PFHEMVVG7K
  • pages router sleepingWorkflow via pages router
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KV997R4Y3RXWNH6N2ZQZQR8A

turso (79 failed):

  • addTenWorkflow | wrun_01KV98M31H4Q3JSGN6HV5BVCZJ
  • addTenWorkflow | wrun_01KV98M31H4Q3JSGN6HV5BVCZJ
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KV98KVZC8YPZPWKJZ5K908BN
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KV98MAA50K1XAMV7C5RZP6PZ
  • promiseRaceWorkflow | wrun_01KV98MF22V7D4C4BX5FPEH4VA
  • promiseAnyWorkflow | wrun_01KV98MH96F5PWMSBHR6WJE554
  • importedStepOnlyWorkflow | wrun_01KV98MB2A66MJD5W7311FMHNF
  • readableStreamWorkflow | wrun_01KV98MKVE6FYFR3YFK3JREHJ9
  • hookWorkflow | wrun_01KV98N0R2MXQD8YSGR4BENY8P
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KV98N91GVT38AV2PYN4TYBNV
  • webhookWorkflow | wrun_01KV98NE45N76N2XXM0FRA26QF
  • parallelStepsThenWebhookWorkflow - no hook_conflict from same-tick replay race | wrun_01KV98NMYQVCH6XYR4ZQ2016MM
  • sleepingWorkflow | wrun_01KV98Q46BDRXMZWGW75NWCTGC
  • parallelSleepWorkflow | wrun_01KV98QMH679XQF9201BE678JN
  • nullByteWorkflow | wrun_01KV98QR6VNY8250G0FYKT7Q2Y
  • workflowAndStepMetadataWorkflow | wrun_01KV98QTCX4WSQBPM72VPXXG1K
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KV98T2JC8FZFVKQDAB5JA8K1
  • writableForwardedFromWorkflowWorkflow | wrun_01KV98TJPJT9DWSRVG8JJ898VG
  • writableForwardedFromStepWorkflow | wrun_01KV98TR1E9DEQN4EEZR442TTC
  • fetchWorkflow | wrun_01KV98TVNER9T1JEWTZ9KFF2DF
  • promiseRaceStressTestWorkflow | wrun_01KV98TZ1TYWNKGEZZJWRRT18R
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KV98YGG1TJ1BQWV2XJ3AT7QZ
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KV98YWQ3000CWG9RP8TN59CH
  • hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload | wrun_01KV98Z8XR51ZFQM9P012YECEQ
  • 'hookGetConflictWithPriorStepWorkflow' - hook.getConflict() does not block step execution | wrun_01KV98ZBD71VG7SC257M48MF1G
  • 'hookGetConflictWithParallelStepWorkfl…' - hook.getConflict() does not block step execution | wrun_01KV98ZE0NDYCAGFTJE5JPE3EK
  • hookGetConflictThenStepParallelWorkflow - hook.getConflict() continuation step runs alongside other steps | wrun_01KV98ZGRE0PP2WG3TNFGJ1Y2E
  • hookGetConflictWorkflow - hook.getConflict() resolves with the conflicting run when token is already registered | wrun_01KV98ZZKDNP25VY06WQG1D6PT
  • hookClaimOnlyMutexWorkflow - hook works as a pure run mutex without payload data | wrun_01KV990TBH99XVBCCXW29WBNSM
  • hookAdoptOwnerResultWorkflow - duplicate adopts the owner result via conflict.returnValue | wrun_01KV990YNAH14VCA65PX4EW3N9
  • hookSignalOwnerWorkflow - duplicate forwards its payload to the owner via resumeHook | wrun_01KV9914PKN1BPEQ4WMP8YW0X0
  • hookSupersedeOwnerWorkflow - duplicate cancels the owner and claims the released token | wrun_01KV991AMMFXEQMQ91826GP029
  • resume-or-start route pattern - resumeHook retried after start() reaches the new run | wrun_01KV991MJZX32941PFHEMVVG7K
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KV991WC53780NZNEE4YW52ZJ
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KV992CVJ6F2HBSRT8VDCXPDC
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KV992PCS9RJTZX7RR8MPY8GX
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KV992W6N0FAVHG8AAXGHF8SC
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KV992YHDR5S1K70PT7WN4AYV
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KV993F0VPKW6FB3ZN3SJ2MS7
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KV993P3F5G5M92GWFGS99V84
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KV993WBZ67WF575B6CW4WK5Q
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KV9943BE4ST811CGN2JS7RBN
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KV994A9CZCKJPGHVCP8QF5WA
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KV994JMM62VCA5J3GYTVF0D8
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KV994TW16C69PXHC518XTRXV
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KV99586QT9JYHAA44FARKKHM
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KV995J44NCP6WXJT5TARXER6
  • cancelRun - cancelling a running workflow | wrun_01KV995S4Q6A0WTMZ6HVM2D3EK
  • cancelRun via CLI - cancelling a running workflow | wrun_01KV9963CXFPF1PZD8BPEX8PTV
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KV996FZKE08Q1TW28CYCX633
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KV9970QJ4PZJYKAWYNW3XQGE
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KV997BP7C5HG0AMV6RJKPZJJ
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KV997K2A69TJN7ZTSHE7542R
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KV997NBK942J5VVW30ZT4RCS
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KV997R4Y3RXWNH6N2ZQZQR8A

Details by Category

✅ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro9407
✅ example9407
✅ express9407
✅ fastify9407
✅ hono9407
✅ nextjs-turbopack9902
✅ nextjs-webpack9902
✅ nitro9407
✅ nuxt9407
✅ sveltekit9407
✅ vite9407
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable9506
✅ express-stable9506
✅ fastify-stable9506
✅ hono-stable9506
✅ nextjs-turbopack-canary82019
✅ nextjs-turbopack-stable10100
✅ nextjs-webpack-canary82019
✅ nextjs-webpack-stable10100
✅ nitro-stable9506
✅ nuxt-stable9506
✅ sveltekit-stable9506
✅ vite-stable9506
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable9506
✅ express-stable9506
✅ fastify-stable9506
✅ hono-stable9506
✅ nextjs-turbopack-canary82019
✅ nextjs-turbopack-stable10100
✅ nextjs-webpack-canary82019
✅ nextjs-webpack-stable10100
✅ nitro-stable9506
✅ nuxt-stable9506
✅ sveltekit-stable9506
✅ vite-stable9506
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable9407
✅ express-stable9407
✅ fastify-stable9407
✅ hono-stable9407
✅ nextjs-turbopack-canary81020
✅ nextjs-turbopack-stable10001
✅ nextjs-webpack-canary81020
✅ nextjs-webpack-stable10001
✅ nitro-stable9407
✅ nuxt-stable9407
✅ sveltekit-stable9407
✅ vite-stable9407
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack10100
❌ 🌍 Community Worlds
AppPassedFailedSkipped
✅ mongodb-dev302
✅ redis-dev302
❌ redis63190
✅ turso-dev302
❌ turso3790
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable9506
✅ e2e-local-dev-tanstack-start-stable9506
✅ e2e-local-postgres-nest-stable9407
✅ e2e-local-postgres-tanstack-start-stable9407
✅ e2e-local-prod-nest-stable9506
✅ e2e-local-prod-tanstack-start-stable9506

📋 View full workflow run

@TooTallNate
TooTallNate merged commit c4ed84f into stableJun 16, 2026
92 of 95 checks passed
@TooTallNate
TooTallNate deleted the backport/pr-2457-to-stable branch June 16, 2026 22:39
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@TooTallNate
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Backport #2457: fix(deps): upgrade astro to 6.4.6 to resolve CVE-2026-54299 - #2461

Merged
TooTallNate merged 1 commit into
stablefrom
backport/pr-2457-to-stable
Jun 16, 2026
Merged

Backport #2457: fix(deps): upgrade astro to 6.4.6 to resolve CVE-2026-54299#2461
TooTallNate merged 1 commit into
stablefrom
backport/pr-2457-to-stable

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Automated backport of #2457 to stable (backport job run).

AI recommendation: This is a security fix (CVE-2026-54299) bumping astro in packages/astro and workbench/astro, both of which exist on stable with the same vulnerable astro@5.18.0 devDependency. The fix is a self-contained dependency bump that does not build on any main-only API, so the vulnerability applies to stable as well and should be backported.

Astro <6.4.6 is vulnerable to CVE-2026-54299 (GHSA-2pvr-wf23-7pc7, host
header SSRF in prerendered error page fetch). The fix only exists in the
6.x line — there is no 5.x backport — so this bumps:
- workbench/astro: astro ^6.4.6, @astrojs/node 10.1.4, @astrojs/vercel ^10.0.8
- packages/astro: astro devDependency 6.4.6 (typecheck only, not shipped)
Removes both vulnerable astro@5.16.3 and astro@5.18.0 from the lockfile.
Verified the example app builds under both the node and vercel adapters.
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Pranay Prakash <pranay.gp@gmail.com>
@changeset-bot

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: bd4e4da

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 16 packages
NameType
@workflow/astroPatch
workflowPatch
@workflow/world-testingPatch
@workflow/corePatch
@workflow/buildersPatch
@workflow/cliPatch
@workflow/nextPatch
@workflow/nitroPatch
@workflow/vitestPatch
@workflow/web-sharedPatch
@workflow/webPatch
@workflow/nestPatch
@workflow/rollupPatch
@workflow/sveltekitPatch
@workflow/vitePatch
@workflow/nuxtPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Jun 16, 2026

Copy link
Copy Markdown
Contributor

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

DiffPackageSupply Chain
Security
VulnerabilityQualityMaintenanceLicense
Addednpm/​@​astrojs/​node@​10.1.41001008297100
Addednpm/​@​astrojs/​vercel@​10.0.81001008397100
Addednpm/​astro@​6.4.6881008898100

View full report

@TooTallNate
TooTallNate enabled auto-merge (squash) June 16, 2026 22:23
@github-actions

github-actionsBot commented Jun 16, 2026

Copy link
Copy Markdown
ContributorAuthor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
✅ ▲ Vercel Production10440671111
✅ 💻 Local Development11260861212
✅ 📦 Local Production11260861212
✅ 🐘 Local Postgres11140981212
✅ 🪟 Windows10100101
❌ 🌍 Community Worlds75986179
✅ 📋 Other568038606
Total5154983815633

❌ Failed Tests

🌍 Community Worlds (98 failed)

redis (19 failed):

  • hookWorkflow | wrun_01KV98N0R2MXQD8YSGR4BENY8P
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KV98N91GVT38AV2PYN4TYBNV
  • parallelStepsThenWebhookWorkflow - no hook_conflict from same-tick replay race | wrun_01KV98NMYQVCH6XYR4ZQ2016MM
  • sleepingWorkflow | wrun_01KV98Q46BDRXMZWGW75NWCTGC
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KV98YWQ3000CWG9RP8TN59CH
  • hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload | wrun_01KV98Z8XR51ZFQM9P012YECEQ
  • hookGetConflictThenStepParallelWorkflow - hook.getConflict() continuation step runs alongside other steps | wrun_01KV98ZGRE0PP2WG3TNFGJ1Y2E
  • hookGetConflictWorkflow - hook.getConflict() resolves with the conflicting run when token is already registered | wrun_01KV98ZZKDNP25VY06WQG1D6PT
  • hookClaimOnlyMutexWorkflow - hook works as a pure run mutex without payload data | wrun_01KV990TBH99XVBCCXW29WBNSM
  • hookAdoptOwnerResultWorkflow - duplicate adopts the owner result via conflict.returnValue | wrun_01KV990YNAH14VCA65PX4EW3N9
  • hookSignalOwnerWorkflow - duplicate forwards its payload to the owner via resumeHook | wrun_01KV9914PKN1BPEQ4WMP8YW0X0
  • hookSupersedeOwnerWorkflow - duplicate cancels the owner and claims the released token | wrun_01KV991AMMFXEQMQ91826GP029
  • resume-or-start route pattern - resumeHook retried after start() reaches the new run | wrun_01KV991MJZX32941PFHEMVVG7K
  • pages router sleepingWorkflow via pages router
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KV997R4Y3RXWNH6N2ZQZQR8A

turso (79 failed):

  • addTenWorkflow | wrun_01KV98M31H4Q3JSGN6HV5BVCZJ
  • addTenWorkflow | wrun_01KV98M31H4Q3JSGN6HV5BVCZJ
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KV98KVZC8YPZPWKJZ5K908BN
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KV98MAA50K1XAMV7C5RZP6PZ
  • promiseRaceWorkflow | wrun_01KV98MF22V7D4C4BX5FPEH4VA
  • promiseAnyWorkflow | wrun_01KV98MH96F5PWMSBHR6WJE554
  • importedStepOnlyWorkflow | wrun_01KV98MB2A66MJD5W7311FMHNF
  • readableStreamWorkflow | wrun_01KV98MKVE6FYFR3YFK3JREHJ9
  • hookWorkflow | wrun_01KV98N0R2MXQD8YSGR4BENY8P
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KV98N91GVT38AV2PYN4TYBNV
  • webhookWorkflow | wrun_01KV98NE45N76N2XXM0FRA26QF
  • parallelStepsThenWebhookWorkflow - no hook_conflict from same-tick replay race | wrun_01KV98NMYQVCH6XYR4ZQ2016MM
  • sleepingWorkflow | wrun_01KV98Q46BDRXMZWGW75NWCTGC
  • parallelSleepWorkflow | wrun_01KV98QMH679XQF9201BE678JN
  • nullByteWorkflow | wrun_01KV98QR6VNY8250G0FYKT7Q2Y
  • workflowAndStepMetadataWorkflow | wrun_01KV98QTCX4WSQBPM72VPXXG1K
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KV98T2JC8FZFVKQDAB5JA8K1
  • writableForwardedFromWorkflowWorkflow | wrun_01KV98TJPJT9DWSRVG8JJ898VG
  • writableForwardedFromStepWorkflow | wrun_01KV98TR1E9DEQN4EEZR442TTC
  • fetchWorkflow | wrun_01KV98TVNER9T1JEWTZ9KFF2DF
  • promiseRaceStressTestWorkflow | wrun_01KV98TZ1TYWNKGEZZJWRRT18R
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KV98YGG1TJ1BQWV2XJ3AT7QZ
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KV98YWQ3000CWG9RP8TN59CH
  • hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload | wrun_01KV98Z8XR51ZFQM9P012YECEQ
  • 'hookGetConflictWithPriorStepWorkflow' - hook.getConflict() does not block step execution | wrun_01KV98ZBD71VG7SC257M48MF1G
  • 'hookGetConflictWithParallelStepWorkfl…' - hook.getConflict() does not block step execution | wrun_01KV98ZE0NDYCAGFTJE5JPE3EK
  • hookGetConflictThenStepParallelWorkflow - hook.getConflict() continuation step runs alongside other steps | wrun_01KV98ZGRE0PP2WG3TNFGJ1Y2E
  • hookGetConflictWorkflow - hook.getConflict() resolves with the conflicting run when token is already registered | wrun_01KV98ZZKDNP25VY06WQG1D6PT
  • hookClaimOnlyMutexWorkflow - hook works as a pure run mutex without payload data | wrun_01KV990TBH99XVBCCXW29WBNSM
  • hookAdoptOwnerResultWorkflow - duplicate adopts the owner result via conflict.returnValue | wrun_01KV990YNAH14VCA65PX4EW3N9
  • hookSignalOwnerWorkflow - duplicate forwards its payload to the owner via resumeHook | wrun_01KV9914PKN1BPEQ4WMP8YW0X0
  • hookSupersedeOwnerWorkflow - duplicate cancels the owner and claims the released token | wrun_01KV991AMMFXEQMQ91826GP029
  • resume-or-start route pattern - resumeHook retried after start() reaches the new run | wrun_01KV991MJZX32941PFHEMVVG7K
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KV991WC53780NZNEE4YW52ZJ
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KV992CVJ6F2HBSRT8VDCXPDC
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KV992PCS9RJTZX7RR8MPY8GX
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KV992W6N0FAVHG8AAXGHF8SC
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KV992YHDR5S1K70PT7WN4AYV
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KV993F0VPKW6FB3ZN3SJ2MS7
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KV993P3F5G5M92GWFGS99V84
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KV993WBZ67WF575B6CW4WK5Q
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KV9943BE4ST811CGN2JS7RBN
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KV994A9CZCKJPGHVCP8QF5WA
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KV994JMM62VCA5J3GYTVF0D8
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KV994TW16C69PXHC518XTRXV
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KV99586QT9JYHAA44FARKKHM
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KV995J44NCP6WXJT5TARXER6
  • cancelRun - cancelling a running workflow | wrun_01KV995S4Q6A0WTMZ6HVM2D3EK
  • cancelRun via CLI - cancelling a running workflow | wrun_01KV9963CXFPF1PZD8BPEX8PTV
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KV996FZKE08Q1TW28CYCX633
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KV9970QJ4PZJYKAWYNW3XQGE
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KV997BP7C5HG0AMV6RJKPZJJ
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KV997K2A69TJN7ZTSHE7542R
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KV997NBK942J5VVW30ZT4RCS
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KV997R4Y3RXWNH6N2ZQZQR8A

Details by Category

✅ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro9407
✅ example9407
✅ express9407
✅ fastify9407
✅ hono9407
✅ nextjs-turbopack9902
✅ nextjs-webpack9902
✅ nitro9407
✅ nuxt9407
✅ sveltekit9407
✅ vite9407
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable9506
✅ express-stable9506
✅ fastify-stable9506
✅ hono-stable9506
✅ nextjs-turbopack-canary82019
✅ nextjs-turbopack-stable10100
✅ nextjs-webpack-canary82019
✅ nextjs-webpack-stable10100
✅ nitro-stable9506
✅ nuxt-stable9506
✅ sveltekit-stable9506
✅ vite-stable9506
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable9506
✅ express-stable9506
✅ fastify-stable9506
✅ hono-stable9506
✅ nextjs-turbopack-canary82019
✅ nextjs-turbopack-stable10100
✅ nextjs-webpack-canary82019
✅ nextjs-webpack-stable10100
✅ nitro-stable9506
✅ nuxt-stable9506
✅ sveltekit-stable9506
✅ vite-stable9506
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable9407
✅ express-stable9407
✅ fastify-stable9407
✅ hono-stable9407
✅ nextjs-turbopack-canary81020
✅ nextjs-turbopack-stable10001
✅ nextjs-webpack-canary81020
✅ nextjs-webpack-stable10001
✅ nitro-stable9407
✅ nuxt-stable9407
✅ sveltekit-stable9407
✅ vite-stable9407
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack10100
❌ 🌍 Community Worlds
AppPassedFailedSkipped
✅ mongodb-dev302
✅ redis-dev302
❌ redis63190
✅ turso-dev302
❌ turso3790
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable9506
✅ e2e-local-dev-tanstack-start-stable9506
✅ e2e-local-postgres-nest-stable9407
✅ e2e-local-postgres-tanstack-start-stable9407
✅ e2e-local-prod-nest-stable9506
✅ e2e-local-prod-tanstack-start-stable9506

📋 View full workflow run

@TooTallNate
TooTallNate merged commit c4ed84f into stableJun 16, 2026
92 of 95 checks passed
@TooTallNate
TooTallNate deleted the backport/pr-2457-to-stable branch June 16, 2026 22:39
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@TooTallNate