Skip to content

[AI Improvement] [Task] Upgrade astro devDependency from ^2 to ^7 and fix Astro type usage - #11196

Draft
joehan wants to merge 3 commits into
mainfrom
ai-improve-567662586-task-upgrade-astro-devdependency-fr
Draft

joehan wants to merge 3 commits into
mainfrom
ai-improve-567662586-task-upgrade-astro-devdependency-fr

Conversation

@joehan

@joehan joehan commented Sep 29, 2026

Copy link
Copy Markdown
Member

Resolves Buganizer b/567662586

Proposed Improvement

Upgraded the astro devDependency from ^2.2.3 to ^7.3.5 and regenerated npm-shrinkwrap.json using npm@11.9.

Key changes:

  • In package.json, bumped astro to ^7.3.5.
  • In src/frameworks/astro/utils.ts, replaced the typeof import("astro/dist/core/config/config") type annotation for legacy openConfig with an explicit local LegacyAstroConfigModule interface. Astro 7 no longer exports openConfig, but runtime user projects on older Astro versions (<2.9.7) still dynamically import it when detected. The local interface maintains complete backward compatibility for those user projects without causing TypeScript compilation errors against Astro 7.
  • Normalized npm-shrinkwrap.json with npx -y npm@11.9 install --package-lock-only --ignore-scripts.
  • Clears high and critical audit vulnerabilities pulled in by Astro 2 (astro, @astrojs/markdown-remark, devalue, deepmerge-ts, cookie, and the nested legacy undici copies in @astrojs/telemetry and @astrojs/webapi).

Verification

  • npm run build: Passed cleanly.
  • npm run lint:quiet: Passed with 0 errors.
  • npm run test:compile: Passed with 0 errors.
  • npx mocha 'src/frameworks/astro/**/*.spec.ts': All 9 tests passing.
  • npm audit: Verified that vulnerabilities from astro, devalue, deepmerge-ts, @astrojs/*, and cookie are resolved.

@joehan joehan self-assigned this Sep 29, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request upgrades the astro dependency to version 7.3.5 and refactors the configuration loading in src/frameworks/astro/utils.ts to use a local LegacyAstroConfigModule interface. Feedback on the changes points out a violation of the repository style guide regarding the use of any and unknown types, suggesting a more robust type definition for the Astro configuration and logging parameters.

Comment on lines +25 to 35
interface LegacyAstroConfigModule {
openConfig: (options: {
cmd: string;
cwd: string;
logging: unknown;
}) => Promise<{ astroConfig: any }>;
}
const { openConfig }: LegacyAstroConfigModule = await dynamicImport(configPath);
const logging: unknown = undefined;
const { astroConfig } = await openConfig({ cmd: "build", cwd, logging });
config = astroConfig;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

According to the repository style guide (GEMINI.md, line 37), we should never use any or unknown as an escape hatch. Instead, we should define proper interfaces/types.

We can define a proper LegacyAstroConfig interface representing the expected shape of the Astro configuration object, and type logging as undefined since it is not used here.

    interface LegacyAstroConfig {
      outDir: string | URL;
      publicDir: string | URL;
      output: string;
      adapter?: { name: string };
    }
    interface LegacyAstroConfigModule {
      openConfig: (options: {
        cmd: string;
        cwd: string;
        logging?: undefined;
      }) => Promise<{ astroConfig: LegacyAstroConfig }>;
    }
    const { openConfig }: LegacyAstroConfigModule = await dynamicImport(configPath);
    const logging = undefined;
    const { astroConfig } = await openConfig({ cmd: 

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants