✨ Major Changes
- #15049
beddfebThanks @Ntale3! - Removes the ability to render Astro components in Vitest client environments - (v6 upgrade guidance)
beddfeb Thanks @Ntale3! - Removes the ability to render Astro components in Vitest client environments - (v6 upgrade guidance)#15006 f361730 Thanks @florian-lefebvre! - Removes session test driver - (v6 upgrade guidance)
#15006 f361730 Thanks @florian-lefebvre! - Deprecates session driver string signature - (v6 upgrade guidance)
#15006 f361730 Thanks @florian-lefebvre! - Adds new session driver object shape
For greater flexibility and improved consistency with other Astro code, session drivers are now specified as an object:
import { defineConfig } from 'astro/config'import { defineConfig, sessionDrivers } from 'astro/config'
export default defineConfig({ session: { driver: 'redis', options: { url: process.env.REDIS_URL }, driver: sessionDrivers.redis({ url: process.env.REDIS_URL }), }})Specifying the session driver as a string has been deprecated, but will continue to work until this feature is removed completely in a future major version. The object shape is the current recommended and documented way to configure a session driver.
#15044 7cac71b Thanks @florian-lefebvre! - Removes an exposed internal API of the preview server
#15047 5580372 Thanks @matthewp! - Fixes wrangler config template in astro add cloudflare to use correct entrypoint and compatibility date
#15053 674b63f Thanks @matthewp! - Excludes astro:* and virtual:astro:* from client optimizeDeps in core. Needed for prefetch users since virtual modules are now in the dependency graph.
#15024 22c48ba Thanks @florian-lefebvre! - Fixes a case where JSON schema generation would fail for unrepresentable types
#15036 f125a73 Thanks @florian-lefebvre! - Fixes certain aliases not working when using images in JSON files with the content layer
#15036 f125a73 Thanks @florian-lefebvre! - Fixes a vite warning log during builds when using npm
#14982 6849e38 Thanks @Princesseuh! - Fixes images outside the project directory not working when using astro:assets in development mode
#14987 9dd9fca Thanks @Princesseuh! - Fixes SVGs not working in dev mode when using the passthrough image service
#15014 a178422 Thanks @delucis! - Adds support for extending the type of the props accepted by Astro’s <Image> component, <Picture> component, and getImage() API.
#14956 0ff51df Thanks @matthewp! - Astro v6.0 upgrades to Zod v4 for schema validation - (v6 upgrade guidance)
#14759 d7889f7 Thanks @florian-lefebvre! - Updates how schema types are inferred for content loaders with schemas (Loader API) - (v6 upgrade guidance)
#14306 141c4a2 Thanks @ematipico! - Removes support for routes with percent-encoded percent signs (e.g. %25) - (v6 upgrade guidance)
#14759 d7889f7 Thanks @florian-lefebvre! - Removes the option to define dynamic schemas in content loaders as functions and adds a new equivalent createSchema() property (Loader API) - (v6 upgrade guidance)
#14306 141c4a2 Thanks @ematipico! - Removes RouteData.generate from the Integration API - (v6 upgrade guidance)
#14989 73e8232 Thanks @florian-lefebvre! - Deprecates exposed astro:transitions internals - (v6 upgrade guidance)
#14758 010f773 Thanks @florian-lefebvre! - Removes the setManifestData method from App and NodeApp (Adapter API) - (v6 upgrade guidance)
#14826 170f64e Thanks @florian-lefebvre! - Removes the experimental.failOnPrerenderConflict flag and replaces it with a new configuration option prerenderConflictBehavior - (v6 upgrade guidance)
#14923 95a1969 Thanks @florian-lefebvre! - Deprecates astro:schema and z from astro:content in favor of astro/zod - (v6 upgrade guidance)
#14844 8d43b1d Thanks @trueberryless! - Removes exposed astro:actions internals - (v6 upgrade guidance)
#14306 141c4a2 Thanks @ematipico! - Changes the shape of SSRManifest properties and adds several new required properties in the Adapter API - (v6 upgrade guidance)
#14306 141c4a2 Thanks @ematipico! - Changes integration hooks and HMR access patterns in the Integration API - (v6 upgrade guidance)
#14306 141c4a2 Thanks @ematipico! - Removes the unused astro:ssr-manifest virtual module - (v6 upgrade guidance)
#14306 141c4a2 Thanks @ematipico! - Adds new optional properties to setAdapter() for adapter entrypoint handling in the Adapter API
Changes:
devEntrypoint?: string | URL - specifies custom dev server entrypointentryType?: 'self' | 'legacy-dynamic' - determines if the adapter provides its own entrypoint ('self') or if Astro constructs one ('legacy-dynamic', default)Migration: Adapter authors can optionally add these properties to support custom dev entrypoints. If not specified, adapters will use the legacy behavior.
#14826 170f64e Thanks @florian-lefebvre! - Adds an option prerenderConflictBehavior to configure the behavior of conflicting prerendered routes
By default, Astro warns you during the build about any conflicts between multiple dynamic routes that can result in the same output path. For example /blog/[slug] and /blog/[...all] both could try to prerender the /blog/post-1 path. In such cases, Astro renders only the highest priority route for the conflicting path. This allows your site to build successfully, although you may discover that some pages are rendered by unexpected routes.
With the new prerenderConflictBehavior configuration option, you can now configure this further:
prerenderConflictBehavior: 'error' fails the buildprerenderConflictBehavior: 'warn' (default) logs a warning and the highest-priority route winsprerenderConflictBehavior: 'ignore' silently picks the highest-priority route when conflicts occurimport { defineConfig } from 'astro/config';
export default defineConfig({ prerenderConflictBehavior: 'error',});#14946 95c40f7 Thanks @ematipico! - Removes the experimental.csp flag and replaces it with a new configuration option security.csp - (v6 upgrade guidance)
6849e38 Thanks @Princesseuh! - Fixes images outside the project directory not working when using astro:assets in development mode#14985 c016f10 Thanks @florian-lefebvre! - Fixes a case where JSDoc annotations wouldn’t show for fonts related APIs in the Astro config
#14973 ed7cc2f Thanks @amankumarpandeyin! - Fixes performance regression and OOM errors when building medium-sized blogs with many content entries. Replaced O(n²) object spread pattern with direct mutation in generateLookupMap.
#14958 70eb542 Thanks @ascorbic! - Gives a helpful error message if a user sets output: "hybrid" in their Astro config.
The option was removed in Astro 5, but lots of content online still references it, and LLMs often suggest it. It’s not always clear that the replacement is output: "static", rather than output: "server". This change adds a helpful error message to guide humans and robots.
#14901 ef53716 Thanks @Darknab! - Updates the glob() loader to log a warning when duplicated IDs are detected
Updated dependencies [d8305f8]:
#14940 2cf79c2 Thanks @ematipico! - Fixes a bug where Astro didn’t properly combine CSP resources from the csp configuration with those added using the runtime API (Astro.csp.insertDirective()) to form grammatically correct CSP headers
Now Astro correctly deduplicate CSP resources. For example, if you have a global resource in the configuration file, and then you add a a new one using the runtime APIs.
#14889 4bceeb0 Thanks @florian-lefebvre! - Fixes actions types when using specific TypeScript configurations
#14929 e0f277d Thanks @matthewp! - Fixes authentication bypass via double URL encoding in middleware
Prevents attackers from bypassing path-based authentication checks using multi-level URL encoding (e.g., /%2561dmin instead of /%61dmin). Pathnames are now validated after decoding to ensure no additional encoding remains.
#14876 b43dc7f Thanks @florian-lefebvre! - Fixes a vite warning log during builds when using npm
#14884 10273e0 Thanks @florian-lefebvre! - Fixes a case where setting the status of a page to 404 in ssr would show an empty page (or 404.astro page if provided) instead of using the current page
#14769 b43ee71 Thanks @adriandlam! - Fixes an unhandled rejection issue when using Astro with Vercel Workflow DevKit
#14761 345eb22 Thanks @ooga! - Updates button attributes types to allow command and commandfor
#14866 65e214b Thanks @GameRoMan! - Fixes Astro.glob to be correctly marked as deprecated
#14894 1ad9a5b Thanks @delucis! - Fixes support for Astro component rendering in Vitest test suites using a “client” environment such as happy-dom or jsdom
#14782 abed929 Thanks @florian-lefebvre! - Improves syncing

#13880 1a2ed01 Thanks @azat-io! - Adds experimental SVGO optimization support for SVG assets
Astro now supports automatic SVG optimization using SVGO during build time. This experimental feature helps reduce SVG file sizes while maintaining visual quality, improving your site’s performance.
To enable SVG optimization with default settings, add the following to your astro.config.mjs:
import { defineConfig } from 'astro/config';
export default defineConfig({ experimental: { svgo: true, },});To customize optimization, pass a SVGO configuration object:
export default defineConfig({ experimental: { svgo: { plugins: [ 'preset-default', { name: 'removeViewBox', active: false, }, ], }, },});For more information on enabling and using this feature in your project, see the experimental SVG optimization docs.
#14810 2e845fe Thanks @ascorbic! - Adds a hint for code agents to use the --yes flag to skip prompts when running astro add
#14698 f42ff9b Thanks @mauriciabad! - Adds the ActionInputSchema utility type to automatically infer the TypeScript type of an action’s input based on its Zod schema
For example, this type can be used to retrieve the input type of a form action:
import { type ActionInputSchema, defineAction } from 'astro:actions';import { z } from 'astro/zod';
const action = defineAction({ accept: 'form', input: z.object({ name: z.string() }), handler: ({ name }) => ({ message: `Welcome, ${name}!` }),});
type Schema = ActionInputSchema<typeof action>;// typeof z.object({ name: z.string() })
type Input = z.input<Schema>;// { name: string }#14574 4356485 Thanks @jacobdalamb! - Adds new CLI shortcuts available when running astro preview:
o + enter: open the site in your browserq + enter: quit the previewh + enter: print all available shortcuts#14813 e1dd377 Thanks @ematipico! - Removes picocolors as dependency in favor of the fork piccolore.
#14609 d774306 Thanks @florian-lefebvre! - Improves astro info
#14796 c29a785 Thanks @florian-lefebvre! - BREAKING CHANGE to the experimental Fonts API only
Updates the default subsets to ["latin"]
Subsets have been a common source of confusion: they caused a lot of files to be downloaded by default. You now have to manually pick extra subsets.
Review your Astro config and update subsets if you need, for example if you need greek characters:
import { defineConfig, fontProviders } from "astro/config"
export default defineConfig({ experimental: { fonts: [{ name: "Roboto", cssVariable: "--font-roboto", provider: fontProviders.google(), subsets: ["latin", "greek"] }] }})#14786 758a891 Thanks @mef! - Add handling of invalid encrypted props and slots in server islands.
#14783 504958f Thanks @florian-lefebvre! - Improves the experimental Fonts API build log to show the number of downloaded files. This can help spotting excessive downloading because of misconfiguration
#14791 9e9c528 Thanks @Princesseuh! - Changes the remote protocol checks for images to require explicit authorization in order to use data URIs.
In order to allow data URIs for remote images, you will need to update your astro.config.mjs file to include the following configuration:
import { defineConfig } from 'astro/config';
export default defineConfig({ images: { remotePatterns: [ { protocol: 'data', }, ], },});#14787 0f75f6b Thanks @matthewp! - Fixes wildcard hostname pattern matching to correctly reject hostnames without dots
Previously, hostnames like localhost or other single-part names would incorrectly match patterns like *.example.com. The wildcard matching logic has been corrected to ensure that only valid subdomains matching the pattern are accepted.
#14776 3537876 Thanks @ktym4a! - Fixes the behavior of passthroughImageService so it does not generate webp.
Updated dependencies [9e9c528, 0f75f6b]:
#14772 00c579a Thanks @matthewp! - Improves the security of Server Islands slots by encrypting them before transmission to the browser, matching the security model used for props. This improves the integrity of slot content and prevents injection attacks, even when component templates don’t explicitly support slots.
Slots continue to work as expected for normal usage—this change has no breaking changes for legitimate requests.
#14771 6f80081 Thanks @matthewp! - Fix middleware pathname matching by normalizing URL-encoded paths
Middleware now receives normalized pathname values, ensuring that encoded paths like /%61dmin are properly decoded to /admin before middleware checks. This prevents potential security issues where middleware checks might be bypassed through URL encoding.
#14765 03fb47c Thanks @florian-lefebvre! - Fixes a case where process.env wouldn’t be properly populated during the build
#14690 ae7197d Thanks @fredriknorlin! - Fixes a bug where Astro’s i18n fallback system with fallbackType: 'rewrite' would not generate fallback files for pages whose filename started with a locale key.
#14751 18c55e1 Thanks @delucis! - Fixes hydration of client components when running the dev server and using a barrel file that re-exports both Astro and UI framework components.
#14750 35122c2 Thanks @florian-lefebvre! - Updates the experimental Fonts API to log a warning if families with a conflicting cssVariable are provided
#14737 74c8852 Thanks @Arecsu! - Fixes an error when using transition:persist with components that use declarative Shadow DOM. Astro now avoids re-attaching a shadow root if one already exists, preventing "Unable to re-attach to existing ShadowDOM" navigation errors.
#14750 35122c2 Thanks @florian-lefebvre! - Updates the experimental Fonts API to allow for more granular configuration of remote font families
A font family is defined by a combination of properties such as weights and styles (e.g. weights: [500, 600] and styles: ["normal", "bold"]), but you may want to download only certain combinations of these.
For greater control over which font files are downloaded, you can specify the same font (ie. with the same cssVariable, name, and provider properties) multiple times with different combinations. Astro will merge the results and download only the required files. For example, it is possible to download normal 500 and 600 while downloading only italic 500:
import { defineConfig, fontProviders } from 'astro/config';
export default defineConfig({ experimental: { fonts: [ { name: 'Roboto', cssVariable: '--roboto', provider: fontProviders.google(), weights: [500, 600], styles: ['normal'], }, { name: 'Roboto', cssVariable: '--roboto', provider: fontProviders.google(), weights: [500], styles: ['italic'], }, ], },});#14712 91780cf Thanks @florian-lefebvre! - Fixes a case where build’s process.env would be inlined in the server output
#14713 666d5a7 Thanks @florian-lefebvre! - Improves fallbacks generation when using the experimental Fonts API
#14743 dafbb1b Thanks @matthewp! - Improves X-Forwarded header validation to prevent cache poisoning and header injection attacks. Now properly validates X-Forwarded-Proto, X-Forwarded-Host, and X-Forwarded-Port headers against configured allowedDomains patterns, rejecting malformed or suspicious values. This is especially important when running behind a reverse proxy or load balancer.
#14703 970ac0f Thanks @ArmandPhilippot! - Adds missing documentation for some public utilities exported from astro:i18n.
#14715 3d55c5d Thanks @ascorbic! - Adds support for client hydration in getContainerRenderer()
The getContainerRenderer() function is exported by Astro framework integrations to simplify the process of rendering framework components when using the experimental Container API inside a Vite or Vitest environment. This update adds the client hydration entrypoint to the returned object, enabling client-side interactivity for components rendered using this function. Previously this required users to manually call container.addClientRenderer() with the appropriate client renderer entrypoint.
See the container-with-vitest demo for a usage example, and the Container API documentation for more information on using framework components with the experimental Container API.
#14711 a4d284d Thanks @deining! - Fixes typos in documenting our error messages and public APIs.
#14701 9be54c7 Thanks @florian-lefebvre! - Fixes a case where the experimental Fonts API would filter available font files too aggressively, which could prevent the download of woff files when using the google provider
#14627 b368de0 Thanks @matthewp! - Fixes skew protection support for images and font URLs
Adapter-level query parameters (assetQueryParams) are now applied to all image and font asset URLs, including:
/_image endpoint#14631 3ad33f9 Thanks @KurtGokhan! - Adds the astro/jsx-dev-runtime export as an alias for astro/jsx-runtime
#14623 c5fe295 Thanks @delucis! - Fixes a leak of server runtime code when importing SVGs in client-side code. Previously, when importing an SVG file in client code, Astro could end up adding code for rendering SVGs on the server to the client bundle.
#14621 e3175d9 Thanks @GameRoMan! - Updates vite version to fix CVE

#14543 9b3241d Thanks @matthewp! - Adds two new adapter configuration options assetQueryParams and internalFetchHeaders to the Adapter API.
Official and community-built adapters can now use client.assetQueryParams to specify query parameters that should be appended to asset URLs (CSS, JavaScript, images, fonts, etc.). The query parameters are automatically appended to all generated asset URLs during the build process.
Adapters can also use client.internalFetchHeaders to specify headers that should be included in Astro’s internal fetch calls (Actions, View Transitions, Server Islands, Prefetch).
This enables features like Netlify’s skew protection, which requires the deploy ID to be sent with both internal requests and asset URLs to ensure client and server versions match during deployments.
#14489 add4277 Thanks @dev-shetty! - Adds a new Copy to Clipboard button to the error overlay stack trace.
When an error occurs in dev mode, you can now copy the stack trace with a single click to more easily share it in a bug report, a support thread, or with your favorite LLM.
#14564 5e7cebb Thanks @florian-lefebvre! - Updates astro add cloudflare to scaffold more configuration files
Running astro add cloudflare will now emit wrangler.jsonc and public/.assetsignore, allowing your Astro project to work out of the box as a worker.
#14591 3e887ec Thanks @matthewp! - Adds TypeScript support for the components prop on MDX Content component when using await render(). Developers now get proper IntelliSense and type checking when passing custom components to override default MDX element rendering.
#14598 7b45c65 Thanks @delucis! - Reduces terminal text styling dependency size by switching from kleur to picocolors
#13826 8079482 Thanks @florian-lefebvre! - Adds the option to specify in the preload directive which weights, styles, or subsets to preload for a given font family when using the experimental Fonts API:
---import { Font } from 'astro:assets';---
<Font cssVariable="--font-roboto" preload={[{ subset: 'latin', style: 'normal' }, { weight: '400' }]}/>Variable weight font files will be preloaded if any weight within its range is requested. For example, a font file for font weight 100 900 will be included when 400 is specified in a preload object.