Astro 6 lifecycle
Current status
Astro 6 has no published vendor calendar support schedule in CompatHub's sources. Release history and dependency requirements are recorded from package metadata without inventing support commitments.
Security: 6 tracked advisories affecting this line. Details below — lifecycle and vulnerability status are separate.
Official lifecycle source: Astro npm releases
- Support phase
- unknown
- End of life
- Not officially published
- Latest release
- 6.4.8
- Released
- 17 Jun 2026
At a glance
- Version line
- 6
- Initial release
- 10 Mar 2026
- Lifecycle phase
- unknown
- Latest stable
- 6.4.8
- Latest release date
- 17 Jun 2026
- EOL
- Not officially published
- Risk
- medium
- Releases tracked
- 41
Lifecycle timeline
Phases from published LifecyclePeriod records. Missing phases are not inferred.
Release
10 Mar 2026
unknowncurrent
10 Mar 2026 → —
Source: Astro npm releases
Astro 6 has no published vendor calendar support schedule in CompatHub's sources. Release history and dependency requirements are recorded from package metadata without inventing support commitments.
Security
Advisories affecting Astro 6 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.
- Known vulnerabilities
- 6
- Known exploited
- 0
- Highest CVSS
- 7.5
- CVE-2026-54299GHSA-2pvr-wf23-7pc7
Astro: Host header SSRF in prerendered error page fetch
- CVSS:
- 7.5 (high) · NVD
- CWE:
- CWE-20, CWE-918
- Affected:
- <6.4.6
- Fixed in:
- 6.4.6
- Source:
- OSV source · Advisory
- CVE-2026-50146GHSA-8hv8-536x-4wqp
Astro: Reflected XSS via unescaped slot name
- CVSS:
- 6.1 (moderate) · NVD
- CWE:
- CWE-80
- Affected:
- <6.3.3
- Fixed in:
- 6.3.3
- Source:
- OSV source · Advisory
- CVE-2026-59729GHSA-f48w-9m4c-m7f5
Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
- CVSS:
- 5.1 (moderate) · NVD
- CWE:
- CWE-79
- Affected:
- <7.0.6
- Fixed in:
- 7.0.6
- Source:
- OSV source · Advisory
- CVE-2026-54298GHSA-jrpj-wcv7-9fh9
Astro: XSS via Unescaped Attribute Names in Spread Props
- Affected:
- <6.4.6
- Fixed in:
- 6.4.6
- Source:
- OSV source · Advisory
- CVE-2026-45028GHSA-xr5h-phrj-8vxv
Astro: Server island encrypted parameters vulnerable to cross-component replay
- Affected:
- <6.1.10
- Fixed in:
- 6.1.10
- Source:
- OSV source · Advisory
- CVE-2026-41067GHSA-j687-52p2-xcff
Astro: XSS in define:vars via incomplete </script> tag sanitization
- Affected:
- <6.1.6
- Fixed in:
- 6.1.6
- Source:
- OSV source · Advisory
Latest release
Previous releases
6.4.7
15 Jun 2026
6.4.6
10 Jun 2026
6.4.5
9 Jun 2026
Release history
41 concrete releases tracked for this line.
| Version | Release date | Channel | Source |
|---|---|---|---|
| 6.1.6 | 13 Apr 2026 | stable | Source |
| 6.1.5 | 8 Apr 2026 | stable | Source |
| 6.1.4 | 6 Apr 2026 | stable | Source |
| 6.1.3 | 1 Apr 2026 | stable | Source |
| 6.1.2 | 30 Mar 2026 | stable | Source |
| 6.1.1 | 26 Mar 2026 | stable | Source |
| 6.1.0 | 26 Mar 2026 | stable | Source |
| 6.0.8 | 20 Mar 2026 | stable | Source |
| 6.0.7 | 19 Mar 2026 | stable | Source |
| 6.0.6 | 18 Mar 2026 | stable | Source |
| 6.0.5 | 16 Mar 2026 | stable | Source |
| 6.0.4 | 12 Mar 2026 | stable | Source |
| 6.0.3 | 11 Mar 2026 | stable | Source |
| 6.0.2 | 10 Mar 2026 | stable | Source |
| 6.0.1 | 10 Mar 2026 | stable | Source |
| 6.0.0 | 10 Mar 2026 | stable | Source |
Release activity
- Total releases
- 41
- Last 30 days
- 0
- Last 90 days
- 4
- Avg. interval
- ~3 days
- Most recent
- 17 Jun 2026
Should I use this version?
Lifecycle status unclear
Astro 6 has no published vendor calendar support schedule. CompatHub does not invent support commitments from release history alone.
Version comparison
Compact comparison against the nearest relevant release lines.
Compatibility
Evidence-backed compatibility results involving Astro 6. Only combinations CompatHub can evaluate from upstream sources are listed.
Sources
Where this information comes from.
Lifecycle sources
- Astro npm releasesfirst party · high confidence
Official source: https://www.npmjs.com/package/astro
Last verified 2 Sept 2026
- OSV.devfirst party
Official source: https://osv.dev
Verification time not recorded
- NVD (NIST)first party
Official source: https://nvd.nist.gov
Verification time not recorded
- CISA Known Exploited Vulnerabilitiesfirst party
Official source: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Verification time not recorded
Release sources
- Astro npm releasesfirst party · high confidence
Official source: https://www.npmjs.com/package/astro
Last verified 2 Sept 2026
Data coverage
Last checked = last successful upstream check. Latest source update = when upstream content last changed.
- Releases tracked
- 41
- Lifecycle periods
- 1
- EOL
- Not officially published
- Provenance records
- 2
- Data last checked
- 2 Sept 2026
- Latest source update
- 2 Sept 2026
EOL: Not officially published
