Shelf · astro
Integrity ledger
Digests are taken once, at fetch time, before the artifact touches any edge. Nothing on this page is computed on demand.
Two forms are published because two audiences want them. Package managers want the base64 sha512 string that goes into a lockfile. Browsers want a sha384 subresource-integrity attribute. They describe different files, so do not mix them up.
Every entry below is distinct. If two versions ever show the same digest, that is a bug on our side and we want to hear about it — see the service policy for how to reach us.
Tarballs — sha512, lockfile form
This is the value that lands in an integrity: field. It covers the published .tgz exactly as upstream produced it.
-
5.14.22026-09-08/r/5.14.2/astro-5.14.2.tgz
sha512-ogE9Jml/R6MGRS0ClvLKAuD/3C6R7K47KckrNK2wxvj7LCrG6BGxQ8C51hyRAt2vEZog/uMD1jjNdRsTBZ/Lzw== -
5.14.12026-08-27/r/5.14.1/astro-5.14.1.tgz
sha512-jeuQyWBt+pRg5AfdZXWBalJ/F0fVtbVh+4zamXUj/fJj0e3wGQ5P5sm3wJY2fDIfv4sEQ/fDIlX+4JzSnBh/lQ== -
5.14.02026-08-12/r/5.14.0/astro-5.14.0.tgz
sha512-x4BK24LOkzNh3cKY8tQZ4HeHxiDG1pNGtRjUgwI9LcLOEi21R1ptcU1XzgdeILQ37YyiaPTkYiuPoRcs+7qRlw== -
5.13.62026-07-24/r/5.13.6/astro-5.13.6.tgz
sha512-ME64v0MRsvukGexGChuiynxLx6yu4+Oa87jMS9pcBdm/UJBwoJCwrjln3WFXxvYYHux1IY9zLxgspmGXJBE1IA== -
5.13.22026-07-02/r/5.13.2/astro-5.13.2.tgz
sha512-YT27hfXuY4uk4y4zJNQ2avt4ZN0B9oSQfpUsimjpkNIBmnNTSV38s+eLoMhL/Y9gz+frbvg9eQP6+wXqKXYygQ== -
5.12.92026-06-10/r/5.12.9/astro-5.12.9.tgz
sha512-v8OSl+sIbRIZqwL/uYv7VdjtgEuoIP/yx8cVMPI3VUaWi1Z5FfYHAcJ3qoss0rZ3eJRF5maIM01GeLCQcUYcww== -
5.12.02026-05-19/r/5.12.0/astro-5.12.0.tgz
sha512-JIa6d1pOi+pvlXS2wf3zorCv67wnSoKp2AQK3R9exDQ/iAjvnPRhmxIdaez3fbUGplsI5ud/qqXLD0g7vpK8Og== -
5.11.42026-04-28/r/5.11.4/astro-5.11.4.tgz
sha512-61lNCRG+yQN6vHUzf4vioP/OpXhTSKGDprxesXUXzzs6vtUxVV6k0JISf7Mn+1fU+cczhzQd919UIaQfNFApBg== -
5.10.32026-03-31/r/5.10.3/astro-5.10.3.tgz
sha512-xOK1wCebcmuhLb5VX/H5zVLm2rXe6uDzWU4kZ77FA2fbYwZOG4gVk4Me8+E8aCglzIKqwgIN0hudqSVIRFGMWQ== -
5.9.82026-02-26/r/5.9.8/astro-5.9.8.tgz
sha512-F+zQ0qmAIxjff/Q9n4KJa3pT5YzLLlKK821kwonSqowG8xqSNKvsOj7VZZ45a4WwKGnuEc1aARy1Kgi6hq9hRQ== -
5.8.22026-01-20/r/5.8.2/astro-5.8.2.tgz
sha512-ueQift0qbhczp136mFFi+RL+cS9vh/kNMq/SJ65oO62eLM6kmnkGIuF4rLYWl1mZZmuJ2wFv2Ms2aR5bFdJIgg== -
4.16.182025-11-12/r/4.16.18/astro-4.16.18.tgz
sha512-P9ZzXWoIbNuL7BkkdiBSQl23mEWN8xsATZeMPEr9XDKaxuU1WwKT/2fk5Bef/W+WKrLF66/tF+m8WsTR40acyg==
Browser builds — sha384, SRI form
These cover the two entry points extracted from each tarball into /r/<version>/b/. Paste the value into an integrity attribute alongside crossorigin="anonymous"; the usage page has a complete snippet.
-
/r/5.14.2/b/config.browser.mjs
sha384-fzMZWLUnxeK3o/fmagtuvRHbHbf6DTW0oAmVpGB5qDTuMOwWMvtVCkUA45A94Kgo -
/r/5.14.2/b/compiler.browser.js
sha384-eGCR86WCXQVLso5IBWIHncLOo+1l3drmwzATlQ37pmE3NXuo6ZQ37okn0Uqix+dX -
/r/5.14.1/b/config.browser.mjs
sha384-kuUmbrD/oxeXn1Yw1tCLJCZ61DyA70aKCsDQ+uKGN553QXQyjQ4pt1Ns9TDspf5q -
/r/5.14.1/b/compiler.browser.js
sha384-kPSsknrnDxxOr2+STvpxLQfA4sujeGq9JLpIvIjBTw/RMiyfeXkKTuGC6fFZSqL7 -
/r/5.13.6/b/config.browser.mjs
sha384-tjET1utRDchLMLCUEI8LMqYYIvY78K+7/D/f6cD5DyazLG+ogAeyho6dvG1ksGa6 -
/r/5.13.6/b/compiler.browser.js
sha384-i7zVh+YtZuGlwpw11WzMc/s2pOzZK4HVI01hKQ7YrXtCb50kcL1NKigbqibPQq/D -
/r/5.12.0/b/config.browser.mjs
sha384-KVJPkYS8ABFXdnlrHbuvoS5YrBzQdX87HilwUD2nhXewGEmP+rRfHjm0daDqqRkG -
/r/5.12.0/b/compiler.browser.js
sha384-rOUBOmfN/dw/ndXudn/FaWSCLR2ZPHOOTa78dMOw8MahqgCjYa7/ULRhHtXh4aPi
Checking by hand
# lockfile-style sha512, base64
openssl dgst -sha512 -binary astro-5.14.2.tgz | openssl base64 -A
# SRI-style sha384, base64
openssl dgst -sha384 -binary config.browser.mjs | openssl base64 -A
A mirror is a trust shortcut, and a trust shortcut you cannot audit is just a risk you moved somewhere less visible. Verify the first pull of anything that will end up in production.
What we sign, and what we do not
- We record
- The digest of every artifact at the moment we fetched it, plus the upstream
ETagandLast-Modifiedwe saw, in each version’smanifest.json. - We do not re-sign
- If a publisher shipped provenance material inside the tarball, it is still in there untouched. We add no signature of our own and ask you to trust none.
- We do not rewrite
- No repacking, no dependency pinning, no patching. A digest mismatch against upstream would mean we broke something.