Skip to content

deps: bump markdown-it from 14.2.0 to 15.0.1 - #58

Merged
DeDuva merged 1 commit into
devfrom
dependabot/npm_and_yarn/markdown-it-15.0.0
Sep 1, 2026
Merged

DeDuva merged 1 commit into
devfrom
dependabot/npm_and_yarn/markdown-it-15.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 3, 2026 •

Copy link
Copy Markdown
Contributor

Bumps markdown-it from 14.2.0 to 15.0.1.

Changelog

Sourced from markdown-it's changelog.

[15.0.1] - 2026-08-27

Changed

  • doc: replace oxide theme with custom one.

Fixed

  • Fixed code span parsing after lookaheads for unclosed link and image labels, #1201.
  • Preserve spaces in code spans whose content consists only of spaces, #1180.
  • Preserve brackets around IPv6 address literals when normalizing links, #1204.

Security

  • Fixed quadratic complexity when replacing fuzzy links.
  • Fixed quadratic complexity in scheme backscan (inline linkify rule).

[15.0.0] - 2026-07-30

Added

  • Exposed parser internals classes as static properties on markdownit.
  • Bundled TypeScript declarations. Remove @types/markdown-it if you used it.
  • Added the markdown-it/browser export with bundled ESM and UMD builds.
  • Added colored CLI help on supported terminals via argparse 3.
  • Added reference labels to link/image tokens, #938.
  • Added reference_definition tokens. They remain stripped by default for backwards compatibility, #1055. Also adjusted the line-break heuristic to keep output exactly the same.

Changed

  • [breaking] linkify-it => v6
    • No fuzzy links by default.
    • No auth part check by default.
    • Unicode punctuation terminates the link by default (should help with CJK).
    • See linkify-it changelog for other changes.
  • Package root now resolves to prebuilt ESM and CJS files instead of raw sources. Distribution files were reorganized under dist/ and dist/browser/.
  • Migrated to Typescript.
  • entities => v8. Can be rolled back to v7 if compatibility issues happen.
  • Moved validateLink, normalizeLink and normalizeLinkText from properties to prototype methods.
  • Reworked issue templates and contribution guidelines.

Removed

  • [breaking] Removed package-internal subpath exports (markdown-it/lib/* and similar). Use the static classes exposed on markdownit instead.
  • [breaking] Removed obsolete StateBlock#ddIndent, #1139. Update markdown-it-deflist to keep it working.

Fixed

... (truncated)

Commits
  • 924b203 15.0.1 released
  • 25c3895 Changelog update
  • aaadcfa Fix quadratic complexity in scheme backscan (inline linkify rule)
  • 09fa071 Fix quadratic complexity when replacing fuzzy links
  • 988c82b fix: don't strip spaces from all-space code spans
  • 26b9a7b Polish previous commit
  • e8c6688 fix: preserve IPv6 brackets in normalizeLink (#1204)
  • 5e9b1cc Rework backticks cache to remove side effects, close #1201
  • 7b9a6a3 doc: fix source link style for methods
  • 1e8ab89 doc: add changelog to menu
  • Additional commits viewable in compare view

@dependabot @github

dependabot Bot commented on behalf of github Aug 3, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, squad:belanna. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot changed the base branch from dev to replatform-0.11 August 7, 2026 23:08
@dependabot dependabot Bot changed the title deps: bump markdown-it from 14.3.0 to 15.0.0 deps: bump markdown-it from 14.2.0 to 15.0.0 Aug 7, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/markdown-it-15.0.0 branch from c806275 to 7f98577 Compare August 7, 2026 23:08
@github-actions

Copy link
Copy Markdown
Contributor

👋 Friendly nudge — this PR has had no activity for 9 days.

What needs attention:

  • 👀 No approving reviews yet. Request a review from a teammate.
  • ⬇️ 38 commits behind dev. Rebase to pick up latest changes.

If this PR is abandoned, please close it. If it's blocked on something external, leave a comment so the team knows.
This is an automated check that runs on weekdays. It won't nudge the same PR more than once per week.

@github-actions

Copy link
Copy Markdown
Contributor

👋 Friendly nudge — this PR has had no activity for 7 days.

What needs attention:

  • 👀 No approving reviews yet. Request a review from a teammate.
  • ⬇️ 38 commits behind dev. Rebase to pick up latest changes.

If this PR is abandoned, please close it. If it's blocked on something external, leave a comment so the team knows.
This is an automated check that runs on weekdays. It won't nudge the same PR more than once per week.

1 similar comment
@github-actions

Copy link
Copy Markdown
Contributor

👋 Friendly nudge — this PR has had no activity for 7 days.

What needs attention:

  • 👀 No approving reviews yet. Request a review from a teammate.
  • ⬇️ 38 commits behind dev. Rebase to pick up latest changes.

If this PR is abandoned, please close it. If it's blocked on something external, leave a comment so the team knows.
This is an automated check that runs on weekdays. It won't nudge the same PR more than once per week.

DeDuva commented Sep 1, 2026 •

Copy link
Copy Markdown
Owner

Not merged — needs refresh (head 7f98577a)

  • Stale base. mergeStateStatus is blocked. This PR was opened 2026-08-03 and predates the current workflows: exactly one check is recorded on this head (Scope Boundary, SKIPPED), so neither required check on dev — claude-md or changes — has run. There is no CI evidence about this head at all, and a SKIPPED check is the absence of a result, not a pass.
  • Scope: clean. package.json and package-lock.json move together, so there is no workspace lockfile drift.

Asking Dependabot to rebase onto current dev so the current checks run:

·@·d·ependabot r·ebase

Note for whoever picks this up: markdown-it 14.2.0 → 15.0.0 is a major, so a green re-run alone will not make it automatically mergeable. It needs a check of where markdown-it is used directly, and whether v15's changes to plugin or renderer APIs touch that usage.

@DeDuva

DeDuva commented Sep 1, 2026

Copy link
Copy Markdown
Owner

@dependabot rebase

Bumps [markdown-it](https://github.com/markdown-it/markdown-it) from 14.2.0 to 15.0.1.
- [Changelog](https://github.com/markdown-it/markdown-it/blob/master/CHANGELOG.md)
- [Commits](markdown-it/markdown-it@14.2.0...15.0.1)

---
updated-dependencies:
- dependency-name: markdown-it
  dependency-version: 15.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title deps: bump markdown-it from 14.2.0 to 15.0.0 deps: bump markdown-it from 14.2.0 to 15.0.1 Sep 1, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/markdown-it-15.0.0 branch from 7f98577 to f49f1b8 Compare September 1, 2026 17:25
@DeDuva

DeDuva commented Sep 1, 2026

Copy link
Copy Markdown
Owner

Merging as part of a manual queue cleanup ahead of the weekly automation.

markdown-it 14.2.0 → 15.0.1 is a major, but the blast radius here is small: it is a root devDependency that no tracked source file imports (git grep markdown-it -- '*.ts' '*.mjs' '*.js' is empty). The real consumers are markdownlint-cli2 and typedoc, which pin their own ^14 and get a nested copy — visible in this diff as the added node_modules/typedoc/node_modules/markdown-it@14.3.1. So the tools that actually parse Markdown here keep the version they were built against.

After a rebase all checks are green, including the full test suite.

@DeDuva
DeDuva merged commit 4d3ae9b into dev Sep 1, 2026
17 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/markdown-it-15.0.0 branch September 1, 2026 17:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant