build(deps): bump markdown-it from 14.2.0 to 14.3.2 - #475
Conversation
Bumps [markdown-it](https://github.com/markdown-it/markdown-it) from 14.2.0 to 14.3.2. - [Changelog](https://github.com/markdown-it/markdown-it/blob/14.3.2/CHANGELOG.md) - [Commits](markdown-it/markdown-it@14.2.0...14.3.2) --- updated-dependencies: - dependency-name: markdown-it dependency-version: 14.3.2 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Looks good, straightforward dependency version bump. Checked the diff: only yarn.lock changed, bumping markdown-it 14.2.0 to 14.3.2 (a security backport release) and its transitive constraints for entities and linkify-it, with a matching checksum update. No source, config, or documentation files are touched.
Extended reasoning...
The only change is to yarn.lock, bumping markdown-it from 14.2.0 to 14.3.2 along with transitive dependency constraints for entities (^4.4.0 to ^4.5.0) and linkify-it (^5.0.1 to ^5.0.2), plus the corresponding integrity checksum. This is a routine dependabot lockfile-only update with no source, config, or CI changes, and no security-sensitive code paths in this repo are touched. It is small, mechanical, and low risk, so no human review is needed.
Bumps markdown-it from 14.2.0 to 14.3.2.
Changelog
Sourced from markdown-it's changelog.
Commits
efb999314.3.2 releaseddaf5a3cBackported 15.0.2 fixesa855f1014.3.1 releasedad70f6bBackported 15.0.1 fixesb407f3bIgnore generated API docs in lintbf025adPrepare package.json for v14 backports2d9bbeafix: recognize lowercase declarations as HTML blocks (CommonMark 4.6) (#1189)a311cfbfix: keep literal backslash before space in link destination (CommonMark 6.3)...ff0ee0814.3.0 released52e2749Bump linkify-it / vite depsDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.