Skip to content

chore(deps-dev): bump the development group across 1 directory with 2 updates#97

Merged
steipete merged 1 commit into
mainfrom
dependabot/npm_and_yarn/development-cb5b837c03
Jul 11, 2026
Merged

chore(deps-dev): bump the development group across 1 directory with 2 updates#97
steipete merged 1 commit into
mainfrom
dependabot/npm_and_yarn/development-cb5b837c03

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 9, 2026

Copy link
Copy Markdown
Contributor

Bumps the development group with 2 updates in the / directory: markdown-it and markdown-it-anchor.

Updates markdown-it from 14.2.0 to 14.3.0

Changelog

Sourced from markdown-it's changelog.

[14.3.0] - 2026-07-02

Changed

  • Reworked build pipeline & tools.
  • Added source maps.
  • Bumped linkify-it to 5.0.2.

Fixed

  • Preserve backslash-space hard line breaks, matching CommonMark 6.7, #1185.
Commits
  • ff0ee08 14.3.0 released
  • 52e2749 Bump linkify-it / vite deps
  • 56c2404 fix: keep backslash-space hard line break (CommonMark 6.7) (#1185)
  • 0fbb18b Bump vite from 8.0.14 to 8.0.16 (#1181)
  • 83450e2 Rework benchmark deps and bump versions
  • 57a6863 benchmark => tinybench
  • 7608db1 Update CI config
  • 9d8eb42 Added package-lock and updated versions to latest possible
  • 0aee70d lint: enable @​stylistic/no-multi-spaces rule
  • 8878985 lint => neostandard
  • Additional commits viewable in compare view

Updates markdown-it-anchor from 9.2.0 to 9.2.1

Changelog

Sourced from markdown-it-anchor's changelog.

[9.2.1] - 2026-07-06

  • Preserve level of inline token in headerLink. (#138)
Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 9, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner July 9, 2026 18:54
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 9, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/development-cb5b837c03 branch from 8e09d86 to c123c18 Compare July 9, 2026 20:12
@socket-security

socket-security Bot commented Jul 10, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedmarkdown-it@​14.2.0 ⏵ 14.3.08610010087 -1100
Updatedmarkdown-it-anchor@​9.2.0 ⏵ 9.2.11001009988 +7100

View full report

… updates

Bumps the development group with 2 updates in the / directory: [markdown-it](https://github.com/markdown-it/markdown-it) and [markdown-it-anchor](https://github.com/valeriangalliat/markdown-it-anchor).


Updates `markdown-it` from 14.2.0 to 14.3.0
- [Changelog](https://github.com/markdown-it/markdown-it/blob/master/CHANGELOG.md)
- [Commits](markdown-it/markdown-it@14.2.0...14.3.0)

Updates `markdown-it-anchor` from 9.2.0 to 9.2.1
- [Release notes](https://github.com/valeriangalliat/markdown-it-anchor/releases)
- [Changelog](https://github.com/valeriangalliat/markdown-it-anchor/blob/master/CHANGELOG.md)
- [Commits](valeriangalliat/markdown-it-anchor@v9.2.0...v9.2.1)

---
updated-dependencies:
- dependency-name: markdown-it
  dependency-version: 14.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development
- dependency-name: markdown-it-anchor
  dependency-version: 9.2.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/development-cb5b837c03 branch from c123c18 to af9483c Compare July 10, 2026 18:54
@steipete

Copy link
Copy Markdown
Contributor

Validated exact head af9483c against current main after #99.

  • Freshness: markdown-it 14.3.0 and markdown-it-anchor 9.2.1 remain current; registry integrity matches the lockfile; npm outdated is empty.
  • Local proof: npm ci resolved the lockfile; npm audit reports 0 vulnerabilities; syntax checks, unit tests, Wrangler dry-run, full docs build, smoke, visual smoke, R2 preparation, and llms-full generation all pass.
  • Build evidence: 27,970 pages rendered; 14,331 pages indexed across 21 languages; R2 manifest prepared 60,606 objects; llms-full generated 714 pages.
  • Black-box proof: English/localized pages, heading anchors, Pagefind, emitted Markdown, 404 handling, and CommonMark hard-break behavior passed; the public hosted getting-started route returned 200.
  • Review/CI: final autoreview reported no accepted/actionable findings; exact-head Docs Code CI, CodeQL, and Socket checks pass; Mintlify correctly skipped.
  • Risk: medium surface area because the parser affects every rendered page, reduced by full build, visual, hosted, and source-blind validation.

@steipete
steipete merged commit 75ab342 into main Jul 11, 2026
7 checks passed
@steipete
steipete deleted the dependabot/npm_and_yarn/development-cb5b837c03 branch July 11, 2026 20:56
@steipete

Copy link
Copy Markdown
Contributor

Post-merge verification:

The dependency change is not implicated; no deployment occurred from the failed run.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant