Skip to content

fix(deps): bump markdown-it and markdownlint-cli - #904

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-2d445e65c1
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-2d445e65c1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 27, 2026

Copy link
Copy Markdown
Contributor

Bumps markdown-it to 14.3.0 and updates ancestor dependency markdownlint-cli. These dependencies need to be updated together.

Updates markdown-it from 14.1.0 to 14.3.0

Changelog

Sourced from markdown-it's changelog.

[14.3.0] - 2026-07-02

Changed

  • Reworked build pipeline & tools.
  • Added source maps.
  • Bumped linkify-it to 5.0.2.

Fixed

  • Preserve backslash-space hard line breaks, matching CommonMark 6.7, #1185.

[14.2.0] - 2026-05-24

Added

  • isPunctCharCode to utilities.

Fixed

  • Don't end HTML comment blocks on a blank line, #1155.
  • Properly recognize astral chars (surrogates) in delimiter scans for emphasis-like markers, #1072. Big thanks to @​tats-u for his global efforts with improving CJK support.
  • Preserve unicode whitespaces when trimm headings/paragraphs, #1074.
  • More strict entities decode to avoid false positives ;, #1096.
  • Restore block parser state on fail in lheading rule, #1131.

Security

  • Fixed poor smartquotes perfomance on > 70k quotes in single block
  • Bumped linkify-it to 5.0.1 with fixed potential perfomance issues.

[14.1.1] - 2026-01-11

Security

  • Fixed regression from v13 in linkify inline rule. Specific patterns could cause high CPU use. Thanks to @​ltduc147 for report.
Commits
  • ff0ee08 14.3.0 released
  • 52e2749 Bump linkify-it / vite deps
  • 56c2404 fix: keep backslash-space hard line break (CommonMark 6.7) (#1185)
  • 0fbb18b Bump vite from 8.0.14 to 8.0.16 (#1181)
  • 83450e2 Rework benchmark deps and bump versions
  • 57a6863 benchmark => tinybench
  • 7608db1 Update CI config
  • 9d8eb42 Added package-lock and updated versions to latest possible
  • 0aee70d lint: enable @​stylistic/no-multi-spaces rule
  • 8878985 lint => neostandard
  • Additional commits viewable in compare view

Updates markdownlint-cli from 0.41.0 to 0.49.1

Release notes

Sourced from markdownlint-cli's releases.

v0.49.1

  • Update markdownlint dependency to 0.41.1
    • Improve MD029
    • Fix module resolution under webpack
    • Update dependencies
  • Update all dependencies via Dependabot

v0.49.0

  • Update markdownlint dependency to 0.41.0
    • Improve MD022/MD028/MD035/MD042/MD051/MD060
    • Remove handling of inline directive syntax (frequent false positives)
    • Remove support for end-of-life Node version 20
  • Update all dependencies via Dependabot

v0.48.0

  • Update all dependencies via Dependabot

v0.47.0

  • Add output and exit code support for warnings
  • Update markdownlint dependency to 0.40.0
    • Improve MD011/MD013/MD051/MD060
  • Update all dependencies via Dependabot

v0.46.0

  • Replace glob dependency with tinyglobby (smaller and fewer dependencies)
  • Update markdownlint dependency to 0.39.0
    • Add MD060/table-column-style
    • Improve MD001/MD007/MD009/MD010/MD029/MD033/MD037/MD059
  • Update all dependencies via Dependabot

v0.45.0

  • Update markdownlint dependency to 0.38.0
    • Add MD059/descriptive-link-text
    • Improve MD025/MD027/MD036/MD038/MD041/MD043/MD045/MD051/MD052
    • Remove support for end-of-life Node version 18
  • Update all dependencies via Dependabot

v0.44.0

  • Update markdownlint dependency to 0.37.4
    • Convert module to ECMAScript (breaking change)
    • Stop using require, convert to import
    • Improve MD032
  • Update all dependencies via Dependabot

v0.43.0

  • Update markdownlint dependency to 0.36.1
    • Improve MD051
    • Make micromark parser available to custom rules
    • Improve performance
  • Update all dependencies via Dependabot

... (truncated)

Commits
  • 5b5dddc Bump version 0.49.1
  • 4e83bdd Bump run-con from 1.3.2 to 1.3.3
  • 4f2127b Bump actions/setup-node from 6 to 7
  • cc62492 Manually address new violations reported by xo.
  • 678b7ee Bump xo from 3.0.2 to 4.0.0
  • 06602e9 Bump ignore from 7.0.5 to 7.0.6
  • eac32dd Bump markdownlint from 0.41.0 to 0.41.1
  • 2864eb0 Bump js-yaml from 5.2.0 to 5.2.1
  • 2748661 Bump markdown-it from 14.2.0 to 14.3.0
  • 0144ebe Manually address new violations reported by xo.
  • Additional commits viewable in compare view

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Copilot AI review requested due to automatic review settings July 27, 2026 17:00
@dependabot
dependabot Bot requested a review from davidicus as a code owner July 27, 2026 17:00
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 27, 2026
@dependabot
dependabot Bot requested a review from scottdickerson as a code owner July 27, 2026 17:00

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot could not run the full agentic suite for this review because it was automatically requested on a bot-authored pull request. Request a review from Copilot under Reviewers to retry with the full agentic suite. Improved support for bot-authored pull requests is coming soon.

Updates the repository’s markdown lint tooling dependency version.

Changes:

  • Bumps markdownlint-cli from ^0.41.0 to ^0.49.1.

@netlify

netlify Bot commented Jul 27, 2026

Copy link
Copy Markdown

Deploy Preview for phillips-seldon ready!

Name Link
🔨 Latest commit 21e6a44
🔍 Latest deploy log https://app.netlify.com/projects/phillips-seldon/deploys/6a67a614148e90000870975f
😎 Deploy Preview https://deploy-preview-904--phillips-seldon.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@chromatic-com

chromatic-com Bot commented Jul 27, 2026

Copy link
Copy Markdown

Important

UI Tests need review – Review now

🟡 UI Tests: 1 visual and accessibility change must be accepted as baseline
UI Review: Comparing 238 stories…
Storybook icon Storybook Publish: 238 stories published

@github-actions

github-actions Bot commented Jul 27, 2026

Copy link
Copy Markdown

Bumps [markdown-it](https://github.com/markdown-it/markdown-it) to 14.3.0 and updates ancestor dependency [markdownlint-cli](https://github.com/igorshubovych/markdownlint-cli). These dependencies need to be updated together.


Updates `markdown-it` from 14.1.0 to 14.3.0
- [Changelog](https://github.com/markdown-it/markdown-it/blob/master/CHANGELOG.md)
- [Commits](markdown-it/markdown-it@14.1.0...14.3.0)

Updates `markdownlint-cli` from 0.41.0 to 0.49.1
- [Release notes](https://github.com/igorshubovych/markdownlint-cli/releases)
- [Commits](igorshubovych/markdownlint-cli@v0.41.0...v0.49.1)

---
updated-dependencies:
- dependency-name: markdown-it
  dependency-version: 14.3.0
  dependency-type: indirect
- dependency-name: markdownlint-cli
  dependency-version: 0.49.1
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/multi-2d445e65c1 branch from 6022872 to 21e6a44 Compare July 27, 2026 18:40

Copy link
Copy Markdown
Contributor

🟢 Dependency Upgrade Risk Assessment: LOW

This assessment was generated automatically by a scheduled dependency review routine.


What are markdown-it and markdownlint-cli?

  • markdownlint-cli is a dev-only CLI tool used to lint .md Markdown files in the repository (e.g., README.md, CHANGELOG.md, CONTRIBUTING.md). It runs in CI as a style/quality gate on documentation files and has no presence in the compiled component library output.
  • markdown-it is a Markdown parser. It enters this project purely as a transitive dependency of markdownlint-cli and is not imported anywhere in the seldon component source (src/).

Neither library has any runtime presence in the built seldon package or in any application that consumes seldon.

What changed?

markdown-it 14.1.0 → 14.3.0:

  • 14.3.0: Reworked build pipeline, added source maps, bumped linkify-it to 5.0.2, fixed backslash-space hard line breaks per CommonMark 6.7 spec
  • 14.2.0: Added isPunctCharCode utility; fixed HTML comment block, astral character, unicode whitespace, and entity parsing edge cases
  • 14.1.1: Fixed a CPU performance regression with high-volume quote processing; bumped linkify-it for performance

markdownlint-cli 0.41.0 → 0.49.1:

  • Multiple incremental improvements to MD lint rules (MD011, MD013, MD022, MD025, MD029, MD032, MD051, MD059, MD060, etc.)
  • v0.44.0: Converted markdownlint module to ESM (could theoretically affect CI scripts using CommonJS require, but markdownlint-cli itself handles this transparently)
  • v0.46.0: Replaced glob dependency with tinyglobby
  • v0.49.0: Dropped support for Node 20 (EOL)

The stricter MD rule improvements in the newer markdownlint-cli versions could potentially cause CI failures if existing .md files violate newly added or tightened rules — but this is a documentation-only concern, not a component regression.

Why LOW?

  • Both libraries are dev-only / tooling — zero impact on the seldon component library's compiled output
  • No changes to any component source files (src/)
  • The only conceivable issue would be CI markdown lint failures from stricter rules, which is easily fixed by updating docs

Suggested Regression Tests

  • CI markdown lint step passes (verify no new rule violations in existing .md files)
  • npm run build still succeeds (sanity check that no transitive dep tree issue was introduced)

Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file dependency-upgrade-risk:low javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants