Skip to content

build(deps): bump linkify-it and markdownlint - #1864

Merged
ashleyshaw merged 2 commits into
developfrom
dependabot/npm_and_yarn/multi-994b545b54
Aug 12, 2026
Merged

build(deps): bump linkify-it and markdownlint#1864
ashleyshaw merged 2 commits into
developfrom
dependabot/npm_and_yarn/multi-994b545b54

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 12, 2026

Copy link
Copy Markdown
Contributor

Bumps linkify-it to 5.0.2 and updates ancestor dependency markdownlint. These dependencies need to be updated together.

Updates linkify-it from 5.0.0 to 5.0.2

Changelog

Sourced from linkify-it's changelog.

5.0.2 / 2026-07-02

  • Fixed DoS in mailto: links (restrict user name to 64 chars).
  • Restricted user/pass part length in links.

5.0.1 / 2026-05-23

  • Fixed DoS in fuzzy links/emails search.
  • Reworked search logic - check each pattern separate, use g regexes instead of slice.
  • Removed internal cache - useless overcomplication.
Commits

Updates markdownlint from 0.28.2 to 0.41.1

Changelog

Sourced from markdownlint's changelog.

0.41.1

  • Improve MD029
  • Fix module resolution under webpack
  • Update dependencies

0.41.0

  • Improve MD022/MD028/MD035/MD042/MD051/MD060
  • Remove handling of inline directive syntax (frequent false positives)
  • Remove deprecated Options.resultVersion (breaking change)
  • Remove deprecated LintResults.toString (breaking change)
  • Remove support for end-of-life Node version 20
  • Update dependencies

0.40.0

  • Improve MD011/MD013/MD051/MD060
  • Update dependencies

0.39.0

  • Add MD060/table-column-style
  • Improve MD001/MD007/MD009/MD010/MD029/MD033/MD037/MD059
  • Add support for reporting violations as severity warning
  • Deprecate resultVersion and toString (breaking change)
  • Improve type definitions
  • Improve demo web page
  • Update dependencies

0.38.0

  • Add MD059/descriptive-link-text
  • Improve MD025/MD027/MD036/MD038/MD041/MD043/MD045/MD051/MD052
  • markdown-it parser no longer a production dependency (breaking change)
    • Add markdownItFactory option, remove markdownItPlugins option
  • Remove support for end-of-life Node version 18
  • Improve performance
  • Update dependencies

0.37.4

  • Stop using module.createRequire, export resolveModule

0.37.3

  • Tweak package.json dependencies to work with pnpm

0.37.2

... (truncated)

Commits
  • e41e5a4 Update to version 0.41.1.
  • bf03d86 Update result object test to normalize versions in URLs for more consistent d...
  • c3b6490 Update MD029/ol-prefix to handle space- and zero-padded fixes correctly while...
  • d3d4c8b Address new lint violations introduced by previous commit.
  • 5161218 Bump eslint-plugin-unicorn from 69.0.0 to 70.0.0
  • f4986a9 Bump markdown-it from 14.2.0 to 14.3.0
  • 96139fe Bump js-yaml from 5.2.0 to 5.2.1
  • ce02ac3 Bump toml from 4.1.1 to 4.1.2
  • 4e26a61 Pin CI workflow's pnpm version to "11.11" because "latest" version tag is bro...
  • 3e1bbf3 Update test repository snapshots.
  • Additional commits viewable in compare view

@dependabotdependabotBot added the area:dependencies Composer/npm dependency work label Aug 12, 2026
@github-actionsgithub-actionsBot added the meta:dependabot-security Dependabot update appears security-related and eligible for guarded automation label Aug 12, 2026
@github-actions

Copy link
Copy Markdown
Contributor

❌ Branch Name Validation Failed

The branch name dependabot/npm_and_yarn/multi-994b545b54 does not follow the LightSpeed branching strategy.

Required Format

{type}/{scope}-{short-title}
  • type: one of the allowed prefixes (lowercase)
  • scope: lowercase, hyphens only (no underscores or uppercase)
  • title: lowercase, hyphens only (no underscores or uppercase)

Allowed Branch Types

feat, fix, hotfix, release, refactor, chore, docs, test, perf, ci, build, deps, security, revert, research, design, a11y, ux, i18n, ops, proto, ds, api, schema, telemetry, content, seo, config, migrate, qa, uat, audit, codex

Valid Examples

  • feat/branch-naming-enforcement
  • fix/validation-script-bug
  • chore/update-dependencies
  • docs/branching-strategy-guide
  • hotfix/critical-security-patch

Invalid Examples

  • claude/my-branch (type "claude" not allowed)
  • Feature/MyBranch (uppercase not allowed)
  • fix-bug (missing type prefix)
  • feat/my_feature (underscores not allowed)
  • feat/MyFeature (uppercase not allowed)

Solution

Rename your branch to follow the pattern and update the PR.

For more information, see docs/BRANCHING_STRATEGY.md.

Bumps [linkify-it](https://github.com/markdown-it/linkify-it) to 5.0.2 and updates ancestor dependency [markdownlint](https://github.com/DavidAnson/markdownlint). These dependencies need to be updated together.
Updates `linkify-it` from 5.0.0 to 5.0.2
- [Changelog](https://github.com/markdown-it/linkify-it/blob/master/CHANGELOG.md)
- [Commits](markdown-it/linkify-it@5.0.0...5.0.2)
Updates `markdownlint` from 0.28.2 to 0.41.1
- [Changelog](https://github.com/DavidAnson/markdownlint/blob/main/CHANGELOG.md)
- [Commits](DavidAnson/markdownlint@v0.28.2...v0.41.1)
---
updated-dependencies:
- dependency-name: linkify-it
dependency-version:
dependency-type: indirect
- dependency-name: markdownlint
dependency-version: 0.41.1
dependency-type: direct:development
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabotBotforce-pushed the dependabot/npm_and_yarn/multi-994b545b54 branch from fdeb479 to 33fac57CompareAugust 12, 2026 15:36
@github-actionsgithub-actionsBot added lang:js JavaScript/TypeScript lang:json JSON config/content status:needs-review Awaiting code review priority:normal Default priority type:chore Chore / small hygiene change type:bug Bug or defect meta:needs-changelog Requires a changelog entry before merge and removed meta:dependabot-security Dependabot update appears security-related and eligible for guarded automation labels Aug 12, 2026
@ashleyshaw
ashleyshaw enabled auto-merge (squash) August 12, 2026 16:42
@github-actionsgithub-actionsBot removed the type:chore Chore / small hygiene change label Aug 12, 2026
@ashleyshaw
ashleyshaw merged commit e1a2528 into developAug 12, 2026
17 of 25 checks passed
@ashleyshaw
ashleyshaw deleted the dependabot/npm_and_yarn/multi-994b545b54 branch August 12, 2026 17:17
ashleyshaw pushed a commit that referenced this pull request Aug 12, 2026
- Add exemption for dependabot[bot] and renovate[bot] PR authors
- Skip validation for branches matching dependabot/* and renovate/* patterns
- Allows automated dependency update PRs to merge without branch naming conflict
This resolves merge blocking on PR #1864 and #1870 (dependabot dependency updates)
ashleyshaw pushed a commit that referenced this pull request Aug 12, 2026
- Add exemption for dependabot[bot] and renovate[bot] PR authors
- Skip validation for branches matching dependabot/* and renovate/* patterns
- Allows automated dependency update PRs to merge without branch naming conflict
This resolves merge blocking on PR #1864 and #1870 (dependabot dependency updates)
ashleyshaw added a commit that referenced this pull request Aug 12, 2026
- Add exemption for dependabot[bot] and renovate[bot] PR authors
- Skip validation for branches matching dependabot/* and renovate/* patterns
- Allows automated dependency update PRs to merge without branch naming conflict
This resolves merge blocking on PR #1864 and #1870 (dependabot dependency updates)
Co-authored-by: Test User <test@test.com>
@ashleyshawashleyshaw self-assigned this Aug 13, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:dependenciesComposer/npm dependency worklang:jsJavaScript/TypeScriptlang:jsonJSON config/contentmeta:needs-changelogRequires a changelog entry before mergepriority:normalDefault prioritystatus:needs-reviewAwaiting code reviewtype:bugBug or defect

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@ashleyshaw