Skip to content

Bump linkify-it, jsdoc and markdownlint#646

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/multi-162b152042
Open

Bump linkify-it, jsdoc and markdownlint#646
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/multi-162b152042

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 23, 2026

Copy link
Copy Markdown
Contributor

Bumps linkify-it to 5.0.2 and updates ancestor dependencies linkify-it, jsdoc and markdownlint. These dependencies need to be updated together.

Updates linkify-it from 3.0.3 to 5.0.2

Changelog

Sourced from linkify-it's changelog.

5.0.2 / 2026-07-02

  • Fixed DoS in mailto: links (restrict user name to 64 chars).
  • Restricted user/pass part length in links.

5.0.1 / 2026-05-23

  • Fixed DoS in fuzzy links/emails search.
  • Reworked search logic - check each pattern separate, use g regexes instead of slice.
  • Removed internal cache - useless overcomplication.

5.0.0 / 2023-12-01

  • Rewrite to ESM.

4.0.1 / 2022-05-02

  • Fix http:// incorrectly returned as a link by matchStart.

4.0.0 / 2022-04-22

  • Add matchAtStart method to match full URLs at the start of the string.
  • Fixed paired symbols ((), {}, "", etc.) after punctuation.
  • --- option now affects parsing of emails (e.g. user@example.com---)
Commits

Updates jsdoc from 4.0.2 to 4.0.5

Release notes

Sourced from jsdoc's releases.

JSDoc 4.0.4

Fixes a compatibility issue with Node.js 23.

Changelog

Sourced from jsdoc's changelog.

4.0.5 (October 2025)

Fixes a performance issue when generating documentation for medium-to-large APIs.

4.0.4 (October 2024)

Fixes a compatibility issue with Node.js 23.

4.0.3 (May 2024)

Updates dependencies.

Commits

Updates markdownlint from 0.29.0 to 0.41.1

Changelog

Sourced from markdownlint's changelog.

0.41.1

  • Improve MD029
  • Fix module resolution under webpack
  • Update dependencies

0.41.0

  • Improve MD022/MD028/MD035/MD042/MD051/MD060
  • Remove handling of inline directive syntax (frequent false positives)
  • Remove deprecated Options.resultVersion (breaking change)
  • Remove deprecated LintResults.toString (breaking change)
  • Remove support for end-of-life Node version 20
  • Update dependencies

0.40.0

  • Improve MD011/MD013/MD051/MD060
  • Update dependencies

0.39.0

  • Add MD060/table-column-style
  • Improve MD001/MD007/MD009/MD010/MD029/MD033/MD037/MD059
  • Add support for reporting violations as severity warning
  • Deprecate resultVersion and toString (breaking change)
  • Improve type definitions
  • Improve demo web page
  • Update dependencies

0.38.0

  • Add MD059/descriptive-link-text
  • Improve MD025/MD027/MD036/MD038/MD041/MD043/MD045/MD051/MD052
  • markdown-it parser no longer a production dependency (breaking change)
    • Add markdownItFactory option, remove markdownItPlugins option
  • Remove support for end-of-life Node version 18
  • Improve performance
  • Update dependencies

0.37.4

  • Stop using module.createRequire, export resolveModule

0.37.3

  • Tweak package.json dependencies to work with pnpm

0.37.2

... (truncated)

Commits
  • e41e5a4 Update to version 0.41.1.
  • bf03d86 Update result object test to normalize versions in URLs for more consistent d...
  • c3b6490 Update MD029/ol-prefix to handle space- and zero-padded fixes correctly while...
  • d3d4c8b Address new lint violations introduced by previous commit.
  • 5161218 Bump eslint-plugin-unicorn from 69.0.0 to 70.0.0
  • f4986a9 Bump markdown-it from 14.2.0 to 14.3.0
  • 96139fe Bump js-yaml from 5.2.0 to 5.2.1
  • ce02ac3 Bump toml from 4.1.1 to 4.1.2
  • 4e26a61 Pin CI workflow's pnpm version to "11.11" because "latest" version tag is bro...
  • 3e1bbf3 Update test repository snapshots.
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [linkify-it](https://github.com/markdown-it/linkify-it) to 5.0.2 and updates ancestor dependencies [linkify-it](https://github.com/markdown-it/linkify-it), [jsdoc](https://github.com/jsdoc/jsdoc) and [markdownlint](https://github.com/DavidAnson/markdownlint). These dependencies need to be updated together.


Updates `linkify-it` from 3.0.3 to 5.0.2
- [Changelog](https://github.com/markdown-it/linkify-it/blob/master/CHANGELOG.md)
- [Commits](markdown-it/linkify-it@3.0.3...5.0.2)

Updates `jsdoc` from 4.0.2 to 4.0.5
- [Release notes](https://github.com/jsdoc/jsdoc/releases)
- [Changelog](https://github.com/jsdoc/jsdoc/blob/4.0.5/CHANGES.md)
- [Commits](jsdoc/jsdoc@4.0.2...4.0.5)

Updates `markdownlint` from 0.29.0 to 0.41.1
- [Changelog](https://github.com/DavidAnson/markdownlint/blob/main/CHANGELOG.md)
- [Commits](DavidAnson/markdownlint@v0.29.0...v0.41.1)

---
updated-dependencies:
- dependency-name: linkify-it
  dependency-version: 5.0.2
  dependency-type: indirect
- dependency-name: jsdoc
  dependency-version: 4.0.5
  dependency-type: direct:development
- dependency-name: markdownlint
  dependency-version: 0.41.1
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Jul 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant