Skip to content

build(deps): bump linkify-it and @wordpress/scripts - #1492

Closed
dependabot[bot] wants to merge 1 commit into
trunkfrom
dependabot/npm_and_yarn/multi-0eb0183e37
Closed

dependabot[bot] wants to merge 1 commit into
trunkfrom
dependabot/npm_and_yarn/multi-0eb0183e37

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Bumps linkify-it to 5.0.2 and updates ancestor dependency @wordpress/scripts. These dependencies need to be updated together.

Updates linkify-it from 3.0.3 to 5.0.2

Changelog

Sourced from linkify-it's changelog.

5.0.2 / 2026-07-02

  • Fixed DoS in mailto: links (restrict user name to 64 chars).
  • Restricted user/pass part length in links.

5.0.1 / 2026-05-23

  • Fixed DoS in fuzzy links/emails search.
  • Reworked search logic - check each pattern separate, use g regexes instead of slice.
  • Removed internal cache - useless overcomplication.

5.0.0 / 2023-12-01

  • Rewrite to ESM.

4.0.1 / 2022-05-02

  • Fix http:// incorrectly returned as a link by matchStart.

4.0.0 / 2022-04-22

  • Add matchAtStart method to match full URLs at the start of the string.
  • Fixed paired symbols ((), {}, "", etc.) after punctuation.
  • --- option now affects parsing of emails (e.g. user@example.com---)
Commits

Updates @wordpress/scripts from 35.0.0 to 36.0.0

Changelog

Sourced from @​wordpress/scripts's changelog.

36.0.0 (2026-09-23)

Breaking Changes

  • Switch test-unit-js to consumer-installed Vitest 5 and Vite 7/8 at the 36.0.0 boundary. Run once by default, discover consumer Vitest/Vite config, and use Vitest lint defaults for test/spec files. Keep test-unit-jest as a maintenance-only adapter for consumer-installed Jest, with no scheduled removal. Remove the bundled Jest dependencies, preset config, Babel transformer, and GitHub Actions reporter. Retire the Jest preset and console package source; published versions remain available. Jest projects must install their own dependencies and configure the published preset if needed. See the migration guide. (#82843).

  • Require Node.js ^22.22.2 || ^24.15.0 || >=26.0.0 and update the bundled markdownlint-cli from ^0.31.1 to ^0.49.1, which moves markdownlint from 0.25 to 0.41. lint-md-docs now runs the rules added since then (MD051 through MD060) by default, so projects may see new reports. The header rule aliases (for example header-increment) no longer work in configuration files; use the heading names (#81917).

  • lint-style: Use stylelint's resolveConfig for config detection instead of a static extension list, supporting all current and future config file formats without manual maintenance overhead. Note that resolveConfig also searches ancestor directories and the global config directory (~/.config/stylelint), so a project with no local config may now pick up an unrelated config found there instead of the bundled default (#79280).

Enhancements

  • check-engines: Check only the tools listed in engines, instead of always passing --node and --npm. Without an engines field in the project, it now checks only the Node.js version (#83326).
  • lint-md-docs: Detect .markdownlint.jsonc so the bundled default config is not used when one is present (#81917).
  • format: Format .cjs and .mjs files when expanding a directory (#82731).
  • format: Format .cts and .mts files when expanding a directory (#83071).
  • The default ESLint config now lints .jsx, .ts, .tsx, .mts and .cts files, which ESLint's own file discovery skips (#83071).
  • build and start: Discover .cjs, .cts and .mts entry points, resolve them from extensionless imports, and transpile .cjs and .cts modules (#83071).
  • The bundled wp-prettier dependency has been upgraded from 3.0.3 to 3.9.6 (#82731).

Bug Fixes

  • Update the bundled webpack to ^5.111.0, which fixes a code-generation regression in webpack 5.110.3 that can make production bundles fail at startup (#82698).
Commits
  • 56d8058 chore(release): publish
  • 9ff3f0e Update changelog files
  • f905a64 Merge changes published in the Gutenberg plugin "release/24.1" branch
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.
Open WordPress Playground Preview

Bumps [linkify-it](https://github.com/markdown-it/linkify-it) to 5.0.2 and updates ancestor dependency [@wordpress/scripts](https://github.com/WordPress/gutenberg/tree/HEAD/packages/scripts). These dependencies need to be updated together.


Updates `linkify-it` from 3.0.3 to 5.0.2
- [Changelog](https://github.com/markdown-it/linkify-it/blob/master/CHANGELOG.md)
- [Commits](markdown-it/linkify-it@3.0.3...5.0.2)

Updates `@wordpress/scripts` from 35.0.0 to 36.0.0
- [Release notes](https://github.com/WordPress/gutenberg/releases)
- [Changelog](https://github.com/WordPress/gutenberg/blob/trunk/packages/scripts/CHANGELOG.md)
- [Commits](https://github.com/WordPress/gutenberg/commits/@wordpress/scripts@36.0.0/packages/scripts)

---
updated-dependencies:
- dependency-name: linkify-it
  dependency-version: 5.0.2
  dependency-type: indirect
- dependency-name: "@wordpress/scripts"
  dependency-version: 36.0.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Sep 29, 2026
@github-actions

Copy link
Copy Markdown
Contributor

The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the props-bot label.

If you're merging code through a pull request on GitHub, copy and paste the following into the bottom of the merge commit message.

Co-authored-by: davidperezgar <davidperez@git.wordpress.org>

To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook.

@dependabot @github

dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 30, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/multi-0eb0183e37 branch September 30, 2026 15:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant