Skip to content

Bump markdown-it and @wordpress/scripts in /dynamic-copyright-date-block - #148

Merged
github-actions[bot] merged 1 commit into
trunkfrom
dependabot/npm_and_yarn/dynamic-copyright-date-block/multi-a7c83e8656
Sep 30, 2026
Merged

github-actions[bot] merged 1 commit into
trunkfrom
dependabot/npm_and_yarn/dynamic-copyright-date-block/multi-a7c83e8656

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor

Bumps markdown-it to 14.3.2 and updates ancestor dependency @wordpress/scripts. These dependencies need to be updated together.

Updates markdown-it from 12.3.2 to 14.3.2

Changelog

Sourced from markdown-it's changelog.

[14.3.2] - 2026-09-12

Security

  • Backported 15.0.2 fixes.

[14.3.1] - 2026-08-27

Security

  • Backported 15.0.1 fixes.

[14.3.0] - 2026-07-02

Changed

  • Reworked build pipeline & tools.
  • Added source maps.
  • Bumped linkify-it to 5.0.2.

Fixed

  • Preserve backslash-space hard line breaks, matching CommonMark 6.7, #1185.

[14.2.0] - 2026-05-24

Added

  • isPunctCharCode to utilities.

Fixed

  • Don't end HTML comment blocks on a blank line, #1155.
  • Properly recognize astral chars (surrogates) in delimiter scans for emphasis-like markers, #1072. Big thanks to @​tats-u for his global efforts with improving CJK support.
  • Preserve unicode whitespaces when trimm headings/paragraphs, #1074.
  • More strict entities decode to avoid false positives ;, #1096.
  • Restore block parser state on fail in lheading rule, #1131.

Security

  • Fixed poor smartquotes perfomance on > 70k quotes in single block
  • Bumped linkify-it to 5.0.1 with fixed potential perfomance issues.

[14.1.1] - 2026-01-11

Security

  • Fixed regression from v13 in linkify inline rule. Specific patterns could cause high CPU use. Thanks to @​ltduc147 for report.

[14.1.0] - 2024-03-19

Changed

  • Updated CM spec compatibility to 0.31.2, #1009.

... (truncated)

Commits
  • efb9993 14.3.2 released
  • daf5a3c Backported 15.0.2 fixes
  • a855f10 14.3.1 released
  • ad70f6b Backported 15.0.1 fixes
  • b407f3b Ignore generated API docs in lint
  • bf025ad Prepare package.json for v14 backports
  • 2d9bbea fix: recognize lowercase declarations as HTML blocks (CommonMark 4.6) (#1189)
  • a311cfb fix: keep literal backslash before space in link destination (CommonMark 6.3)...
  • ff0ee08 14.3.0 released
  • 52e2749 Bump linkify-it / vite deps
  • Additional commits viewable in compare view

Updates @wordpress/scripts from 35.0.0 to 36.0.0

Changelog

Sourced from @​wordpress/scripts's changelog.

36.0.0 (2026-09-23)

Breaking Changes

  • Switch test-unit-js to consumer-installed Vitest 5 and Vite 7/8 at the 36.0.0 boundary. Run once by default, discover consumer Vitest/Vite config, and use Vitest lint defaults for test/spec files. Keep test-unit-jest as a maintenance-only adapter for consumer-installed Jest, with no scheduled removal. Remove the bundled Jest dependencies, preset config, Babel transformer, and GitHub Actions reporter. Retire the Jest preset and console package source; published versions remain available. Jest projects must install their own dependencies and configure the published preset if needed. See the migration guide. (#82843).

  • Require Node.js ^22.22.2 || ^24.15.0 || >=26.0.0 and update the bundled markdownlint-cli from ^0.31.1 to ^0.49.1, which moves markdownlint from 0.25 to 0.41. lint-md-docs now runs the rules added since then (MD051 through MD060) by default, so projects may see new reports. The header rule aliases (for example header-increment) no longer work in configuration files; use the heading names (#81917).

  • lint-style: Use stylelint's resolveConfig for config detection instead of a static extension list, supporting all current and future config file formats without manual maintenance overhead. Note that resolveConfig also searches ancestor directories and the global config directory (~/.config/stylelint), so a project with no local config may now pick up an unrelated config found there instead of the bundled default (#79280).

Enhancements

  • check-engines: Check only the tools listed in engines, instead of always passing --node and --npm. Without an engines field in the project, it now checks only the Node.js version (#83326).
  • lint-md-docs: Detect .markdownlint.jsonc so the bundled default config is not used when one is present (#81917).
  • format: Format .cjs and .mjs files when expanding a directory (#82731).
  • format: Format .cts and .mts files when expanding a directory (#83071).
  • The default ESLint config now lints .jsx, .ts, .tsx, .mts and .cts files, which ESLint's own file discovery skips (#83071).
  • build and start: Discover .cjs, .cts and .mts entry points, resolve them from extensionless imports, and transpile .cjs and .cts modules (#83071).
  • The bundled wp-prettier dependency has been upgraded from 3.0.3 to 3.9.6 (#82731).

Bug Fixes

  • Update the bundled webpack to ^5.111.0, which fixes a code-generation regression in webpack 5.110.3 that can make production bundles fail at startup (#82698).
Commits
  • 56d8058 chore(release): publish
  • 9ff3f0e Update changelog files
  • f905a64 Merge changes published in the Gutenberg plugin "release/24.1" branch
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [markdown-it](https://github.com/markdown-it/markdown-it) to 14.3.2 and updates ancestor dependency [@wordpress/scripts](https://github.com/WordPress/gutenberg/tree/HEAD/packages/scripts). These dependencies need to be updated together.


Updates `markdown-it` from 12.3.2 to 14.3.2
- [Changelog](https://github.com/markdown-it/markdown-it/blob/14.3.2/CHANGELOG.md)
- [Commits](markdown-it/markdown-it@12.3.2...14.3.2)

Updates `@wordpress/scripts` from 35.0.0 to 36.0.0
- [Release notes](https://github.com/WordPress/gutenberg/releases)
- [Changelog](https://github.com/WordPress/gutenberg/blob/trunk/packages/scripts/CHANGELOG.md)
- [Commits](https://github.com/WordPress/gutenberg/commits/@wordpress/scripts@36.0.0/packages/scripts)

---
updated-dependencies:
- dependency-name: markdown-it
  dependency-version: 14.3.2
  dependency-type: indirect
- dependency-name: "@wordpress/scripts"
  dependency-version: 36.0.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 30, 2026
@github-actions
github-actions Bot enabled auto-merge September 30, 2026 06:18
@github-actions
github-actions Bot merged commit 61e6cd9 into trunk Sep 30, 2026
3 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/dynamic-copyright-date-block/multi-a7c83e8656 branch September 30, 2026 06:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant