Skip to content

chore(deps): bump markdown-it 14.3.2 and fast-uri 4.2.1 - #46

Merged
VatsalSy merged 1 commit into
mainfrom
rayleigh-cloud/markdown-it-14.3.1-e1a8
Oct 5, 2026
Merged

VatsalSy merged 1 commit into
mainfrom
rayleigh-cloud/markdown-it-14.3.1-e1a8

Conversation

@VatsalSy

@VatsalSy VatsalSy commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

Description

Dependabot security alert #74 is open because the markdown-it npm override was pinned at 14.2.0 (vulnerable below 14.3.1), so no Dependabot PR appeared. Alert #72 (fast-uri below 4.1.5) is already covered by green Dependabot PR #45.

This PR raises the markdown-it override to 14.3.2 (latest patched 14.x) and folds the fast-uri 4.2.1 bump into the same lockfile update. It supersedes #45; that Dependabot PR is left open.

Type of Change

  • Other (please describe): npm security override and lockfile hygiene

Changes Made

  • overrides.markdown-it: 14.2.0 → 14.3.2 (stays on the 14.x line)
  • overrides.fast-uri: >=3.1.5 → 4.2.1 (matches Dependabot chore(deps): bump fast-uri from 4.1.4 to 4.2.1 #45)
  • package-lock.json: markdown-it 14.2.0 → 14.3.2, fast-uri 4.1.4 → 4.2.1
  • No major-version bumps (Babel 8, jest-dom 7, dotenv 18, jsdom, TypeScript majors remain deferred)
  • No site content changes

Testing Done

  • Tested locally using bundle exec jekyll serve
  • Checked all links and references
  • Verified content formatting
  • Cross-browser testing (if UI changes)

Local npm ci, npm test, npm run lint, and bundle exec jekyll build run after this pre-testing revision.

Related Issues

Supersedes #45 (do not close until this merges).
Addresses Dependabot alerts #74 (markdown-it < 14.3.1) and #72 (fast-uri < 4.1.5).

Checklist

  • Code follows the project's style guidelines
  • All links are valid and working
  • Images are optimized and properly sized
  • Content is properly formatted
  • Documentation has been updated (if needed)
  • Changes have been tested locally

Additional Notes

Majors deliberately left untouched. Review should focus on override pins and lockfile integrity hashes.

Open in Web Open in Cursor 

Summary by CodeRabbit

  • Chores
    • Updated the versions of two underlying packages.

Pin the markdown-it override to a patched 14.x release so Dependabot
alert #74 is no longer held at 14.2.0. Fold the fast-uri 4.2.1 bump
that already addresses alert #72.
@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Essentials
  • Run ID: 9c0e31cf-3b9e-4403-b00a-411eb76fc832
📥 Commits

Reviewing files that changed from the base of the PR and between 117338c and 21f733d.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (1)
  • package.json

Included review availability: This review used your included allowance. 4 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (1)
  • GitHub Check: build
🔇 Additional comments (1)
package.json (1)

40-40: LGTM!

Also applies to: 45-45


📝 Walkthrough

Walkthrough

The fast-uri override changes from >=3.1.5 to 4.2.1. The markdown-it override changes from 14.2.0 to 14.3.2. Other overrides in the changed block remain unchanged.

Changes

Dependency overrides

Layer / File(s) Summary
Update override versions
package.json
The fast-uri override is set to 4.2.1, and the markdown-it override is set to 14.3.2. Other overrides in the changed block remain unchanged.

Priority: ➖ Normal

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 21f73

No actionable merge-blocking risk is established: the dependency lockfile contains the requested versions, and the stale installed tree predates this change.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely identifies the two dependency version updates, which are the main changes in the pull request.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
✨ Simplify code
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@VatsalSy
VatsalSy merged commit feedd1c into main Oct 5, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants