Repository navigation
chore(deps): bump markdown-it 14.3.2 and fast-uri 4.2.1 - #46
Conversation
Pin the markdown-it override to a patched 14.x release so Dependabot alert #74 is no longer held at 14.2.0. Fold the fast-uri 4.2.1 bump that already addresses alert #72.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
Included review availability: This review used your included allowance. 4 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour. 📜 Recent review details⏰ Context from checks skipped due to timeout. (1)
🔇 Additional comments (1)
📝 WalkthroughWalkthroughThe ChangesDependency overrides
Priority: ➖ Normal Estimated code review effort: 1 (Trivial) | ~3 minutes Change: Other Merge Risk: ⚪ Minimal · up to No actionable merge-blocking risk is established: the dependency lockfile contains the requested versions, and the stale installed tree predates this change. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches✨ Simplify code
Comment |
Description
Dependabot security alert #74 is open because the
markdown-itnpm override was pinned at 14.2.0 (vulnerable below 14.3.1), so no Dependabot PR appeared. Alert #72 (fast-uribelow 4.1.5) is already covered by green Dependabot PR #45.This PR raises the
markdown-itoverride to 14.3.2 (latest patched 14.x) and folds thefast-uri4.2.1 bump into the same lockfile update. It supersedes #45; that Dependabot PR is left open.Type of Change
Changes Made
overrides.markdown-it: 14.2.0 → 14.3.2 (stays on the 14.x line)overrides.fast-uri:>=3.1.5→ 4.2.1 (matches Dependabot chore(deps): bump fast-uri from 4.1.4 to 4.2.1 #45)package-lock.json:markdown-it14.2.0 → 14.3.2,fast-uri4.1.4 → 4.2.1Testing Done
bundle exec jekyll serveLocal
npm ci,npm test,npm run lint, andbundle exec jekyll buildrun after this pre-testing revision.Related Issues
Supersedes #45 (do not close until this merges).
Addresses Dependabot alerts #74 (
markdown-it< 14.3.1) and #72 (fast-uri< 4.1.5).Checklist
Additional Notes
Majors deliberately left untouched. Review should focus on override pins and lockfile integrity hashes.
Summary by CodeRabbit