Skip to content

npm(deps): bump markdown-it and @wordpress/scripts - #1057

Closed
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/multi-a7c83e8656
Closed

dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/multi-a7c83e8656

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Bumps markdown-it to 14.3.2 and updates ancestor dependency @wordpress/scripts. These dependencies need to be updated together.

Updates markdown-it from 12.3.2 to 14.3.2

Changelog

Sourced from markdown-it's changelog.

[14.3.2] - 2026-09-12

Security

  • Backported 15.0.2 fixes.

[14.3.1] - 2026-08-27

Security

  • Backported 15.0.1 fixes.

[14.3.0] - 2026-07-02

Changed

  • Reworked build pipeline & tools.
  • Added source maps.
  • Bumped linkify-it to 5.0.2.

Fixed

  • Preserve backslash-space hard line breaks, matching CommonMark 6.7, #1185.

[14.2.0] - 2026-05-24

Added

  • isPunctCharCode to utilities.

Fixed

  • Don't end HTML comment blocks on a blank line, #1155.
  • Properly recognize astral chars (surrogates) in delimiter scans for emphasis-like markers, #1072. Big thanks to @​tats-u for his global efforts with improving CJK support.
  • Preserve unicode whitespaces when trimm headings/paragraphs, #1074.
  • More strict entities decode to avoid false positives ;, #1096.
  • Restore block parser state on fail in lheading rule, #1131.

Security

  • Fixed poor smartquotes perfomance on > 70k quotes in single block
  • Bumped linkify-it to 5.0.1 with fixed potential perfomance issues.

[14.1.1] - 2026-01-11

Security

  • Fixed regression from v13 in linkify inline rule. Specific patterns could cause high CPU use. Thanks to @​ltduc147 for report.

[14.1.0] - 2024-03-19

Changed

  • Updated CM spec compatibility to 0.31.2, #1009.

... (truncated)

Commits
  • efb9993 14.3.2 released
  • daf5a3c Backported 15.0.2 fixes
  • a855f10 14.3.1 released
  • ad70f6b Backported 15.0.1 fixes
  • b407f3b Ignore generated API docs in lint
  • bf025ad Prepare package.json for v14 backports
  • 2d9bbea fix: recognize lowercase declarations as HTML blocks (CommonMark 4.6) (#1189)
  • a311cfb fix: keep literal backslash before space in link destination (CommonMark 6.3)...
  • ff0ee08 14.3.0 released
  • 52e2749 Bump linkify-it / vite deps
  • Additional commits viewable in compare view

Updates @wordpress/scripts from 32.5.1 to 36.1.0

Changelog

Sourced from @​wordpress/scripts's changelog.

36.1.0 (2026-10-07)

Enhancements

  • lint-js: Allow unit-test titles passed through variables (#83995).

Bug Fixes

  • Add the stylelint-scss dependency, a peer of @wordpress/stylelint-config (#83765).
  • build, start and lint-pkg-json: Resolve the default browserslist and npm-package-json-lint configs when dependencies are not hoisted to the project root (npm install-strategy=linked, pnpm). lint-pkg-json now defaults to config/npmpackagejsonlint.js; config/npmpackagejsonlint.json stays for projects that reference it (#83902).
  • lint-js, lint-style and lint-md-docs: a file passed right after --fix is now treated as a file instead of that flag's value, so only the listed files get processed. Same for --require-pragma in format (#83521).

36.0.0 (2026-09-23)

Breaking Changes

  • Switch test-unit-js to consumer-installed Vitest 5 and Vite 7/8 at the 36.0.0 boundary. Run once by default, discover consumer Vitest/Vite config, and use Vitest lint defaults for test/spec files. Keep test-unit-jest as a maintenance-only adapter for consumer-installed Jest, with no scheduled removal. Remove the bundled Jest dependencies, preset config, Babel transformer, and GitHub Actions reporter. Retire the Jest preset and console package source; published versions remain available. Jest projects must install their own dependencies and configure the published preset if needed. See the migration guide. (#82843).

  • Require Node.js ^22.22.2 || ^24.15.0 || >=26.0.0 and update the bundled markdownlint-cli from ^0.31.1 to ^0.49.1, which moves markdownlint from 0.25 to 0.41. lint-md-docs now runs the rules added since then (MD051 through MD060) by default, so projects may see new reports. The header rule aliases (for example header-increment) no longer work in configuration files; use the heading names (#81917).

  • lint-style: Use stylelint's resolveConfig for config detection instead of a static extension list, supporting all current and future config file formats without manual maintenance overhead. Note that resolveConfig also searches ancestor directories and the global config directory (~/.config/stylelint), so a project with no local config may now pick up an unrelated config found there instead of the bundled default (#79280).

Enhancements

  • check-engines: Check only the tools listed in engines, instead of always passing --node and --npm. Without an engines field in the project, it now checks only the Node.js version (#83326).
  • lint-md-docs: Detect .markdownlint.jsonc so the bundled default config is not used when one is present (#81917).
  • format: Format .cjs and .mjs files when expanding a directory (#82731).
  • format: Format .cts and .mts files when expanding a directory (#83071).
  • The default ESLint config now lints .jsx, .ts, .tsx, .mts and .cts files, which ESLint's own file discovery skips (#83071).
  • build and start: Discover .cjs, .cts and .mts entry points, resolve them from extensionless imports, and transpile .cjs and .cts modules (#83071).
  • The bundled wp-prettier dependency has been upgraded from 3.0.3 to 3.9.6 (#82731).

Bug Fixes

  • Update the bundled webpack to ^5.111.0, which fixes a code-generation regression in webpack 5.110.3 that can make production bundles fail at startup (#82698).

35.0.0 (2026-09-10)

Breaking Changes

  • Require Node.js ^20.19.0 || >=22.13.0 and upgrade the bundled Stylelint to ^17.14.1 (#80738).

Bug Fixes

  • test-playwright: Install browsers with the bundled @playwright/test CLI, so they match the Playwright that runs the tests. A bare npx playwright could resolve another version, or download one (#82331).
  • build: Strip JavaScript and TypeScript source extensions from legacy positional entry names so generated output uses names such as index.js instead of index.tsx.js or index.jsx.js (#80990).

Enhancements

  • Include .jsx unit tests in the default lint configuration (#80990).

... (truncated)

Commits
  • 12441e2 chore(release): publish
  • 36c194f Update changelog files
  • 7b99cae Merge changes published in the Gutenberg plugin "release/24.2" branch
  • 56d8058 chore(release): publish
  • 9ff3f0e Update changelog files
  • f905a64 Merge changes published in the Gutenberg plugin "release/24.1" branch
  • 485f42a chore(release): publish
  • c89dd70 Update changelog files
  • a55a0d7 Merge changes published in the Gutenberg plugin "release/24.0" branch
  • d06b010 chore(release): publish (#82084)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added the dependencies Dependency updates label Sep 29, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 29, 2026 18:00
@dependabot dependabot Bot added the dependencies Dependency updates label Sep 29, 2026
Bumps [markdown-it](https://github.com/markdown-it/markdown-it) to 14.3.2 and updates ancestor dependency [@wordpress/scripts](https://github.com/WordPress/gutenberg/tree/HEAD/packages/scripts). These dependencies need to be updated together.


Updates `markdown-it` from 12.3.2 to 14.3.2
- [Changelog](https://github.com/markdown-it/markdown-it/blob/14.3.2/CHANGELOG.md)
- [Commits](markdown-it/markdown-it@12.3.2...14.3.2)

Updates `@wordpress/scripts` from 32.5.1 to 36.1.0
- [Release notes](https://github.com/WordPress/gutenberg/releases)
- [Changelog](https://github.com/WordPress/gutenberg/blob/trunk/packages/scripts/CHANGELOG.md)
- [Commits](https://github.com/WordPress/gutenberg/commits/@wordpress/scripts@36.1.0/packages/scripts)

---
updated-dependencies:
- dependency-name: "@wordpress/scripts"
  dependency-version: 36.0.0
  dependency-type: direct:development
- dependency-name: markdown-it
  dependency-version: 14.3.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/multi-a7c83e8656 branch from e64b300 to 4af215d Compare October 10, 2026 15:56
@GaryJones

Copy link
Copy Markdown
Contributor

Superseded by #1067, which upgrades @wordpress/scripts to 36 (moving the JS unit tests to Vitest) and folds in these @wordpress/* bumps.

@GaryJones GaryJones closed this Oct 10, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 10, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/multi-a7c83e8656 branch October 10, 2026 16:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency updates

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant