Bump @eslint/markdown from 7.3.0 to 7.4.1 - #1661
Conversation
Bumps [@eslint/markdown](https://github.com/eslint/markdown) from 7.3.0 to 7.4.1. - [Release notes](https://github.com/eslint/markdown/releases) - [Changelog](https://github.com/eslint/markdown/blob/main/CHANGELOG.md) - [Commits](eslint/markdown@v7.3.0...v7.4.1) --- updated-dependencies: - dependency-name: "@eslint/markdown" dependency-version: 7.4.1 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
✓ Safe to upgradeI recommend merging this upgrade because it brings 3 new features and 1 bug fix to the ESLint Markdown linting tooling with no breaking changes detected. The package is used exclusively as a development dependency for linting code blocks in documentation files via the standard 'processor' configuration pattern. While a low-severity ReDoS vulnerability (CVE-2024-21539) is noted in the broader ecosystem, the @eslint/markdown maintainers have demonstrated proactive security maintenance by updating dependencies in version 7.0.0 to resolve vulnerabilities. The upgrade path from 7.3.0 to 7.4.1 is straightforward with no API changes required. What we checked
Dependency UsageThe @eslint/markdown package is used exclusively in the project's linting infrastructure to enable code quality checks for code blocks embedded within Markdown documentation files. This supports the project's development workflow by ensuring that example code in documentation maintains the same quality standards as production code. The dependency is configured centrally in the ESLint configuration file as a processor, demonstrating a standard development tooling pattern rather than runtime application functionality. Changes@eslint/markdown receives improved line ending handling across rules and utilities to properly support CR and CRLF line endings per CommonMark specification. The update also adds new location mapping methods (
View 6 more changes
References (5)[1]: @eslint/markdown declared as devDependency at version 7.4.1, confirming this is development tooling only eslint-plugin-top/package.json Line 35 in f97cc39 [2]: Package imported and used in standard ESLint configuration eslint-plugin-top/eslint.config.mjs Line 7 in f97cc39 [3]: Uses standard 'processor' configuration pattern which remains stable across versions eslint-plugin-top/eslint.config.mjs Line 13 in f97cc39 [4]: Official ESLint announcement confirms @eslint/markdown is the officially supported package for Markdown linting, replacing the deprecated eslint-plugin-markdown (source link) [5]: Version 7.0.0 updated plugin-kit dependency to resolve security vulnerabilities, demonstrating proactive security maintenance by the package maintainers (source link) fossabot analyzed this PR using dependency research. |
Bumps @eslint/markdown from 7.3.0 to 7.4.1.
Release notes
Sourced from
@eslint/markdown's releases.Changelog
Sourced from
@eslint/markdown's changelog.Commits
e354f98chore: release 7.4.1 🚀 (#556)20e88fefix: handle CR in rules to follow CommonMark spec (#493)0d01b19docs: add migration docs (#559)6d1bd73ci: centralizeci-bun.yml(#563)e7c5868ci: add Node.js 25 toci.ymland fix Bun CI (#562)868153bci: resolve failure in therelease-please.ymlworkflow (#558)c95c017docs: Update README sponsors6c88ae1ci: Switch to trusted publishing (#557)d1ad828fix: handle CR inMarkdownSourceCodeand Front Matter util (#554)8992a4drefactor: replacefindOffsetshelper with native methods (#536)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)