Skip to content

build(deps): bump linkify-it and @wordpress/scripts - #319

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-0eb0183e37
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-0eb0183e37

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Bumps linkify-it to 5.0.2 and updates ancestor dependency @wordpress/scripts. These dependencies need to be updated together.

Updates linkify-it from 3.0.3 to 5.0.2

Changelog

Sourced from linkify-it's changelog.

5.0.2 / 2026-07-02

  • Fixed DoS in mailto: links (restrict user name to 64 chars).
  • Restricted user/pass part length in links.

5.0.1 / 2026-05-23

  • Fixed DoS in fuzzy links/emails search.
  • Reworked search logic - check each pattern separate, use g regexes instead of slice.
  • Removed internal cache - useless overcomplication.

5.0.0 / 2023-12-01

  • Rewrite to ESM.

4.0.1 / 2022-05-02

  • Fix http:// incorrectly returned as a link by matchStart.

4.0.0 / 2022-04-22

  • Add matchAtStart method to match full URLs at the start of the string.
  • Fixed paired symbols ((), {}, "", etc.) after punctuation.
  • --- option now affects parsing of emails (e.g. user@example.com---)
Commits

Updates @wordpress/scripts from 35.0.0 to 36.0.0

Changelog

Sourced from @​wordpress/scripts's changelog.

36.0.0 (2026-09-23)

Breaking Changes

  • Switch test-unit-js to consumer-installed Vitest 5 and Vite 7/8 at the 36.0.0 boundary. Run once by default, discover consumer Vitest/Vite config, and use Vitest lint defaults for test/spec files. Keep test-unit-jest as a maintenance-only adapter for consumer-installed Jest, with no scheduled removal. Remove the bundled Jest dependencies, preset config, Babel transformer, and GitHub Actions reporter. Retire the Jest preset and console package source; published versions remain available. Jest projects must install their own dependencies and configure the published preset if needed. See the migration guide. (#82843).

  • Require Node.js ^22.22.2 || ^24.15.0 || >=26.0.0 and update the bundled markdownlint-cli from ^0.31.1 to ^0.49.1, which moves markdownlint from 0.25 to 0.41. lint-md-docs now runs the rules added since then (MD051 through MD060) by default, so projects may see new reports. The header rule aliases (for example header-increment) no longer work in configuration files; use the heading names (#81917).

  • lint-style: Use stylelint's resolveConfig for config detection instead of a static extension list, supporting all current and future config file formats without manual maintenance overhead. Note that resolveConfig also searches ancestor directories and the global config directory (~/.config/stylelint), so a project with no local config may now pick up an unrelated config found there instead of the bundled default (#79280).

Enhancements

  • check-engines: Check only the tools listed in engines, instead of always passing --node and --npm. Without an engines field in the project, it now checks only the Node.js version (#83326).
  • lint-md-docs: Detect .markdownlint.jsonc so the bundled default config is not used when one is present (#81917).
  • format: Format .cjs and .mjs files when expanding a directory (#82731).
  • format: Format .cts and .mts files when expanding a directory (#83071).
  • The default ESLint config now lints .jsx, .ts, .tsx, .mts and .cts files, which ESLint's own file discovery skips (#83071).
  • build and start: Discover .cjs, .cts and .mts entry points, resolve them from extensionless imports, and transpile .cjs and .cts modules (#83071).
  • The bundled wp-prettier dependency has been upgraded from 3.0.3 to 3.9.6 (#82731).

Bug Fixes

  • Update the bundled webpack to ^5.111.0, which fixes a code-generation regression in webpack 5.110.3 that can make production bundles fail at startup (#82698).
Commits
  • 56d8058 chore(release): publish
  • 9ff3f0e Update changelog files
  • f905a64 Merge changes published in the Gutenberg plugin "release/24.1" branch
  • See full diff in compare view

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 24, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/multi-0eb0183e37 branch from 15cb0f3 to 91aeffa Compare October 1, 2026 16:02
Bumps [linkify-it](https://github.com/markdown-it/linkify-it) to 5.0.2 and updates ancestor dependency [@wordpress/scripts](https://github.com/WordPress/gutenberg/tree/HEAD/packages/scripts). These dependencies need to be updated together.


Updates `linkify-it` from 3.0.3 to 5.0.2
- [Changelog](https://github.com/markdown-it/linkify-it/blob/master/CHANGELOG.md)
- [Commits](markdown-it/linkify-it@3.0.3...5.0.2)

Updates `@wordpress/scripts` from 35.0.0 to 36.0.0
- [Release notes](https://github.com/WordPress/gutenberg/releases)
- [Changelog](https://github.com/WordPress/gutenberg/blob/trunk/packages/scripts/CHANGELOG.md)
- [Commits](https://github.com/WordPress/gutenberg/commits/@wordpress/scripts@36.0.0/packages/scripts)

---
updated-dependencies:
- dependency-name: "@wordpress/scripts"
  dependency-version: 36.0.0
  dependency-type: direct:development
- dependency-name: linkify-it
  dependency-version: 5.0.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): bump linkify-it and @wordpress/scripts build(deps): bump linkify-it and @wordpress/scripts Oct 5, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/multi-0eb0183e37 branch from 91aeffa to dde1485 Compare October 5, 2026 07:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants