-
Notifications
You must be signed in to change notification settings - Fork 5
build(deps): bump marked from 15.0.12 to 18.0.11 in /client - #2253
build(deps): bump marked from 15.0.12 to 18.0.11 in /client #2253dependabot[bot] wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks good, straightforward dependency bump.
What was reviewed: confirmed the diff is limited to client/package.json (marked ^15.0.8 → ^18.0.10) and the corresponding client/package-lock.json lockfile update; no application source, tests, or config files are touched. Checked marked's usage isn't wrapped by custom renderer overrides that would be sensitive to the major version bump within this diff itself (none present in the changed files).
Extended reasoning...
Overview
The PR is a Dependabot-generated dependency bump limited to two files: client/package.json (bumping marked from ^15.0.8 to ^18.0.10) and client/package-lock.json (the corresponding lockfile resolution, tarball URL, integrity hash, and updated engines.node requirement for the marked package). No application source code, route handlers, authentication logic, or configuration schemas are touched.
Security risks
None identified. The change does not touch authentication, authorization, secret handling, or any server-side code path. marked is a client-side markdown rendering library; a supply-chain risk exists in principle with any dependency bump, but this is standard practice via Dependabot with lockfile integrity hashes updated correctly, and is not something this automated review can meaningfully further audit beyond checking the lockfile matches the intended version (which it does).
Level of scrutiny
This warrants low scrutiny: it is a mechanical, single-dependency version bump with an accompanying lockfile update, no other files changed, and no CODEOWNERS conflict for client/package.json. The major version jump (15→18) could in theory introduce markdown-rendering behavior changes (e.g., GFM handling, emphasis parsing edge cases per the release notes), but no application code depends on marked internals or renderer customization in this diff, so a full behavioral regression test is out of scope for this review and would fall to normal CI/QA rather than static code review.
Other factors
The Node engine requirement change (>= 18 to >= 20) is worth noting but is a transitive package-level requirement in the lockfile metadata, not a change to this repo's own engines field, and does not affect the ability to install/build unless the CI/build environment runs Node < 20, which is outside the scope of this diff. No test or config changes were needed for a pure dependency bump per repository conventions.
Bumps [marked](https://github.com/markedjs/marked) from 15.0.12 to 18.0.11. - [Release notes](https://github.com/markedjs/marked/releases) - [Commits](markedjs/marked@v15.0.12...v18.0.11) --- updated-dependencies: - dependency-name: marked dependency-version: 18.0.10 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
c3f71d1 to
82fabed
Compare
Superseded by #2269.
Uh oh!
There was an error while loading. Please reload this page.
Bumps marked from 15.0.12 to 18.0.11.
Release notes
Sourced from marked's releases.
... (truncated)
Commits
53cb13fchore(release): 18.0.11 [skip ci]0c6b2a6docs: add adaptable bullet point (#4058)c430a64chore(deps-dev): bump eslint from 10.8.1 to 10.9.0 (#4069)b699db3fix: keep emphasis in the text of a rejected reference link (#4059)0653c24fix: inlineTokens rebuilds the reflink-mask preamble per call (#4040)e250e31fix: do not nest a link inside a link (#4051)8698d35chore(release): 18.0.10 [skip ci]58367a5chore(deps-dev): bump eslint from 10.8.0 to 10.8.1 (#4055)a426c4dchore(deps-dev): bump esbuild from 0.28.1 to 0.28.2 (#4056)a5cf277chore(deps-dev): bump highlight.js from 11.11.1 to 11.12.0 (#4057)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for marked since your current version.