Skip to content

chore(deps): update dependency markdown-it to v14.1.1 [security] (stable33)#8267

Open
renovate[bot] wants to merge 1 commit intostable33from
renovate/stable33-npm-markdown-it-vulnerability
Open

chore(deps): update dependency markdown-it to v14.1.1 [security] (stable33)#8267
renovate[bot] wants to merge 1 commit intostable33from
renovate/stable33-npm-markdown-it-vulnerability

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Feb 13, 2026

This PR contains the following updates:

Package Change Age Confidence
markdown-it 14.1.014.1.1 age confidence

GitHub Vulnerability Alerts

CVE-2026-2327

Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the use of the regex /*+$/ in the linkify function. An attacker can supply a long sequence of * characters followed by a non-matching character, which triggers excessive backtracking and may lead to a denial-of-service condition.


Release Notes

markdown-it/markdown-it (markdown-it)

v14.1.1

Compare Source

Security
  • Fixed regression from v13 in linkify inline rule. Specific patterns could
    cause high CPU use. Thanks to @​ltduc147 for report.

Configuration

📅 Schedule: Branch creation - "" in timezone Europe/Berlin, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the dependencies Pull requests that update a dependency file label Feb 13, 2026
@github-actions github-actions bot enabled auto-merge February 13, 2026 20:09
@codecov
Copy link

codecov bot commented Feb 13, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@renovate renovate bot changed the title chore(deps): update dependency markdown-it to v14.1.1 [security] (stable33) chore(deps): update dependency markdown-it to v14.1.1 [security] (stable33) - autoclosed Feb 14, 2026
@renovate renovate bot closed this Feb 14, 2026
auto-merge was automatically disabled February 14, 2026 00:29

Pull request was closed

@renovate renovate bot deleted the renovate/stable33-npm-markdown-it-vulnerability branch February 14, 2026 00:29
@renovate renovate bot changed the title chore(deps): update dependency markdown-it to v14.1.1 [security] (stable33) - autoclosed chore(deps): update dependency markdown-it to v14.1.1 [security] (stable33) Feb 14, 2026
@renovate renovate bot reopened this Feb 14, 2026
@renovate renovate bot force-pushed the renovate/stable33-npm-markdown-it-vulnerability branch 2 times, most recently from c0061f3 to 9837201 Compare February 14, 2026 16:25
@github-actions github-actions bot enabled auto-merge February 14, 2026 16:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants