Skip to content

build(deps): bump markdown-it and @quasar/quasar-app-extension-qmarkdown in /opal-ui - #4156

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/opal-ui/multi-af50133f44
Open

build(deps): bump markdown-it and @quasar/quasar-app-extension-qmarkdown in /opal-ui#4156
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/opal-ui/multi-af50133f44

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 16, 2026

Copy link
Copy Markdown
Contributor

Bumps markdown-it to 14.2.0 and updates ancestor dependency @quasar/quasar-app-extension-qmarkdown. These dependencies need to be updated together.

Updates markdown-it from 12.3.2 to 14.2.0

Changelog

Sourced from markdown-it's changelog.

[14.2.0] - 2026-05-24

Added

  • isPunctCharCode to utilities.

Fixed

  • Don't end HTML comment blocks on a blank line, #1155.
  • Properly recognize astral chars (surrogates) in delimiter scans for emphasis-like markers, #1072. Big thanks to @​tats-u for his global efforts with improving CJK support.
  • Preserve unicode whitespaces when trimm headings/paragraphs, #1074.
  • More strict entities decode to avoid false positives ;, #1096.
  • Restore block parser state on fail in lheading rule, #1131.

Security

  • Fixed poor smartquotes perfomance on > 70k quotes in single block
  • Bumped linkify-it to 5.0.1 with fixed potential perfomance issues.

[14.1.1] - 2026-01-11

Security

  • Fixed regression from v13 in linkify inline rule. Specific patterns could cause high CPU use. Thanks to @​ltduc147 for report.

[14.1.0] - 2024-03-19

Changed

  • Updated CM spec compatibility to 0.31.2, #1009.

Fixed

  • Fixed quadratic complexity when parsing references, #996.
  • Fixed quadratic output size with pathological user input in tables, #1000.

[14.0.0] - 2023-12-08

Changed

  • Drop ancient browsers support (use .fromCodePoint and other features).
  • Rewrite to ESM (including all plugins/deps). CJS fallback still available. No signatures changed, except markdown-it-emoji plugin.
  • Dropped dist/ folder from repo, build on package publish.
  • Set punicode.js as external dependency.

Fixed

  • Html tokens inside img alt are now rendered as their original text, #896.
  • Hardbreaks inside img alt are now rendered as newlines.

[13.0.2] - 2023-09-26

Security

  • Fixed crash/infinite loop caused by linkify inline rule, #957.

... (truncated)

Commits

Updates @quasar/quasar-app-extension-qmarkdown from 2.0.5 to 3.0.0-rc.0

Release notes

Sourced from @​quasar/quasar-app-extension-qmarkdown's releases.

QMarkdown v3.0.0-rc.0

Target branch: v3-beta

QMarkdown v3.0.0-rc.0

Summary

This is the first QMarkdown v3 release candidate and moves the v3 line onto the latest channel for release-candidate testing. It aligns QMarkdown with Quasar 2.20.0, @quasar/app-vite 3.0.0-rc.1, and the latest Q-Press/md-plugins RC docs tooling.

Compatibility

  • Node.js: >=22.13
  • pnpm: >=11.5.0
  • Quasar: ^2.20.0
  • Quasar app-vite target: @​quasar/app-vite >=3.0.0-rc.1
  • Q-Press/md-plugins target: 0.1.0-rc.2
  • npm dist-tag for this line: latest

Highlights

  • Promotes QMarkdown v3 from beta to release candidate.
  • Updates the docs workspace for Quasar app-vite RC and Q-Press/md-plugins RC releases.
  • Adds Q-Press SSG docs build support and keeps docs build-only packages in devDependencies.
  • Refreshes docs polish, including the landing page, footer/support links, README structure, and social preview metadata.
  • Fixes docs rendering issues around release-note links and API description Markdown.
  • Renames reserved docs example components to avoid framework component-name warnings.
  • Updates installation and upgrade docs for latest-channel installs instead of beta-channel installs.

Installation

For Quasar projects using the app extension:

quasar ext add @quasar/qmarkdown

For direct package installs:

pnpm add @quasar/quasar-ui-qmarkdown
# or
bun add @quasar/quasar-ui-qmarkdown
# or
yarn add @quasar/quasar-ui-qmarkdown
# or
npm install @quasar/quasar-ui-qmarkdown

Donations

... (truncated)

Commits
  • 56324d0 chore: prepare QMarkdown rc.0 release
  • be6cc93 chore: update md-plugins to rc.2
  • ab562ee chore: update md-plugins to rc.1
  • 7e5f16c chore: move docs build deps to dev dependencies
  • 792e189 chore: keep vite ssg plugin as dev dependency
  • dc7f898 chore: update md-plugins to rc.0
  • ca828ec docs: standardize README support section
  • fea6cea docs: standardize README structure section
  • fb9adad docs: clarify Q-Press docs site wording
  • 7d9ddda chore: update Quasar RC dependencies
  • Additional commits viewable in compare view

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [markdown-it](https://github.com/markdown-it/markdown-it) to 14.2.0 and updates ancestor dependency [@quasar/quasar-app-extension-qmarkdown](https://github.com/quasarframework/quasar-ui-qmarkdown). These dependencies need to be updated together.


Updates `markdown-it` from 12.3.2 to 14.2.0
- [Changelog](https://github.com/markdown-it/markdown-it/blob/master/CHANGELOG.md)
- [Commits](markdown-it/markdown-it@12.3.2...14.2.0)

Updates `@quasar/quasar-app-extension-qmarkdown` from 2.0.5 to 3.0.0-rc.0
- [Release notes](https://github.com/quasarframework/quasar-ui-qmarkdown/releases)
- [Commits](quasarframework/quasar-ui-qmarkdown@v2.0.5...v3.0.0-rc.0)

---
updated-dependencies:
- dependency-name: markdown-it
  dependency-version: 14.2.0
  dependency-type: indirect
- dependency-name: "@quasar/quasar-app-extension-qmarkdown"
  dependency-version: 3.0.0-rc.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Jun 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants