ReviewOS

also looking at this

stacks/bunpress

fix(deps): update vulnerable dependencies

#80
Open github-actions[bot] wants to merge buddy-bot/update-security-updates into main
1 file +1 -1

This PR contains the following updates:

🔒 Security Advisories

This PR resolves 1 known vulnerability across 1 package.

PackageSeverityAdvisoryFixed inSummary
markdown-it🟡 ModerateGHSA-6v5v-wf23-fmfq (CVE-2026-48988)14.2.0markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations

npm

PackageChangeAgeAdoptionPassingConfidence
markdown-it (source)14.1.1 -> 15.0.1ageadoptionpassingconfidence

Release Notes

markdown-it/markdown-it (markdown-it)

14.1.1 -> 15.0.1

Compare Source

Markdown-it - modern pluggable markdown parser.

📖 View Release Notes

🔗 View Changelog

Release Notes

Changelog


📊 Package Statistics

  • markdown-it: 29,697,659 weekly downloads

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Buddy 🤖

{"schemaVersion":1,"updates":[{"name":"markdown-it","current":"14.1.1","target":"15.0.1","type":"major","file":"benchmark/package.json","dependencyType":"dependencies"}],"group":"Security Updates","generatedAt":"2026-08-28T03:56:38.150Z"} -->

1 changed file on the files tab, with 0 review threads.