Skip to content

chore(deps): bump github.com/yuin/goldmark from 1.8.5 to 1.8.6 - #14378

Merged
williammartin merged 1 commit into
trunkfrom
dependabot/go_modules/github.com/yuin/goldmark-1.8.6
Sep 10, 2026
Merged

williammartin merged 1 commit into
trunkfrom
dependabot/go_modules/github.com/yuin/goldmark-1.8.6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 7, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/yuin/goldmark from 1.8.5 to 1.8.6.

Release notes

Sourced from github.com/yuin/goldmark's releases.

v1.8.6

  • fix(extension): fix #571
  • Merge pull request #569
Commits
  • e3e8a53 Merge pull request #569 from binggao1230/fix-urlescape-percent-hex-guard
  • 8701257 Merge pull request #570 from BananaJeanss/patch-1
  • c52d4b3 fix(extension): fix #571
  • 37b454c Remove Go Report Card badge
  • 72f79b9 fix: URLEscape dropped a truncated utf8 leading byte
  • 67a4ecf fix: URLEscape validated the same hex digit twice
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/yuin/goldmark](https://github.com/yuin/goldmark) from 1.8.5 to 1.8.6.
- [Release notes](https://github.com/yuin/goldmark/releases)
- [Commits](yuin/goldmark@v1.8.5...v1.8.6)

---
updated-dependencies:
- dependency-name: github.com/yuin/goldmark
  dependency-version: 1.8.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Sep 7, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 7, 2026 14:03
@dependabot
dependabot Bot requested a review from sergiou87 September 7, 2026 14:03
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Sep 7, 2026
@cli-triage

cli-triage Bot commented Sep 7, 2026

Copy link
Copy Markdown

Recommendation: Merge, Confidence: High

The upstream diff is exactly two bug fixes to util/util.go's URLEscape (fixing a truncated-UTF8-leading-byte drop and a duplicate hex-digit validation), both in e3e8a53 and its parent 72f79b9, consistent with the claimed patch bump. goldmark is a direct, compiled-in dependency used by this repo (internal/attachments/references.go) for parsing embedded links, but the changed function only affects malformed/edge-case UTF-8 URL escaping, which this repo's usage does not exercise in any special way, so there's no material coverage gap to call out.

Assessed at head commit 5a7c407d1098541be9ee226fc93d4bbe56da7304.

Generated by Dependabot PR Triage (skills-driven) · copilot · auto · 41.1 AIC · ⌖ 2.58 AIC · ⊞ 8.7K · ◷

@williammartin
williammartin merged commit 66ae8d8 into trunk Sep 10, 2026
42 checks passed
@williammartin
williammartin deleted the dependabot/go_modules/github.com/yuin/goldmark-1.8.6 branch September 10, 2026 13:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant