Skip to content

Update mistune requirement from >=3.0.0 to >=3.3.4 - #12

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/mistune-gte-3.3.4
Open

Update mistune requirement from >=3.0.0 to >=3.3.4#12
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/mistune-gte-3.3.4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 2, 2026

Copy link
Copy Markdown

Updates the requirements on mistune to permit the latest version.

Release notes

Sourced from mistune's releases.

v3.3.4

   🐞 Bug Fixes

   🏎 Performance

    View changes on GitHub
Changelog

Sourced from mistune's changelog.

Version 3.3.4

Released on Jul 22, 2026

  • Harden inline parsing against deeply nested and adversarial link, image, emphasis, formatting, math, and reference inputs.
  • Improve performance for repeated link suffixes, dense emphasis, unclosed formatting markers, inline spoilers, and adjacent ruby tokens.
  • Refactor the inline parser into dedicated emphasis and link modules.
  • Escape literal */_ emphasis markers in the Markdown renderer so round-tripping escaped text does not re-introduce emphasis.

Version 3.3.3

Released on Jul 9, 2026

  • Limit deeply nested emphasis and image parsing to avoid RecursionError.
  • Fix repeated link suffix and unclosed formatting marker performance issues.
  • Fix unclosed inline spoiler performance issues.
  • Avoid recursive parsing for adjacent ruby tokens.
  • Speed up footnote reference indexing.

Version 3.3.2

Released on Jun 23, 2026

  • Fix Python 3.8 import compatibility in the inline parser.
  • Fix mypy compatibility for list parsing on Python 3.8 and 3.9+.

Version 3.3.1

Released on Jun 22, 2026

  • Fix abbr plugin compatibility with escaped inline text.
  • Normalize included Markdown line endings before parsing directives.

Version 3.3.0

Released on Jun 21, 2026

  • Improve CommonMark compatibility and parser performance.
  • Add command line entrypoint with UTF-8 output.
  • Support display and backtick math.
  • Render plugin list and table nodes in Markdown renderer.
  • Escape leading block markers in Markdown renderer.

... (truncated)

Commits
  • 69ec2b8 chore: release 3.3.4
  • 234aa25 test: more deadline for pypy
  • b77ee58 fix: prevent deep alt parsing
  • 66b2171 refactor: expose entity boundary helper
  • 30ef44b refactor: move link token construction
  • 3066209 refactor: require explicit emphasis depth
  • 0396492 refactor: split inline parser modules
  • 80b3e85 refactor: isolate inline parser state bounds
  • 7b0194c test: cover inline performance edge cases
  • b4dd328 perf: optimize inline edge-case parsing
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Updates the requirements on [mistune](https://github.com/lepture/mistune) to permit the latest version.
- [Release notes](https://github.com/lepture/mistune/releases)
- [Changelog](https://github.com/lepture/mistune/blob/main/docs/changes.rst)
- [Commits](lepture/mistune@v3.0.0...v3.3.4)

---
updated-dependencies:
- dependency-name: mistune
  dependency-version: 3.3.4
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Aug 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants