Skip to content

build(deps): bump pymdown-extensions from 10.16.1 to 11.0.1 - #2072

Merged
Dav1dde merged 1 commit into
masterfrom
dependabot/uv/pymdown-extensions-11.0.1
Oct 2, 2026
Merged

Dav1dde merged 1 commit into
masterfrom
dependabot/uv/pymdown-extensions-11.0.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps pymdown-extensions from 10.16.1 to 11.0.1.

Release notes

Sourced from pymdown-extensions's releases.

11.0.1

  • FIX: BetterEm: Fix regex pattern inefficiencies.
  • FIX: Tilde: Fix regex pattern inefficiencies.
  • FIX: Caret: Fix regex pattern inefficiencies.
  • FIX: MagicLink: Fix regex pattern inefficiencies.

11.0

  • BREAK: B64: Restricts relative links to base_path by default. Can be disabled by setting new restrict_path option to False. The new root_path can be specified if paths are desired to be restricted to a different location separate base_path which is also used as a relative base for image paths.
  • NEW: Drop Python 3.9 support.
  • FIX: Tabbed: Fix issue where an empty title would cause an exception.

10.21.3

  • FIX: Fix regression that allows a snippet to be loaded outside of the base path using directory traversal when restrict_base_path is enabled (the default). Found by @​gistrec.

10.21. 2

10.21.2

  • FIX: Highlight: Latest Pygments versions cannot handle a "filename" for code block titles of None.

10.20.1

  • FIX: Quotes: Ensure the first class for callouts (the alert type) is always rendered lowercase.

10.21

  • NEW: Caption: Add support for specifying not only IDs but classes and arbitrary attributes. Initial work by @​joapuiib.
  • FIX: MagicLink: Fix a matching pattern for Bitbucket repo.

10.20

  • NEW: Quotes: New blockquotes extension added that uses a more modern approach when compared to Python Markdown's default. Quotes specifically will not group consecutive blockquotes together in the same lazy fashion that the default Python Markdown does which follows a more modern trend to how parsers these days handle block quotes.

    In addition, Quotes also provides an optional feature to enable specifying callouts/alerts in the style used by GitHub and Obsidian.

10.19.1

  • FIX: Arithmatex: Fix issue where block $$ math used inline within a paragraph could result in nested math parsing.

10.19

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Oct 1, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner October 1, 2026 10:52
@tobias-wilfert

Copy link
Copy Markdown
Member

@dependabot recreate

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 01123f4. Configure here.

Comment thread uv.lock
name = "babel"
version = "2.17.0"
source = { registry = "https://pypi.devinfra.sentry.io/simple" }
source = { registry = "https://sfw.security.sentry.io/pypi/simple" }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lockfile registry diverges from project index

Medium Severity

Every package in uv.lock now resolves from sfw.security.sentry.io instead of the default index declared in pyproject.toml (pypi.devinfra.sentry.io). uv sync --frozen downloads those lockfile URLs, so docs CI, pre-commit, and local devenv sync can fail if that host is unreachable, and the next uv lock will rewrite the file again.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 01123f4. Configure here.

@Dav1dde

Dav1dde commented Oct 2, 2026

Copy link
Copy Markdown
Member

@dependabot recreate

@dependabot
dependabot Bot force-pushed the dependabot/uv/pymdown-extensions-11.0.1 branch from 01123f4 to 8e31aae Compare October 2, 2026 12:31
tobias-wilfert added a commit that referenced this pull request Oct 2, 2026
Relay PR for reference: getsentry/relay#6460
seeing the same issue now here (#2072, #2073).
@Dav1dde

Dav1dde commented Oct 2, 2026

Copy link
Copy Markdown
Member

@dependabot recreate

@dependabot
dependabot Bot force-pushed the dependabot/uv/pymdown-extensions-11.0.1 branch from 8e31aae to 340d29f Compare October 2, 2026 12:35
Bumps [pymdown-extensions](https://github.com/facelessuser/pymdown-extensions) from 10.16.1 to 11.0.1.
- [Release notes](https://github.com/facelessuser/pymdown-extensions/releases)
- [Commits](facelessuser/pymdown-extensions@10.16.1...11.0.1)

---
updated-dependencies:
- dependency-name: pymdown-extensions
  dependency-version: 11.0.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/uv/pymdown-extensions-11.0.1 branch from 340d29f to 65e1091 Compare October 2, 2026 12:55
@Dav1dde
Dav1dde merged commit 5066f4c into master Oct 2, 2026
27 checks passed
@Dav1dde
Dav1dde deleted the dependabot/uv/pymdown-extensions-11.0.1 branch October 2, 2026 13:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants