Bump mistune from 0.8.4 to 2.0.4
Bumps mistune from 0.8.4 to 2.0.4.
Release notes
Sourced from mistune's releases.
Version 2.0.2
Fix
escape_urlvia lepture/mistune#295Version 2.0.1
Fix XSS for image link syntax.
Version 2.0.0
First release of Mistune v2.
Version 2.0.0 RC1
In this release, we have a Security Fix for harmful links.
Version 2.0.0 Alpha 1
This is the first release of v2. An alpha version for users to have a preview of the new mistune.
Changelog
Sourced from mistune's changelog.
Changelog
Here is the full history of mistune v2.
Version 2.0.4
Released on Jul 15, 2022
- Fix
urlplugin in<a>tag- Fix
*formattingVersion 2.0.3
Released on Jun 27, 2022
- Fix
tableplugin- Security fix for CVE-2022-34749
Version 2.0.2
Released on Jan 14, 2022Fix
escape_urlVersion 2.0.1
Released on Dec 30, 2021
XSS fix for image link syntax.
Version 2.0.0
Released on Dec 5, 2021This is the first non-alpha release of mistune v2.
Version 2.0.0rc1
Released on Feb 16, 2021
Version 2.0.0a6
</tr></table>
... (truncated)
Commits
b92a5feVersion bump 2.0.498a1c0aFix url plugin render, #308979d6d3Fix * parsing, #312f857f04Trigger GitHub dependency graph3f422f1Version bump 2.0.3a6d4321Fix asteris emphasis regex CVE-2022-347495638e46Merge pull request #307 from jieter/patch-10eba471Fix typo in guide.rst61e9337Fix table plugin76dec68Add documentation for renderer heading when TOC enabled- Additional commits viewable in compare view
You can trigger a rebase of this PR by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
@dependabot recreate
nbconvert 7 will add support for mistune 2
Looks like mistune is up-to-date now, so this is no longer needed.