Skip to content

NO-JIRA: build(deps): bump pymdown-extensions from 10.21.3 to 11.0 in /docs - #9154

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/docs/pymdown-extensions-11.0
Closed

NO-JIRA: build(deps): bump pymdown-extensions from 10.21.3 to 11.0 in /docs#9154
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/docs/pymdown-extensions-11.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 29, 2026

Copy link
Copy Markdown
Contributor

Bumps pymdown-extensions from 10.21.3 to 11.0.

Release notes

Sourced from pymdown-extensions's releases.

11.0

  • BREAK: B64: Restricts relative links to base_path by default. Can be disabled by setting new restrict_path option to False. The new root_path can be specified if paths are desired to be restricted to a different location separate base_path which is also used as a relative base for image paths.
  • NEW: Drop Python 3.9 support.
  • FIX: Tabbed: Fix issue where an empty title would cause an exception.
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Summary by CodeRabbit

  • Documentation
    • Updated the documentation build tooling to use the latest pymdown-extensions release.

Bumps [pymdown-extensions](https://github.com/facelessuser/pymdown-extensions) from 10.21.3 to 11.0.
- [Release notes](https://github.com/facelessuser/pymdown-extensions/releases)
- [Commits](facelessuser/pymdown-extensions@10.21.3...11.0)

---
updated-dependencies:
- dependency-name: pymdown-extensions
  dependency-version: '11.0'
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Jul 29, 2026
@openshift-merge-bot

Copy link
Copy Markdown
Contributor

Pipeline controller notification
This repo is configured to use the pipeline controller. Second-stage tests will be triggered either automatically or after lgtm label is added, depending on the repository configuration. The pipeline controller will automatically detect which contexts are required and will utilize /test Prow commands to trigger the second stage.

For optional jobs, comment /test ? to see a list of all defined jobs. To trigger manually all jobs from second stage use /pipeline required command.

This repository is configured in: LGTM mode

@coderabbitai

coderabbitai Bot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

Updated pymdown-extensions in the documentation requirements from version 10.21.3 to 11.0, along with its SHA256 hashes.

Suggested reviewers: mgencur

🚥 Pre-merge checks | ✅ 11
✅ Passed checks (11 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Stable And Deterministic Test Names ✅ Passed Only docs/requirements.txt changed; no Go/Ginkgo test titles were added or modified.
Test Structure And Quality ✅ Passed PR only bumps docs/requirements.txt; no Ginkgo test code changed, so the test-structure check is not applicable.
Topology-Aware Scheduling Compatibility ✅ Passed PASS: The PR only updates docs/requirements.txt (pymdown-extensions); no deployment manifests, controllers, or scheduling code were modified.
Ipv6 And Disconnected Network Test Compatibility ✅ Passed Only docs/requirements.txt changed (dependency pins); no Ginkgo/e2e tests or networking code were added, so the check is not implicated.
No-Weak-Crypto ✅ Passed Only docs/requirements.txt changed (pymdown-extensions pin/hash); no code paths or crypto primitives were added or modified.
Container-Privileges ✅ Passed PR only updates docs/requirements.txt; no container/K8s manifests were changed and no new privileged settings were introduced.
No-Sensitive-Data-In-Logs ✅ Passed PR only updates docs/requirements.txt dependency pins and hashes; no logging code or sensitive data exposure is introduced.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the dependency update, the previous and new versions, and the affected /docs directory.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dependabot/pip/docs/pymdown-extensions-11.0

Comment @coderabbitai help to get the list of available commands.

@openshift-ci
openshift-ci Bot requested review from clebs and devguyio July 29, 2026 09:05
@openshift-ci openshift-ci Bot added the needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test. label Jul 29, 2026
@openshift-ci

openshift-ci Bot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

Hi @dependabot[bot]. Thanks for your PR.

I'm waiting for a openshift member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work.

Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@openshift-ci openshift-ci Bot added the area/documentation Indicates the PR includes changes for documentation label Jul 29, 2026
@openshift-ci

openshift-ci Bot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: dependabot[bot]
Once this PR has been reviewed and has the lgtm label, please assign csrwng for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
docs/requirements.txt (1)

301-303: 🚀 Performance & Scalability | 🔵 Trivial | ⚡ Quick win

Pin the latest patched release, 11.0.1.

Line [301-303] still pins 11.0, while 11.0.1 was released on July 2, 2026 and fixes regex-pattern inefficiencies in several extensions. Regenerate the exact hashes for 11.0.1; PyPI provides both sdist and wheel hashes. (pypi.org)

Proposed update
-pymdown-extensions==11.0 \
-    --hash=sha256:8269cef0247f9e2d0a62fcea10860aba05c1cbab5470fd4b63230b96434dc589 \
-    --hash=sha256:fbc4acb641814fa9d17521bbd21a5240ef739a662f11c06330c4b78c93e954d6
+pymdown-extensions==11.0.1 \
+    --hash=sha256:dd2905ae6fc5b75582fafb139a1266ffc754705efa902aa50067fa7ff4f94ec0 \
+    --hash=sha256:db3943a62bab7e03af1364f0c4083e64b91fb097675a4b6cceccfbe9a77e5eb2

As per path instructions, production dependencies must use exact versions and hashes and avoid stale releases.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@docs/requirements.txt` around lines 301 - 303, Update the pymdown-extensions
requirement in the dependency list from 11.0 to the patched 11.0.1 release, and
replace both existing hash entries with the exact sdist and wheel hashes for
11.0.1. Preserve the current exact-version and hash-pinning format.

Source: Path instructions

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Nitpick comments:
In `@docs/requirements.txt`:
- Around line 301-303: Update the pymdown-extensions requirement in the
dependency list from 11.0 to the patched 11.0.1 release, and replace both
existing hash entries with the exact sdist and wheel hashes for 11.0.1. Preserve
the current exact-version and hash-pinning format.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Enterprise

Run ID: 15c6bc8d-45e5-47b2-8d9e-c7caf57c1c24

📥 Commits

Reviewing files that changed from the base of the PR and between 845e625 and 81f4da4.

📒 Files selected for processing (1)
  • docs/requirements.txt

@mgencur

mgencur commented Jul 30, 2026

Copy link
Copy Markdown
Contributor

/hold

Updating the dependencies will be resolved by #9139
Let's close this PR once the PR is merged.

@openshift-ci openshift-ci Bot added the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label Jul 30, 2026
@mgencur

mgencur commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

/retitle NO-JIRA: build(deps): bump pymdown-extensions from 10.21.3 to 11.0 in /docs

@openshift-ci openshift-ci Bot changed the title build(deps): bump pymdown-extensions from 10.21.3 to 11.0 in /docs NO-JIRA: build(deps): bump pymdown-extensions from 10.21.3 to 11.0 in /docs Jul 31, 2026
@openshift-ci-robot openshift-ci-robot added the jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. label Jul 31, 2026
@openshift-ci-robot

Copy link
Copy Markdown

@dependabot[bot]: This pull request explicitly references no jira issue.

Details

In response to this:

Bumps pymdown-extensions from 10.21.3 to 11.0.

Release notes

Sourced from pymdown-extensions's releases.

11.0

  • BREAK: B64: Restricts relative links to base_path by default. Can be disabled by setting new restrict_path option to False. The new root_path can be specified if paths are desired to be restricted to a different location separate base_path which is also used as a relative base for image paths.
  • NEW: Drop Python 3.9 support.
  • FIX: Tabbed: Fix issue where an empty title would cause an exception.
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Summary by CodeRabbit

  • Documentation
  • Updated the documentation build tooling to use the latest pymdown-extensions release.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@dependabot @github

dependabot Bot commented on behalf of github Aug 9, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #9266.

@dependabot dependabot Bot closed this Aug 9, 2026
@dependabot
dependabot Bot deleted the dependabot/pip/docs/pymdown-extensions-11.0 branch August 9, 2026 10:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/documentation Indicates the PR includes changes for documentation dependencies Pull requests that update a dependency file do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test. python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants