chore(deps-dev): bump mkdocs-material from 9.6.16 to 9.7.7 - #4976
chore(deps-dev): bump mkdocs-material from 9.6.16 to 9.7.7#4976dependabot[bot] wants to merge 2 commits into
Conversation
Bumps [mkdocs-material](https://github.com/squidfunk/mkdocs-material) from 9.6.16 to 9.7.7. - [Release notes](https://github.com/squidfunk/mkdocs-material/releases) - [Changelog](https://github.com/squidfunk/mkdocs-material/blob/master/CHANGELOG) - [Commits](squidfunk/mkdocs-material@9.6.16...9.7.7) --- updated-dependencies: - dependency-name: mkdocs-material dependency-version: 9.7.7 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 60fbd0e790
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
HAYDEN-OAI
left a comment
There was a problem hiding this comment.
No actionable findings in the complete four-file diff at 9ee753346d4199b0bda9b8c5c64b6013543fffed. The previous redeployment concern is addressed: uv.lock selects the docs build and main-branch deployment even in mixed pushes, while missing commits or failed diffs still deny deployment. Pushes without a lockfile change retain the existing docs-only behavior.
Reviewed the detector and its callers, workflow privilege boundaries, complete lockfile changes, current docs configuration, and published Material 9.7.7 artifacts. The non-Material marker edits preserve reachable Python environments; the retained dependencies satisfy the upgraded theme's requirements. Both Material artifact hashes match the lockfile and PyPI metadata. The published search-suggestion advisory is fixed in 9.7.7, but search.suggest is not enabled here, so this review does not establish that the prior site was exploitable.
Static source/metadata/artifact review only. No installation, builds, tests, lint, CI or mergeability assessment, workflow execution, or live deployed-asset verification. Published provenance metadata was inspected, not its complete Sigstore certificate/transparency chain.
Bumps mkdocs-material from 9.6.16 to 9.7.7.
Release notes
Sourced from mkdocs-material's releases.
... (truncated)
Changelog
Sourced from mkdocs-material's changelog.
... (truncated)
Commits
b3e6dd8Prepare 9.7.7 release52fb6beMerge commit from fork901e633AddedSECURITY.mdwith EOL notice5b36f2aBump js-yaml from 4.1.1 to 4.2.0 (#8598)2d11e7bBump form-data from 3.0.4 to 3.0.5 (#8597)ae05a53Bump esbuild from 0.27.2 to 0.28.1 (#8596)434af93Bump shell-quote from 1.7.3 to 1.8.4 (#8593)4447cdaDocumentation (#8590)8f8d551Updated copyright year (#8588)08d8514Bump fast-uri from 3.0.3 to 3.1.2 (#8587)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.