Skip to content

fix(deps): update dependency mkdocs-git-revision-date-localized-plugin to v1.5.4 - #494

Merged
mschoettle merged 1 commit into
mainfrom
renovate/mkdocs-git-revision-date-localized-plugin-1.x
Sep 9, 2026
Merged

mschoettle merged 1 commit into
mainfrom
renovate/mkdocs-git-revision-date-localized-plugin-1.x

Conversation

@renovate

@renovate renovate Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
mkdocs-git-revision-date-localized-plugin ==1.5.1==1.5.4 age confidence

Release Notes

timvink/mkdocs-git-revision-date-localized-plugin (mkdocs-git-revision-date-localized-plugin)

v1.5.4

Compare Source

Security

Raises the gitpython floor from >=3.1.44 to >=3.1.59.

Earlier dependabot bumps only touched this repo's uv.lock, which pins the CI
environment and nothing else. Downstream users installing from PyPI resolved
against pyproject.toml, so they could still land on a GitPython carrying the
2026 option-injection advisories — GHSA-wvpp-8hx9-p66j and GHSA-jm78-9fvv-mhgr
among them, all patched by 3.1.58, with further option hardening in 3.1.59.

This plugin never passes user input as git options, so it was not exploitable
through those. The floor bump forces the upgrade in environments that already
hold an older GitPython, and clears the warnings downstream scanners report.

Thanks to @​nucleus-ffm for reporting it in #​222.

Maintenance

Full Changelog: timvink/mkdocs-git-revision-date-localized-plugin@v1.5.3...v1.5.4

v1.5.3

Compare Source

What's Changed

New Contributors

Full Changelog: timvink/mkdocs-git-revision-date-localized-plugin@v1.5.2...v1.5.3

v1.5.2

Compare Source

What's Changed

Bug fixes
  • Guard against page is None in mkdocs theme override Jinja2 templates by @​Copilot in #​202
Dependency updates (security)

Full Changelog: timvink/mkdocs-git-revision-date-localized-plugin@v1.5.1...v1.5.2


Configuration

📅 Schedule: (in timezone America/Toronto)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies label Sep 9, 2026
@mschoettle
mschoettle merged commit f91bfd9 into main Sep 9, 2026
6 checks passed
@mschoettle
mschoettle deleted the renovate/mkdocs-git-revision-date-localized-plugin-1.x branch September 9, 2026 13:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant