Skip to content

build(deps): update Pygments to 2.20.0 - #503

Merged
james-d-mitchell merged 1 commit into
mainfrom
codex/fix-dependabot-35
Sep 10, 2026
Merged

james-d-mitchell merged 1 commit into
mainfrom
codex/fix-dependabot-35

Conversation

@james-d-mitchell

Copy link
Copy Markdown
Member

Update Pygments from 2.19.2 to 2.20.0 in uv.lock to address Dependabot alert #35 (CVE-2026-4539: inefficient regular expressions in the ADL lexer). requirements.txt already pins 2.20.0. Only the Pygments version and distribution metadata change.

Validation:

  • uv lock --check --offline and git diff --check passed; a structural comparison confirmed that only the Pygments package entry changed.
  • Installed all locked extras and development dependencies in an isolated temporary environment with uv sync --locked --all-extras --no-install-project; uv pip check passed.
  • python -m pytest -q -W error /private/tmp/codex-dependabot-35-smoke/test_pygments.py: 3 passed, covering the patched version and Python requirement metadata, GUID highlighting, and long-input handling in the ADL lexer.
  • Temporary Sphinx HTML and doctest smoke builds passed with warnings treated as errors; all 4 doctest examples passed.
  • Both pre-commit hook stages completed for uv.lock: codespell passed; other hooks had no applicable files.
  • No C++ rebuild was needed for this lockfile-only change. The full project tests and documentation build were not run because the compiled extension was absent from the selected environment.

AI disclosure: OpenAI Codex investigated the alert, prepared the dependency update, commit message, and PR description, and ran the validation checks.

Update the uv lockfile to the patched version for CVE-2026-4539,
addressing Dependabot alert 35. requirements.txt already pins 2.20.0.

Validation: uv lock --check --offline, uv pip check, three targeted
Pygments smoke tests, Sphinx HTML and doctest smoke builds with warnings
as errors, and both pre-commit hook stages for uv.lock.

AI assistance: OpenAI Codex investigated the alert, updated the lockfile,
and performed dependency validation, smoke checks, and repository hooks.

Co-authored-by: Codex <codex@openai.com>
@james-d-mitchell
james-d-mitchell merged commit ce0963d into main Sep 10, 2026
24 checks passed
@james-d-mitchell
james-d-mitchell deleted the codex/fix-dependabot-35 branch September 10, 2026 14:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants