Repository navigation
Commit f9ab85c
authored
Bump pygments to 2.20.0 in lockfile (ReDoS fix) (#628)
## Summary
- Bumps transitive `pygments` from 2.19.2 to 2.20.0 in `uv.lock`
- Fixes ReDoS vulnerability due to inefficient regex for GUID matching
- Dev-only dependency (via `sphinx`), lockfile-only change
- Resolves [Dependabot alert
#63](https://github.com/pinecone-io/pinecone-python-client/security/dependabot/63)
## Test plan
- [x] Lockfile-only change, no code or dependency spec changes
<!-- CURSOR_SUMMARY -->
---
> [!NOTE]
> **Low Risk**
> Lockfile-only change updating the resolved `pygments` artifact
URLs/hashes; minimal runtime risk unless downstream tooling relies on
the previous transitive version.
>
> **Overview**
> Updates the `uv.lock` resolution for transitive dependency `pygments`
from `2.19.2` to `2.20.0`, including the associated sdist/wheel URLs,
hashes, and metadata (security patch release).
>
> No application code or dependency specifications are changed—this PR
only alters the lockfile resolution.
>
> <sup>Written by [Cursor
Bugbot](https://cursor.com/dashboard?tab=bugbot) for commit
d1fb488. This will update automatically
on new commits. Configure
[here](https://cursor.com/dashboard?tab=bugbot).</sup>
<!-- /CURSOR_SUMMARY -->1 parent a4c5bde commit f9ab85c
1 file changed
Lines changed: 3 additions & 3 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
0 commit comments