Skip to content

Commit f9ab85c

Browse files
authored
Bump pygments to 2.20.0 in lockfile (ReDoS fix) (#628)
## Summary - Bumps transitive `pygments` from 2.19.2 to 2.20.0 in `uv.lock` - Fixes ReDoS vulnerability due to inefficient regex for GUID matching - Dev-only dependency (via `sphinx`), lockfile-only change - Resolves [Dependabot alert #63](https://github.com/pinecone-io/pinecone-python-client/security/dependabot/63) ## Test plan - [x] Lockfile-only change, no code or dependency spec changes <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **Low Risk** > Lockfile-only change updating the resolved `pygments` artifact URLs/hashes; minimal runtime risk unless downstream tooling relies on the previous transitive version. > > **Overview** > Updates the `uv.lock` resolution for transitive dependency `pygments` from `2.19.2` to `2.20.0`, including the associated sdist/wheel URLs, hashes, and metadata (security patch release). > > No application code or dependency specifications are changed—this PR only alters the lockfile resolution. > > <sup>Written by [Cursor Bugbot](https://cursor.com/dashboard?tab=bugbot) for commit d1fb488. This will update automatically on new commits. Configure [here](https://cursor.com/dashboard?tab=bugbot).</sup> <!-- /CURSOR_SUMMARY -->
1 parent a4c5bde commit f9ab85c

1 file changed

Lines changed: 3 additions & 3 deletions

File tree

‎uv.lock‎

Lines changed: 3 additions & 3 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)