chore(deps): update dependency pygments to v2.20.0 [security] - #385
chore(deps): update dependency pygments to v2.20.0 [security]#385renovate[bot] wants to merge 1 commit into
Conversation
|
Overview
Policies (1 improved, 1 worsened, 3 missing data)
Packages and Vulnerabilities (107 package changes and 11 vulnerability changes)
Changes for packages of type
|
| Package | Versiondjaytan/papermc-server:1.21.11 |
Versiondjaytan/papermc-server:test |
|
|---|---|---|---|
| ➖ | openjdk | 21.0.10 |
|
| ➕ | openjdk | 21.0.10 |
Changes for packages of type golang (20 changes)
| Package | Versiondjaytan/papermc-server:1.21.11 |
Versiondjaytan/papermc-server:test |
|
|---|---|---|---|
| ➕ | cuelabs.dev/go/oci/ociregistry | 0.0.0-20250304105642-27e071d2c9b1 |
|
| ➖ | cuelabs.dev/go/oci/ociregistry | 0.0.0-20250304105642-27e071d2c9b1 |
|
| ➖ | github.com/cenkalti/backoff/v5 | 5.0.3 |
|
| ➕ | github.com/cenkalti/backoff/v5 | 5.0.3 |
|
| ➕ | github.com/cespare/xxhash/v2 | 2.3.0 |
|
| ➖ | github.com/cespare/xxhash/v2 | 2.3.0 |
|
| ➕ | github.com/cockroachdb/apd/v3 | 3.2.1 |
|
| ➖ | github.com/cockroachdb/apd/v3 | 3.2.1 |
|
| ➕ | github.com/grpc-ecosystem/grpc-gateway/v2 | 2.27.7 |
|
| ➖ | github.com/grpc-ecosystem/grpc-gateway/v2 | 2.27.7 |
|
| ➕ | github.com/pelletier/go-toml/v2 | 2.2.4 |
|
| ➖ | github.com/pelletier/go-toml/v2 | 2.2.4 |
|
| ➕ | go.opentelemetry.io/contrib/instrumentation/runtime | 0.65.0 |
|
| ➖ | go.opentelemetry.io/contrib/instrumentation/runtime | 0.65.0 |
|
| ➖ | go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc | 1.40.0 |
|
| ➕ | go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc | 1.40.0 |
|
| ➖ | go.opentelemetry.io/otel/sdk/metric | 1.40.0 |
|
| ➖ | google.golang.org/genproto/googleapis/api | 0.0.0-20260203192932-546029d2fa20 |
|
| ➕ | google.golang.org/genproto/googleapis/rpc | 0.0.0-20260203192932-546029d2fa20 |
|
| ➖ | google.golang.org/genproto/googleapis/rpc | 0.0.0-20260203192932-546029d2fa20 |
Changes for packages of type maven (76 changes)
🔍 Vulnerabilities of
|
| digest | sha256:0f5f372484a22afed7ef08e101d9f9db9264054f6c83797a46360ad761a3c8a1 |
| vulnerabilities | |
| platform | linux/amd64 |
| size | 147 MB |
| packages | 176 |
📦 Base Image alpine:3
| also known as |
|
| digest | sha256:59855d3dceb3ae53991193bd03301e082b2a7faa56a514b03527ae0ec2ce3a95 |
| vulnerabilities |
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
Description
Description
Description
Description
Description
Description
Description
Description
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
Description
Description
Description
Description
Description
Description
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
Description
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
Description
Description
Description
Description
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
Description
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
Description
Description
Description | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
|
55e06de to
eac308c
Compare
|
|
❌ The last analysis has failed. |



This PR contains the following updates:
==2.19.2→==2.20.0Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching
CVE-2026-4539 / GHSA-5239-wwwm-4pmq / PYSEC-2026-2987
More information
Details
A security flaw has been discovered in pygments before 2.20.0. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Severity
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:PReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching
CVE-2026-4539 / GHSA-5239-wwwm-4pmq / PYSEC-2026-2987
More information
Details
A security flaw has been discovered in pygments before 2.20.0. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Severity
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:PReferences
This data is provided by OSV and the PyPI Advisory Database (CC-BY 4.0).
Release Notes
pygments/pygments (Pygments)
v2.20.0Compare Source
(released March 29th, 2026)
New lexers:
Updated lexers:
analyse_text(#3028, #3032)]',]?,]!(#2946)__PROPERTY__magic constant (#2924), add reserved keywords (#3002)t-string support (#2973, #3009, #3010).xbrlas file ending (#2890, #2891)Drop Python 3.8, and add Python 3.14 as a supported version (#2987, #3012)
Various improvements to
autopygmentize(#2894)Update
onedarkstyle to support more token types (#2977)Update
rttstyle to support more token types (#2895)Cache entry points to improve performance (#2979)
Fix
xterm-256color table (#3043)Fix
kwargsdictionary getting mutated on each call (#3044)Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.