Bump astral-sh/setup-uv from 7.6.0 to 8.0.0#75
Conversation
Security Vulnerabilities — Partial Fix Appliedaieng-bot has fixed 2 of 3 security vulnerabilities reported by pip-audit:
pygments GHSA-5239-wwwm-4pmq — No Safe Fix Available YetWhy this cannot be auto-fixed: The only available upgrade is Root cause: In Confirmed:
Recommended Next Steps
This PR will not be auto-merged until the pygments vulnerability is resolved. |
Security Vulnerability — No Safe Patch Available Yetaieng-bot found the following security vulnerability reported by pip-audit, but cannot fix it automatically because no patched version without a known regression has been released to PyPI:
Why this cannot be auto-fixedWhile pygments 2.20.0 is technically available on PyPI and patches GHSA-5239-wwwm-4pmq, it introduces a regression (NoneType filename crash) that breaks the docs build. The current
There is no newer pygments release (e.g., 2.20.1+) that resolves both the vulnerability and the regression. The latest available version on PyPI is 2.20.0. Recommended next steps
This PR will not be auto-merged until the vulnerability is resolved. |
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 7.6.0 to 8.0.0. - [Release notes](https://github.com/astral-sh/setup-uv/releases) - [Commits](astral-sh/setup-uv@v7.6...v8.0.0) --- updated-dependencies: - dependency-name: astral-sh/setup-uv dependency-version: 8.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
…ilities - cryptography>=46.0.6 to address GHSA-m959-cc7f-wv43 - requests>=2.33.0 to address GHSA-gc5v-m9x4-r6x2 - pygments>=2.20.0 to address GHSA-5239-wwwm-4pmq Co-authored-by: aieng-bot <aieng-bot@vectorinstitute.ai>
…ests - cryptography>=46.0.6 to address GHSA-m959-cc7f-wv43 - requests>=2.33.0 to address GHSA-gc5v-m9x4-r6x2 - pygments pinned <2.20.0 due to regression in 2.20.0 that breaks docs build; GHSA-5239-wwwm-4pmq cannot be auto-fixed until upstream patches the regression Co-authored-by: aieng-bot <aieng-bot@vectorinstitute.ai>
299670e to
0db8787
Compare
Bumps astral-sh/setup-uv from 7.6.0 to 8.0.0.
Release notes
Sourced from astral-sh/setup-uv's releases.
Commits
cec2083Shortcircuit latest version from manifest (#828)4dd8ab4Simplify inputs.ts (#827)7fdbe7cRemove update-major-minor-tags workflow (#826)485abd0Bump release-drafter to v7.1.1 (#825)f82eb19Refactor inputs (#823)868d1f7Replace inline compile args with tsconfig (#824)447e6d0chore: update known checksums for 0.11.2 (#821)5c62c59chore: update known checksums for 0.11.1 (#817)e1a7373chore: update known checksums for 0.11.0 (#815)8970931Remove deprecrated custom manifest (#813)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)