Skip to content

[pre-commit.ci] pre-commit autoupdate#76

Merged
amrit110 merged 2 commits intomainfrom
pre-commit-ci-update-config
Mar 31, 2026
Merged

[pre-commit.ci] pre-commit autoupdate#76
amrit110 merged 2 commits intomainfrom
pre-commit-ci-update-config

Conversation

@pre-commit-ci
Copy link
Copy Markdown
Contributor

@pre-commit-ci pre-commit-ci bot commented Mar 30, 2026

@amrit110
Copy link
Copy Markdown
Member

Security Vulnerability — No Patch Available Yet

aieng-bot found the following security vulnerabilities reported by pip-audit, but cannot fix them automatically because no patched version has been released to PyPI yet:

Package Version Vulnerability Status
pygments 2.19.2 GHSA-5239-wwwm-4pmq No fix available on PyPI

Why this cannot be auto-fixed

The vulnerability exists in pygments itself (inefficient regular expression complexity in pygments/lexers/archetype.py). A fix requires the upstream maintainers to release a new version. According to the advisory, the project was informed of the problem but has not yet responded. Once a patched release is published to PyPI, aieng-bot can re-run and apply the update automatically.

What was fixed in this run

The following vulnerabilities were fixed:

Recommended next steps

  1. Monitor the pygments GHSA-5239-wwwm-4pmq advisory for a patch release
  2. Check if a pip-audit ignore/exception can be added temporarily with justification (requires human review)
  3. Consider whether this dependency can be replaced with an alternative

This PR will not be auto-merged until the vulnerability is resolved.

pre-commit-ci bot and others added 2 commits March 31, 2026 17:25
updates:
- [github.com/astral-sh/uv-pre-commit: 0.10.12 → 0.11.2](astral-sh/uv-pre-commit@0.10.12...0.11.2)
- [github.com/astral-sh/ruff-pre-commit: v0.15.7 → v0.15.8](astral-sh/ruff-pre-commit@v0.15.7...v0.15.8)
- cryptography>=46.0.6 to fix GHSA-m959-cc7f-wv43
- requests>=2.33.0 to fix GHSA-gc5v-m9x4-r6x2

Co-authored-by: aieng-bot <aieng-bot@vectorinstitute.ai>
@amrit110 amrit110 force-pushed the pre-commit-ci-update-config branch from 90112a2 to ce9dda6 Compare March 31, 2026 17:26
@amrit110 amrit110 merged commit a1c6919 into main Mar 31, 2026
11 checks passed
@amrit110 amrit110 deleted the pre-commit-ci-update-config branch March 31, 2026 17:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant