Skip to content

chore(deps): update dependency pygments to v2.7.4 #80

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

dev-mend-for-github.lhy31512.workers.dev[bot]

This PR contains the following updates:

Package Update Change
pygments (changelog) minor ==2.6.1 -> ==2.7.4

By merging this PR, the issue #38 will be automatically resolved and closed:

Severity CVSS Score CVE Reachability
High High 7.5 CVE-2021-20270
High High 7.5 CVE-2021-27291

Release Notes

pygments/pygments (pygments)

v2.7.4

Compare Source

(released January 12, 2021)

  • Updated lexers:

  • Fix infinite loop in SML lexer (#​1625), CVE-2021-20270 <https://nvd.nist.gov/vuln/detail/CVE-2021-20270>_

  • Fix backtracking string regexes in JavaScript/TypeScript, Modula2
    and many other lexers (#​1637) CVE-2021-27291 <https://nvd.nist.gov/vuln/detail/CVE-2021-27291>_

  • Limit recursion with nesting Ruby heredocs (#​1638)

  • Fix a few inefficient regexes for guessing lexers

  • Fix the raw token lexer handling of Unicode (#​1616)

  • Revert a private API change in the HTML formatter (#​1655) --
    please note that private APIs remain subject to change!

  • Fix several exponential/cubic-complexity regexes found by
    Ben Caller/Doyensec (#​1675)

  • Fix incorrect MATLAB example (#​1582)

Thanks to Google's OSS-Fuzz project for finding many of these bugs.

v2.7.3

Compare Source

(released December 6, 2020)

v2.7.2

Compare Source

(released October 24, 2020)

v2.7.1

Compare Source

(released September 16, 2020)

  • Fixed a regression in the JSON lexer (#​1544)

v2.7.0

Compare Source

(released September 12, 2020)


  • If you want to rebase/retry this PR, check this box

@dev-mend-for-github.lhy31512.workers.dev dev-mend-for-github.lhy31512.workers.dev bot added the security fix Security fix generated by Mend label Jan 7, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security fix Security fix generated by Mend
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants