From 098c762955cfd92c180584ff6b99eab1c886b7e9 Mon Sep 17 00:00:00 2001 From: Waldo Malqui Date: Sun, 23 Aug 2026 13:01:27 -0500 Subject: [PATCH] fix: upgrade pymdown-extensions to resolve Dependabot CVEs Regenerates docs/requirements.txt via pip-compile to pull in pymdown-extensions 11.0.2, closing two open Dependabot alerts: a ReDoS in inline processors (high) and a path-traversal via the b64 extension (medium). Docs-only dependency, no runtime impact. - docs/requirements.txt: pymdown-extensions 10.21.3 -> 11.0.2 - VERSION: v0.4.1 -> v0.4.2 - CHANGELOG.md: add [0.4.2] entry --- CHANGELOG.md | 9 ++++++++- VERSION | 2 +- docs/requirements.txt | 6 +++--- 3 files changed, 12 insertions(+), 5 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 86004ae..9826424 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,6 +7,12 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ## [Unreleased] +## [0.4.2] - 2026-08-23 + +### Fixed + +- **`pymdown-extensions` upgraded to 11.0.2** in `docs/requirements.txt` — resolves two Dependabot alerts: a ReDoS in inline processors (high) and a path-traversal in the `b64` extension (medium). Docs-only dependency; no runtime impact. + ## [0.4.1] - 2026-08-23 ### Fixed @@ -64,7 +70,8 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 - **Multi-arch container** — supports `linux/amd64` and `linux/arm64`; ARM64 (Graviton) preferred for lower cost and better performance-per-watt - **Build-time version embedding** — version string injected via `-ldflags` and logged at startup -[Unreleased]: https://github.com/fayrus/syncret/compare/v0.4.1...HEAD +[Unreleased]: https://github.com/fayrus/syncret/compare/v0.4.2...HEAD +[0.4.2]: https://github.com/fayrus/syncret/compare/v0.4.1...v0.4.2 [0.4.1]: https://github.com/fayrus/syncret/compare/v0.4.0...v0.4.1 [0.4.0]: https://github.com/fayrus/syncret/compare/v0.3.0...v0.4.0 [0.3.0]: https://github.com/fayrus/syncret/compare/v0.2.0...v0.3.0 diff --git a/VERSION b/VERSION index 5aff472..0eec13e 100644 --- a/VERSION +++ b/VERSION @@ -1 +1 @@ -v0.4.1 +v0.4.2 diff --git a/docs/requirements.txt b/docs/requirements.txt index 8c4541b..fcabc10 100644 --- a/docs/requirements.txt +++ b/docs/requirements.txt @@ -315,9 +315,9 @@ pygments==2.20.0 \ --hash=sha256:6757cd03768053ff99f3039c1a36d6c0aa0b263438fcab17520b30a303a82b5f \ --hash=sha256:81a9e26dd42fd28a23a2d169d86d7ac03b46e2f8b59ed4698fb4785f946d0176 # via mkdocs-material -pymdown-extensions==10.21.3 \ - --hash=sha256:72cfcf55f07aea0d4af2c4f11dd4e52466ddfb1bb819673146398e0bd3a77354 \ - --hash=sha256:d7a5d08014fc571e80ca21dd6f854e31f94c489800350564d55d15b3c41e76b6 +pymdown-extensions==11.0.2 \ + --hash=sha256:259910762019732caa1dfd76f3faa62c59f191d46573e80bcb1d13c0f675bbe5 \ + --hash=sha256:9506fcbe66fa355a775b768084334238dd6805020ac4b92bea0c0dda6f8f223d # via mkdocs-material python-dateutil==2.9.0.post0 \ --hash=sha256:37dd54208da7e1cd875388217d5e00ebd4179249f90fb72437e91a35459a0ad3 \