Skip to content

ci(deploy): correct the stale Pygments override comment - #86

Merged
rivassec merged 1 commit into
mainfrom
docs/deploy-pygments-comment
Sep 29, 2026
Merged

rivassec merged 1 commit into
mainfrom
docs/deploy-pygments-comment

Conversation

@rivassec

Copy link
Copy Markdown
Owner

The deploy.yml comment claimed requirements.txt overrides Pygments to 2.20.0. It doesn't: requirements.txt pins 2.19.2.

  • The override (8e361f3, re-applied in a502144) was washed out again by a later pip-compile run.
  • The advisory it targeted (GHSA-5239-wwwm-4pmq, low, GUID-lexer ReDoS) was dismissed as tolerable_risk on 2026-07-28 (Dependabot alert Improve build pipeline, SEO, and repo hygiene #1). The build only highlights code blocks written in this repo.
  • Pelican 4.12.0 is still the latest release, and it still caps pygments<2.20.0.

This is a comment-only change; the install command is unchanged. The new comment records the actual state and when to revisit it.

🤖 Generated with Claude Code

The comment claimed requirements.txt overrides Pygments to 2.20.0. It
doesn't: the override (8e361f3, re-applied in a502144) was washed out
again by a later pip-compile, and requirements.txt pins 2.19.2. The
advisory (GHSA-5239-wwwm-4pmq, low) was dismissed as tolerable risk
on 2026-07-28 (Dependabot alert #1), because Pelican 4.12.0, still the
latest, caps Pygments at <2.20.0.

Comment-only change; the install command is unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@rivassec
rivassec merged commit 7103086 into main Sep 29, 2026
19 checks passed
@rivassec
rivassec deleted the docs/deploy-pygments-comment branch September 29, 2026 05:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant