diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml index 56169b29..4dc7a9fb 100644 --- a/.github/workflows/deploy.yml +++ b/.github/workflows/deploy.yml @@ -31,11 +31,14 @@ jobs: cache: pip - name: Install dependencies - # --no-deps because Pelican 4.12 hard-pins Pygments<2.20.0, but we - # override Pygments to 2.20.0 in requirements.txt to patch the - # AdlLexer ReDoS advisory (GHSA, dependabot alert #1). Every - # transitive dep is already pinned with hashes in requirements.txt, - # so --no-deps is safe and avoids the resolver conflict. + # --no-deps: every transitive dep is already pinned with hashes in + # requirements.txt, so pip's resolver adds nothing here. + # Pygments stays at 2.19.2 because Pelican 4.12 caps it at <2.20.0, and + # pip-compile washed out the manual 2.20.0 override twice. The ReDoS + # advisory it was meant to fix (GHSA-5239-wwwm-4pmq, low: GUID lexer) + # was dismissed as tolerable risk on 2026-07-28 (Dependabot alert #1): + # the build only highlights repo-authored code fences. Bump to >=2.20.0 + # once a Pelican release lifts the cap. run: pip install --require-hashes --no-deps -r requirements.txt - name: Refresh About page from GitHub profile README