From de6c6f0e2dbcba1931ef8e277e74f911fb4dbd15 Mon Sep 17 00:00:00 2001 From: rivassec Date: Mon, 28 Sep 2026 22:15:54 -0700 Subject: [PATCH] ci(deploy): correct the stale Pygments override comment The comment claimed requirements.txt overrides Pygments to 2.20.0. It doesn't: the override (8e361f3, re-applied in a502144) was washed out again by a later pip-compile, and requirements.txt pins 2.19.2. The advisory (GHSA-5239-wwwm-4pmq, low) was dismissed as tolerable risk on 2026-07-28 (Dependabot alert #1), because Pelican 4.12.0, still the latest, caps Pygments at <2.20.0. Comment-only change; the install command is unchanged. Co-Authored-By: Claude Opus 5.5 --- .github/workflows/deploy.yml | 13 ++++++++----- 1 file changed, 8 insertions(+), 5 deletions(-) diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml index 56169b29..4dc7a9fb 100644 --- a/.github/workflows/deploy.yml +++ b/.github/workflows/deploy.yml @@ -31,11 +31,14 @@ jobs: cache: pip - name: Install dependencies - # --no-deps because Pelican 4.12 hard-pins Pygments<2.20.0, but we - # override Pygments to 2.20.0 in requirements.txt to patch the - # AdlLexer ReDoS advisory (GHSA, dependabot alert #1). Every - # transitive dep is already pinned with hashes in requirements.txt, - # so --no-deps is safe and avoids the resolver conflict. + # --no-deps: every transitive dep is already pinned with hashes in + # requirements.txt, so pip's resolver adds nothing here. + # Pygments stays at 2.19.2 because Pelican 4.12 caps it at <2.20.0, and + # pip-compile washed out the manual 2.20.0 override twice. The ReDoS + # advisory it was meant to fix (GHSA-5239-wwwm-4pmq, low: GUID lexer) + # was dismissed as tolerable risk on 2026-07-28 (Dependabot alert #1): + # the build only highlights repo-authored code fences. Bump to >=2.20.0 + # once a Pelican release lifts the cap. run: pip install --require-hashes --no-deps -r requirements.txt - name: Refresh About page from GitHub profile README