Skip to content

Update dependency pygments to v2.20.0 [SECURITY]#4824

Open
tmt-renovate-bot[bot] wants to merge 1 commit into
mainfrom
renovate/pypi-pygments-vulnerability
Open

Update dependency pygments to v2.20.0 [SECURITY]#4824
tmt-renovate-bot[bot] wants to merge 1 commit into
mainfrom
renovate/pypi-pygments-vulnerability

Conversation

@tmt-renovate-bot
Copy link
Copy Markdown

@tmt-renovate-bot tmt-renovate-bot Bot commented Apr 22, 2026

This PR contains the following updates:

Package Change Age Confidence
pygments (changelog) 2.19.22.20.0 age confidence

GitHub Vulnerability Alerts

CVE-2026-4539

A security flaw has been discovered in pygments before 2.20.0. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.


Release Notes

pygments/pygments (pygments)

v2.20.0

Compare Source

(released March 29th, 2026)


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@tmt-renovate-bot tmt-renovate-bot Bot force-pushed the renovate/pypi-pygments-vulnerability branch 11 times, most recently from 1a8d999 to a73f672 Compare April 29, 2026 05:04
@github-project-automation github-project-automation Bot moved this to backlog in planning Apr 29, 2026
@therazix therazix moved this from backlog to merge in planning Apr 29, 2026
@therazix therazix moved this from merge to review in planning Apr 29, 2026
@tmt-renovate-bot tmt-renovate-bot Bot force-pushed the renovate/pypi-pygments-vulnerability branch 3 times, most recently from a4a6ccf to 68a90fe Compare May 8, 2026 02:59
@tmt-renovate-bot tmt-renovate-bot Bot force-pushed the renovate/pypi-pygments-vulnerability branch from 68a90fe to bbe6f71 Compare May 11, 2026 21:08
@tmt-renovate-bot tmt-renovate-bot Bot force-pushed the renovate/pypi-pygments-vulnerability branch from bbe6f71 to 11cd096 Compare May 15, 2026 03:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

Status: review

Development

Successfully merging this pull request may close these issues.

2 participants