Skip to content

Rename metadata_config#63

Closed
yarden-slon wants to merge 1 commit intomainfrom
2f0120
Closed

Rename metadata_config#63
yarden-slon wants to merge 1 commit intomainfrom
2f0120

Conversation

@yarden-slon
Copy link
Copy Markdown
Contributor

No description provided.

@jhamon jhamon deleted the 2f0120 branch June 20, 2024 17:22
jhamon added a commit that referenced this pull request Apr 1, 2026
pygments < 2.20.0 has a ReDoS vulnerability in GUID matching regex.
It's a transitive dev-only dependency via sphinx. Lockfile-only change.
jhamon added a commit that referenced this pull request Apr 1, 2026
## Summary
- Bumps transitive `pygments` from 2.19.2 to 2.20.0 in `uv.lock`
- Fixes ReDoS vulnerability due to inefficient regex for GUID matching
- Dev-only dependency (via `sphinx`), lockfile-only change
- Resolves [Dependabot alert
#63](https://github.com/pinecone-io/pinecone-python-client/security/dependabot/63)

## Test plan
- [x] Lockfile-only change, no code or dependency spec changes

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Low Risk**
> Lockfile-only change updating the resolved `pygments` artifact
URLs/hashes; minimal runtime risk unless downstream tooling relies on
the previous transitive version.
> 
> **Overview**
> Updates the `uv.lock` resolution for transitive dependency `pygments`
from `2.19.2` to `2.20.0`, including the associated sdist/wheel URLs,
hashes, and metadata (security patch release).
> 
> No application code or dependency specifications are changed—this PR
only alters the lockfile resolution.
> 
> <sup>Written by [Cursor
Bugbot](https://cursor.com/dashboard?tab=bugbot) for commit
d1fb488. This will update automatically
on new commits. Configure
[here](https://cursor.com/dashboard?tab=bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants