Skip to content

Conversation

@mend-for-github.zerozr99.workers.dev
Copy link

@mend-for-github.zerozr99.workers.dev mend-for-github.zerozr99.workers.dev bot commented Aug 9, 2023

This PR contains the following updates:

Package Update Change
Pygments (changelog) minor ==2.2.0 -> ==2.7.4

By merging this PR, the below issues will be automatically resolved and closed:

Severity CVSS Score CVE GitHub Issue
High 7.5 CVE-2021-20270 #27
High 7.5 CVE-2021-27291 #28
Medium 5.5 CVE-2022-40896 #-1

Release Notes

pygments/pygments

v2.7.4

Compare Source

(released January 12, 2021)

  • Updated lexers:

  • Fix infinite loop in SML lexer (#​1625), CVE-2021-20270 <https://nvd.nist.gov/vuln/detail/CVE-2021-20270>_

  • Fix backtracking string regexes in JavaScript/TypeScript, Modula2
    and many other lexers (#​1637) CVE-2021-27291 <https://nvd.nist.gov/vuln/detail/CVE-2021-27291>_

  • Limit recursion with nesting Ruby heredocs (#​1638)

  • Fix a few inefficient regexes for guessing lexers

  • Fix the raw token lexer handling of Unicode (#​1616)

  • Revert a private API change in the HTML formatter (#​1655) --
    please note that private APIs remain subject to change!

  • Fix several exponential/cubic-complexity regexes found by
    Ben Caller/Doyensec (#​1675)

  • Fix incorrect MATLAB example (#​1582)

Thanks to Google's OSS-Fuzz project for finding many of these bugs.

v2.7.3

Compare Source

(released December 6, 2020)

v2.7.2

Compare Source

(released October 24, 2020)

v2.7.1

Compare Source

(released September 16, 2020)

  • Fixed a regression in the JSON lexer (#​1544)

v2.7.0

Compare Source

(released September 12, 2020)

v2.6.1

Compare Source

(released March 8, 2020)

  • This release fixes a packaging issue. No functional changes.

v2.6.0

Compare Source

v2.5.2

Compare Source

(released November 29, 2019)

  • Fix incompatibility with some setuptools versions (PR#​1316)

  • Fix lexing of ReST field lists (PR#​1279)

  • Fix lexing of Matlab keywords as field names (PR#​1282)

  • Recognize double-quoted strings in Matlab (PR#​1278)

  • Avoid slow backtracking in Vim lexer (PR#​1312)

  • Fix Scala highlighting of types (PR#​1315)

  • Highlight field lists more consistently in ReST (PR#​1279)

  • Fix highlighting Matlab keywords in field names (PR#​1282)

  • Recognize Matlab double quoted strings (PR#​1278)

  • Add some Terraform keywords

  • Update Modelica lexer to 3.4

  • Update Crystal examples

v2.5.1

Compare Source

(released November 26, 2019)

  • This release fixes a packaging issue. No functional changes.

v2.4.2

Compare Source

(released May 28, 2019)

  • Fix encoding error when guessing lexer with given encoding option
    (#​1438)

v2.4.1

Compare Source

(released May 24, 2019)

v2.4.0

Compare Source

(released May 8, 2019)

v2.3.1

Compare Source

(released Dec 16, 2018)

v2.3.0

Compare Source

(released Nov 25, 2018)

  • Added lexers:

  • Updated lexers:

  • Minimum Python versions changed to 2.7 and 3.5

  • Added support for Python 3.7 generator changes (PR#​772)

  • Fix incorrect token type in SCSS for single-quote strings (#​1322)

  • Use terminal256 formatter if TERM contains 256 (PR#​666)

  • Fix incorrect handling of GitHub style fences in Markdown (PR#​741, #​1389)

  • Fix %a not being highlighted in Python3 strings (PR#​727)


  • If you want to rebase/retry this PR, check this box

@mend-for-github.zerozr99.workers.dev mend-for-github.zerozr99.workers.dev bot added the security fix Security fix generated by WhiteSource label Aug 9, 2023
@mend-for-github.zerozr99.workers.dev mend-for-github.zerozr99.workers.dev bot force-pushed the whitesource-remediate/pygments-2.x branch from 8317499 to 79bc959 Compare August 10, 2023 19:16
@mend-for-github.zerozr99.workers.dev mend-for-github.zerozr99.workers.dev bot changed the title chore(deps): update dependency pygments to v2.7.4 chore(deps): update dependency pygments to v2.15.0 Aug 10, 2023
@mend-for-github.zerozr99.workers.dev mend-for-github.zerozr99.workers.dev bot changed the title chore(deps): update dependency pygments to v2.15.0 chore(deps): update dependency pygments to v2.15.0 - autoclosed Aug 14, 2023
@mend-for-github.zerozr99.workers.dev mend-for-github.zerozr99.workers.dev bot deleted the whitesource-remediate/pygments-2.x branch August 14, 2023 02:37
@mend-for-github.zerozr99.workers.dev mend-for-github.zerozr99.workers.dev bot changed the title chore(deps): update dependency pygments to v2.15.0 - autoclosed chore(deps): update dependency pygments to v2.15.0 Aug 15, 2023
@mend-for-github.zerozr99.workers.dev mend-for-github.zerozr99.workers.dev bot restored the whitesource-remediate/pygments-2.x branch August 15, 2023 08:03
@mend-for-github.zerozr99.workers.dev mend-for-github.zerozr99.workers.dev bot force-pushed the whitesource-remediate/pygments-2.x branch from 79bc959 to 26d05e3 Compare August 15, 2023 08:03
@mend-for-github.zerozr99.workers.dev mend-for-github.zerozr99.workers.dev bot changed the title chore(deps): update dependency pygments to v2.15.0 chore(deps): update dependency pygments to v2.7.4 Aug 15, 2023
@mend-for-github.zerozr99.workers.dev mend-for-github.zerozr99.workers.dev bot force-pushed the whitesource-remediate/pygments-2.x branch from 26d05e3 to 0970b5f Compare August 17, 2023 14:15
@mend-for-github.zerozr99.workers.dev mend-for-github.zerozr99.workers.dev bot changed the title chore(deps): update dependency pygments to v2.7.4 chore(deps): update dependency pygments to v2.15.0 Aug 17, 2023
@mend-for-github.zerozr99.workers.dev mend-for-github.zerozr99.workers.dev bot changed the title chore(deps): update dependency pygments to v2.15.0 chore(deps): update dependency pygments to v2.15.0 - autoclosed Aug 19, 2023
@mend-for-github.zerozr99.workers.dev mend-for-github.zerozr99.workers.dev bot deleted the whitesource-remediate/pygments-2.x branch August 19, 2023 03:33
@mend-for-github.zerozr99.workers.dev mend-for-github.zerozr99.workers.dev bot changed the title chore(deps): update dependency pygments to v2.15.0 - autoclosed chore(deps): update dependency pygments to v2.15.0 Aug 20, 2023
@mend-for-github.zerozr99.workers.dev mend-for-github.zerozr99.workers.dev bot restored the whitesource-remediate/pygments-2.x branch August 20, 2023 11:19
@mend-for-github.zerozr99.workers.dev mend-for-github.zerozr99.workers.dev bot force-pushed the whitesource-remediate/pygments-2.x branch from 0970b5f to e83a713 Compare August 20, 2023 11:20
@mend-for-github.zerozr99.workers.dev mend-for-github.zerozr99.workers.dev bot force-pushed the whitesource-remediate/pygments-2.x branch from e83a713 to 43afee1 Compare August 21, 2023 15:33
@mend-for-github.zerozr99.workers.dev mend-for-github.zerozr99.workers.dev bot changed the title chore(deps): update dependency pygments to v2.15.0 chore(deps): update dependency pygments to v2.7.4 Aug 21, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fix Security fix generated by WhiteSource

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant