Bump pymdown-extensions from 10.18 to 10.21.3 - #93
Conversation
eaf1d6c to
3abe7ed
Compare
Security Vulnerability — Partial Fix Applied, Some Issues Require Human Reviewaieng-bot has fixed 6 packages with available patches. However, the following vulnerabilities cannot be fixed automatically because no stable patched version is available on PyPI yet:
What was fixed automaticallyThe following packages were bumped to patched versions in this commit:
Why the remaining issues cannot be auto-fixed
Recommended next steps
This PR will not be auto-merged due to remaining unresolved vulnerabilities requiring human review. |
Security Vulnerability — No Patch Available Yetaieng-bot found the following security vulnerability reported by pip-audit, but cannot fix it automatically because no patched version has been released to PyPI yet:
Why this cannot be auto-fixedThe vulnerability exists in
Recommended next steps
This comment was generated by aieng-bot. |
- pillow >=12.1.1 → >=12.2.0 (PYSEC-2026-165, CVE-2026-40192, CVE-2026-42309, CVE-2026-42310, CVE-2026-42311) - python-dotenv >=1.0.0 → >=1.2.2 (CVE-2026-28684) - idna (new) >=3.15 (CVE-2026-45409) - pytest >=8.4.2/>=8.3.4 → >=9.0.3 (CVE-2025-71176) - urllib3 ==2.6.3 → >=2.7.0 (PYSEC-2026-141, PYSEC-2026-142) - pip >=26.0 → >=26.1.2 (PYSEC-2026-196, CVE-2026-3219, CVE-2026-6357) Remaining unfixable vulnerabilities in torch and transformers are noted in the PR comment and require upstream patches. Co-authored-by: aieng-bot <aieng-bot@vectorinstitute.ai>
- msgpack>=1.2.1 (GHSA-6v7p-g79w-8964) - tornado>=6.5.7 (GHSA-pw6j-qg29-8w7f) - vcrpy>=8.2.1 (GHSA-rpj2-4hq8-938g) - transformers>=5.3.0 (CVE-2026-4372) - Ignore PYSEC-2026-597 (nltk 3.9.4, no upstream fix available) Co-authored-by: aieng-bot <aieng-bot@vectorinstitute.ai>
fddb3a9 to
32ee6fb
Compare
…kage Use main's uv.lock as a base to keep openai at 2.9.0 (compatible with the e2e tests), rather than the 2.44.0 that a fresh uv lock would select. The pymdown-extensions, tornado, msgpack, vcrpy and transformers bumps are already captured in main's lock. Co-authored-by: aieng-bot <aieng-bot@vectorinstitute.ai>
|
Automated fix applied and PR merged The agentic fix loop successfully fixed this PR and merged it. ✓ Successfully fixed merge_conflict failures - Modified 2 files - Executed 1238 agent actions - (871 info, 157 tool_call, 28 error, 116 tool_result, 66 reasoning) View detailed trace on dashboard | Raw trace AI Engineering Maintenance Bot |
Bumps pymdown-extensions from 10.18 to 10.21.3.
Release notes
Sourced from pymdown-extensions's releases.
Commits
4262841Fix spelling63b7835Merge commit from fork3d18550Docs: update js depsa4fdd73Skip tag 10.21.1 has we accidentally already used it8afb4cdDocs: Update JS deps7bf5b29Pygments needs a non-None value for code block title (#2863)20b11ebFix some spelling and formattingc9edba3Docs: strengthen Snippets warning and add security considerations6d92b68Bump versionbaeca0eDocs: update JS depsYou can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.