fix: address pysentry vulnerabilities (idna, pymdown-extensions, markdown) #21
No reviewers
Labels
No labels
bug
contribution welcome
duplicate
enhancement
good first issue
help wanted
invalid
question
upstream
No milestone
No assignees
1 participant
Notifications
Due date
No due date set.
Reference
marvin8/zaojun!21
Loading…
Reference in a new issue
No description provided.
Delete branch "fix/issue-20-address-pysentry-vulnerabilities"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Closes #20
Summary
idna>=3.15(→ resolved 3.16) viaconstraint-dependencies— fixes GHSA-65pc-fj4g-8rjx (DoS inidna.encode())pymdown-extensions>=10.21.3viaconstraint-dependencies— fixes GHSA-62q4-447f-wv8h (path traversal bypass in snippets)PYSEC-2026-89(markdown, no fix available) via[tool.pysentry.ignore] while_no_fixand[tool.zaojun] vuln-ignore— both will re-alert automatically when a fix landsTest plan
uv run nox -s pysentryexits 0 with "0 vulnerabilities found"uv run nox -s dependency_versionsdoes not report PYSEC-2026-89