From be39775341b55f948c1d523d22457a5262d87b2f Mon Sep 17 00:00:00 2001 From: SmartLamScott Date: Mon, 6 Apr 2026 16:36:29 -0500 Subject: [PATCH 1/4] Upgrade pygments to >=2.20.0 --- pyproject.toml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pyproject.toml b/pyproject.toml index e51cafbd747..35e37d40390 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -51,7 +51,7 @@ dependencies = [ "iniconfig>=1.0.1", "packaging>=22", "pluggy>=1.5,<2", - "pygments>=2.7.2", + "pygments>=2.20.0", "tomli>=1; python_version<'3.11'", ] optional-dependencies.dev = [ From a2afb91efba374d9155d1d1731a9741f2a34380f Mon Sep 17 00:00:00 2001 From: SmartLamScott Date: Mon, 6 Apr 2026 16:52:38 -0500 Subject: [PATCH 2/4] change pygments version requirement from >=2.20.0 >=2.20 --- pyproject.toml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pyproject.toml b/pyproject.toml index 35e37d40390..bd07fef6cec 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -51,7 +51,7 @@ dependencies = [ "iniconfig>=1.0.1", "packaging>=22", "pluggy>=1.5,<2", - "pygments>=2.20.0", + "pygments>=2.20", "tomli>=1; python_version<'3.11'", ] optional-dependencies.dev = [ From efec9f75aacc01b2a09c8365b73ea2ebcb26996e Mon Sep 17 00:00:00 2001 From: SmartLamScott Date: Mon, 6 Apr 2026 16:58:10 -0500 Subject: [PATCH 3/4] added contribution record for #14359 --- changelog/14359.improvement.rst | 2 ++ 1 file changed, 2 insertions(+) create mode 100644 changelog/14359.improvement.rst diff --git a/changelog/14359.improvement.rst b/changelog/14359.improvement.rst new file mode 100644 index 00000000000..2d786226e5f --- /dev/null +++ b/changelog/14359.improvement.rst @@ -0,0 +1,2 @@ +Updated pygments requirement to ``pygments>=2.20``. +This avoids a regular expression denial-of-service attack described in `CVE-2026-4539 `__. From 0f469753ce28c3b176b5c73bb44dc792be26e408 Mon Sep 17 00:00:00 2001 From: SmartLamScott Date: Mon, 6 Apr 2026 17:00:28 -0500 Subject: [PATCH 4/4] added Scott Ratchford to AUTHORS for #14359 --- AUTHORS | 1 + 1 file changed, 1 insertion(+) diff --git a/AUTHORS b/AUTHORS index 2f8e26b2cb1..915ad17ae18 100644 --- a/AUTHORS +++ b/AUTHORS @@ -423,6 +423,7 @@ Samuele Pedroni Sanket Duthade Sankt Petersbug Saravanan Padmanaban +Scott Ratchford Sean Malloy Segev Finer Serhii Mozghovyi