From ac75d4957fa5b8ee8af9296651a55432055d16bf Mon Sep 17 00:00:00 2001 From: maziggy Date: Thu, 26 Mar 2026 13:52:52 +0100 Subject: [PATCH] Changed pipeline --- .github/workflows/security.yml | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index 01aea0df6..5ab7eef78 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -130,8 +130,10 @@ jobs: - name: Run pip-audit id: pip-audit run: | - pip-audit --desc on --format json --output pip-audit-results.json || echo "vulnerabilities_found=true" >> $GITHUB_OUTPUT - pip-audit --desc on || true + # CVE-2026-4539: low-severity ReDoS in Pygments AdlLexer (indirect dep via mkdocs-material/pytest/rich). + # No fix available yet. Remove --ignore-vuln once Pygments releases a patched version. + pip-audit --desc on --format json --output pip-audit-results.json --ignore-vuln CVE-2026-4539 || echo "vulnerabilities_found=true" >> $GITHUB_OUTPUT + pip-audit --desc on --ignore-vuln CVE-2026-4539 || true - name: Upload audit results if: always()