Skip to content

fix: bump pymdown-extensions and click to clear four advisories - #20

Merged
Navi Bot (project-navi-bot) merged 1 commit into
mainfrom
fix/pymdown-extensions-advisories
Oct 1, 2026
Merged

Navi Bot (project-navi-bot) merged 1 commit into
mainfrom
fix/pymdown-extensions-advisories

Conversation

@Fieldnote-Echo

Copy link
Copy Markdown
Member

Dependabot has three open alerts on pymdown-extensions 10.21.2 (one high, two medium; the highest fix is 11.0.1). pip-audit also flags click 8.3.1 (PYSEC-2026-2132, fixed in 8.3.3). Both come in through zensical in the docs group. uv resolves them to pymdown-extensions 12.1 and click 8.5.0, which drops colorama. After the change pip-audit finds no known vulnerabilities in the docs group and uv lock --check passes.

pymdown-extensions crosses two major versions. The docs workflow on this PR is the build check; I didn't build the site locally.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-30T22:58:00.663532Z 9f878c9 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@qodo-code-review

Copy link
Copy Markdown

PR Summary by Qodo

Update docs dependencies to clear four security advisories

🐞 Bug fix ⚙️ Configuration changes 🕐 10-20 Minutes

Grey Divider

AI Description

• Update locked pymdown-extensions and click versions to address four docs dependency advisories.
• Remove colorama, which is no longer required by the resolved click version.
• Rely on the PR docs workflow to check compatibility across the pymdown-extensions major-version
 upgrades.
Diagram

graph TD
  A["Docs group"] --> B["uv.lock"] --> C["Zensical"] --> F["Docs build"]
  C --> D["click 8.5.0"]
  C --> E["pymdown 12.1"]
Loading
High-Level Assessment

Keep the targeted lockfile refresh. Adding direct pins for transitive dependencies or upgrading Zensical would broaden the change without a demonstrated need; the existing PR docs build is the important compatibility check for the pymdown-extensions upgrade.

Files changed (1) +6 / -18

Other (1) +6 / -18
uv.lockRefresh vulnerable docs dependency resolutions +6/-18

Refresh vulnerable docs dependency resolutions

• Updates click from 8.3.1 to 8.5.0 and pymdown-extensions from 10.21.2 to 12.1, including their locked artifact URLs and hashes. Removes colorama because the newly resolved click version no longer requires it.

uv.lock

@qodo-code-review

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Grey Divider

Great, no issues found!

Qodo reviewed your code and found no material issues that require review

Grey Divider

Tip of the day
💡 Did you know, you can route each severity your way: inline, summary, both, or drop

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

@project-navi-bot
Navi Bot (project-navi-bot) merged commit d05c1c0 into main Oct 1, 2026
7 checks passed
@project-navi-bot
Navi Bot (project-navi-bot) deleted the fix/pymdown-extensions-advisories branch October 1, 2026 13:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants