Parcourir la source

Changed pipeline

maziggy il y a 2 mois
Parent
commit
a699270c7a
1 fichiers modifiés avec 4 ajouts et 2 suppressions
  1. 4 2
      .github/workflows/security.yml

+ 4 - 2
.github/workflows/security.yml

@@ -130,8 +130,10 @@ jobs:
       - name: Run pip-audit
         id: pip-audit
         run: |
-          pip-audit --desc on --format json --output pip-audit-results.json || echo "vulnerabilities_found=true" >> $GITHUB_OUTPUT
-          pip-audit --desc on || true
+          # CVE-2026-4539: low-severity ReDoS in Pygments AdlLexer (indirect dep via mkdocs-material/pytest/rich).
+          # No fix available yet. Remove --ignore-vuln once Pygments releases a patched version.
+          pip-audit --desc on --format json --output pip-audit-results.json --ignore-vuln CVE-2026-4539 || echo "vulnerabilities_found=true" >> $GITHUB_OUTPUT
+          pip-audit --desc on --ignore-vuln CVE-2026-4539 || true
 
       - name: Upload audit results
         if: always()