Skip to content

chore: bump pygments, requests, and cryptography versions#2404

Open
tonyandrewmeyer wants to merge 2 commits intocanonical:mainfrom
tonyandrewmeyer:bump-pygments-mar-2026
Open

chore: bump pygments, requests, and cryptography versions#2404
tonyandrewmeyer wants to merge 2 commits intocanonical:mainfrom
tonyandrewmeyer:bump-pygments-mar-2026

Conversation

@tonyandrewmeyer
Copy link
Copy Markdown
Collaborator

@tonyandrewmeyer tonyandrewmeyer commented Mar 30, 2026

pygments is used by pytest. This release fixes a security issue, but does have other changes (dropping Python 3.8 support, and a bunch more). See #2403 for more details. The security issue is not one that we are likely to be impacted by, but we might as well move to the new version, particularly since this is a CI/dev dependency.

Also bumps requests, which has another security issue that would also not impact us.

Also bumps cryptography, which has another security issue that as far as I can tell, likely also does not impact us.

(We could wait a week before merging this if we decided that was safer.)

@tonyandrewmeyer tonyandrewmeyer changed the title chore: bump pygments version to 2.20.0 chore: bump pygments, requests, and cryptography versions Mar 30, 2026
Copy link
Copy Markdown
Contributor

@james-garner-canonical james-garner-canonical left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for taking care of this. I guess we can discuss whether to wait in daily.

Copy link
Copy Markdown
Contributor

@dwilding dwilding left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I guess we ought to bump pygments in the Charmcraft profiles too? I can take care of that.

@dwilding
Copy link
Copy Markdown
Contributor

FYI here's the corresponding Charmcraft PR: canonical/charmcraft#2622

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants