pygments is not a direct dependency of Owncast Sentry. It is pulled in transitively by hatch and, ironically, pip-audit, both of which are dev dependencies. It is not present in the production runtime environment and is never invoked by Owncast Sentry itself, so this vulnerability has no impact on deployed instances.
The upstream issue has been reported at pygments/pygments#3058 but has not yet been addressed. There is no fixed version available at this time.
`pip-audit` flagged CVE-2026-4539 in `pygments`.
`pygments` is not a direct dependency of Owncast Sentry. It is pulled in transitively by `hatch` and, ironically, `pip-audit`, both of which are dev dependencies. It is not present in the production runtime environment and is never invoked by Owncast Sentry itself, so this vulnerability has no impact on deployed instances.
The upstream issue has been reported at [pygments/pygments#3058](https://github.com/pygments/pygments/issues/3058) but has not yet been addressed. There is no fixed version available at this time.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
pip-auditflagged CVE-2026-4539 inpygments.pygmentsis not a direct dependency of Owncast Sentry. It is pulled in transitively byhatchand, ironically,pip-audit, both of which are dev dependencies. It is not present in the production runtime environment and is never invoked by Owncast Sentry itself, so this vulnerability has no impact on deployed instances.The upstream issue has been reported at pygments/pygments#3058 but has not yet been addressed. There is no fixed version available at this time.