Skip to content

Add initial support of CSS Notes - #2905

Merged
liZe merged 16 commits into
mainfrom
notes
Sep 7, 2026
Merged

liZe merged 16 commits into
mainfrom
notes

Conversation

@liZe

@liZe liZe commented Sep 2, 2026 •

Copy link
Copy Markdown
Member

This pull request adds an initial support of CSS Notes, including:

  • notes in the @note-area or in page margins,
  • the ::note-call, ::note-callback and ::note-marker pseudo-elements,
  • note counters,
  • links on call and callback elements,
  • the note() function,
  • the all-once parameter of the element() function.

It does not include other features, defined in this specification draft or elsewhere, including:

  • the note-policy property,
  • named page areas,
  • complex cases of reported notes,
  • notes split between multiple areas,
  • page floats.

@liZe liZe added the feature New feature that should be supported label Sep 2, 2026
@liZe liZe added this to the 70.0 milestone Sep 2, 2026
@liZe
liZe marked this pull request as ready for review September 7, 2026 15:04
@liZe
liZe merged commit 371e4de into main Sep 7, 2026
17 checks passed
@liZe
liZe deleted the notes branch September 7, 2026 15:04
@grewn0uille grewn0uille added the sponsored Issues sponsored to be resolved faster label Sep 7, 2026
yyyyyyyan added a commit to percona/pmm-extensions that referenced this pull request Sep 12, 2026
Bumps [weasyprint](https://github.com/Kozea/WeasyPrint) from 69.0 to
70.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/Kozea/WeasyPrint/releases">weasyprint's
releases</a>.</em></p>
<blockquote>
<h2>v70.0</h2>
<p>Read about this release <a
href="https://www.courtbouillon.org/blog/00074-weasyprint-70/">on our
blog</a>.</p>
<p><strong>This is a security update (CVE-2026-55073,
GHSA-r543-q48m-4c9j).</strong></p>
<p>We strongly recommend to upgrade WeasyPrint to the latest version if
you: * embed untrusted images, or * rely on the URL fetcher to filter
metadata or stylesheets passed as Python parameters.</p>
<h2>Security</h2>
<ul>
<li>Don’t render EPS images.</li>
<li>Always use original URL fetcher when available.</li>
</ul>
<h2>Features</h2>
<ul>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2905">#2905</a>:
Add initial support of CSS Notes, with financial support from NLnet</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2731">#2731</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2781">#2781</a>:
Log an error on unknown render and write_pdf options</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2802">#2802</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2805">#2805</a>:
Create immutable releases on GitHub</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2809">#2809</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2810">#2810</a>:
Switch to MSYS2 UCRT64 environment for Windows tests and
executables</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2777">#2777</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2814">#2814</a>:
Support COLR emoji fonts</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2667">#2667</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2744">#2744</a>:
Support context paint in SVG markers</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/1862">#1862</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2844">#2844</a>:
Improve filename detection for attachments</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2816">#2816</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2827">#2827</a>:
Set SVG title as alternative text</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2718">#2718</a>:
Provide a 'onedir' Windows executable</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2863">#2863</a>:
Support box-shadow</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2755">#2755</a>:
Support RTL SVG text anchoring</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2866">#2866</a>:
Don’t use f-strings in logs</li>
</ul>
<h2>Bug fixes</h2>
<ul>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2799">#2799</a>:
Keep HarfBuzz font faces alive during PDF subsetting</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2764">#2764</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2793">#2793</a>:
Accept Path as base URL in CSS</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2800">#2800</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2801">#2801</a>:
Fix position of raster emojis</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2782">#2782</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2807">#2807</a>:
Use POSIX paths in Fontconfig</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2766">#2766</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2779">#2779</a>:
Use response bytes when image file path doesn’t exist</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2277">#2277</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2728">#2728</a>:
Honor page breaks on floated elements</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2789">#2789</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2818">#2818</a>:
Use base URL when solving pending properties</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2820">#2820</a>:
Ignore unresolvable math in image slices</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2901">#2901</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2825">#2825</a>:
Transform SVG size into CSS to apply CSS sizing algorithm</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2819">#2819</a>:
Resolve calc() division by zero to infinity</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2824">#2824</a>:
Remove old deprecation warnings</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2762">#2762</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2780">#2780</a>:
Set SVG gradient color before path construction</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2761">#2761</a>:
Handle split tables with captions</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2215">#2215</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2747">#2747</a>:
Discard broken at-rules</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2736">#2736</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2738">#2738</a>:
Apply transformations to SVG opacity groups</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2830">#2830</a>:
Use a stack to draw simple borders</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2831">#2831</a>:
Fix line_height() crash on calc() values</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2784">#2784</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2832">#2832</a>:
Set fallback font for Unicode test</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2726">#2726</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2881">#2881</a>:
Improve accessibility of PDF forms</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2803">#2803</a>:
Fix inline width after backtracked line breaks</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2833">#2833</a>:
Store root style in anonymous style</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/Kozea/WeasyPrint/blob/main/docs/changelog.rst">weasyprint's
changelog</a>.</em></p>
<blockquote>
<h2>Version 70.0</h2>
<p>Released on 2026-09-08.</p>
<p><strong>This is a security update (CVE-2026-55073,
GHSA-r543-q48m-4c9j).</strong></p>
<p>We strongly recommend to upgrade WeasyPrint to the latest version if
you:</p>
<ul>
<li>embed untrusted images, or</li>
<li>rely on the URL fetcher to filter metadata or stylesheets passed as
Python parameters.</li>
</ul>
<p>Security:</p>
<ul>
<li>Don’t render EPS images.</li>
<li>Always use original URL fetcher when available.</li>
</ul>
<p>Features:</p>
<ul>
<li><code>[#2905](Kozea/WeasyPrint#2905)
&lt;https://github.com/Kozea/WeasyPrint/pull/2905&gt;</code>_:
Add initial support of CSS Notes, with financial support from NLnet</li>
<li><code>[#2731](Kozea/WeasyPrint#2731)
&lt;https://github.com/Kozea/WeasyPrint/issues/2731&gt;</code><em>,
<code>[#2781](Kozea/WeasyPrint#2781)
&lt;https://github.com/Kozea/WeasyPrint/pull/2781&gt;</code></em>:
Log an error on unknown render and write_pdf options</li>
<li><code>[#2802](Kozea/WeasyPrint#2802)
&lt;https://github.com/Kozea/WeasyPrint/issues/2802&gt;</code><em>,
<code>[#2805](Kozea/WeasyPrint#2805)
&lt;https://github.com/Kozea/WeasyPrint/pull/2805&gt;</code></em>:
Create immutable releases on GitHub</li>
<li><code>[#2809](Kozea/WeasyPrint#2809)
&lt;https://github.com/Kozea/WeasyPrint/issues/2809&gt;</code><em>,
<code>[#2810](Kozea/WeasyPrint#2810)
&lt;https://github.com/Kozea/WeasyPrint/pull/2810&gt;</code></em>:
Switch to MSYS2 UCRT64 environment for Windows tests and
executables</li>
<li><code>[#2777](Kozea/WeasyPrint#2777)
&lt;https://github.com/Kozea/WeasyPrint/issues/2777&gt;</code><em>,
<code>[#2814](Kozea/WeasyPrint#2814)
&lt;https://github.com/Kozea/WeasyPrint/pull/2814&gt;</code></em>:
Support COLR emoji fonts</li>
<li><code>[#2667](Kozea/WeasyPrint#2667)
&lt;https://github.com/Kozea/WeasyPrint/issues/2667&gt;</code><em>,
<code>[#2744](Kozea/WeasyPrint#2744)
&lt;https://github.com/Kozea/WeasyPrint/pull/2744&gt;</code></em>:
Support context paint in SVG markers</li>
<li><code>[#1862](Kozea/WeasyPrint#1862)
&lt;https://github.com/Kozea/WeasyPrint/issues/1862&gt;</code><em>,
<code>[#2844](Kozea/WeasyPrint#2844)
&lt;https://github.com/Kozea/WeasyPrint/pull/2844&gt;</code></em>:
Improve filename detection for attachments</li>
<li><code>[#2816](Kozea/WeasyPrint#2816)
&lt;https://github.com/Kozea/WeasyPrint/issues/2816&gt;</code><em>,
<code>[#2827](Kozea/WeasyPrint#2827)
&lt;https://github.com/Kozea/WeasyPrint/pull/2827&gt;</code></em>:
Set SVG title as alternative text</li>
<li><code>[#2718](Kozea/WeasyPrint#2718)
&lt;https://github.com/Kozea/WeasyPrint/issues/2718&gt;</code>_:
Provide a 'onedir' Windows executable</li>
<li><code>[#2863](Kozea/WeasyPrint#2863)
&lt;https://github.com/Kozea/WeasyPrint/pull/2863&gt;</code>_:
Support box-shadow</li>
<li><code>[#2755](Kozea/WeasyPrint#2755)
&lt;https://github.com/Kozea/WeasyPrint/pull/2755&gt;</code>_:
Support RTL SVG text anchoring</li>
<li><code>[#2866](Kozea/WeasyPrint#2866)
&lt;https://github.com/Kozea/WeasyPrint/issues/2866&gt;</code>_:
Don’t use f-strings in logs</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/4d3b7b6449e3494f59c7c2f36b512d129225679c"><code>4d3b7b6</code></a>
Version 70.0</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/289e278439b017cd9263b4cd4727026987f86443"><code>289e278</code></a>
Always use original URL fetcher when available</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/aeb3be74e3c904e4b772014006410e23e0512b4b"><code>aeb3be7</code></a>
Merge remote-tracking branch 'security/main'</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/48357241f949c3f6880ec1a40f56d2f5106fdef3"><code>4835724</code></a>
Merge pull request <a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2915">#2915</a>
from havelaer/fix-nested-svg-viewport-restore</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/03310511d8afac08f80939e7fa317ad6051e251f"><code>0331051</code></a>
Restore nested SVG viewport size on the SVG object, not the drawing
function</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/e4b8b45e409392197441bc449d110f323b0eeb66"><code>e4b8b45</code></a>
Add harfbuzz-vector requirement for Fedora</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/371e4debb4805fa3d5a138f2cbb044fc176284da"><code>371e4de</code></a>
Merge pull request <a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2905">#2905</a>
from Kozea/notes</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/590bf63301d77eaf6aac6b1eb3a3fbb9494e3b23"><code>590bf63</code></a>
Merge pull request <a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2913">#2913</a>
from Kozea/fast-svg-paths</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/f6570c3038b60695f715b12c7805f6933e58490a"><code>f6570c3</code></a>
Use a faster regex-based parser for SVG paths</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/bc0516240c5f8a1eaaf658621d52a09eebecdea9"><code>bc05162</code></a>
Use faster deque for SVG vertices</li>
<li>Additional commits viewable in <a
href="https://github.com/Kozea/WeasyPrint/compare/v69.0...v70.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=weasyprint&package-manager=pip&previous-version=69.0&new-version=70.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts page](https://github.com/percona/SEP/network/alerts).

</details>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Yan Orestes <yan.orestes@percona.com>
EgorPopelyaev pushed a commit to paritytech/release-registry that referenced this pull request Sep 15, 2026
Bumps [weasyprint](https://github.com/Kozea/WeasyPrint) from 68.0 to
70.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/Kozea/WeasyPrint/releases">weasyprint's
releases</a>.</em></p>
<blockquote>
<h2>v70.0</h2>
<p>Read about this release <a
href="https://www.courtbouillon.org/blog/00074-weasyprint-70/">on our
blog</a>.</p>
<p><strong>This is a security update (CVE-2026-55073,
GHSA-r543-q48m-4c9j).</strong></p>
<p>We strongly recommend to upgrade WeasyPrint to the latest version if
you: * embed untrusted images, or * rely on the URL fetcher to filter
metadata or stylesheets passed as Python parameters.</p>
<h2>Security</h2>
<ul>
<li>Don’t render EPS images.</li>
<li>Always use original URL fetcher when available.</li>
</ul>
<h2>Features</h2>
<ul>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2905">#2905</a>:
Add initial support of CSS Notes, with financial support from NLnet</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2731">#2731</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2781">#2781</a>:
Log an error on unknown render and write_pdf options</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2802">#2802</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2805">#2805</a>:
Create immutable releases on GitHub</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2809">#2809</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2810">#2810</a>:
Switch to MSYS2 UCRT64 environment for Windows tests and
executables</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2777">#2777</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2814">#2814</a>:
Support COLR emoji fonts</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2667">#2667</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2744">#2744</a>:
Support context paint in SVG markers</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/1862">#1862</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2844">#2844</a>:
Improve filename detection for attachments</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2816">#2816</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2827">#2827</a>:
Set SVG title as alternative text</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2718">#2718</a>:
Provide a 'onedir' Windows executable</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2863">#2863</a>:
Support box-shadow</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2755">#2755</a>:
Support RTL SVG text anchoring</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2866">#2866</a>:
Don’t use f-strings in logs</li>
</ul>
<h2>Bug fixes</h2>
<ul>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2799">#2799</a>:
Keep HarfBuzz font faces alive during PDF subsetting</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2764">#2764</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2793">#2793</a>:
Accept Path as base URL in CSS</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2800">#2800</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2801">#2801</a>:
Fix position of raster emojis</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2782">#2782</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2807">#2807</a>:
Use POSIX paths in Fontconfig</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2766">#2766</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2779">#2779</a>:
Use response bytes when image file path doesn’t exist</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2277">#2277</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2728">#2728</a>:
Honor page breaks on floated elements</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2789">#2789</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2818">#2818</a>:
Use base URL when solving pending properties</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2820">#2820</a>:
Ignore unresolvable math in image slices</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2901">#2901</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2825">#2825</a>:
Transform SVG size into CSS to apply CSS sizing algorithm</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2819">#2819</a>:
Resolve calc() division by zero to infinity</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2824">#2824</a>:
Remove old deprecation warnings</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2762">#2762</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2780">#2780</a>:
Set SVG gradient color before path construction</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2761">#2761</a>:
Handle split tables with captions</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2215">#2215</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2747">#2747</a>:
Discard broken at-rules</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2736">#2736</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2738">#2738</a>:
Apply transformations to SVG opacity groups</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2830">#2830</a>:
Use a stack to draw simple borders</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2831">#2831</a>:
Fix line_height() crash on calc() values</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2784">#2784</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2832">#2832</a>:
Set fallback font for Unicode test</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2726">#2726</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2881">#2881</a>:
Improve accessibility of PDF forms</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2803">#2803</a>:
Fix inline width after backtracked line breaks</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2833">#2833</a>:
Store root style in anonymous style</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/Kozea/WeasyPrint/blob/main/docs/changelog.rst">weasyprint's
changelog</a>.</em></p>
<blockquote>
<h2>Version 70.0</h2>
<p>Released on 2026-09-08.</p>
<p><strong>This is a security update (CVE-2026-55073,
GHSA-r543-q48m-4c9j).</strong></p>
<p>We strongly recommend to upgrade WeasyPrint to the latest version if
you:</p>
<ul>
<li>embed untrusted images, or</li>
<li>rely on the URL fetcher to filter metadata or stylesheets passed as
Python parameters.</li>
</ul>
<p>Security:</p>
<ul>
<li>Don’t render EPS images.</li>
<li>Always use original URL fetcher when available.</li>
</ul>
<p>Features:</p>
<ul>
<li><code>[#2905](Kozea/WeasyPrint#2905)
&lt;https://github.com/Kozea/WeasyPrint/pull/2905&gt;</code>_:
Add initial support of CSS Notes, with financial support from NLnet</li>
<li><code>[#2731](Kozea/WeasyPrint#2731)
&lt;https://github.com/Kozea/WeasyPrint/issues/2731&gt;</code><em>,
<code>[#2781](Kozea/WeasyPrint#2781)
&lt;https://github.com/Kozea/WeasyPrint/pull/2781&gt;</code></em>:
Log an error on unknown render and write_pdf options</li>
<li><code>[#2802](Kozea/WeasyPrint#2802)
&lt;https://github.com/Kozea/WeasyPrint/issues/2802&gt;</code><em>,
<code>[#2805](Kozea/WeasyPrint#2805)
&lt;https://github.com/Kozea/WeasyPrint/pull/2805&gt;</code></em>:
Create immutable releases on GitHub</li>
<li><code>[#2809](Kozea/WeasyPrint#2809)
&lt;https://github.com/Kozea/WeasyPrint/issues/2809&gt;</code><em>,
<code>[#2810](Kozea/WeasyPrint#2810)
&lt;https://github.com/Kozea/WeasyPrint/pull/2810&gt;</code></em>:
Switch to MSYS2 UCRT64 environment for Windows tests and
executables</li>
<li><code>[#2777](Kozea/WeasyPrint#2777)
&lt;https://github.com/Kozea/WeasyPrint/issues/2777&gt;</code><em>,
<code>[#2814](Kozea/WeasyPrint#2814)
&lt;https://github.com/Kozea/WeasyPrint/pull/2814&gt;</code></em>:
Support COLR emoji fonts</li>
<li><code>[#2667](Kozea/WeasyPrint#2667)
&lt;https://github.com/Kozea/WeasyPrint/issues/2667&gt;</code><em>,
<code>[#2744](Kozea/WeasyPrint#2744)
&lt;https://github.com/Kozea/WeasyPrint/pull/2744&gt;</code></em>:
Support context paint in SVG markers</li>
<li><code>[#1862](Kozea/WeasyPrint#1862)
&lt;https://github.com/Kozea/WeasyPrint/issues/1862&gt;</code><em>,
<code>[#2844](Kozea/WeasyPrint#2844)
&lt;https://github.com/Kozea/WeasyPrint/pull/2844&gt;</code></em>:
Improve filename detection for attachments</li>
<li><code>[#2816](Kozea/WeasyPrint#2816)
&lt;https://github.com/Kozea/WeasyPrint/issues/2816&gt;</code><em>,
<code>[#2827](Kozea/WeasyPrint#2827)
&lt;https://github.com/Kozea/WeasyPrint/pull/2827&gt;</code></em>:
Set SVG title as alternative text</li>
<li><code>[#2718](Kozea/WeasyPrint#2718)
&lt;https://github.com/Kozea/WeasyPrint/issues/2718&gt;</code>_:
Provide a 'onedir' Windows executable</li>
<li><code>[#2863](Kozea/WeasyPrint#2863)
&lt;https://github.com/Kozea/WeasyPrint/pull/2863&gt;</code>_:
Support box-shadow</li>
<li><code>[#2755](Kozea/WeasyPrint#2755)
&lt;https://github.com/Kozea/WeasyPrint/pull/2755&gt;</code>_:
Support RTL SVG text anchoring</li>
<li><code>[#2866](Kozea/WeasyPrint#2866)
&lt;https://github.com/Kozea/WeasyPrint/issues/2866&gt;</code>_:
Don’t use f-strings in logs</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/4d3b7b6449e3494f59c7c2f36b512d129225679c"><code>4d3b7b6</code></a>
Version 70.0</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/289e278439b017cd9263b4cd4727026987f86443"><code>289e278</code></a>
Always use original URL fetcher when available</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/aeb3be74e3c904e4b772014006410e23e0512b4b"><code>aeb3be7</code></a>
Merge remote-tracking branch 'security/main'</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/48357241f949c3f6880ec1a40f56d2f5106fdef3"><code>4835724</code></a>
Merge pull request <a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2915">#2915</a>
from havelaer/fix-nested-svg-viewport-restore</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/03310511d8afac08f80939e7fa317ad6051e251f"><code>0331051</code></a>
Restore nested SVG viewport size on the SVG object, not the drawing
function</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/e4b8b45e409392197441bc449d110f323b0eeb66"><code>e4b8b45</code></a>
Add harfbuzz-vector requirement for Fedora</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/371e4debb4805fa3d5a138f2cbb044fc176284da"><code>371e4de</code></a>
Merge pull request <a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2905">#2905</a>
from Kozea/notes</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/590bf63301d77eaf6aac6b1eb3a3fbb9494e3b23"><code>590bf63</code></a>
Merge pull request <a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2913">#2913</a>
from Kozea/fast-svg-paths</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/f6570c3038b60695f715b12c7805f6933e58490a"><code>f6570c3</code></a>
Use a faster regex-based parser for SVG paths</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/bc0516240c5f8a1eaaf658621d52a09eebecdea9"><code>bc05162</code></a>
Use faster deque for SVG vertices</li>
<li>Additional commits viewable in <a
href="https://github.com/Kozea/WeasyPrint/compare/v68.0...v70.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=weasyprint&package-manager=pip&previous-version=68.0&new-version=70.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/paritytech/release-registry/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Spigushe added a commit to Spigushe/barrins-project that referenced this pull request Sep 17, 2026
…pdates (#152)

[//]: # (dependabot-start)
⚠️  **Dependabot is rebasing this PR** ⚠️ 

Rebasing might not happen immediately, so don't worry if this takes some
time.

Note: if you make any changes to this PR yourself, they will take
precedence over the rebase.

---

[//]: # (dependabot-end)

Bumps the all-updates group with 6 updates in the /apps/barrins_api
directory:

| Package | From | To |
| --- | --- | --- |
| [psycopg2-binary](https://github.com/psycopg/psycopg2) | `2.9.12` |
`2.9.13` |
| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.13.0` | `2.14.0` |
| [weasyprint](https://github.com/Kozea/WeasyPrint) | `69.0` | `70.0` |
| [alembic](https://github.com/sqlalchemy/alembic) | `1.19.2` | `1.20.0`
|
| [ruff](https://github.com/astral-sh/ruff) | `0.16.6` | `0.16.7` |
| [ty](https://github.com/astral-sh/ty) | `0.0.78` | `0.0.80` |

Bumps the all-updates group with 5 updates in the /apps/barrins_identity
directory:

| Package | From | To |
| --- | --- | --- |
| [psycopg2-binary](https://github.com/psycopg/psycopg2) | `2.9.12` |
`2.9.13` |
| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.13.0` | `2.14.0` |
| [alembic](https://github.com/sqlalchemy/alembic) | `1.19.2` | `1.20.0`
|
| [ruff](https://github.com/astral-sh/ruff) | `0.16.6` | `0.16.7` |
| [ty](https://github.com/astral-sh/ty) | `0.0.78` | `0.0.80` |

Bumps the all-updates group with 3 updates in the
/apps/barrins_scripture directory:
[ruff](https://github.com/astral-sh/ruff),
[ty](https://github.com/astral-sh/ty) and
[selenium](https://github.com/SeleniumHQ/Selenium).
Bumps the all-updates group with 5 updates in the /apps/karn_tablets
directory:

| Package | From | To |
| --- | --- | --- |
| [psycopg2-binary](https://github.com/psycopg/psycopg2) | `2.9.12` |
`2.9.13` |
| [ruff](https://github.com/astral-sh/ruff) | `0.16.6` | `0.16.7` |
| [ty](https://github.com/astral-sh/ty) | `0.0.78` | `0.0.80` |
| [numpy](https://github.com/numpy/numpy) | `2.5.2` | `2.5.3` |
| [scikit-learn](https://github.com/scikit-learn/scikit-learn) | `1.9.0`
| `1.9.1` |


Updates `psycopg2-binary` from 2.9.12 to 2.9.13
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/psycopg/psycopg2/blob/master/NEWS">psycopg2-binary's
changelog</a>.</em></p>
<blockquote>
<h2>Current release</h2>
<p>What's new in psycopg 2.9.13
^^^^^^^^^^^^^^^^^^^^^^^^^^^^</p>
<ul>
<li>Add support for Python 3.15
(:ticket:<code>[#1848](https://github.com/psycopg/psycopg2/issues/1848)</code>).</li>
<li>Fix parsing of malformed bytea input.</li>
<li>Fix parsing of malformed int64 input in arrays
(:ticket:<code>[#1847](https://github.com/psycopg/psycopg2/issues/1847)</code>).</li>
<li>Add a <code>pyproject.toml</code> file to declare a PEP 517 build
backend

(:ticket:<code>[#1788](https://github.com/psycopg/psycopg2/issues/1788)</code>).</li>
<li>Drop support for Python 3.9.</li>
</ul>
<p>What's new in psycopg 2.9.12
^^^^^^^^^^^^^^^^^^^^^^^^^^^^</p>
<ul>
<li>Fix infinite loop with malformed interval
(:ticket:<code>1835</code>).</li>
</ul>
<p>What's new in psycopg 2.9.11
^^^^^^^^^^^^^^^^^^^^^^^^^^^^</p>
<ul>
<li>Add support for Python 3.14.</li>
<li>Avoid a segfault passing more arguments than placeholders if Python
is built
with assertions enabled
(:ticket:<code>[#1791](https://github.com/psycopg/psycopg2/issues/1791)</code>).</li>
<li>Add riscv64 platform binary packages
(:ticket:<code>[#1813](https://github.com/psycopg/psycopg2/issues/1813)</code>).</li>
<li><code>~psycopg2.errorcodes</code> map and
<code>~psycopg2.errors</code> classes updated to
PostgreSQL 18.</li>
<li>Drop support for Python 3.8.</li>
</ul>
<p>What's new in psycopg 2.9.10
^^^^^^^^^^^^^^^^^^^^^^^^^^^^</p>
<ul>
<li>Add support for Python 3.13.</li>
<li>Receive notifications on commit
(:ticket:<code>[#1728](https://github.com/psycopg/psycopg2/issues/1728)</code>).</li>
<li><code>~psycopg2.errorcodes</code> map and
<code>~psycopg2.errors</code> classes updated to
PostgreSQL 17.</li>
<li>Drop support for Python 3.7.</li>
</ul>
<p>What's new in psycopg 2.9.9
^^^^^^^^^^^^^^^^^^^^^^^^^^^</p>
<ul>
<li>Add support for Python 3.12.</li>
<li>Drop support for Python 3.6.</li>
</ul>
<p>What's new in psycopg 2.9.8</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/psycopg/psycopg2/commit/f650e7afed0c94f596594e8328a0c7fa65a9d0e5"><code>f650e7a</code></a>
chore: bump to release 2.9.13</li>
<li><a
href="https://github.com/psycopg/psycopg2/commit/368c8a1ca6d80088703a693ce64b68ad7d346698"><code>368c8a1</code></a>
chore!: drop support for Python 3.9</li>
<li><a
href="https://github.com/psycopg/psycopg2/commit/9b39e65ab232f0a267a278cdaef1bd9975d88c65"><code>9b39e65</code></a>
chore: drop scaleway build support</li>
<li><a
href="https://github.com/psycopg/psycopg2/commit/2ca70416be6d4d3d8170ec439876c0b3569af718"><code>2ca7041</code></a>
fix: fix handling of PostgreSQL 18 exceptions</li>
<li><a
href="https://github.com/psycopg/psycopg2/commit/5385c027ef62ce14e57a7379e0375868507d6746"><code>5385c02</code></a>
Build CPython 3.15 wheels</li>
<li><a
href="https://github.com/psycopg/psycopg2/commit/1d32e1f6678ffa8ab8897ca81826bf4dde6354cd"><code>1d32e1f</code></a>
ci: only attempt triggering documentation refresh when pushing on main
repo</li>
<li><a
href="https://github.com/psycopg/psycopg2/commit/433e7b77a7b700fbb1cdc6e9dca6b5948d07fc23"><code>433e7b7</code></a>
chore: add pyproject.toml file to declare a PEP 517 build backend</li>
<li><a
href="https://github.com/psycopg/psycopg2/commit/8fb80bc3b2c358f4e3c54e33a37326d3f8b3ff6a"><code>8fb80bc</code></a>
fix: fix parsing of malformed int64 input in arrays</li>
<li><a
href="https://github.com/psycopg/psycopg2/commit/f98014a46a1e34f024ebd6134d1d87b77490c500"><code>f98014a</code></a>
fix: fix parsing of malformed bytea input</li>
<li><a
href="https://github.com/psycopg/psycopg2/commit/822b79cfe12ca0a04482acd382cae669a16aa789"><code>822b79c</code></a>
chore: bump dependencies in binary package</li>
<li>Additional commits viewable in <a
href="https://github.com/psycopg/psycopg2/compare/2.9.12...2.9.13">compare
view</a></li>
</ul>
</details>
<br />

Updates `pyjwt` from 2.13.0 to 2.14.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/jpadilla/pyjwt/releases">pyjwt's
releases</a>.</em></p>
<blockquote>
<h2>PyJWT 2.14.0</h2>
<p>See the <a
href="https://github.com/jpadilla/pyjwt/blob/2.14.0/CHANGELOG.rst">2.14.0
changelog</a> for the complete release details and related security
advisories.</p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst">pyjwt's
changelog</a>.</em></p>
<blockquote>
<h2><code>v2.14.0
&lt;https://github.com/jpadilla/pyjwt/compare/2.13.0...2.14.0&gt;</code>__</h2>
<p>Security</p>
<pre><code>
- Harden HMAC key validation against public-key material supplied as
JWK,
  JWKS, array, encoded, BOM-prefixed, DER, or PEM input. See
`GHSA-r6x4-923q-g947
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-r6x4-923q-g947&gt;`__,
`GHSA-ffc3-869f-jxw9
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-ffc3-869f-jxw9&gt;`__,
`GHSA-p4g4-x82p-q773
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-p4g4-x82p-q773&gt;`__,
and `GHSA-w2cx-738m-mc7w
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w2cx-738m-mc7w&gt;`__.
- Reject automatic redirects when ``PyJWKClient`` fetches a JWKS,
preventing
  redirected destinations from being treated as trusted key sources. See
`GHSA-9v7f-9g4p-ffgj
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-9v7f-9g4p-ffgj&gt;`__.
- Limit repeated JWKS refreshes caused by unknown key IDs while
preserving
  normal key-rotation behavior. See
`GHSA-2gx3-rcp4-g85q
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-2gx3-rcp4-g85q&gt;`__.
- Handle deeply nested and malformed JWS/JWK input without uncaught
recursion
  errors or whole-set parsing failures. See
`GHSA-8wjv-2p76-3863
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-8wjv-2p76-3863&gt;`__
and `GHSA-w6j9-cwv2-h6wq
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w6j9-cwv2-h6wq&gt;`__.
- Enforce compact JWS encoding rules during decoding. See
`GHSA-hxm8-2xgr-2p9m
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-hxm8-2xgr-2p9m&gt;`__.
- Reject detached-payload arguments for attached JWS inputs. Thanks to
`@xclow3n
&lt;https://github.com/xclow3n&gt;`__ for reporting this behavior; fixed
in commit
`37b54877
&lt;https://github.com/jpadilla/pyjwt/commit/37b54877bf7bea67e8149130e96929e3ec798122&gt;`__.
<p>Fixed</p>
<pre><code>
- Apply HMAC key validation consistently when keys are loaded through
  ``PyJWK`` and ``PyJWKClient``. See
`GHSA-pxh4-856f-4h89
&amp;lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-pxh4-856f-4h89&amp;gt;`__.
- Reject empty HMAC keys when represented as JWKs.
See `GHSA-pxh4-856f-4h89
&amp;lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-pxh4-856f-4h89&amp;gt;`__.

Fixed
</code></pre>
<ul>
<li>Raise the documented <code>PyJWTError</code> subclass instead of
leaking a<br />
<code>TypeError</code> when the <code>exp</code>, <code>nbf</code>, or
<code>iat</code> claim decodes to a<br />
non-numeric, non-string value such as a list, dict, or
<code>null</code>.<br />
</code></pre></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/c6fe464b356ff4b1ebc9ba62172d331a40aa27df"><code>c6fe464</code></a>
release: prepare v2.14.0</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/f5413029ae7a2e31b1367b5303ea86a2f54ccf42"><code>f541302</code></a>
style: apply Ruff formatting</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/801cd128528c62d9b23fcd161d1a2e1c17982f95"><code>801cd12</code></a>
fix: reject public JWK container HMAC keys</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/af8181ca0bec5e6b372fbba9afbe23702b787ceb"><code>af8181c</code></a>
fix: reject empty HMAC keys from JWKs</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/ba4853a75fb9676362da17f67d0f64bd18afd4e1"><code>ba4853a</code></a>
Throttle repeated PyJWKClient refreshes</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/2798504fa2663364573cf2d1043d8d7fef389499"><code>2798504</code></a>
fix: reject DER public keys as HMAC secrets</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/8b4e233a22206b34ec1186e912e75c0b2396ac07"><code>8b4e233</code></a>
fix: reject loader-accepted PEM variants</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/1f8180a211256dfe5cf32294b6753f554a5a4258"><code>1f8180a</code></a>
fix: format JWS tests</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/cff1ac55fe5f1096fd05295b269fce053ee290ab"><code>cff1ac5</code></a>
Fix redirect handler return annotation</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/0a795b8e1f6ef08f634aa7086fc41cc6d5ce3e56"><code>0a795b8</code></a>
Reject redirects in PyJWKClient fetches</li>
<li>Additional commits viewable in <a
href="https://github.com/jpadilla/pyjwt/compare/2.13.0...2.14.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `weasyprint` from 69.0 to 70.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/Kozea/WeasyPrint/releases">weasyprint's
releases</a>.</em></p>
<blockquote>
<h2>v70.0</h2>
<p>Read about this release <a
href="https://www.courtbouillon.org/blog/00074-weasyprint-70/">on our
blog</a>.</p>
<p><strong>This is a security update (CVE-2026-55073,
GHSA-r543-q48m-4c9j).</strong></p>
<p>We strongly recommend to upgrade WeasyPrint to the latest version if
you: * embed untrusted images, or * rely on the URL fetcher to filter
metadata or stylesheets passed as Python parameters.</p>
<h2>Security</h2>
<ul>
<li>Don’t render EPS images.</li>
<li>Always use original URL fetcher when available.</li>
</ul>
<h2>Features</h2>
<ul>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2905">#2905</a>:
Add initial support of CSS Notes, with financial support from NLnet</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2731">#2731</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2781">#2781</a>:
Log an error on unknown render and write_pdf options</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2802">#2802</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2805">#2805</a>:
Create immutable releases on GitHub</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2809">#2809</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2810">#2810</a>:
Switch to MSYS2 UCRT64 environment for Windows tests and
executables</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2777">#2777</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2814">#2814</a>:
Support COLR emoji fonts</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2667">#2667</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2744">#2744</a>:
Support context paint in SVG markers</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/1862">#1862</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2844">#2844</a>:
Improve filename detection for attachments</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2816">#2816</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2827">#2827</a>:
Set SVG title as alternative text</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2718">#2718</a>:
Provide a 'onedir' Windows executable</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2863">#2863</a>:
Support box-shadow</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2755">#2755</a>:
Support RTL SVG text anchoring</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2866">#2866</a>:
Don’t use f-strings in logs</li>
</ul>
<h2>Bug fixes</h2>
<ul>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2799">#2799</a>:
Keep HarfBuzz font faces alive during PDF subsetting</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2764">#2764</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2793">#2793</a>:
Accept Path as base URL in CSS</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2800">#2800</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2801">#2801</a>:
Fix position of raster emojis</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2782">#2782</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2807">#2807</a>:
Use POSIX paths in Fontconfig</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2766">#2766</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2779">#2779</a>:
Use response bytes when image file path doesn’t exist</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2277">#2277</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2728">#2728</a>:
Honor page breaks on floated elements</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2789">#2789</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2818">#2818</a>:
Use base URL when solving pending properties</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2820">#2820</a>:
Ignore unresolvable math in image slices</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2901">#2901</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2825">#2825</a>:
Transform SVG size into CSS to apply CSS sizing algorithm</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2819">#2819</a>:
Resolve calc() division by zero to infinity</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2824">#2824</a>:
Remove old deprecation warnings</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2762">#2762</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2780">#2780</a>:
Set SVG gradient color before path construction</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2761">#2761</a>:
Handle split tables with captions</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2215">#2215</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2747">#2747</a>:
Discard broken at-rules</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2736">#2736</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2738">#2738</a>:
Apply transformations to SVG opacity groups</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2830">#2830</a>:
Use a stack to draw simple borders</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2831">#2831</a>:
Fix line_height() crash on calc() values</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2784">#2784</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2832">#2832</a>:
Set fallback font for Unicode test</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2726">#2726</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2881">#2881</a>:
Improve accessibility of PDF forms</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2803">#2803</a>:
Fix inline width after backtracked line breaks</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2833">#2833</a>:
Store root style in anonymous style</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/Kozea/WeasyPrint/blob/main/docs/changelog.rst">weasyprint's
changelog</a>.</em></p>
<blockquote>
<h2>Version 70.0</h2>
<p>Released on 2026-09-08.</p>
<p><strong>This is a security update (CVE-2026-55073,
GHSA-r543-q48m-4c9j).</strong></p>
<p>We strongly recommend to upgrade WeasyPrint to the latest version if
you:</p>
<ul>
<li>embed untrusted images, or</li>
<li>rely on the URL fetcher to filter metadata or stylesheets passed as
Python parameters.</li>
</ul>
<p>Security:</p>
<ul>
<li>Don’t render EPS images.</li>
<li>Always use original URL fetcher when available.</li>
</ul>
<p>Features:</p>
<ul>
<li><code>[#2905](https://github.com/Kozea/WeasyPrint/issues/2905)
&lt;https://github.com/Kozea/WeasyPrint/pull/2905&gt;</code>_:
Add initial support of CSS Notes, with financial support from NLnet</li>
<li><code>[#2731](https://github.com/Kozea/WeasyPrint/issues/2731)
&lt;https://github.com/Kozea/WeasyPrint/issues/2731&gt;</code><em>,
<code>[#2781](https://github.com/Kozea/WeasyPrint/issues/2781)
&lt;https://github.com/Kozea/WeasyPrint/pull/2781&gt;</code></em>:
Log an error on unknown render and write_pdf options</li>
<li><code>[#2802](https://github.com/Kozea/WeasyPrint/issues/2802)
&lt;https://github.com/Kozea/WeasyPrint/issues/2802&gt;</code><em>,
<code>[#2805](https://github.com/Kozea/WeasyPrint/issues/2805)
&lt;https://github.com/Kozea/WeasyPrint/pull/2805&gt;</code></em>:
Create immutable releases on GitHub</li>
<li><code>[#2809](https://github.com/Kozea/WeasyPrint/issues/2809)
&lt;https://github.com/Kozea/WeasyPrint/issues/2809&gt;</code><em>,
<code>[#2810](https://github.com/Kozea/WeasyPrint/issues/2810)
&lt;https://github.com/Kozea/WeasyPrint/pull/2810&gt;</code></em>:
Switch to MSYS2 UCRT64 environment for Windows tests and
executables</li>
<li><code>[#2777](https://github.com/Kozea/WeasyPrint/issues/2777)
&lt;https://github.com/Kozea/WeasyPrint/issues/2777&gt;</code><em>,
<code>[#2814](https://github.com/Kozea/WeasyPrint/issues/2814)
&lt;https://github.com/Kozea/WeasyPrint/pull/2814&gt;</code></em>:
Support COLR emoji fonts</li>
<li><code>[#2667](https://github.com/Kozea/WeasyPrint/issues/2667)
&lt;https://github.com/Kozea/WeasyPrint/issues/2667&gt;</code><em>,
<code>[#2744](https://github.com/Kozea/WeasyPrint/issues/2744)
&lt;https://github.com/Kozea/WeasyPrint/pull/2744&gt;</code></em>:
Support context paint in SVG markers</li>
<li><code>[#1862](https://github.com/Kozea/WeasyPrint/issues/1862)
&lt;https://github.com/Kozea/WeasyPrint/issues/1862&gt;</code><em>,
<code>[#2844](https://github.com/Kozea/WeasyPrint/issues/2844)
&lt;https://github.com/Kozea/WeasyPrint/pull/2844&gt;</code></em>:
Improve filename detection for attachments</li>
<li><code>[#2816](https://github.com/Kozea/WeasyPrint/issues/2816)
&lt;https://github.com/Kozea/WeasyPrint/issues/2816&gt;</code><em>,
<code>[#2827](https://github.com/Kozea/WeasyPrint/issues/2827)
&lt;https://github.com/Kozea/WeasyPrint/pull/2827&gt;</code></em>:
Set SVG title as alternative text</li>
<li><code>[#2718](https://github.com/Kozea/WeasyPrint/issues/2718)
&lt;https://github.com/Kozea/WeasyPrint/issues/2718&gt;</code>_:
Provide a 'onedir' Windows executable</li>
<li><code>[#2863](https://github.com/Kozea/WeasyPrint/issues/2863)
&lt;https://github.com/Kozea/WeasyPrint/pull/2863&gt;</code>_:
Support box-shadow</li>
<li><code>[#2755](https://github.com/Kozea/WeasyPrint/issues/2755)
&lt;https://github.com/Kozea/WeasyPrint/pull/2755&gt;</code>_:
Support RTL SVG text anchoring</li>
<li><code>[#2866](https://github.com/Kozea/WeasyPrint/issues/2866)
&lt;https://github.com/Kozea/WeasyPrint/issues/2866&gt;</code>_:
Don’t use f-strings in logs</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/4d3b7b6449e3494f59c7c2f36b512d129225679c"><code>4d3b7b6</code></a>
Version 70.0</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/289e278439b017cd9263b4cd4727026987f86443"><code>289e278</code></a>
Always use original URL fetcher when available</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/aeb3be74e3c904e4b772014006410e23e0512b4b"><code>aeb3be7</code></a>
Merge remote-tracking branch 'security/main'</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/48357241f949c3f6880ec1a40f56d2f5106fdef3"><code>4835724</code></a>
Merge pull request <a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2915">#2915</a>
from havelaer/fix-nested-svg-viewport-restore</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/03310511d8afac08f80939e7fa317ad6051e251f"><code>0331051</code></a>
Restore nested SVG viewport size on the SVG object, not the drawing
function</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/e4b8b45e409392197441bc449d110f323b0eeb66"><code>e4b8b45</code></a>
Add harfbuzz-vector requirement for Fedora</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/371e4debb4805fa3d5a138f2cbb044fc176284da"><code>371e4de</code></a>
Merge pull request <a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2905">#2905</a>
from Kozea/notes</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/590bf63301d77eaf6aac6b1eb3a3fbb9494e3b23"><code>590bf63</code></a>
Merge pull request <a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2913">#2913</a>
from Kozea/fast-svg-paths</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/f6570c3038b60695f715b12c7805f6933e58490a"><code>f6570c3</code></a>
Use a faster regex-based parser for SVG paths</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/bc0516240c5f8a1eaaf658621d52a09eebecdea9"><code>bc05162</code></a>
Use faster deque for SVG vertices</li>
<li>Additional commits viewable in <a
href="https://github.com/Kozea/WeasyPrint/compare/v69.0...v70.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `alembic` from 1.19.2 to 1.20.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/sqlalchemy/alembic/releases">alembic's
releases</a>.</em></p>
<blockquote>
<h1>1.20.0</h1>
<p>Released: September 11, 2026</p>
<h2>usecase</h2>
<ul>
<li>
<p><strong>[usecase] [batch]</strong> Added a warning for the case where
an unnamed CHECK constraint on a
reflected table is omitted from a batch &quot;recreate&quot; operation.
An unnamed
CHECK constraint can't be reliably carried over in a batch recreate
as it may refer to columns that are being dropped or changed.  This
omission was previously a silent operation.   The presence of any
<code>~sqlalchemy.schema.CheckConstraint</code> in
<code>Operations.batch_alter_table.table_args</code> is taken to
indicate
that the case has been accommodated, and no warning is emitted.</p>
<p>References: <a
href="https://redirect.github.com/sqlalchemy/alembic/issues/1846">#1846</a></p>
</li>
<li>
<p><strong>[usecase] [autogenerate]</strong> Autogenerate now renders a
warning comment above any rendered
<code>Operations.drop_constraint()</code> directive for which the
constraint name
is <code>None</code>, as is the case when a constraint that has no name
in the model
is dropped, most typically within the <code>downgrade()</code> function
of a
migration that adds an unnamed constraint.  A warning is also emitted on
the console when the migration script is generated.   The directive
requires a non-None name in order to be able to emit a &quot;DROP
CONSTRAINT&quot;
command.</p>
<p>References: <a
href="https://redirect.github.com/sqlalchemy/alembic/issues/916">#916</a></p>
</li>
</ul>
<h2>bug</h2>
<ul>
<li>
<p><strong>[bug] [batch]</strong> Fixed bug in batch mode where adding a
column with a type that generates
its own CHECK constraint, such as <code>~sqlalchemy.types.Boolean</code>
or
<code>~sqlalchemy.types.Enum</code> with
<code>~sqlalchemy.types.Boolean.create_constraint</code> set to
<code>True</code>,
would emit the constraint twice when the table was recreated, once under
the name generated by the naming convention in use and once under the
name given to the type.  The constraint is now emitted once, using the
same name that would be used outside of batch mode.</p>
<p>References: <a
href="https://redirect.github.com/sqlalchemy/alembic/issues/1768">#1768</a></p>
</li>
<li>
<p><strong>[bug] [batch]</strong> Fixed bug in batch mode where a CHECK
constraint generated by a type such
as <code>~sqlalchemy.types.Boolean</code> or
<code>~sqlalchemy.types.Enum</code>
would lose the name established for it by the naming convention in use
when the table was recreated, as the constraint was regenerated against
the temporary table used for the recreate operation.  The naming
convention is now resolved against the name of the table being
replaced.</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/sqlalchemy/alembic/commits">compare
view</a></li>
</ul>
</details>
<br />

Updates `ruff` from 0.16.6 to 0.16.7
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/releases">ruff's
releases</a>.</em></p>
<blockquote>
<h2>0.16.7</h2>
<h2>Release Notes</h2>
<p>Released on 2026-09-10.</p>
<h3>Preview features</h3>
<ul>
<li>[<code>ruff</code>] Add rule for default values on method receivers
(<code>RUF077</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/26700">#26700</a>)</li>
<li>[<code>ruff</code>] Recognize <code>re.prefixmatch</code>
(<code>RUF039</code>, <code>RUF055</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28311">#28311</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>Alternate nested quotes inside format spec interpolations (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28259">#28259</a>)</li>
<li>[<code>flake8-implicit-str-concat</code>] Mark fix unsafe when it
creates a docstring (<code>ISC003</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27981">#27981</a>)</li>
<li>[<code>flake8-tidy-imports</code>] Skip fixes for multi-member
imports (<code>TID254</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/26584">#26584</a>)</li>
<li>[<code>pylint</code>] Gate <code>ImportCycleError</code> on Python
3.15 (<code>PLW0133</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28310">#28310</a>)</li>
</ul>
<h3>Rule changes</h3>
<ul>
<li>Correct <code>D211</code> and <code>D203</code> rule conflict
diagnostic (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28444">#28444</a>)</li>
<li>Recognize <code>slice</code> and <code>frozendict</code> generics
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28477">#28477</a>)</li>
<li>Stop defining <code>__cached__</code> for Python 3.15 (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28476">#28476</a>)</li>
<li>[<code>pyupgrade</code>] Stop recommending removed
<code>typing.no_type_check_decorator</code> (<code>UP035</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28475">#28475</a>)</li>
</ul>
<h3>Performance</h3>
<ul>
<li>Reuse parser name lookups when interning (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28399">#28399</a>)</li>
<li>Speed up inherited configuration resolution (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28299">#28299</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Fix <code>line-length</code> path in <code>--config</code> example
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28392">#28392</a>)</li>
<li>Remove the &quot;Who’s Using Ruff?&quot; list (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28455">#28455</a>)</li>
</ul>
<h3>Other changes</h3>
<ul>
<li>Embed archive checksums in the shell installer (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28281">#28281</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/The-Compiler"><code>@​The-Compiler</code></a></li>
<li><a
href="https://github.com/mdiniz97"><code>@​mdiniz97</code></a></li>
<li><a href="https://github.com/zsol"><code>@​zsol</code></a></li>
<li><a
href="https://github.com/gorewilliams"><code>@​gorewilliams</code></a></li>
<li><a
href="https://github.com/RafaelJohn9"><code>@​RafaelJohn9</code></a></li>
<li><a href="https://github.com/qatcod"><code>@​qatcod</code></a></li>
<li><a href="https://github.com/zanieb"><code>@​zanieb</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's
changelog</a>.</em></p>
<blockquote>
<h2>0.16.7</h2>
<p>Released on 2026-09-10.</p>
<h3>Preview features</h3>
<ul>
<li>[<code>ruff</code>] Add rule for default values on method receivers
(<code>RUF077</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/26700">#26700</a>)</li>
<li>[<code>ruff</code>] Recognize <code>re.prefixmatch</code>
(<code>RUF039</code>, <code>RUF055</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28311">#28311</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>Alternate nested quotes inside format spec interpolations (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28259">#28259</a>)</li>
<li>[<code>flake8-implicit-str-concat</code>] Mark fix unsafe when it
creates a docstring (<code>ISC003</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27981">#27981</a>)</li>
<li>[<code>flake8-tidy-imports</code>] Skip fixes for multi-member
imports (<code>TID254</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/26584">#26584</a>)</li>
<li>[<code>pylint</code>] Gate <code>ImportCycleError</code> on Python
3.15 (<code>PLW0133</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28310">#28310</a>)</li>
</ul>
<h3>Rule changes</h3>
<ul>
<li>Correct <code>D211</code> and <code>D203</code> rule conflict
diagnostic (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28444">#28444</a>)</li>
<li>Recognize <code>slice</code> and <code>frozendict</code> generics
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28477">#28477</a>)</li>
<li>Stop defining <code>__cached__</code> for Python 3.15 (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28476">#28476</a>)</li>
<li>[<code>pyupgrade</code>] Stop recommending removed
<code>typing.no_type_check_decorator</code> (<code>UP035</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28475">#28475</a>)</li>
</ul>
<h3>Performance</h3>
<ul>
<li>Reuse parser name lookups when interning (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28399">#28399</a>)</li>
<li>Speed up inherited configuration resolution (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28299">#28299</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Fix <code>line-length</code> path in <code>--config</code> example
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28392">#28392</a>)</li>
<li>Remove the &quot;Who’s Using Ruff?&quot; list (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28455">#28455</a>)</li>
</ul>
<h3>Other changes</h3>
<ul>
<li>Embed archive checksums in the shell installer (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28281">#28281</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/The-Compiler"><code>@​The-Compiler</code></a></li>
<li><a
href="https://github.com/mdiniz97"><code>@​mdiniz97</code></a></li>
<li><a href="https://github.com/zsol"><code>@​zsol</code></a></li>
<li><a
href="https://github.com/gorewilliams"><code>@​gorewilliams</code></a></li>
<li><a
href="https://github.com/RafaelJohn9"><code>@​RafaelJohn9</code></a></li>
<li><a href="https://github.com/qatcod"><code>@​qatcod</code></a></li>
<li><a href="https://github.com/zanieb"><code>@​zanieb</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a
href="https://github.com/nightt5879"><code>@​nightt5879</code></a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/ruff/commit/b5dba861cc38e3f7fb4524c9ceba3e01a474ea13"><code>b5dba86</code></a>
Bump version to 0.16.7 (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28496">#28496</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/5992d0504697d86565d8fc3a4d8245a5f4047d24"><code>5992d05</code></a>
Install rustfmt before linting releases (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28495">#28495</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/1713a1f4325494d883a080d590a25a1946f399e8"><code>1713a1f</code></a>
ensure prepare release changes pass prek (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28488">#28488</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/18cdbb4f3d14058794420e758864795f55336334"><code>18cdbb4</code></a>
use scoped token for release workflow (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28484">#28484</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/c3813a501faf887fd01948c98bb8d58ad26488bd"><code>c3813a5</code></a>
add a workflow for preparing releases (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28486">#28486</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/00948c00a671b81f5358af9f038436bcbb993b38"><code>00948c0</code></a>
Remove the &quot;Who’s Using Ruff?&quot; list (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28455">#28455</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/86a2eba7b48e3c10386f7ab8a5425c7275d2b427"><code>86a2eba</code></a>
[<code>pyupgrade</code>] Stop recommending removed
<code>typing.no_type_check_decorator</code> (`UP...</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/609e184aa35f0034b7ef63e3e04327081c484af6"><code>609e184</code></a>
Stop defining <code>__cached__</code> for Python 3.15 (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28476">#28476</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/859ff2f01670c43ffff1ea597c8a2e375ada0fbe"><code>859ff2f</code></a>
[ty] Track symlinked directory status in listings (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28482">#28482</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/77f653825800ddaf3bc221ae6db49a500e1002d5"><code>77f6538</code></a>
Use paid GitHub-hosted runners for Linux (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28478">#28478</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/astral-sh/ruff/compare/0.16.6...0.16.7">compare
view</a></li>
</ul>
</details>
<br />

Updates `ty` from 0.0.78 to 0.0.80
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ty/releases">ty's
releases</a>.</em></p>
<blockquote>
<h2>0.0.80</h2>
<h2>Release Notes</h2>
<p>Released on 2026-09-09.</p>
<h3>Bug fixes</h3>
<ul>
<li>Fix <code>--force-exclude</code> for directories with an excluded
ancestor (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28451">#28451</a>)</li>
<li>Preserve metaclass candidates after conflicts (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28461">#28461</a>)</li>
</ul>
<h3>LSP server</h3>
<ul>
<li>Give existing autofixes descriptive titles (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28456">#28456</a>)</li>
<li>Prevent LSP hangs during inlay hint bursts (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28390">#28390</a>)</li>
</ul>
<h3>Diagnostic improvements</h3>
<ul>
<li>Preserve redundant-condition diagnostics with unreachable operands
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28374">#28374</a>)</li>
</ul>
<h3>Core type checking</h3>
<ul>
<li>Check captured receivers when calling wrapped classmethods (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28467">#28467</a>)</li>
<li>Fix cached classmethods on generic classes (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28207">#28207</a>)</li>
<li>Fix disjointness of type guards and boolean literals (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28363">#28363</a>)</li>
<li>Infer tuple variance from the full tuple spec (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28446">#28446</a>)</li>
<li>Infer tuple variance more precisely (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28426">#28426</a>)</li>
<li>Preserve callable identity across specialized types (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28409">#28409</a>)</li>
<li>Preserve callback type context through ParamSpec forwarding (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28439">#28439</a>)</li>
<li>Preserve wrapped functions in precise <code>functools.partial</code>
relations (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28460">#28460</a>)</li>
<li>Respect descriptor protocol for <code>__set__</code> itself (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28408">#28408</a>)</li>
<li>Respect type-variable bounds in argument context (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28448">#28448</a>)</li>
<li>Unwrap union alternatives in overload implementations (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28468">#28468</a>)</li>
</ul>
<h3>Performance</h3>
<ul>
<li>Distribute <code>len</code> inference over unions (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28470">#28470</a>)</li>
<li>Fast-path concrete literal intersections (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28348">#28348</a>)</li>
</ul>
<h3>Memory usage improvements</h3>
<ul>
<li>Avoid excess capacity in multi-binding tables (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28412">#28412</a>)</li>
<li>Share equivalent place tables within a file (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28319">#28319</a>)</li>
<li>Share names in synthesized constructor parameters (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28398">#28398</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a href="https://github.com/sharkdp"><code>@​sharkdp</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a
href="https://github.com/ibraheemdev"><code>@​ibraheemdev</code></a></li>
<li><a
href="https://github.com/AlexWaygood"><code>@​AlexWaygood</code></a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ty/blob/main/CHANGELOG.md">ty's
changelog</a>.</em></p>
<blockquote>
<h2>0.0.80</h2>
<p>Released on 2026-09-09.</p>
<h3>Bug fixes</h3>
<ul>
<li>Fix <code>--force-exclude</code> for directories with an excluded
ancestor (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28451">#28451</a>)</li>
<li>Preserve metaclass candidates after conflicts (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28461">#28461</a>)</li>
</ul>
<h3>LSP server</h3>
<ul>
<li>Give existing autofixes descriptive titles (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28456">#28456</a>)</li>
<li>Prevent LSP hangs during inlay hint bursts (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28390">#28390</a>)</li>
</ul>
<h3>Diagnostic improvements</h3>
<ul>
<li>Preserve redundant-condition diagnostics with unreachable operands
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28374">#28374</a>)</li>
</ul>
<h3>Core type checking</h3>
<ul>
<li>Check captured receivers when calling wrapped classmethods (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28467">#28467</a>)</li>
<li>Fix cached classmethods on generic classes (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28207">#28207</a>)</li>
<li>Fix disjointness of type guards and boolean literals (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28363">#28363</a>)</li>
<li>Infer tuple variance from the full tuple spec (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28446">#28446</a>)</li>
<li>Infer tuple variance more precisely (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28426">#28426</a>)</li>
<li>Preserve callable identity across specialized types (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28409">#28409</a>)</li>
<li>Preserve callback type context through ParamSpec forwarding (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28439">#28439</a>)</li>
<li>Preserve wrapped functions in precise <code>functools.partial</code>
relations (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28460">#28460</a>)</li>
<li>Respect descriptor protocol for <code>__set__</code> itself (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28408">#28408</a>)</li>
<li>Respect type-variable bounds in argument context (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28448">#28448</a>)</li>
<li>Unwrap union alternatives in overload implementations (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28468">#28468</a>)</li>
</ul>
<h3>Performance</h3>
<ul>
<li>Distribute <code>len</code> inference over unions (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28470">#28470</a>)</li>
<li>Fast-path concrete literal intersections (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28348">#28348</a>)</li>
</ul>
<h3>Memory usage improvements</h3>
<ul>
<li>Avoid excess capacity in multi-binding tables (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28412">#28412</a>)</li>
<li>Share equivalent place tables within a file (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28319">#28319</a>)</li>
<li>Share names in synthesized constructor parameters (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28398">#28398</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a href="https://github.com/sharkdp"><code>@​sharkdp</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a
href="https://github.com/ibraheemdev"><code>@​ibraheemdev</code></a></li>
<li><a
href="https://github.com/AlexWaygood"><code>@​AlexWaygood</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/ty/commit/7fd8e15694f869200f7778082564c5968c50ce30"><code>7fd8e15</code></a>
Bump version to 0.0.80 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4501">#4501</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/c163f21ed4be7a5608ae5791720b43040b08cf5c"><code>c163f21</code></a>
Update dependency prek to v0.4.12 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4494">#4494</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/8ce0450332e815c0f734fb84d03d63be3eb96829"><code>8ce0450</code></a>
Update prek dependencies (<a
href="https://redirect.github.com/astral-sh/ty/issues/4495">#4495</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/5d0aa7a142189fc1955759c2987029b8ff8ef4a7"><code>5d0aa7a</code></a>
Update actions/attest-build-provenance action to v4.2.2 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4497">#4497</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/e22b86b3e6d461af46b549e5ebef5474b6256783"><code>e22b86b</code></a>
Update Swatinem/rust-cache action to v2.9.2 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4496">#4496</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/5cde40f5cb83f1cb164b91282e6a72f3dfe4580c"><code>5cde40f</code></a>
Document uv integration and workspace trust settings (<a
href="https://redirect.github.com/astral-sh/ty/issues/4339">#4339</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/b4cd79275b7ce22c4cf4208f8b005adb53e92523"><code>b4cd792</code></a>
Bump version to 0.0.79 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4484">#4484</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/52f2d5b12ff4a86f1100f3b9c3e2d61b086d8a89"><code>52f2d5b</code></a>
Add a GitHub repository threat model for ty (<a
href="https://redirect.github.com/astral-sh/ty/issues/4481">#4481</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/fd0d789cc54f9a234da75025ef6d0777280675be"><code>fd0d789</code></a>
Declare support for Python 3.15 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4476">#4476</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/7e7a87da9849d3f322690ae5b74b0409799668b6"><code>7e7a87d</code></a>
Improve rooster-generated changelog sections (<a
href="https://redirect.github.com/astral-sh/ty/issues/4473">#4473</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/astral-sh/ty/compare/0.0.78...0.0.80">compare
view</a></li>
</ul>
</details>
<br />

Updates `psycopg2-binary` from 2.9.12 to 2.9.13
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/psycopg/psycopg2/blob/master/NEWS">psycopg2-binary's
changelog</a>.</em></p>
<blockquote>
<h2>Current release</h2>
<p>What's new in psycopg 2.9.13
^^^^^^^^^^^^^^^^^^^^^^^^^^^^</p>
<ul>
<li>Add support for Python 3.15
(:ticket:<code>[#1848](https://github.com/psycopg/psycopg2/issues/1848)</code>).</li>
<li>Fix parsing of malformed bytea input.</li>
<li>Fix parsing of malformed int64 input in arrays
(:ticket:<code>[#1847](https://github.com/psycopg/psycopg2/issues/1847)</code>).</li>
<li>Add a <code>pyproject.toml</code> file to declare a PEP 517 build
backend

(:ticket:<code>[#1788](https://github.com/psycopg/psycopg2/issues/1788)</code>).</li>
<li>Drop support for Python 3.9.</li>
</ul>
<p>What's new in psycopg 2.9.12
^^^^^^^^^^^^^^^^^^^^^^^^^^^^</p>
<ul>
<li>Fix infinite loop with malformed interval
(:ticket:<code>1835</code>).</li>
</ul>
<p>What's new in psycopg 2.9.11
^^^^^^^^^^^^^^^^^^^^^^^^^^^^</p>
<ul>
<li>Add support for Python 3.14.</li>
<li>Avoid a segfault passing more arguments than placeholders if Python
is built
with assertions enabled
(:ticket:<code>[#1791](https://github.com/psycopg/psycopg2/issues/1791)</code>).</li>
<li>Add riscv64 platform binary packages
(:ticket:<code>[#1813](https://github.com/psycopg/psycopg2/issues/1813)</code>).</li>
<li><code>~psycopg2.errorcodes</code> map and
<code>~psycopg2.errors</code> classes updated to
PostgreSQL 18.</li>
<li>Drop support for Python 3.8.</li>
</ul>
<p>What's new in psycopg 2.9.10
^^^^^^^^^^^^^^^^^^^^^^^^^^^^</p>
<ul>
<li>Add support for Python 3.13.</li>
<li>Receive notifications on commit
(:ticket:<code>[#1728](https://github.com/psycopg/psycopg2/issues/1728)</code>).</li>
<li><code>~psycopg2.errorcodes</code> map and
<code>~psycopg2.errors</code> classes updated to
PostgreSQL 17.</li>
<li>Drop support for Python 3.7.</li>
</ul>
<p>What's new in psycopg 2.9.9
^^^^^^^^^^^^^^^^^^^^^^^^^^^</p>
<ul>
<li>Add support for Python 3.12.</li>
<li>Drop support for Python 3.6.</li>
</ul>
<p>What's new in psycopg 2.9.8</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/psycopg/psycopg2/commit/f650e7afed0c94f596594e8328a0c7fa65a9d0e5"><code>f650e7a</code></a>
chore: bump to release 2.9.13</li>
<li><a
href="https://github.com/psycopg/psycopg2/commit/368c8a1ca6d80088703a693ce64b68ad7d346698"><code>368c8a1</code></a>
chore!: drop support for Python 3.9</li>
<li><a
href="https://github.com/psycopg/psycopg2/commit/9b39e65ab232f0a267a278cdaef1bd9975d88c65"><code>9b39e65</code></a>
chore: drop scaleway build support</li>
<li><a
href="https://github.com/psycopg/psycopg2/commit/2ca70416be6d4d3d8170ec439876c0b3569af718"><code>2ca7041</code></a>
fix: fix handling of PostgreSQL 18 exceptions</li>
<li><a
href="https://github.com/psycopg/psycopg2/commit/5385c027ef62ce14e57a7379e0375868507d6746"><code>5385c02</code></a>
Build CPython 3.15 wheels</li>
<li><a
href="https://github.com/psycopg/psycopg2/commit/1d32e1f6678ffa8ab8897ca81826bf4dde6354cd"><code>1d32e1f</code></a>
ci: only attempt triggering documentation refresh when pushing on main
repo</li>
<li><a
href="https://github.com/psycopg/psycopg2/commit/433e7b77a7b700fbb1cdc6e9dca6b5948d07fc23"><code>433e7b7</code></a>
chore: add pyproject.toml file to declare a PEP 517 build backend</li>
<li><a
href="https://github.com/psycopg/psycopg2/commit/8fb80bc3b2c358f4e3c54e33a37326d3f8b3ff6a"><code>8fb80bc</code></a>
fix: fix parsing of malformed int64 input in arrays</li>
<li><a
href="https://github.com/psycopg/psycopg2/commit/f98014a46a1e34f024ebd6134d1d87b77490c500"><code>f98014a</code></a>
fix: fix parsing of malformed bytea input</li>
<li><a
href="https://github.com/psycopg/psycopg2/commit/822b79cfe12ca0a04482acd382cae669a16aa789"><code>822b79c</code></a>
chore: bump dependencies in binary package</li>
<li>Additional commits viewable in <a
href="https://github.com/psycopg/psycopg2/compare/2.9.12...2.9.13">compare
view</a></li>
</ul>
</details>
<br />

Updates `pyjwt` from 2.13.0 to 2.14.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/jpadilla/pyjwt/releases">pyjwt's
releases</a>.</em></p>
<blockquote>
<h2>PyJWT 2.14.0</h2>
<p>See the <a
href="https://github.com/jpadilla/pyjwt/blob/2.14.0/CHANGELOG.rst">2.14.0
changelog</a> for the complete release details and related security
advisories.</p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst">pyjwt's
changelog</a>.</em></p>
<blockquote>
<h2><code>v2.14.0
&lt;https://github.com/jpadilla/pyjwt/compare/2.13.0...2.14.0&gt;</code>__</h2>
<p>Security</p>
<pre><code>
- Harden HMAC key validation against public-key material supplied as
JWK,
  JWKS, array, encoded, BOM-prefixed, DER, or PEM input. See
`GHSA-r6x4-923q-g947
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-r6x4-923q-g947&gt;`__,
`GHSA-ffc3-869f-jxw9
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-ffc3-869f-jxw9&gt;`__,
`GHSA-p4g4-x82p-q773
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-p4g4-x82p-q773&gt;`__,
and `GHSA-w2cx-738m-mc7w
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w2cx-738m-mc7w&gt;`__.
- Reject automatic redirects when ``PyJWKClient`` fetches a JWKS,
preventing
  redirected destinations from being treated as trusted key sources. See
`GHSA-9v7f-9g4p-ffgj
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-9v7f-9g4p-ffgj&gt;`__.
- Limit repeated JWKS refreshes caused by unknown key IDs while
preserving
  normal key-rotation behavior. See
`GHSA-2gx3-rcp4-g85q
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-2gx3-rcp4-g85q&gt;`__.
- Handle deeply nested and malformed JWS/JWK input without uncaught
recursion
  errors or whole-set parsing failures. See
`GHSA-8wjv-2p76-3863
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-8wjv-2p76-3863&gt;`__
and `GHSA-w6j9-cwv2-h6wq
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w6j9-cwv2-h6wq&gt;`__.
- Enforce compact JWS encoding rules during decoding. See
`GHSA-hxm8-2xgr-2p9m
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-hxm8-2xgr-2p9m&gt;`__.
- Reject detached-payload arguments for attached JWS inputs. Thanks to
`@xclow3n
&lt;https://github.com/xclow3n&gt;`__ for reporting this behavior; fixed
in commit
`37b54877
&lt;https://github.com/jpadilla/pyjwt/commit/37b54877bf7bea67e8149130e96929e3ec798122&gt;`__.
<p>Fixed</p>
<pre><code>
- Apply HMAC key validation consistently when keys are loaded through
  ``PyJWK`` and ``PyJWKClient``. See
`GHSA-pxh4-856f-4h89
&amp;lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-pxh4-856f-4h89&amp;gt;`__.
- Reject empty HMAC keys when represented as JWKs.
See `GHSA-pxh4-856f-4h89
&amp;lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-pxh4-856f-4h89&amp;gt;`__.

Fixed
</code></pre>
<ul>
<li>Raise the documented <code>PyJWTError</code> subclass instead of
leaking a<br />
<code>TypeError</code> when the <code>exp</code>, <code>nbf</code>, or
<code>iat</code> claim decodes to a<br />
non-numeric, non-string value such as a list, dict, or
<code>null</code>.<br />
</code></pre></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/c6fe464b356ff4b1ebc9ba62172d331a40aa27df"><code>c6fe464</code></a>
release: prepare v2.14.0</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/f5413029ae7a2e31b1367b5303ea86a2f54ccf42"><code>f541302</code></a>
style: apply Ruff formatting</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/801cd128528c62d9b23fcd161d1a2e1c17982f95"><code>801cd12</code></a>
fix: reject public JWK container HMAC keys</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/af8181ca0bec5e6b372fbba9afbe23702b787ceb"><code>af8181c</code></a>
fix: reject empty HMAC keys from JWKs</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/ba4853a75fb9676362da17f67d0f64bd18afd4e1"><code>ba4853a</code></a>
Throttle repeated PyJWKClient refreshes</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/2798504fa2663364573cf2d1043d8d7fef389499"><code>2798504</code></a>
fix: reject DER public keys as HMAC secrets</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/8b4e233a22206b34ec1186e912e75c0b2396ac07"><code>8b4e233</code></a>
fix: reject loader-accepted PEM variants</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/1f8180a211256dfe5cf32294b6753f554a5a4258"><code>1f8180a</code></a>
fix: format JWS tests</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/cff1ac55fe5f1096fd05295b269fce053ee290ab"><code>cff1ac5</code></a>
Fix redirect handler return annotation</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/0a795b8e1f6ef08f634aa7086fc41cc6d5ce3e56"><code>0a795b8</code></a>
Reject redirects in PyJWKClient fetches</li>
<li>Additional commits viewable in <a
href="https://github.com/jpadilla/pyjwt/compare/2.13.0...2.14.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `alembic` from 1.19.2 to 1.20.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/sqlalchemy/alembic/releases">alembic's
releases</a>.</em></p>
<blockquote>
<h1>1.20.0</h1>
<p>Released: September 11, 2026</p>
<h2>usecase</h2>
<ul>
<li>
<p><strong>[usecase] [batch]</strong> Added a warning for the case where
an unnamed CHECK constraint on a
reflected table is omitted from a batch &quot;recreate&quot; operation.
An unnamed
CHECK constraint can't be reliably carried over in a batch recreate
as it may refer to columns that are being dropped or changed.  This
omission was previously a silent operation.   The presence of any
<code>~sqlalchemy.schema.CheckConstraint</code> in
<code>Operations.batch_alter_table.table_args</code> is taken to
indicate
that the case has been accommodated, and no warning is emitted.</p>
<p>References: <a
href="https://redirect.github.com/sqlalchemy/alembic/issues/1846">#1846</a></p>
</li>
<li>
<p><strong>[usecase] [autogenerate]</strong> Autogenerate now renders a
warning comment above any rendered
<code>Operations.drop_constraint()</code> directive for which the
constraint name
is <code>None</code>, as is the case when a constraint that has no name
in the model
is dropped, most typically within the <code>downgrade()</code> function
of a
migration that adds an unnamed constraint.  A warning is also emitted on
the console when the migration script is generated.   The directive
requires a non-None name in order to be able to emit a &quot;DROP
CONSTRAINT&quot;
command.</p>
<p>References: <a
href="https://redirect.github.com/sqlalchemy/alembic/issues/916">#916</a></p>
</li>
</ul>
<h2>bug</h2>
<ul>
<li>
<p><strong>[bug] [batch]</strong> Fixed bug in batch mode where adding a
column with a type that generates
its own CHECK constraint, such as <code>~sqlalchemy.types.Boolean</code>
or
<code>~sqlalchemy.types.Enum</code> with
<code>~sqlalchemy.types.Boolean.create_constraint</code> set to
<code>True</code>,
would emit the constraint twice when the table was recreated, once under
the name generated by the naming convention in use and once under the
name given to the type.  The constraint is now emitted once, using the
same name that would be used outside of batch mode.</p>
<p>References: <a
href="https://redirect.github.com/sqlalchemy/alembic/issues/1768">#1768</a></p>
</li>
<li>
<p><strong>[bug] [batch]</strong> Fixed bug in batch mode where a CHECK
constraint generated by a type such
as <code>~sqlalchemy.types.Boolean</code> or
<code>~sqlalchemy.types.Enum</code>
would lose the name established for it by the naming convention in use
when the table was recreated, as the constraint was regenerated against
the temporary table used for the recreate operation.  The naming
convention is now resolved against the name of the table being
replaced.</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/sqlalchemy/alembic/commits">compare
view</a></li>
</ul>
</details>
<br />

Updates `ruff` from 0.16.6 to 0.16.7
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/releases">ruff's
releases</a>.</em></p>
<blockquote>
<h2>0.16.7</h2>
<h2>Release Notes</h2>
<p>Released on 2026-09-10.</p>
<h3>Preview features</h3>
<ul>
<li>[<code>ruff</code>] Add rule for default values on method receivers
(<code>RUF077</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/26700">#26700</a>)</li>
<li>[<code>ruff</code>] Recognize <code>re.prefixmatch</code>
(<code>RUF039</code>, <code>RUF055</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28311">#28311</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>Alternate nested quotes inside format spec interpolations (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28259">#28259</a>)</li>
<li>[<code>flake8-implicit-str-concat</code>] Mark fix unsafe when it
creates a docstring (<code>ISC003</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27981">#27981</a>)</li>
<li>[<code>flake8-tidy-imports</code>] Skip fixes for multi-member
imports (<code>TID254</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/26584">#26584</a>)</li>
<li>[<code>pylint</code>] Gate <code>ImportCycleError</code> on Python
3.15 (<code>PLW0133</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28310">#28310</a>)</li>
</ul>
<h3>Rule changes</h3>
<ul>
<li>Correct <code>D211</code> and <code>D203</code> rule conflict
diagnostic (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28444">#28444</a>)</li>
<li>Recognize <code>slice</code> and <code>frozendict</code> generics
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28477">#28477</a>)</li>
<li>Stop defining <code>__cached__</code> for Python 3.15 (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28476">#28476</a>)</li>
<li>[<code>pyupgrade</code>] Stop recommending removed
<code>typing.no_type_check_decorator</code> (<code>UP035</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28475">#28475</a>)</li>
</ul>
<h3>Performance</h3>
<ul>
<li>Reuse parser name lookups when interning (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28399">#28399</a>)</li>
<li>Speed up inherited configuration resolution (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28299">#28299</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Fix <code>line-length</code> path in <code>--config</code> example
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28392">#28392</a>)</li>
<li>Remove the &quot;Who’s Using Ruff?&quot; list (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28455">#28455</a>)</li>
</ul>
<h3>Other changes</h3>
<ul>
<li>Embed archive checksums in the shell installer (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28281">#28281</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/The-Compiler"><code>@​The-Compiler</code></a></li>
<li><a
href="https://github.com/mdiniz97"><code>@​mdiniz97</code></a></li>
<li><a href="https://github.com/zsol"><code>@​zsol</code></a></li>
<li><a
href="https://github.com/gorewilliams"><code>@​gorewilliams</code></a></li>
<li><a
href="https://github.com/RafaelJohn9"><code>@​RafaelJohn9</code></a></li>
<li><a href="https://github.com/qatcod"><code>@​qatcod</code></a></li>
<li><a href="https://github.com/zanieb"><code>@​zanieb</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's
changelog</a>.</em></p>
<blockquote>
<h2>0.16.7</h2>
<p>Released on 2026-09-10.</p>
<h3>Preview features</h3>
<ul>
<li>[<code>ruff</code>] Add rule for default values on method receivers
(<code>RUF077</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/26700">#26700</a>)</li>
<li>[<code>ruff</code>] Recognize <code>re.prefixmatch</code>
(<code>RUF039</code>, <code>RUF055</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28311">#28311</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>Alternate nested quotes inside format spec interpolations (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28259">#28259</a>)</li>
<li>[<code>flake8-implicit-str-concat</code>] Mark fix unsafe when it
creates a docstring (<code>ISC003</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27981">#27981</a>)</li>
<li>[<code>flake8-tidy-imports</code>] Skip fixes for multi-member
imports (<code>TID254</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/26584">#26584</a>)</li>
<li>[<code>pylint</code>] Gate <code>ImportCycleError</code> on Python
3.15 (<code>PLW0133</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28310">#28310</a>)</li>
</ul>
<h3>Rule changes</h3>
<ul>
<li>Correct <code>D211</code> and <code>D203</code> rule conflict
diagnostic (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28444">#28444</a>)</li>
<li>Recognize <code>slice</code> and <code>frozendict</code> generics
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28477">#28477</a>)</li>
<li>Stop defining <code>__cached__</code> for Python 3.15 (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28476">#28476</a>)</li>
<li>[<code>pyupgrade</code>] Stop recommending removed
<code>typing.no_type_check_decorator</code> (<code>UP035</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28475">#28475</a>)</li>
</ul>
<h3>Performan…
Spigushe added a commit to Spigushe/barrins-project that referenced this pull request Sep 17, 2026
…updates (#155)

Bumps the all-updates group with 7 updates in the /apps/barrins_api
directory:

| Package | From | To |
| --- | --- | --- |
| [psycopg2-binary](https://github.com/psycopg/psycopg2) | `2.9.12` |
`2.9.13` |
| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.13.0` | `2.14.0` |
| [uvicorn](https://github.com/Kludex/uvicorn) | `0.52.4` | `0.53.0` |
| [weasyprint](https://github.com/Kozea/WeasyPrint) | `69.0` | `70.0` |
| [alembic](https://github.com/sqlalchemy/alembic) | `1.19.2` | `1.20.0`
|
| [ruff](https://github.com/astral-sh/ruff) | `0.16.6` | `0.16.7` |
| [ty](https://github.com/astral-sh/ty) | `0.0.78` | `0.0.80` |
| [psycopg2-binary](https://github.com/psycopg/psycopg2) | `2.9.12` |
`2.9.13` |
| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.13.0` | `2.14.0` |
| [uvicorn](https://github.com/Kludex/uvicorn) | `0.52.4` | `0.53.0` |
| [alembic](https://github.com/sqlalchemy/alembic) | `1.19.2` | `1.20.0`
|
| [ruff](https://github.com/astral-sh/ruff) | `0.16.6` | `0.16.7` |
| [ty](https://github.com/astral-sh/ty) | `0.0.78` | `0.0.80` |
| [ruff](https://github.com/astral-sh/ruff) | `0.16.6` | `0.16.7` |
| [ty](https://github.com/astral-sh/ty) | `0.0.78` | `0.0.80` |
| [psycopg2-binary](https://github.com/psycopg/psycopg2) | `2.9.12` |
`2.9.13` |
| [ruff](https://github.com/astral-sh/ruff) | `0.16.6` | `0.16.7` |
| [ty](https://github.com/astral-sh/ty) | `0.0.78` | `0.0.80` |

Bumps the all-updates group with 6 updates in the /apps/barrins_identity
directory:

| Package | From | To |
| --- | --- | --- |
| [psycopg2-binary](https://github.com/psycopg/psycopg2) | `2.9.12` |
`2.9.13` |
| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.13.0` | `2.14.0` |
| [uvicorn](https://github.com/Kludex/uvicorn) | `0.52.4` | `0.53.0` |
| [alembic](https://github.com/sqlalchemy/alembic) | `1.19.2` | `1.20.0`
|
| [ruff](https://github.com/astral-sh/ruff) | `0.16.6` | `0.16.7` |
| [ty](https://github.com/astral-sh/ty) | `0.0.78` | `0.0.80` |
| [psycopg2-binary](https://github.com/psycopg/psycopg2) | `2.9.12` |
`2.9.13` |
| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.13.0` | `2.14.0` |
| [uvicorn](https://github.com/Kludex/uvicorn) | `0.52.4` | `0.53.0` |
| [alembic](https://github.com/sqlalchemy/alembic) | `1.19.2` | `1.20.0`
|
| [ruff](https://github.com/astral-sh/ruff) | `0.16.6` | `0.16.7` |
| [ty](https://github.com/astral-sh/ty) | `0.0.78` | `0.0.80` |
| [ruff](https://github.com/astral-sh/ruff) | `0.16.6` | `0.16.7` |
| [ty](https://github.com/astral-sh/ty) | `0.0.78` | `0.0.80` |
| [psycopg2-binary](https://github.com/psycopg/psycopg2) | `2.9.12` |
`2.9.13` |
| [ruff](https://github.com/astral-sh/ruff) | `0.16.6` | `0.16.7` |
| [ty](https://github.com/astral-sh/ty) | `0.0.78` | `0.0.80` |

Bumps the all-updates group with 3 updates in the
/apps/barrins_scripture directory:
[ruff](https://github.com/astral-sh/ruff),
[ty](https://github.com/astral-sh/ty) and
[selenium](https://github.com/SeleniumHQ/Selenium).
Bumps the all-updates group with 5 updates in the /apps/karn_tablets
directory:

| Package | From | To |
| --- | --- | --- |
| [psycopg2-binary](https://github.com/psycopg/psycopg2) | `2.9.12` |
`2.9.13` |
| [ruff](https://github.com/astral-sh/ruff) | `0.16.6` | `0.16.7` |
| [ty](https://github.com/astral-sh/ty) | `0.0.78` | `0.0.80` |
| [psycopg2-binary](https://github.com/psycopg/psycopg2) | `2.9.12` |
`2.9.13` |
| [ruff](https://github.com/astral-sh/ruff) | `0.16.6` | `0.16.7` |
| [ty](https://github.com/astral-sh/ty) | `0.0.78` | `0.0.80` |
| [ruff](https://github.com/astral-sh/ruff) | `0.16.6` | `0.16.7` |
| [ty](https://github.com/astral-sh/ty) | `0.0.78` | `0.0.80` |
| [psycopg2-binary](https://github.com/psycopg/psycopg2) | `2.9.12` |
`2.9.13` |
| [numpy](https://github.com/numpy/numpy) | `2.5.2` | `2.5.3` |
| [scikit-learn](https://github.com/scikit-learn/scikit-learn) | `1.9.0`
| `1.9.1` |
| [ruff](https://github.com/astral-sh/ruff) | `0.16.6` | `0.16.7` |
| [ty](https://github.com/astral-sh/ty) | `0.0.78` | `0.0.80` |


Updates `psycopg2-binary` from 2.9.12 to 2.9.13
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/psycopg/psycopg2/blob/master/NEWS">psycopg2-binary's
changelog</a>.</em></p>
<blockquote>
<h2>Current release</h2>
<p>What's new in psycopg 2.9.13
^^^^^^^^^^^^^^^^^^^^^^^^^^^^</p>
<ul>
<li>Add support for Python 3.15
(:ticket:<code>[#1848](https://github.com/psycopg/psycopg2/issues/1848)</code>).</li>
<li>Fix parsing of malformed bytea input.</li>
<li>Fix parsing of malformed int64 input in arrays
(:ticket:<code>[#1847](https://github.com/psycopg/psycopg2/issues/1847)</code>).</li>
<li>Add a <code>pyproject.toml</code> file to declare a PEP 517 build
backend

(:ticket:<code>[#1788](https://github.com/psycopg/psycopg2/issues/1788)</code>).</li>
<li>Drop support for Python 3.9.</li>
</ul>
<p>What's new in psycopg 2.9.12
^^^^^^^^^^^^^^^^^^^^^^^^^^^^</p>
<ul>
<li>Fix infinite loop with malformed interval
(:ticket:<code>1835</code>).</li>
</ul>
<p>What's new in psycopg 2.9.11
^^^^^^^^^^^^^^^^^^^^^^^^^^^^</p>
<ul>
<li>Add support for Python 3.14.</li>
<li>Avoid a segfault passing more arguments than placeholders if Python
is built
with assertions enabled
(:ticket:<code>[#1791](https://github.com/psycopg/psycopg2/issues/1791)</code>).</li>
<li>Add riscv64 platform binary packages
(:ticket:<code>[#1813](https://github.com/psycopg/psycopg2/issues/1813)</code>).</li>
<li><code>~psycopg2.errorcodes</code> map and
<code>~psycopg2.errors</code> classes updated to
PostgreSQL 18.</li>
<li>Drop support for Python 3.8.</li>
</ul>
<p>What's new in psycopg 2.9.10
^^^^^^^^^^^^^^^^^^^^^^^^^^^^</p>
<ul>
<li>Add support for Python 3.13.</li>
<li>Receive notifications on commit
(:ticket:<code>[#1728](https://github.com/psycopg/psycopg2/issues/1728)</code>).</li>
<li><code>~psycopg2.errorcodes</code> map and
<code>~psycopg2.errors</code> classes updated to
PostgreSQL 17.</li>
<li>Drop support for Python 3.7.</li>
</ul>
<p>What's new in psycopg 2.9.9
^^^^^^^^^^^^^^^^^^^^^^^^^^^</p>
<ul>
<li>Add support for Python 3.12.</li>
<li>Drop support for Python 3.6.</li>
</ul>
<p>What's new in psycopg 2.9.8</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/psycopg/psycopg2/commit/f650e7afed0c94f596594e8328a0c7fa65a9d0e5"><code>f650e7a</code></a>
chore: bump to release 2.9.13</li>
<li><a
href="https://github.com/psycopg/psycopg2/commit/368c8a1ca6d80088703a693ce64b68ad7d346698"><code>368c8a1</code></a>
chore!: drop support for Python 3.9</li>
<li><a
href="https://github.com/psycopg/psycopg2/commit/9b39e65ab232f0a267a278cdaef1bd9975d88c65"><code>9b39e65</code></a>
chore: drop scaleway build support</li>
<li><a
href="https://github.com/psycopg/psycopg2/commit/2ca70416be6d4d3d8170ec439876c0b3569af718"><code>2ca7041</code></a>
fix: fix handling of PostgreSQL 18 exceptions</li>
<li><a
href="https://github.com/psycopg/psycopg2/commit/5385c027ef62ce14e57a7379e0375868507d6746"><code>5385c02</code></a>
Build CPython 3.15 wheels</li>
<li><a
href="https://github.com/psycopg/psycopg2/commit/1d32e1f6678ffa8ab8897ca81826bf4dde6354cd"><code>1d32e1f</code></a>
ci: only attempt triggering documentation refresh when pushing on main
repo</li>
<li><a
href="https://github.com/psycopg/psycopg2/commit/433e7b77a7b700fbb1cdc6e9dca6b5948d07fc23"><code>433e7b7</code></a>
chore: add pyproject.toml file to declare a PEP 517 build backend</li>
<li><a
href="https://github.com/psycopg/psycopg2/commit/8fb80bc3b2c358f4e3c54e33a37326d3f8b3ff6a"><code>8fb80bc</code></a>
fix: fix parsing of malformed int64 input in arrays</li>
<li><a
href="https://github.com/psycopg/psycopg2/commit/f98014a46a1e34f024ebd6134d1d87b77490c500"><code>f98014a</code></a>
fix: fix parsing of malformed bytea input</li>
<li><a
href="https://github.com/psycopg/psycopg2/commit/822b79cfe12ca0a04482acd382cae669a16aa789"><code>822b79c</code></a>
chore: bump dependencies in binary package</li>
<li>Additional commits viewable in <a
href="https://github.com/psycopg/psycopg2/compare/2.9.12...2.9.13">compare
view</a></li>
</ul>
</details>
<br />

Updates `pyjwt` from 2.13.0 to 2.14.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/jpadilla/pyjwt/releases">pyjwt's
releases</a>.</em></p>
<blockquote>
<h2>PyJWT 2.14.0</h2>
<p>See the <a
href="https://github.com/jpadilla/pyjwt/blob/2.14.0/CHANGELOG.rst">2.14.0
changelog</a> for the complete release details and related security
advisories.</p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst">pyjwt's
changelog</a>.</em></p>
<blockquote>
<h2><code>v2.14.0
&lt;https://github.com/jpadilla/pyjwt/compare/2.13.0...2.14.0&gt;</code>__</h2>
<p>Security</p>
<pre><code>
- Harden HMAC key validation against public-key material supplied as
JWK,
  JWKS, array, encoded, BOM-prefixed, DER, or PEM input. See
`GHSA-r6x4-923q-g947
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-r6x4-923q-g947&gt;`__,
`GHSA-ffc3-869f-jxw9
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-ffc3-869f-jxw9&gt;`__,
`GHSA-p4g4-x82p-q773
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-p4g4-x82p-q773&gt;`__,
and `GHSA-w2cx-738m-mc7w
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w2cx-738m-mc7w&gt;`__.
- Reject automatic redirects when ``PyJWKClient`` fetches a JWKS,
preventing
  redirected destinations from being treated as trusted key sources. See
`GHSA-9v7f-9g4p-ffgj
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-9v7f-9g4p-ffgj&gt;`__.
- Limit repeated JWKS refreshes caused by unknown key IDs while
preserving
  normal key-rotation behavior. See
`GHSA-2gx3-rcp4-g85q
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-2gx3-rcp4-g85q&gt;`__.
- Handle deeply nested and malformed JWS/JWK input without uncaught
recursion
  errors or whole-set parsing failures. See
`GHSA-8wjv-2p76-3863
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-8wjv-2p76-3863&gt;`__
and `GHSA-w6j9-cwv2-h6wq
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w6j9-cwv2-h6wq&gt;`__.
- Enforce compact JWS encoding rules during decoding. See
`GHSA-hxm8-2xgr-2p9m
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-hxm8-2xgr-2p9m&gt;`__.
- Reject detached-payload arguments for attached JWS inputs. Thanks to
`@xclow3n
&lt;https://github.com/xclow3n&gt;`__ for reporting this behavior; fixed
in commit
`37b54877
&lt;https://github.com/jpadilla/pyjwt/commit/37b54877bf7bea67e8149130e96929e3ec798122&gt;`__.
<p>Fixed</p>
<pre><code>
- Apply HMAC key validation consistently when keys are loaded through
  ``PyJWK`` and ``PyJWKClient``. See
`GHSA-pxh4-856f-4h89
&amp;lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-pxh4-856f-4h89&amp;gt;`__.
- Reject empty HMAC keys when represented as JWKs.
See `GHSA-pxh4-856f-4h89
&amp;lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-pxh4-856f-4h89&amp;gt;`__.

Fixed
</code></pre>
<ul>
<li>Raise the documented <code>PyJWTError</code> subclass instead of
leaking a<br />
<code>TypeError</code> when the <code>exp</code>, <code>nbf</code>, or
<code>iat</code> claim decodes to a<br />
non-numeric, non-string value such as a list, dict, or
<code>null</code>.<br />
</code></pre></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/c6fe464b356ff4b1ebc9ba62172d331a40aa27df"><code>c6fe464</code></a>
release: prepare v2.14.0</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/f5413029ae7a2e31b1367b5303ea86a2f54ccf42"><code>f541302</code></a>
style: apply Ruff formatting</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/801cd128528c62d9b23fcd161d1a2e1c17982f95"><code>801cd12</code></a>
fix: reject public JWK container HMAC keys</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/af8181ca0bec5e6b372fbba9afbe23702b787ceb"><code>af8181c</code></a>
fix: reject empty HMAC keys from JWKs</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/ba4853a75fb9676362da17f67d0f64bd18afd4e1"><code>ba4853a</code></a>
Throttle repeated PyJWKClient refreshes</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/2798504fa2663364573cf2d1043d8d7fef389499"><code>2798504</code></a>
fix: reject DER public keys as HMAC secrets</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/8b4e233a22206b34ec1186e912e75c0b2396ac07"><code>8b4e233</code></a>
fix: reject loader-accepted PEM variants</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/1f8180a211256dfe5cf32294b6753f554a5a4258"><code>1f8180a</code></a>
fix: format JWS tests</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/cff1ac55fe5f1096fd05295b269fce053ee290ab"><code>cff1ac5</code></a>
Fix redirect handler return annotation</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/0a795b8e1f6ef08f634aa7086fc41cc6d5ce3e56"><code>0a795b8</code></a>
Reject redirects in PyJWKClient fetches</li>
<li>Additional commits viewable in <a
href="https://github.com/jpadilla/pyjwt/compare/2.13.0...2.14.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `uvicorn` from 0.52.4 to 0.53.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/Kludex/uvicorn/releases">uvicorn's
releases</a>.</em></p>
<blockquote>
<h2>Version 0.53.0</h2>
<h2>🌐 Opt-in HTTP/2 support</h2>
<p><code>uvicorn</code> 0.53.0 adds experimental HTTP/2 through
<code>zttp</code>, alongside a new <code>zuvloop</code> integration and
connection-handling improvements.</p>
<pre lang="console"><code>uv add uvicorn==0.53.0
</code></pre>
<ul>
<li><strong>Serve HTTP/1.1 and HTTP/2 with <code>zttp</code></strong>
(<a
href="https://redirect.github.com/Kludex/uvicorn/pull/2982">#2982</a>,
<a
href="https://redirect.github.com/Kludex/uvicorn/pull/3101">#3101</a>).
Install <code>zttp</code>, then enable HTTP/2 with <code>--http zttp
--http2</code>. Uvicorn negotiates HTTP/2 over TLS with ALPN and
supports cleartext prior knowledge.</li>
<li><strong>HTTP/2 remains experimental.</strong> Upgrade-based h2c and
WebSockets over HTTP/2 are not supported.</li>
</ul>
<h2>⚙️ More event loop choice</h2>
<ul>
<li><strong>Run Uvicorn with <code>zuvloop</code></strong> (<a
href="https://redirect.github.com/Kludex/uvicorn/pull/3104">#3104</a>).
Install <code>zuvloop</code> separately and select it explicitly with
<code>--loop zuvloop</code> on CPython 3.14 or newer.</li>
</ul>
<h2>🛡️ More reliable connections and proxies</h2>
<ul>
<li><strong>Honor <code>Connection: close</code> token lists</strong>
(<a
href="https://redirect.github.com/Kludex/uvicorn/pull/3103">#3103</a>).
Uvicorn now parses comma-separated tokens case-insensitively across HTTP
implementations.</li>
<li><strong>Trust IPv6 loopback proxies by default</strong> (<a
href="https://redirect.github.com/Kludex/uvicorn/pull/3119">#3119</a>).
The default <code>FORWARDED_ALLOW_IPS</code> value now includes
<code>::1</code>.</li>
<li><strong>Keep upgraded WebSockets alive</strong> (<a
href="https://redirect.github.com/Kludex/uvicorn/pull/3107">#3107</a>).
Uvicorn cancels the HTTP keep-alive timer when the connection becomes a
WebSocket.</li>
</ul>
<p><strong>Full changelog:</strong> <a
href="https://github.com/Kludex/uvicorn/compare/0.52.4...0.53.0">0.52.4...0.53.0</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md">uvicorn's
changelog</a>.</em></p>
<blockquote>
<h2>0.53.0 (September 14, 2026)</h2>
<p>This release adds experimental HTTP/2 support through
<code>zttp</code>. Enable it with <code>--http zttp --http2</code>.
Upgrade-based h2c and WebSockets over HTTP/2 are not supported.</p>
<h3>Added</h3>
<ul>
<li>Add experimental HTTP/2 support through <code>zttp</code> (<a
href="https://redirect.github.com/Kludex/uvicorn/pull/2982">#2982</a>,
<a
href="https://redirect.github.com/Kludex/uvicorn/pull/3101">#3101</a>)</li>
<li>Add support for <code>zuvloop</code> (<a
href="https://redirect.github.com/Kludex/uvicorn/pull/3104">#3104</a>)</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Handle comma-separated, case-insensitive <code>Connection:
close</code> tokens across HTTP implementations (<a
href="https://redirect.github.com/Kludex/uvicorn/pull/3103">#3103</a>)</li>
<li>Trust IPv6 loopback in the default <code>FORWARDED_ALLOW_IPS</code>
value (<a
href="https://redirect.github.com/Kludex/uvicorn/pull/3119">#3119</a>)</li>
<li>Cancel the HTTP keep-alive timer when upgrading to WebSocket (<a
href="https://redirect.github.com/Kludex/uvicorn/pull/3107">#3107</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/Kludex/uvicorn/commit/421708fbc1a704dac8bd4053a7c4c0bf4d3704ee"><code>421708f</code></a>
Version 0.53.0 (<a
href="https://redirect.github.com/Kludex/uvicorn/issues/3136">#3136</a>)</li>
<li><a
href="https://github.com/Kludex/uvicorn/commit/f1a1bff7be819f5724d6fdf86dfd448a97c62e23"><code>f1a1bff</code></a>
Unset the keep-alive timer when upgrading to WebSocket (<a
href="https://redirect.github.com/Kludex/uvicorn/issues/3107">#3107</a>)</li>
<li><a
href="https://github.com/Kludex/uvicorn/commit/63971ed952090438896e6eba7d07178b616d97cc"><code>63971ed</code></a>
Document HTTP/2 support (<a
href="https://redirect.github.com/Kludex/uvicorn/issues/3130">#3130</a>)</li>
<li><a
href="https://github.com/Kludex/uvicorn/commit/7d1a0055aee5e281accc646b559ddd147486bf8a"><code>7d1a005</code></a>
Remove race from multiprocess health check test (<a
href="https://redirect.github.com/Kludex/uvicorn/issues/3128">#3128</a>)</li>
<li><a
href="https://github.com/Kludex/uvicorn/commit/5ac6265a01ff6dcadb0e4250152c3deaf8a168a9"><code>5ac6265</code></a>
Add ::1 to FORWARDED_ALLOW_IPS (<a
href="https://redirect.github.com/Kludex/uvicorn/issues/3119">#3119</a>)</li>
<li><a
href="https://github.com/Kludex/uvicorn/commit/098b206ff7b01098561956ff4e7746d05e02acc6"><code>098b206</code></a>
Remove timing race from SIGHUP supervisor test (<a
href="https://redirect.github.com/Kludex/uvicorn/issues/3127">#3127</a>)</li>
<li><a
href="https://github.com/Kludex/uvicorn/commit/968f15e5d09df5f6b8959975f18687b9d755862d"><code>968f15e</code></a>
chore(deps): bump the github-actions group with 4 updates (<a
href="https://redirect.github.com/Kludex/uvicorn/issues/3113">#3113</a>)</li>
<li><a
href="https://github.com/Kludex/uvicorn/commit/7d4c08cce9eeabf64695c326b0e45c47c6a0337b"><code>7d4c08c</code></a>
chore(deps): bump the python-packages group across 1 directory with 11
update...</li>
<li><a
href="https://github.com/Kludex/uvicorn/commit/fe528a480c0aec3aea3ee8ef13251b5216c47ae9"><code>fe528a4</code></a>
Require explicit opt-in for zttp HTTP/2 (<a
href="https://redirect.github.com/Kludex/uvicorn/issues/3101">#3101</a>)</li>
<li><a
href="https://github.com/Kludex/uvicorn/commit/fa324a415364563cf45908966435e2480a6b46bf"><code>fa324a4</code></a>
chore(deps-dev): bump httpx2 from 2.10.0 to 2.12.0 (<a
href="https://redirect.github.com/Kludex/uvicorn/issues/3121">#3121</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/Kludex/uvicorn/compare/0.52.4...0.53.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `weasyprint` from 69.0 to 70.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/Kozea/WeasyPrint/releases">weasyprint's
releases</a>.</em></p>
<blockquote>
<h2>v70.0</h2>
<p>Read about this release <a
href="https://www.courtbouillon.org/blog/00074-weasyprint-70/">on our
blog</a>.</p>
<p><strong>This is a security update (CVE-2026-55073,
GHSA-r543-q48m-4c9j).</strong></p>
<p>We strongly recommend to upgrade WeasyPrint to the latest version if
you: * embed untrusted images, or * rely on the URL fetcher to filter
metadata or stylesheets passed as Python parameters.</p>
<h2>Security</h2>
<ul>
<li>Don’t render EPS images.</li>
<li>Always use original URL fetcher when available.</li>
</ul>
<h2>Features</h2>
<ul>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2905">#2905</a>:
Add initial support of CSS Notes, with financial support from NLnet</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2731">#2731</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2781">#2781</a>:
Log an error on unknown render and write_pdf options</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2802">#2802</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2805">#2805</a>:
Create immutable releases on GitHub</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2809">#2809</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2810">#2810</a>:
Switch to MSYS2 UCRT64 environment for Windows tests and
executables</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2777">#2777</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2814">#2814</a>:
Support COLR emoji fonts</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2667">#2667</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2744">#2744</a>:
Support context paint in SVG markers</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/1862">#1862</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2844">#2844</a>:
Improve filename detection for attachments</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2816">#2816</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2827">#2827</a>:
Set SVG title as alternative text</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2718">#2718</a>:
Provide a 'onedir' Windows executable</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2863">#2863</a>:
Support box-shadow</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2755">#2755</a>:
Support RTL SVG text anchoring</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2866">#2866</a>:
Don’t use f-strings in logs</li>
</ul>
<h2>Bug fixes</h2>
<ul>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2799">#2799</a>:
Keep HarfBuzz font faces alive during PDF subsetting</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2764">#2764</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2793">#2793</a>:
Accept Path as base URL in CSS</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2800">#2800</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2801">#2801</a>:
Fix position of raster emojis</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2782">#2782</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2807">#2807</a>:
Use POSIX paths in Fontconfig</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2766">#2766</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2779">#2779</a>:
Use response bytes when image file path doesn’t exist</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2277">#2277</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2728">#2728</a>:
Honor page breaks on floated elements</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2789">#2789</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2818">#2818</a>:
Use base URL when solving pending properties</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2820">#2820</a>:
Ignore unresolvable math in image slices</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2901">#2901</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2825">#2825</a>:
Transform SVG size into CSS to apply CSS sizing algorithm</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2819">#2819</a>:
Resolve calc() division by zero to infinity</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2824">#2824</a>:
Remove old deprecation warnings</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2762">#2762</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2780">#2780</a>:
Set SVG gradient color before path construction</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2761">#2761</a>:
Handle split tables with captions</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2215">#2215</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2747">#2747</a>:
Discard broken at-rules</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2736">#2736</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2738">#2738</a>:
Apply transformations to SVG opacity groups</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2830">#2830</a>:
Use a stack to draw simple borders</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2831">#2831</a>:
Fix line_height() crash on calc() values</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2784">#2784</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2832">#2832</a>:
Set fallback font for Unicode test</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2726">#2726</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2881">#2881</a>:
Improve accessibility of PDF forms</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2803">#2803</a>:
Fix inline width after backtracked line breaks</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2833">#2833</a>:
Store root style in anonymous style</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/Kozea/WeasyPrint/blob/main/docs/changelog.rst">weasyprint's
changelog</a>.</em></p>
<blockquote>
<h2>Version 70.0</h2>
<p>Released on 2026-09-08.</p>
<p><strong>This is a security update (CVE-2026-55073,
GHSA-r543-q48m-4c9j).</strong></p>
<p>We strongly recommend to upgrade WeasyPrint to the latest version if
you:</p>
<ul>
<li>embed untrusted images, or</li>
<li>rely on the URL fetcher to filter metadata or stylesheets passed as
Python parameters.</li>
</ul>
<p>Security:</p>
<ul>
<li>Don’t render EPS images.</li>
<li>Always use original URL fetcher when available.</li>
</ul>
<p>Features:</p>
<ul>
<li><code>[#2905](https://github.com/Kozea/WeasyPrint/issues/2905)
&lt;https://github.com/Kozea/WeasyPrint/pull/2905&gt;</code>_:
Add initial support of CSS Notes, with financial support from NLnet</li>
<li><code>[#2731](https://github.com/Kozea/WeasyPrint/issues/2731)
&lt;https://github.com/Kozea/WeasyPrint/issues/2731&gt;</code><em>,
<code>[#2781](https://github.com/Kozea/WeasyPrint/issues/2781)
&lt;https://github.com/Kozea/WeasyPrint/pull/2781&gt;</code></em>:
Log an error on unknown render and write_pdf options</li>
<li><code>[#2802](https://github.com/Kozea/WeasyPrint/issues/2802)
&lt;https://github.com/Kozea/WeasyPrint/issues/2802&gt;</code><em>,
<code>[#2805](https://github.com/Kozea/WeasyPrint/issues/2805)
&lt;https://github.com/Kozea/WeasyPrint/pull/2805&gt;</code></em>:
Create immutable releases on GitHub</li>
<li><code>[#2809](https://github.com/Kozea/WeasyPrint/issues/2809)
&lt;https://github.com/Kozea/WeasyPrint/issues/2809&gt;</code><em>,
<code>[#2810](https://github.com/Kozea/WeasyPrint/issues/2810)
&lt;https://github.com/Kozea/WeasyPrint/pull/2810&gt;</code></em>:
Switch to MSYS2 UCRT64 environment for Windows tests and
executables</li>
<li><code>[#2777](https://github.com/Kozea/WeasyPrint/issues/2777)
&lt;https://github.com/Kozea/WeasyPrint/issues/2777&gt;</code><em>,
<code>[#2814](https://github.com/Kozea/WeasyPrint/issues/2814)
&lt;https://github.com/Kozea/WeasyPrint/pull/2814&gt;</code></em>:
Support COLR emoji fonts</li>
<li><code>[#2667](https://github.com/Kozea/WeasyPrint/issues/2667)
&lt;https://github.com/Kozea/WeasyPrint/issues/2667&gt;</code><em>,
<code>[#2744](https://github.com/Kozea/WeasyPrint/issues/2744)
&lt;https://github.com/Kozea/WeasyPrint/pull/2744&gt;</code></em>:
Support context paint in SVG markers</li>
<li><code>[#1862](https://github.com/Kozea/WeasyPrint/issues/1862)
&lt;https://github.com/Kozea/WeasyPrint/issues/1862&gt;</code><em>,
<code>[#2844](https://github.com/Kozea/WeasyPrint/issues/2844)
&lt;https://github.com/Kozea/WeasyPrint/pull/2844&gt;</code></em>:
Improve filename detection for attachments</li>
<li><code>[#2816](https://github.com/Kozea/WeasyPrint/issues/2816)
&lt;https://github.com/Kozea/WeasyPrint/issues/2816&gt;</code><em>,
<code>[#2827](https://github.com/Kozea/WeasyPrint/issues/2827)
&lt;https://github.com/Kozea/WeasyPrint/pull/2827&gt;</code></em>:
Set SVG title as alternative text</li>
<li><code>[#2718](https://github.com/Kozea/WeasyPrint/issues/2718)
&lt;https://github.com/Kozea/WeasyPrint/issues/2718&gt;</code>_:
Provide a 'onedir' Windows executable</li>
<li><code>[#2863](https://github.com/Kozea/WeasyPrint/issues/2863)
&lt;https://github.com/Kozea/WeasyPrint/pull/2863&gt;</code>_:
Support box-shadow</li>
<li><code>[#2755](https://github.com/Kozea/WeasyPrint/issues/2755)
&lt;https://github.com/Kozea/WeasyPrint/pull/2755&gt;</code>_:
Support RTL SVG text anchoring</li>
<li><code>[#2866](https://github.com/Kozea/WeasyPrint/issues/2866)
&lt;https://github.com/Kozea/WeasyPrint/issues/2866&gt;</code>_:
Don’t use f-strings in logs</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/4d3b7b6449e3494f59c7c2f36b512d129225679c"><code>4d3b7b6</code></a>
Version 70.0</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/289e278439b017cd9263b4cd4727026987f86443"><code>289e278</code></a>
Always use original URL fetcher when available</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/aeb3be74e3c904e4b772014006410e23e0512b4b"><code>aeb3be7</code></a>
Merge remote-tracking branch 'security/main'</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/48357241f949c3f6880ec1a40f56d2f5106fdef3"><code>4835724</code></a>
Merge pull request <a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2915">#2915</a>
from havelaer/fix-nested-svg-viewport-restore</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/03310511d8afac08f80939e7fa317ad6051e251f"><code>0331051</code></a>
Restore nested SVG viewport size on the SVG object, not the drawing
function</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/e4b8b45e409392197441bc449d110f323b0eeb66"><code>e4b8b45</code></a>
Add harfbuzz-vector requirement for Fedora</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/371e4debb4805fa3d5a138f2cbb044fc176284da"><code>371e4de</code></a>
Merge pull request <a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2905">#2905</a>
from Kozea/notes</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/590bf63301d77eaf6aac6b1eb3a3fbb9494e3b23"><code>590bf63</code></a>
Merge pull request <a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2913">#2913</a>
from Kozea/fast-svg-paths</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/f6570c3038b60695f715b12c7805f6933e58490a"><code>f6570c3</code></a>
Use a faster regex-based parser for SVG paths</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/bc0516240c5f8a1eaaf658621d52a09eebecdea9"><code>bc05162</code></a>
Use faster deque for SVG vertices</li>
<li>Additional commits viewable in <a
href="https://github.com/Kozea/WeasyPrint/compare/v69.0...v70.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `alembic` from 1.19.2 to 1.20.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/sqlalchemy/alembic/releases">alembic's
releases</a>.</em></p>
<blockquote>
<h1>1.20.0</h1>
<p>Released: September 11, 2026</p>
<h2>usecase</h2>
<ul>
<li>
<p><strong>[usecase] [batch]</strong> Added a warning for the case where
an unnamed CHECK constraint on a
reflected table is omitted from a batch &quot;recreate&quot; operation.
An unnamed
CHECK constraint can't be reliably carried over in a batch recreate
as it may refer to columns that are being dropped or changed.  This
omission was previously a silent operation.   The presence of any
<code>~sqlalchemy.schema.CheckConstraint</code> in
<code>Operations.batch_alter_table.table_args</code> is taken to
indicate
that the case has been accommodated, and no warning is emitted.</p>
<p>References: <a
href="https://redirect.github.com/sqlalchemy/alembic/issues/1846">#1846</a></p>
</li>
<li>
<p><strong>[usecase] [autogenerate]</strong> Autogenerate now renders a
warning comment above any rendered
<code>Operations.drop_constraint()</code> directive for which the
constraint name
is <code>None</code>, as is the case when a constraint that has no name
in the model
is dropped, most typically within the <code>downgrade()</code> function
of a
migration that adds an unnamed constraint.  A warning is also emitted on
the console when the migration script is generated.   The directive
requires a non-None name in order to be able to emit a &quot;DROP
CONSTRAINT&quot;
command.</p>
<p>References: <a
href="https://redirect.github.com/sqlalchemy/alembic/issues/916">#916</a></p>
</li>
</ul>
<h2>bug</h2>
<ul>
<li>
<p><strong>[bug] [batch]</strong> Fixed bug in batch mode where adding a
column with a type that generates
its own CHECK constraint, such as <code>~sqlalchemy.types.Boolean</code>
or
<code>~sqlalchemy.types.Enum</code> with
<code>~sqlalchemy.types.Boolean.create_constraint</code> set to
<code>True</code>,
would emit the constraint twice when the table was recreated, once under
the name generated by the naming convention in use and once under the
name given to the type.  The constraint is now emitted once, using the
same name that would be used outside of batch mode.</p>
<p>References: <a
href="https://redirect.github.com/sqlalchemy/alembic/issues/1768">#1768</a></p>
</li>
<li>
<p><strong>[bug] [batch]</strong> Fixed bug in batch mode where a CHECK
constraint generated by a type such
as <code>~sqlalchemy.types.Boolean</code> or
<code>~sqlalchemy.types.Enum</code>
would lose the name established for it by the naming convention in use
when the table was recreated, as the constraint was regenerated against
the temporary table used for the recreate operation.  The naming
convention is now resolved against the name of the table being
replaced.</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/sqlalchemy/alembic/commits">compare
view</a></li>
</ul>
</details>
<br />

Updates `ruff` from 0.16.6 to 0.16.7
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/releases">ruff's
releases</a>.</em></p>
<blockquote>
<h2>0.16.7</h2>
<h2>Release Notes</h2>
<p>Released on 2026-09-10.</p>
<h3>Preview features</h3>
<ul>
<li>[<code>ruff</code>] Add rule for default values on method receivers
(<code>RUF077</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/26700">#26700</a>)</li>
<li>[<code>ruff</code>] Recognize <code>re.prefixmatch</code>
(<code>RUF039</code>, <code>RUF055</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28311">#28311</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>Alternate nested quotes inside format spec interpolations (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28259">#28259</a>)</li>
<li>[<code>flake8-implicit-str-concat</code>] Mark fix unsafe when it
creates a docstring (<code>ISC003</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27981">#27981</a>)</li>
<li>[<code>flake8-tidy-imports</code>] Skip fixes for multi-member
imports (<code>TID254</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/26584">#26584</a>)</li>
<li>[<code>pylint</code>] Gate <code>ImportCycleError</code> on Python
3.15 (<code>PLW0133</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28310">#28310</a>)</li>
</ul>
<h3>Rule changes</h3>
<ul>
<li>Correct <code>D211</code> and <code>D203</code> rule conflict
diagnostic (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28444">#28444</a>)</li>
<li>Recognize <code>slice</code> and <code>frozendict</code> generics
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28477">#28477</a>)</li>
<li>Stop defining <code>__cached__</code> for Python 3.15 (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28476">#28476</a>)</li>
<li>[<code>pyupgrade</code>] Stop recommending removed
<code>typing.no_type_check_decorator</code> (<code>UP035</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28475">#28475</a>)</li>
</ul>
<h3>Performance</h3>
<ul>
<li>Reuse parser name lookups when interning (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28399">#28399</a>)</li>
<li>Speed up inherited configuration resolution (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28299">#28299</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Fix <code>line-length</code> path in <code>--config</code> example
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28392">#28392</a>)</li>
<li>Remove the &quot;Who’s Using Ruff?&quot; list (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28455">#28455</a>)</li>
</ul>
<h3>Other changes</h3>
<ul>
<li>Embed archive checksums in the shell installer (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28281">#28281</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/The-Compiler"><code>@​The-Compiler</code></a></li>
<li><a
href="https://github.com/mdiniz97"><code>@​mdiniz97</code></a></li>
<li><a href="https://github.com/zsol"><code>@​zsol</code></a></li>
<li><a
href="https://github.com/gorewilliams"><code>@​gorewilliams</code></a></li>
<li><a
href="https://github.com/RafaelJohn9"><code>@​RafaelJohn9</code></a></li>
<li><a href="https://github.com/qatcod"><code>@​qatcod</code></a></li>
<li><a href="https://github.com/zanieb"><code>@​zanieb</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's
changelog</a>.</em></p>
<blockquote>
<h2>0.16.7</h2>
<p>Released on 2026-09-10.</p>
<h3>Preview features</h3>
<ul>
<li>[<code>ruff</code>] Add rule for default values on method receivers
(<code>RUF077</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/26700">#26700</a>)</li>
<li>[<code>ruff</code>] Recognize <code>re.prefixmatch</code>
(<code>RUF039</code>, <code>RUF055</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28311">#28311</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>Alternate nested quotes inside format spec interpolations (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28259">#28259</a>)</li>
<li>[<code>flake8-implicit-str-concat</code>] Mark fix unsafe when it
creates a docstring (<code>ISC003</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27981">#27981</a>)</li>
<li>[<code>flake8-tidy-imports</code>] Skip fixes for multi-member
imports (<code>TID254</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/26584">#26584</a>)</li>
<li>[<code>pylint</code>] Gate <code>ImportCycleError</code> on Python
3.15 (<code>PLW0133</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28310">#28310</a>)</li>
</ul>
<h3>Rule changes</h3>
<ul>
<li>Correct <code>D211</code> and <code>D203</code> rule conflict
diagnostic (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28444">#28444</a>)</li>
<li>Recognize <code>slice</code> and <code>frozendict</code> generics
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28477">#28477</a>)</li>
<li>Stop defining <code>__cached__</code> for Python 3.15 (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28476">#28476</a>)</li>
<li>[<code>pyupgrade</code>] Stop recommending removed
<code>typing.no_type_check_decorator</code> (<code>UP035</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28475">#28475</a>)</li>
</ul>
<h3>Performance</h3>
<ul>
<li>Reuse parser name lookups when interning (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28399">#28399</a>)</li>
<li>Speed up inherited configuration resolution (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28299">#28299</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Fix <code>line-length</code> path in <code>--config</code> example
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28392">#28392</a>)</li>
<li>Remove the &quot;Who’s Using Ruff?&quot; list (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28455">#28455</a>)</li>
</ul>
<h3>Other changes</h3>
<ul>
<li>Embed archive checksums in the shell installer (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28281">#28281</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/The-Compiler"><code>@​The-Compiler</code></a></li>
<li><a
href="https://github.com/mdiniz97"><code>@​mdiniz97</code></a></li>
<li><a href="https://github.com/zsol"><code>@​zsol</code></a></li>
<li><a
href="https://github.com/gorewilliams"><code>@​gorewilliams</code></a></li>
<li><a
href="https://github.com/RafaelJohn9"><code>@​RafaelJohn9</code></a></li>
<li><a href="https://github.com/qatcod"><code>@​qatcod</code></a></li>
<li><a href="https://github.com/zanieb"><code>@​zanieb</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a
href="https://github.com/nightt5879"><code>@​nightt5879</code></a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/ruff/commit/b5dba861cc38e3f7fb4524c9ceba3e01a474ea13"><code>b5dba86</code></a>
Bump version to 0.16.7 (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28496">#28496</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/5992d0504697d86565d8fc3a4d8245a5f4047d24"><code>5992d05</code></a>
Install rustfmt before linting releases (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28495">#28495</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/1713a1f4325494d883a080d590a25a1946f399e8"><code>1713a1f</code></a>
ensure prepare release changes pass prek (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28488">#28488</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/18cdbb4f3d14058794420e758864795f55336334"><code>18cdbb4</code></a>
use scoped token for release workflow (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28484">#28484</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/c3813a501faf887fd01948c98bb8d58ad26488bd"><code>c3813a5</code></a>
add a workflow for preparing releases (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28486">#28486</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/00948c00a671b81f5358af9f038436bcbb993b38"><code>00948c0</code></a>
Remove the &quot;Who’s Using Ruff?&quot; list (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28455">#28455</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/86a2eba7b48e3c10386f7ab8a5425c7275d2b427"><code>86a2eba</code></a>
[<code>pyupgrade</code>] Stop recommending removed
<code>typing.no_type_check_decorator</code> (`UP...</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/609e184aa35f0034b7ef63e3e04327081c484af6"><code>609e184</code></a>
Stop defining <code>__cached__</code> for Python 3.15 (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28476">#28476</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/859ff2f01670c43ffff1ea597c8a2e375ada0fbe"><code>859ff2f</code></a>
[ty] Track symlinked directory status in listings (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28482">#28482</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/77f653825800ddaf3bc221ae6db49a500e1002d5"><code>77f6538</code></a>
Use paid GitHub-hosted runners for Linux (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28478">#28478</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/astral-sh/ruff/compare/0.16.6...0.16.7">compare
view</a></li>
</ul>
</details>
<br />

Updates `ty` from 0.0.78 to 0.0.80
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ty/releases">ty's
releases</a>.</em></p>
<blockquote>
<h2>0.0.80</h2>
<h2>Release Notes</h2>
<p>Released on 2026-09-09.</p>
<h3>Bug fixes</h3>
<ul>
<li>Fix <code>--force-exclude</code> for directories with an excluded
ancestor (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28451">#28451</a>)</li>
<li>Preserve metaclass candidates after conflicts (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28461">#28461</a>)</li>
</ul>
<h3>LSP server</h3>
<ul>
<li>Give existing autofixes descriptive titles (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28456">#28456</a>)</li>
<li>Prevent LSP hangs during inlay hint bursts (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28390">#28390</a>)</li>
</ul>
<h3>Diagnostic improvements</h3>
<ul>
<li>Preserve redundant-condition diagnostics with unreachable operands
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28374">#28374</a>)</li>
</ul>
<h3>Core type checking</h3>
<ul>
<li>Check captured receivers when calling wrapped classmethods (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28467">#28467</a>)</li>
<li>Fix cached classmethods on generic classes (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28207">#28207</a>)</li>
<li>Fix disjointness of type guards and boolean literals (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28363">#28363</a>)</li>
<li>Infer tuple variance from the full tuple spec (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28446">#28446</a>)</li>
<li>Infer tuple variance more precisely (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28426">#28426</a>)</li>
<li>Preserve callable identity across specialized types (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28409">#28409</a>)</li>
<li>Preserve callback type context through ParamSpec forwarding (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28439">#28439</a>)</li>
<li>Preserve wrapped functions in precise <code>functools.partial</code>
relations (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28460">#28460</a>)</li>
<li>Respect descriptor protocol for <code>__set__</code> itself (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28408">#28408</a>)</li>
<li>Respect type-variable bounds in argument context (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28448">#28448</a>)</li>
<li>Unwrap union alternatives in overload implementations (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28468">#28468</a>)</li>
</ul>
<h3>Performance</h3>
<ul>
<li>Distribute <code>len</code> inference over unions (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28470">#28470</a>)</li>
<li>Fast-path concrete literal intersections (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28348">#28348</a>)</li>
</ul>
<h3>Memory usage improvements</h3>
<ul>
<li>Avoid excess capacity in multi-binding tables (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28412">#28412</a>)</li>
<li>Share equivalent place tables within a file (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28319">#28319</a>)</li>
<li>Share names in synthesized constructor parameters (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28398">#28398</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a href="https://github.com/sharkdp"><code>@​sharkdp</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a
href="https://github.com/ibraheemdev"><code>@​ibraheemdev</code></a></li>
<li><a
href="https://github.com/AlexWaygood"><code>@​AlexWaygood</code></a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ty/blob/main/CHANGELOG.md">ty's
changelog</a>.</em></p>
<blockquote>
<h2>0.0.80</h2>
<p>Released on 2026-09-09.</p>
<h3>Bug fixes</h3>
<ul>
<li>Fix <code>--force-exclude</code> for directories with an excluded
ancestor (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28451">#28451</a>)</li>
<li>Preserve metaclass candidates after conflicts (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28461">#28461</a>)</li>
</ul>
<h3>LSP server</h3>
<ul>
<li>Give existing autofixes descriptive titles (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28456">#28456</a>)</li>
<li>Prevent LSP hangs during inlay hint bursts (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28390">#28390</a>)</li>
</ul>
<h3>Diagnostic improvements</h3>
<ul>
<li>Preserve redundant-condition diagnostics with unreachable operands
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28374">#28374</a>)</li>
</ul>
<h3>Core type checking</h3>
<ul>
<li>Check captured receivers when calling wrapped classmethods (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28467">#28467</a>)</li>
<li>Fix cached classmethods on generic classes (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28207">#28207</a>)</li>
<li>Fix disjointness of type guards and boolean literals (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28363">#28363</a>)</li>
<li>Infer tuple variance from the full tuple spec (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28446">#28446</a>)</li>
<li>Infer tuple variance more precisely (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28426">#28426</a>)</li>
<li>Preserve callable identity across specialized types (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28409">#28409</a>)</li>
<li>Preserve callback type context through ParamSpec forwarding (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28439">#28439</a>)</li>
<li>Preserve wrapped functions in precise <code>functools.partial</code>
relations (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28460">#28460</a>)</li>
<li>Respect descriptor protocol for <code>__set__</code> itself (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28408">#28408</a>)</li>
<li>Respect type-variable bounds in argument context (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28448">#28448</a>)</li>
<li>Unwrap union alternatives in overload implementations (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28468">#28468</a>)</li>
</ul>
<h3>Performance</h3>
<ul>
<li>Distribute <code>len</code> inference over unions (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28470">#28470</a>)</li>
<li>Fast-path concrete literal intersections (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28348">#28348</a>)</li>
</ul>
<h3>Memory usage improvements</h3>
<ul>
<li>Avoid excess capacity in multi-binding tables (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28412">#28412</a>)</li>
<li>Share equivalent place tables within a file (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28319">#28319</a>)</li>
<li>Share names in synthesized constructor parameters (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28398">#28398</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a href="https://github.com/sharkdp"><code>@​sharkdp</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a
href="https://github.com/ibraheemdev"><code>@​ibraheemdev</code></a></li>
<li><a
href="https://github.com/AlexWaygood"><code>@​AlexWaygood</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/ty/commit/7fd8e15694f869200f7778082564c5968c50ce30"><code>7fd8e15</code></a>
Bump version to 0.0.80 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4501">#4501</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/c163f21ed4be7a5608ae5791720b43040b08cf5c"><code>c163f21</code></a>
Update dependency prek to v0.4.12 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4494">#4494</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/8ce0450332e815c0f734fb84d03d63be3eb96829"><code>8ce0450</code></a>
Update prek dependencies (<a
href="https://redirect.github.com/astral-sh/ty/issues/4495">#4495</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/5d0aa7a142189fc1955759c2987029b8ff8ef4a7"><code>5d0aa7a</code></a>
Update actions/attest-build-provenance action to v4.2.2 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4497">#4497</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/e22b86b3e6d461af46b549e5ebef5474b6256783"><code>e22b86b</code></a>
Update Swatinem/rust-cache action to v2.9.2 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4496">#4496</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/5cde40f5cb83f1cb164b91282e6a72f3dfe4580c"><code>5cde40f</code></a>
Document uv integration and workspace trust settings (<a
href="https://redirect.github.com/astral-sh/ty/issues/4339">#4339</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/b4cd79275b7ce22c4cf4208f8b005adb53e92523"><code>b4cd792</code></a>
Bump version to 0.0.79 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4484">#4484</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/52f2d5b12ff4a86f1100f3b9c3e2d61b086d8a89"><code>52f2d5b</code></a>
Add a GitHub repository threat model for ty (<a
href="https://redirect.github.com/astral-sh/ty/issues/4481">#4481</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/fd0d789cc54f9a234da75025ef6d0777280675be"><code>fd0d789</code></a>
Declare support for Python 3.15 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4476">#4476</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/7e7a87da9849d3f322690ae5b74b0409799668b6"><code>7e7a87d</code></a>
Improve rooster-generated changelog sections (<a
href="https://redirect.github.com/astral-sh/ty/issues/4473">#4473</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/astral-sh/ty/compare/0.0.78...0.0.80">compare
view</a></li>
</ul>
</details>
<br />

Updates `psycopg2-binary` from 2.9.12 to 2.9.13
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/psycopg/psycopg2/blob/master/NEWS">psycopg2-binary's
changelog</a>.</em></p>
<blockquote>
<h2>Current release</h2>
<p>What's new in psycopg 2.9.13
^^^^^^^^^^^^^^^^^^^^^^^^^^^^</p>
<ul>
<li>Add support for Python 3.15
(:ticket:<code>[#1848](https://github.com/psycopg/psycopg2/issues/1848)</code>).</li>
<li>Fix parsing of malformed bytea input.</li>
<li>Fix parsing of malformed int64 input in arrays
(:ticket:<code>[#1847](https://github.com/psycopg/psycopg2/issues/1847)</code>).</li>
<li>Add a <code>pyproject.toml</code> file to declare a PEP 517 build
backend

(:ticket:<code>[#1788](https://github.com/psycopg/psycopg2/issues/1788)</code>).</li>
<li>Drop support for Python 3.9.</li>
</ul>
<p>What's new in psycopg 2.9.12
^^^^^^^^^^^^^^^^^^^^^^^^^^^^</p>
<ul>
<li>Fix infinite loop with malformed interval
(:ticket:<code>1835</code>).</li>
</ul>
<p>What's new in psycopg 2.9.11
^^^^^^^^^^^^^^^^^^^^^^^^^^^^</p>
<ul>
<li>Add support for Python 3.14.</li>
<li>Avoid a segfault passing more arguments than placeholders if Python
is built
with assertions enabled
(:ticket:<code>[#1791](https://github.com/psycopg/psycopg2/issues/1791)</code>).</li>
<li>Add riscv64 platform binary packages
(:ticket:<code>[#1813](https://github.com/psycopg/psycopg2/issues/1813)</code>).</li>
<li><code>~psycopg2.errorcodes</code> map and
<code>~psycopg2.errors</code> classes updated to
PostgreSQL 18.</li>
<li>Drop support for Python 3.8.</li>
</ul>
<p>What's new in psycopg 2.9.10
^^^^^^^^^^^^^^^^^^^^^^^^^^^^</p>
<ul>
<li>Add support for Python 3.13.</li>
<li>Receive notifications on commit
(:ticket:<code>[#1728](https://github.com/psycopg/psycopg2/issues/1728)</code>).</li>
<li><code>~psycopg2.errorcodes</code> map and
<code>~psycopg2.errors</code> classes updated to
PostgreSQL 17.</li>
<li>Drop support for Python 3.7.</li>
</ul>
<p>What's new in psycopg 2.9.9
^^^^^^^^^^^^^^^^^^^^^^^^^^^</p>
<ul>
<li>Add support for Python 3.12.</li>
<li>Drop support for Python 3.6.</li>
</ul>
<p>What's new in psycopg 2.9.8</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/psycopg/psycopg2/commit/f650e7afed0c94f596594e8328a0c7fa65a9d0e5"><code>f650e7a</code></a>
chore: bump to release 2.9.13</li>
<li><a
href="https://github.com/psycopg/psycopg2/commit/368c8a1ca6d80088703a693ce64b68ad7d346698"><code>368c8a1</code></a>
chore!: drop support for Python 3.9</li>
<li><a
href="https://github.com/psycopg/psycopg2/commit/9b39e65ab232f0a267a278cdaef1bd9975d88c65"><code>9b39e65</code></a>
chore: drop scaleway build support</li>
<li><a
href="https://github.com/psycopg/psycopg2/commit/2ca70416be6d4d3d8170ec439876c0b3569af718"><code>2ca7041</code></a>
fix: fix handling of PostgreSQL 18 exceptions</li>
<li><a
href="https://github.com/psycopg/psycopg2/commit/5385c027ef62ce14e57a7379e0375868507d6746"><code>5385c02</code></a>
Build CPython 3.15 wheels</li>
<li><a
href="https://github.com/psycopg/psycopg2/commit/1d32e1f6678ffa8ab8897ca81826bf4dde6354cd"><code>1d32e1f</code></a>
ci: only attempt triggering documentation refresh when pushing on main
repo</li>
<li><a
href="https://github.com/psycopg/psycopg2/commit/433e7b77a7b700fbb1cdc6e9dca6b5948d07fc23"><code>433e7b7</code></a>
chore: add pyproject.toml file to declare a PEP 517 build backend</li>
<li><a
href="https://github.com/psycopg/psycopg2/commit/8fb80bc3b2c358f4e3c54e33a37326d3f8b3ff6a"><code>8fb80bc</code></a>
fix: fix parsing of malformed int64 input in arrays</li>
<li><a
href="https://github.com/psycopg/psycopg2/commit/f98014a46a1e34f024ebd6134d1d87b77490c500"><code>f98014a</code></a>
fix: fix parsing of malformed bytea input</li>
<li><a
href="https://github.com/psycopg/psycopg2/commit/822b79cfe12ca0a04482acd382cae669a16aa789"><code>822b79c</code></a>
chore: bump dependencies in binary package</li>
<li>Additional commits viewable in <a
href="https://github.com/psycopg/psycopg2/compare/2.9.12...2.9.13">compare
view</a></li>
</ul>
</details>
<br />

Updates `pyjwt` from 2.13.0 to 2.14.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/jpadilla/pyjwt/releases">pyjwt's
releases</a>.</em></p>
<blockquote>
<h2>PyJWT 2.14.0</h2>
<p>See the <a
href="https://github.com/jpadilla/pyjwt/blob/2.14.0/CHANGELOG.rst">2.14.0
changelog</a> for the complete release details and related security
advisories.</p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst">pyjwt's
changelog</a>.</em></p>
<blockquote>
<h2><code>v2.14.0
&lt;https://github.com/jpadilla/pyjwt/compare/2.13.0...2.14.0&gt;</code>__</h2>
<p>Security</p>
<pre><code>
- Harden HMAC key validation against public-key material supplied as
JWK,
  JWKS, array, encoded, BOM-prefixed, DER, or PEM input. See
`GHSA-r6x4-923q-g947
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-r6x4-923q-g947&gt;`__,
`GHSA-ffc3-869f-jxw9
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-ffc3-869f-jxw9&gt;`__,
`GHSA-p4g4-x82p-q773
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-p4g4-x82p-q773&gt;`__,
and `GHSA-w2cx-738m-mc7w
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w2cx-738m-mc7w&gt;`__.
- Reject automatic redirects when ``PyJWKClient`` fetches a JWKS,
preventing
  redirected destinations from being treated as trusted key sources. See
`GHSA-9v7f-9g4p-ffgj
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-9v7f-9g4p-ffgj&gt;`__.
- Limit repeated JWKS refreshes caused by unknown key IDs while
preserving
  normal key-rotation behavior. See
`GHSA-2gx3-rcp4-g85q
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-2gx3-rcp4-g85q&gt;`__.
- Handle deeply nested and malformed JWS/JWK input without uncaught
recursion
  errors or whole-set parsing failures. See
`GHSA-8wjv-2p76-3863
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-8wjv-2p76-3863&gt;`__
and `GHSA-w6j9-cwv2-h6wq
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w6j9-cwv2-h6wq&gt;`__.
- Enforce compact JWS encoding rules during decoding. See
`GHSA-hxm8-2xgr-2p9m
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-hxm8-2xgr-2p9m&gt;`__.
- Reject detached-payload arguments for attached JWS inputs. Thanks to
`@xclow3n
&lt;https://github.com/xclow3n&gt;`__ for reporting this behavior; fixed
in commit
`37b54877
&lt;https://github.com/jpadilla/pyjwt/commit/37b54877bf7bea67e8149130e96929e3ec798122&gt;`__.
<p>Fixed</p>
<pre><code>
- Apply HMAC key validation consistently when keys are loaded through
  ``PyJWK`` and ``PyJWKClient``. See
`GHSA-pxh4-856f-4h89
&amp;lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-pxh4-856f-4h89&amp;gt;`__.
- Reject empty HMAC keys when represented as JWKs.
See `GHSA-pxh4-856f-4h89
&amp;lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-pxh4-856f-4h89&amp;gt;`__.

Fixed
</code></pre>
<ul>
<li>Raise the documented <code>PyJWTError</code> subclass instead of
leaking a<br />
<code>TypeError</code> when the <code>exp</code>, <code>nbf</code>, or
<code>iat</code> claim decodes to a<br />
non-numeric, non-string value such as a list, dict, or
<code>null</code>.<br />
</code></pre></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/c6fe464b356ff4b1ebc9ba62172d331a40aa27df"><code>c6fe464</code></a>
release: prepare v2.14.0</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/f5413029ae7a2e31b1367b5303ea86a2f54ccf42"><code>f541302</code></a>
style: apply Ruff formatting</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/801cd128528c62d9b23fcd161d1a2e1c17982f95"><code>801cd12</code></a>
fix: reject public JWK container HMAC keys</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/af8181ca0bec5e6b372fbba9afbe23702b787ceb"><code>af8181c</code></a>
fix: reject empty HMAC keys from JWKs</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/ba4853a75fb9676362da17f67d0f64bd18afd4e1"><code>ba4853a</code></a>
Throttle repeated PyJWKClient refreshes</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/2798504fa2663364573cf2d1043d8d7fef389499"><code>2798504</code></a>
fix: reject DER public keys as HMAC secrets</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/8b4e233a22206b34ec1186e912e75c0b2396ac07"><code>8b4e233</code></a>
fix: reject loader-accepted PEM variants</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/1f8180a211256dfe5cf32294b6753f554a5a4258"><code>1f8180a</code></a>
fix: format JWS tests</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/cff1ac55fe5f1096fd05295b269fce053ee290ab"><code>cff1ac5</code></a>
Fix redirect handler return annotation</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/0a795b8e1f6ef08f634aa7086fc41cc6d5ce3e56"><code>0a795b8</code></a>
Reject redirects in PyJWKClient fetches</li>
<li>Additional commits viewable in <a
href="https://github.com/jpadilla/pyjwt/compare/2.13.0...2.14.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `uvicorn` from 0.52.4 to 0.53.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/Kludex/uvicorn/releases">uvicorn's
releases</a>.</em></p>
<blockquote>
<h2>Version 0.53.0</h2>
<h2>🌐 Opt-in HTTP/2 support</h2>
<p><code>uvicorn</code> 0.53.0 adds experimental HTTP/2 through
<code>zttp</code>, alongside a new <code>zuvloop</code> integration and
connection-handling improvements.</p>
<pre lang="console"><code>uv add uvicorn==0.53.0
</code></pre>
<ul>
<li><strong>Serve HTTP/1.1 and HTTP/2 with <code>zttp</code></strong>
(<a
href="https://redirect.github.com/Kludex/uvicorn/pull/2982">#2982</a>,
<a
href="https://redirect.github.com/Kludex/uvicorn/pull/3101">#3101</a>).
Install <code>zttp</code>, then enable HTTP/2 with <code>--http z…
chrischall added a commit to chrischall/outlook-to-pdf that referenced this pull request Sep 18, 2026
Bumps [weasyprint](https://github.com/Kozea/WeasyPrint) from 69.0 to
70.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/Kozea/WeasyPrint/releases">weasyprint's
releases</a>.</em></p>
<blockquote>
<h2>v70.0</h2>
<p>Read about this release <a
href="https://www.courtbouillon.org/blog/00074-weasyprint-70/">on our
blog</a>.</p>
<p><strong>This is a security update (CVE-2026-55073,
GHSA-r543-q48m-4c9j).</strong></p>
<p>We strongly recommend to upgrade WeasyPrint to the latest version if
you: * embed untrusted images, or * rely on the URL fetcher to filter
metadata or stylesheets passed as Python parameters.</p>
<h2>Security</h2>
<ul>
<li>Don’t render EPS images.</li>
<li>Always use original URL fetcher when available.</li>
</ul>
<h2>Features</h2>
<ul>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2905">#2905</a>:
Add initial support of CSS Notes, with financial support from NLnet</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2731">#2731</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2781">#2781</a>:
Log an error on unknown render and write_pdf options</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2802">#2802</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2805">#2805</a>:
Create immutable releases on GitHub</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2809">#2809</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2810">#2810</a>:
Switch to MSYS2 UCRT64 environment for Windows tests and
executables</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2777">#2777</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2814">#2814</a>:
Support COLR emoji fonts</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2667">#2667</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2744">#2744</a>:
Support context paint in SVG markers</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/1862">#1862</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2844">#2844</a>:
Improve filename detection for attachments</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2816">#2816</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2827">#2827</a>:
Set SVG title as alternative text</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2718">#2718</a>:
Provide a 'onedir' Windows executable</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2863">#2863</a>:
Support box-shadow</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2755">#2755</a>:
Support RTL SVG text anchoring</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2866">#2866</a>:
Don’t use f-strings in logs</li>
</ul>
<h2>Bug fixes</h2>
<ul>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2799">#2799</a>:
Keep HarfBuzz font faces alive during PDF subsetting</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2764">#2764</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2793">#2793</a>:
Accept Path as base URL in CSS</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2800">#2800</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2801">#2801</a>:
Fix position of raster emojis</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2782">#2782</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2807">#2807</a>:
Use POSIX paths in Fontconfig</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2766">#2766</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2779">#2779</a>:
Use response bytes when image file path doesn’t exist</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2277">#2277</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2728">#2728</a>:
Honor page breaks on floated elements</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2789">#2789</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2818">#2818</a>:
Use base URL when solving pending properties</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2820">#2820</a>:
Ignore unresolvable math in image slices</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2901">#2901</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2825">#2825</a>:
Transform SVG size into CSS to apply CSS sizing algorithm</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2819">#2819</a>:
Resolve calc() division by zero to infinity</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2824">#2824</a>:
Remove old deprecation warnings</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2762">#2762</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2780">#2780</a>:
Set SVG gradient color before path construction</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2761">#2761</a>:
Handle split tables with captions</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2215">#2215</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2747">#2747</a>:
Discard broken at-rules</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2736">#2736</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2738">#2738</a>:
Apply transformations to SVG opacity groups</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2830">#2830</a>:
Use a stack to draw simple borders</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2831">#2831</a>:
Fix line_height() crash on calc() values</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2784">#2784</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2832">#2832</a>:
Set fallback font for Unicode test</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2726">#2726</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2881">#2881</a>:
Improve accessibility of PDF forms</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2803">#2803</a>:
Fix inline width after backtracked line breaks</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2833">#2833</a>:
Store root style in anonymous style</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/Kozea/WeasyPrint/blob/main/docs/changelog.rst">weasyprint's
changelog</a>.</em></p>
<blockquote>
<h2>Version 70.0</h2>
<p>Released on 2026-09-08.</p>
<p><strong>This is a security update (CVE-2026-55073,
GHSA-r543-q48m-4c9j).</strong></p>
<p>We strongly recommend to upgrade WeasyPrint to the latest version if
you:</p>
<ul>
<li>embed untrusted images, or</li>
<li>rely on the URL fetcher to filter metadata or stylesheets passed as
Python parameters.</li>
</ul>
<p>Security:</p>
<ul>
<li>Don’t render EPS images.</li>
<li>Always use original URL fetcher when available.</li>
</ul>
<p>Features:</p>
<ul>
<li><code>[#2905](Kozea/WeasyPrint#2905)
&lt;https://github.com/Kozea/WeasyPrint/pull/2905&gt;</code>_:
Add initial support of CSS Notes, with financial support from NLnet</li>
<li><code>[#2731](Kozea/WeasyPrint#2731)
&lt;https://github.com/Kozea/WeasyPrint/issues/2731&gt;</code><em>,
<code>[#2781](Kozea/WeasyPrint#2781)
&lt;https://github.com/Kozea/WeasyPrint/pull/2781&gt;</code></em>:
Log an error on unknown render and write_pdf options</li>
<li><code>[#2802](Kozea/WeasyPrint#2802)
&lt;https://github.com/Kozea/WeasyPrint/issues/2802&gt;</code><em>,
<code>[#2805](Kozea/WeasyPrint#2805)
&lt;https://github.com/Kozea/WeasyPrint/pull/2805&gt;</code></em>:
Create immutable releases on GitHub</li>
<li><code>[#2809](Kozea/WeasyPrint#2809)
&lt;https://github.com/Kozea/WeasyPrint/issues/2809&gt;</code><em>,
<code>[#2810](Kozea/WeasyPrint#2810)
&lt;https://github.com/Kozea/WeasyPrint/pull/2810&gt;</code></em>:
Switch to MSYS2 UCRT64 environment for Windows tests and
executables</li>
<li><code>[#2777](Kozea/WeasyPrint#2777)
&lt;https://github.com/Kozea/WeasyPrint/issues/2777&gt;</code><em>,
<code>[#2814](Kozea/WeasyPrint#2814)
&lt;https://github.com/Kozea/WeasyPrint/pull/2814&gt;</code></em>:
Support COLR emoji fonts</li>
<li><code>[#2667](Kozea/WeasyPrint#2667)
&lt;https://github.com/Kozea/WeasyPrint/issues/2667&gt;</code><em>,
<code>[#2744](Kozea/WeasyPrint#2744)
&lt;https://github.com/Kozea/WeasyPrint/pull/2744&gt;</code></em>:
Support context paint in SVG markers</li>
<li><code>[#1862](Kozea/WeasyPrint#1862)
&lt;https://github.com/Kozea/WeasyPrint/issues/1862&gt;</code><em>,
<code>[#2844](Kozea/WeasyPrint#2844)
&lt;https://github.com/Kozea/WeasyPrint/pull/2844&gt;</code></em>:
Improve filename detection for attachments</li>
<li><code>[#2816](Kozea/WeasyPrint#2816)
&lt;https://github.com/Kozea/WeasyPrint/issues/2816&gt;</code><em>,
<code>[#2827](Kozea/WeasyPrint#2827)
&lt;https://github.com/Kozea/WeasyPrint/pull/2827&gt;</code></em>:
Set SVG title as alternative text</li>
<li><code>[#2718](Kozea/WeasyPrint#2718)
&lt;https://github.com/Kozea/WeasyPrint/issues/2718&gt;</code>_:
Provide a 'onedir' Windows executable</li>
<li><code>[#2863](Kozea/WeasyPrint#2863)
&lt;https://github.com/Kozea/WeasyPrint/pull/2863&gt;</code>_:
Support box-shadow</li>
<li><code>[#2755](Kozea/WeasyPrint#2755)
&lt;https://github.com/Kozea/WeasyPrint/pull/2755&gt;</code>_:
Support RTL SVG text anchoring</li>
<li><code>[#2866](Kozea/WeasyPrint#2866)
&lt;https://github.com/Kozea/WeasyPrint/issues/2866&gt;</code>_:
Don’t use f-strings in logs</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/4d3b7b6449e3494f59c7c2f36b512d129225679c"><code>4d3b7b6</code></a>
Version 70.0</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/289e278439b017cd9263b4cd4727026987f86443"><code>289e278</code></a>
Always use original URL fetcher when available</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/aeb3be74e3c904e4b772014006410e23e0512b4b"><code>aeb3be7</code></a>
Merge remote-tracking branch 'security/main'</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/48357241f949c3f6880ec1a40f56d2f5106fdef3"><code>4835724</code></a>
Merge pull request <a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2915">#2915</a>
from havelaer/fix-nested-svg-viewport-restore</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/03310511d8afac08f80939e7fa317ad6051e251f"><code>0331051</code></a>
Restore nested SVG viewport size on the SVG object, not the drawing
function</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/e4b8b45e409392197441bc449d110f323b0eeb66"><code>e4b8b45</code></a>
Add harfbuzz-vector requirement for Fedora</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/371e4debb4805fa3d5a138f2cbb044fc176284da"><code>371e4de</code></a>
Merge pull request <a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2905">#2905</a>
from Kozea/notes</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/590bf63301d77eaf6aac6b1eb3a3fbb9494e3b23"><code>590bf63</code></a>
Merge pull request <a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2913">#2913</a>
from Kozea/fast-svg-paths</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/f6570c3038b60695f715b12c7805f6933e58490a"><code>f6570c3</code></a>
Use a faster regex-based parser for SVG paths</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/bc0516240c5f8a1eaaf658621d52a09eebecdea9"><code>bc05162</code></a>
Use faster deque for SVG vertices</li>
<li>Additional commits viewable in <a
href="https://github.com/Kozea/WeasyPrint/compare/v69.0...v70.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=weasyprint&package-manager=uv&previous-version=69.0&new-version=70.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/chrischall/outlook-to-pdf/network/alerts).

</details>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Chris Hall <chris.c.hall@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
sonnyp added a commit to fairscope/PlanktoScope that referenced this pull request Sep 22, 2026
[//]: # (dependabot-start)
⚠️  **Dependabot is rebasing this PR** ⚠️ 

Rebasing might not happen immediately, so don't worry if this takes some
time.

Note: if you make any changes to this PR yourself, they will take
precedence over the rebase.

---

[//]: # (dependabot-end)

Bumps [weasyprint](https://github.com/Kozea/WeasyPrint) from 69.0 to
70.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/Kozea/WeasyPrint/releases">weasyprint's
releases</a>.</em></p>
<blockquote>
<h2>v70.0</h2>
<p>Read about this release <a
href="https://www.courtbouillon.org/blog/00074-weasyprint-70/">on our
blog</a>.</p>
<p><strong>This is a security update (CVE-2026-55073,
GHSA-r543-q48m-4c9j).</strong></p>
<p>We strongly recommend to upgrade WeasyPrint to the latest version if
you: * embed untrusted images, or * rely on the URL fetcher to filter
metadata or stylesheets passed as Python parameters.</p>
<h2>Security</h2>
<ul>
<li>Don’t render EPS images.</li>
<li>Always use original URL fetcher when available.</li>
</ul>
<h2>Features</h2>
<ul>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2905">#2905</a>:
Add initial support of CSS Notes, with financial support from NLnet</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2731">#2731</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2781">#2781</a>:
Log an error on unknown render and write_pdf options</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2802">#2802</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2805">#2805</a>:
Create immutable releases on GitHub</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2809">#2809</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2810">#2810</a>:
Switch to MSYS2 UCRT64 environment for Windows tests and
executables</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2777">#2777</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2814">#2814</a>:
Support COLR emoji fonts</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2667">#2667</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2744">#2744</a>:
Support context paint in SVG markers</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/1862">#1862</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2844">#2844</a>:
Improve filename detection for attachments</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2816">#2816</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2827">#2827</a>:
Set SVG title as alternative text</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2718">#2718</a>:
Provide a 'onedir' Windows executable</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2863">#2863</a>:
Support box-shadow</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2755">#2755</a>:
Support RTL SVG text anchoring</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2866">#2866</a>:
Don’t use f-strings in logs</li>
</ul>
<h2>Bug fixes</h2>
<ul>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2799">#2799</a>:
Keep HarfBuzz font faces alive during PDF subsetting</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2764">#2764</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2793">#2793</a>:
Accept Path as base URL in CSS</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2800">#2800</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2801">#2801</a>:
Fix position of raster emojis</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2782">#2782</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2807">#2807</a>:
Use POSIX paths in Fontconfig</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2766">#2766</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2779">#2779</a>:
Use response bytes when image file path doesn’t exist</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2277">#2277</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2728">#2728</a>:
Honor page breaks on floated elements</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2789">#2789</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2818">#2818</a>:
Use base URL when solving pending properties</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2820">#2820</a>:
Ignore unresolvable math in image slices</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2901">#2901</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2825">#2825</a>:
Transform SVG size into CSS to apply CSS sizing algorithm</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2819">#2819</a>:
Resolve calc() division by zero to infinity</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2824">#2824</a>:
Remove old deprecation warnings</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2762">#2762</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2780">#2780</a>:
Set SVG gradient color before path construction</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2761">#2761</a>:
Handle split tables with captions</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2215">#2215</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2747">#2747</a>:
Discard broken at-rules</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2736">#2736</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2738">#2738</a>:
Apply transformations to SVG opacity groups</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2830">#2830</a>:
Use a stack to draw simple borders</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2831">#2831</a>:
Fix line_height() crash on calc() values</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2784">#2784</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2832">#2832</a>:
Set fallback font for Unicode test</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2726">#2726</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2881">#2881</a>:
Improve accessibility of PDF forms</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2803">#2803</a>:
Fix inline width after backtracked line breaks</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2833">#2833</a>:
Store root style in anonymous style</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/Kozea/WeasyPrint/blob/main/docs/changelog.rst">weasyprint's
changelog</a>.</em></p>
<blockquote>
<h2>Version 70.0</h2>
<p>Released on 2026-09-08.</p>
<p><strong>This is a security update (CVE-2026-55073,
GHSA-r543-q48m-4c9j).</strong></p>
<p>We strongly recommend to upgrade WeasyPrint to the latest version if
you:</p>
<ul>
<li>embed untrusted images, or</li>
<li>rely on the URL fetcher to filter metadata or stylesheets passed as
Python parameters.</li>
</ul>
<p>Security:</p>
<ul>
<li>Don’t render EPS images.</li>
<li>Always use original URL fetcher when available.</li>
</ul>
<p>Features:</p>
<ul>
<li><code>[#2905](Kozea/WeasyPrint#2905)
&lt;https://github.com/Kozea/WeasyPrint/pull/2905&gt;</code>_:
Add initial support of CSS Notes, with financial support from NLnet</li>
<li><code>[#2731](Kozea/WeasyPrint#2731)
&lt;https://github.com/Kozea/WeasyPrint/issues/2731&gt;</code><em>,
<code>[#2781](Kozea/WeasyPrint#2781)
&lt;https://github.com/Kozea/WeasyPrint/pull/2781&gt;</code></em>:
Log an error on unknown render and write_pdf options</li>
<li><code>[#2802](Kozea/WeasyPrint#2802)
&lt;https://github.com/Kozea/WeasyPrint/issues/2802&gt;</code><em>,
<code>[#2805](Kozea/WeasyPrint#2805)
&lt;https://github.com/Kozea/WeasyPrint/pull/2805&gt;</code></em>:
Create immutable releases on GitHub</li>
<li><code>[#2809](Kozea/WeasyPrint#2809)
&lt;https://github.com/Kozea/WeasyPrint/issues/2809&gt;</code><em>,
<code>[#2810](Kozea/WeasyPrint#2810)
&lt;https://github.com/Kozea/WeasyPrint/pull/2810&gt;</code></em>:
Switch to MSYS2 UCRT64 environment for Windows tests and
executables</li>
<li><code>[#2777](Kozea/WeasyPrint#2777)
&lt;https://github.com/Kozea/WeasyPrint/issues/2777&gt;</code><em>,
<code>[#2814](Kozea/WeasyPrint#2814)
&lt;https://github.com/Kozea/WeasyPrint/pull/2814&gt;</code></em>:
Support COLR emoji fonts</li>
<li><code>[#2667](Kozea/WeasyPrint#2667)
&lt;https://github.com/Kozea/WeasyPrint/issues/2667&gt;</code><em>,
<code>[#2744](Kozea/WeasyPrint#2744)
&lt;https://github.com/Kozea/WeasyPrint/pull/2744&gt;</code></em>:
Support context paint in SVG markers</li>
<li><code>[#1862](Kozea/WeasyPrint#1862)
&lt;https://github.com/Kozea/WeasyPrint/issues/1862&gt;</code><em>,
<code>[#2844](Kozea/WeasyPrint#2844)
&lt;https://github.com/Kozea/WeasyPrint/pull/2844&gt;</code></em>:
Improve filename detection for attachments</li>
<li><code>[#2816](Kozea/WeasyPrint#2816)
&lt;https://github.com/Kozea/WeasyPrint/issues/2816&gt;</code><em>,
<code>[#2827](Kozea/WeasyPrint#2827)
&lt;https://github.com/Kozea/WeasyPrint/pull/2827&gt;</code></em>:
Set SVG title as alternative text</li>
<li><code>[#2718](Kozea/WeasyPrint#2718)
&lt;https://github.com/Kozea/WeasyPrint/issues/2718&gt;</code>_:
Provide a 'onedir' Windows executable</li>
<li><code>[#2863](Kozea/WeasyPrint#2863)
&lt;https://github.com/Kozea/WeasyPrint/pull/2863&gt;</code>_:
Support box-shadow</li>
<li><code>[#2755](Kozea/WeasyPrint#2755)
&lt;https://github.com/Kozea/WeasyPrint/pull/2755&gt;</code>_:
Support RTL SVG text anchoring</li>
<li><code>[#2866](Kozea/WeasyPrint#2866)
&lt;https://github.com/Kozea/WeasyPrint/issues/2866&gt;</code>_:
Don’t use f-strings in logs</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/4d3b7b6449e3494f59c7c2f36b512d129225679c"><code>4d3b7b6</code></a>
Version 70.0</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/289e278439b017cd9263b4cd4727026987f86443"><code>289e278</code></a>
Always use original URL fetcher when available</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/aeb3be74e3c904e4b772014006410e23e0512b4b"><code>aeb3be7</code></a>
Merge remote-tracking branch 'security/main'</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/48357241f949c3f6880ec1a40f56d2f5106fdef3"><code>4835724</code></a>
Merge pull request <a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2915">#2915</a>
from havelaer/fix-nested-svg-viewport-restore</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/03310511d8afac08f80939e7fa317ad6051e251f"><code>0331051</code></a>
Restore nested SVG viewport size on the SVG object, not the drawing
function</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/e4b8b45e409392197441bc449d110f323b0eeb66"><code>e4b8b45</code></a>
Add harfbuzz-vector requirement for Fedora</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/371e4debb4805fa3d5a138f2cbb044fc176284da"><code>371e4de</code></a>
Merge pull request <a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2905">#2905</a>
from Kozea/notes</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/590bf63301d77eaf6aac6b1eb3a3fbb9494e3b23"><code>590bf63</code></a>
Merge pull request <a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2913">#2913</a>
from Kozea/fast-svg-paths</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/f6570c3038b60695f715b12c7805f6933e58490a"><code>f6570c3</code></a>
Use a faster regex-based parser for SVG paths</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/bc0516240c5f8a1eaaf658621d52a09eebecdea9"><code>bc05162</code></a>
Use faster deque for SVG vertices</li>
<li>Additional commits viewable in <a
href="https://github.com/Kozea/WeasyPrint/compare/v69.0...v70.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=weasyprint&package-manager=uv&previous-version=69.0&new-version=70.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/fairscope/PlanktoScope/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Sonny Piers <sonny@fairscope.com>
glromero pushed a commit to BlueRingsLabs/Clinical-Deep-Research_CDR that referenced this pull request Sep 30, 2026
Bumps [weasyprint](https://github.com/Kozea/WeasyPrint) from 68.1 to
70.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/Kozea/WeasyPrint/releases">weasyprint's
releases</a>.</em></p>
<blockquote>
<h2>v70.0</h2>
<p>Read about this release <a
href="https://www.courtbouillon.org/blog/00074-weasyprint-70/">on our
blog</a>.</p>
<p><strong>This is a security update (CVE-2026-55073,
GHSA-r543-q48m-4c9j).</strong></p>
<p>We strongly recommend to upgrade WeasyPrint to the latest version if
you: * embed untrusted images, or * rely on the URL fetcher to filter
metadata or stylesheets passed as Python parameters.</p>
<h2>Security</h2>
<ul>
<li>Don’t render EPS images.</li>
<li>Always use original URL fetcher when available.</li>
</ul>
<h2>Features</h2>
<ul>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2905">#2905</a>:
Add initial support of CSS Notes, with financial support from NLnet</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2731">#2731</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2781">#2781</a>:
Log an error on unknown render and write_pdf options</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2802">#2802</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2805">#2805</a>:
Create immutable releases on GitHub</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2809">#2809</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2810">#2810</a>:
Switch to MSYS2 UCRT64 environment for Windows tests and
executables</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2777">#2777</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2814">#2814</a>:
Support COLR emoji fonts</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2667">#2667</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2744">#2744</a>:
Support context paint in SVG markers</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/1862">#1862</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2844">#2844</a>:
Improve filename detection for attachments</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2816">#2816</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2827">#2827</a>:
Set SVG title as alternative text</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2718">#2718</a>:
Provide a 'onedir' Windows executable</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2863">#2863</a>:
Support box-shadow</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2755">#2755</a>:
Support RTL SVG text anchoring</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2866">#2866</a>:
Don’t use f-strings in logs</li>
</ul>
<h2>Bug fixes</h2>
<ul>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2799">#2799</a>:
Keep HarfBuzz font faces alive during PDF subsetting</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2764">#2764</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2793">#2793</a>:
Accept Path as base URL in CSS</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2800">#2800</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2801">#2801</a>:
Fix position of raster emojis</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2782">#2782</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2807">#2807</a>:
Use POSIX paths in Fontconfig</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2766">#2766</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2779">#2779</a>:
Use response bytes when image file path doesn’t exist</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2277">#2277</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2728">#2728</a>:
Honor page breaks on floated elements</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2789">#2789</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2818">#2818</a>:
Use base URL when solving pending properties</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2820">#2820</a>:
Ignore unresolvable math in image slices</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2901">#2901</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2825">#2825</a>:
Transform SVG size into CSS to apply CSS sizing algorithm</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2819">#2819</a>:
Resolve calc() division by zero to infinity</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2824">#2824</a>:
Remove old deprecation warnings</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2762">#2762</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2780">#2780</a>:
Set SVG gradient color before path construction</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2761">#2761</a>:
Handle split tables with captions</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2215">#2215</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2747">#2747</a>:
Discard broken at-rules</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2736">#2736</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2738">#2738</a>:
Apply transformations to SVG opacity groups</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2830">#2830</a>:
Use a stack to draw simple borders</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2831">#2831</a>:
Fix line_height() crash on calc() values</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2784">#2784</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2832">#2832</a>:
Set fallback font for Unicode test</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2726">#2726</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2881">#2881</a>:
Improve accessibility of PDF forms</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2803">#2803</a>:
Fix inline width after backtracked line breaks</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2833">#2833</a>:
Store root style in anonymous style</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/Kozea/WeasyPrint/blob/main/docs/changelog.rst">weasyprint's
changelog</a>.</em></p>
<blockquote>
<h2>Version 70.0</h2>
<p>Released on 2026-09-08.</p>
<p><strong>This is a security update (CVE-2026-55073,
GHSA-r543-q48m-4c9j).</strong></p>
<p>We strongly recommend to upgrade WeasyPrint to the latest version if
you:</p>
<ul>
<li>embed untrusted images, or</li>
<li>rely on the URL fetcher to filter metadata or stylesheets passed as
Python parameters.</li>
</ul>
<p>Security:</p>
<ul>
<li>Don’t render EPS images.</li>
<li>Always use original URL fetcher when available.</li>
</ul>
<p>Features:</p>
<ul>
<li><code>[#2905](Kozea/WeasyPrint#2905)
&lt;https://github.com/Kozea/WeasyPrint/pull/2905&gt;</code>_:
Add initial support of CSS Notes, with financial support from NLnet</li>
<li><code>[#2731](Kozea/WeasyPrint#2731)
&lt;https://github.com/Kozea/WeasyPrint/issues/2731&gt;</code><em>,
<code>[#2781](Kozea/WeasyPrint#2781)
&lt;https://github.com/Kozea/WeasyPrint/pull/2781&gt;</code></em>:
Log an error on unknown render and write_pdf options</li>
<li><code>[#2802](Kozea/WeasyPrint#2802)
&lt;https://github.com/Kozea/WeasyPrint/issues/2802&gt;</code><em>,
<code>[#2805](Kozea/WeasyPrint#2805)
&lt;https://github.com/Kozea/WeasyPrint/pull/2805&gt;</code></em>:
Create immutable releases on GitHub</li>
<li><code>[#2809](Kozea/WeasyPrint#2809)
&lt;https://github.com/Kozea/WeasyPrint/issues/2809&gt;</code><em>,
<code>[#2810](Kozea/WeasyPrint#2810)
&lt;https://github.com/Kozea/WeasyPrint/pull/2810&gt;</code></em>:
Switch to MSYS2 UCRT64 environment for Windows tests and
executables</li>
<li><code>[#2777](Kozea/WeasyPrint#2777)
&lt;https://github.com/Kozea/WeasyPrint/issues/2777&gt;</code><em>,
<code>[#2814](Kozea/WeasyPrint#2814)
&lt;https://github.com/Kozea/WeasyPrint/pull/2814&gt;</code></em>:
Support COLR emoji fonts</li>
<li><code>[#2667](Kozea/WeasyPrint#2667)
&lt;https://github.com/Kozea/WeasyPrint/issues/2667&gt;</code><em>,
<code>[#2744](Kozea/WeasyPrint#2744)
&lt;https://github.com/Kozea/WeasyPrint/pull/2744&gt;</code></em>:
Support context paint in SVG markers</li>
<li><code>[#1862](Kozea/WeasyPrint#1862)
&lt;https://github.com/Kozea/WeasyPrint/issues/1862&gt;</code><em>,
<code>[#2844](Kozea/WeasyPrint#2844)
&lt;https://github.com/Kozea/WeasyPrint/pull/2844&gt;</code></em>:
Improve filename detection for attachments</li>
<li><code>[#2816](Kozea/WeasyPrint#2816)
&lt;https://github.com/Kozea/WeasyPrint/issues/2816&gt;</code><em>,
<code>[#2827](Kozea/WeasyPrint#2827)
&lt;https://github.com/Kozea/WeasyPrint/pull/2827&gt;</code></em>:
Set SVG title as alternative text</li>
<li><code>[#2718](Kozea/WeasyPrint#2718)
&lt;https://github.com/Kozea/WeasyPrint/issues/2718&gt;</code>_:
Provide a 'onedir' Windows executable</li>
<li><code>[#2863](Kozea/WeasyPrint#2863)
&lt;https://github.com/Kozea/WeasyPrint/pull/2863&gt;</code>_:
Support box-shadow</li>
<li><code>[#2755](Kozea/WeasyPrint#2755)
&lt;https://github.com/Kozea/WeasyPrint/pull/2755&gt;</code>_:
Support RTL SVG text anchoring</li>
<li><code>[#2866](Kozea/WeasyPrint#2866)
&lt;https://github.com/Kozea/WeasyPrint/issues/2866&gt;</code>_:
Don’t use f-strings in logs</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/4d3b7b6449e3494f59c7c2f36b512d129225679c"><code>4d3b7b6</code></a>
Version 70.0</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/289e278439b017cd9263b4cd4727026987f86443"><code>289e278</code></a>
Always use original URL fetcher when available</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/aeb3be74e3c904e4b772014006410e23e0512b4b"><code>aeb3be7</code></a>
Merge remote-tracking branch 'security/main'</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/48357241f949c3f6880ec1a40f56d2f5106fdef3"><code>4835724</code></a>
Merge pull request <a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2915">#2915</a>
from havelaer/fix-nested-svg-viewport-restore</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/03310511d8afac08f80939e7fa317ad6051e251f"><code>0331051</code></a>
Restore nested SVG viewport size on the SVG object, not the drawing
function</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/e4b8b45e409392197441bc449d110f323b0eeb66"><code>e4b8b45</code></a>
Add harfbuzz-vector requirement for Fedora</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/371e4debb4805fa3d5a138f2cbb044fc176284da"><code>371e4de</code></a>
Merge pull request <a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2905">#2905</a>
from Kozea/notes</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/590bf63301d77eaf6aac6b1eb3a3fbb9494e3b23"><code>590bf63</code></a>
Merge pull request <a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2913">#2913</a>
from Kozea/fast-svg-paths</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/f6570c3038b60695f715b12c7805f6933e58490a"><code>f6570c3</code></a>
Use a faster regex-based parser for SVG paths</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/bc0516240c5f8a1eaaf658621d52a09eebecdea9"><code>bc05162</code></a>
Use faster deque for SVG vertices</li>
<li>Additional commits viewable in <a
href="https://github.com/Kozea/WeasyPrint/compare/v68.1...v70.0">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
timothybrush pushed a commit to timothybrush/Stirling-PDF that referenced this pull request Oct 5, 2026
)

Bumps the uv group with 4 updates in the /engine directory:
[urllib3](https://github.com/urllib3/urllib3),
[weasyprint](https://github.com/Kozea/WeasyPrint),
[httpx2](https://github.com/pydantic/httpx2) and
[pypdf](https://github.com/py-pdf/pypdf).

Updates `urllib3` from 2.7.0 to 2.8.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/urllib3/urllib3/releases">urllib3's
releases</a>.</em></p>
<blockquote>
<h2>2.8.0</h2>
<h2>🚀 urllib3 is fundraising for HTTP/2 support</h2>
<p><a
href="https://sethmlarson.dev/urllib3-is-fundraising-for-http2-support">urllib3
is raising ~$40,000 USD</a> to release HTTP/2 support and ensure
long-term sustainable maintenance of the project. If your company or
organization uses Python and would benefit from HTTP/2 support in
Requests, pip, cloud SDKs, and thousands of other projects <a
href="https://opencollective.com/urllib3">please consider contributing
financially</a> to ensure HTTP/2 support is developed sustainably and
maintained for the long-haul.</p>
<p>Thank you for your support.</p>
<h2>Security</h2>
<p>Fixed the following security issues:</p>
<ul>
<li>The TLS configuration for HTTPS proxies could be ignored or
overridden. (High severity, GHSA-8988-9cw3-xx77)</li>
<li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code>
could buffer a chunk-size line of unbounded length in memory. (High
severity, GHSA-vxq7-64xx-v4gw)</li>
<li>Chunked Deflate streaming could enter an infinite loop. (Medium
severity, GHSA-gh4c-6fx4-qh6g)</li>
</ul>
<blockquote>
<p>[!IMPORTANT]
urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.</p>
<p>Configure proxy CA certificates and client certificates in
<code>proxy_ssl_context</code>, and proxy identity checks with
<code>proxy_assert_hostname</code> or
<code>proxy_assert_fingerprint</code>. Destination client certificates
and identity overrides no longer apply to HTTPS forwarding proxy
connections.</p>
</blockquote>
<blockquote>
<p>[!NOTE]
CVE IDs had not yet been assigned to these advisories at the time of
release due to a backlog at GitHub's CNA.</p>
</blockquote>
<h2>Deprecations &amp; Removals</h2>
<ul>
<li>Deprecated using an empty collection as the <code>Retry</code>
option <code>allowed_methods</code> to retry any verb. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5044">#5044</a>)</li>
</ul>
<h2>Features</h2>
<ul>
<li>Added <code>Url.auth_decoded</code> and
<code>Url.auth_decoded_joined</code> convenience properties to the
result of <code>parse_url()</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/4945">#4945</a>)</li>
<li>Added <code>basic_auth_encoding</code> and
<code>proxy_basic_auth_encoding</code> parameters to
<code>urllib3.util.make_headers()</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5092">#5092</a>)</li>
</ul>
<h2>Bugfixes</h2>
<ul>
<li>
<p>Fixed response header handling to replace obsolete folded header
lines (<code>obs-fold</code>) with spaces in accordance with RFC 9112,
preventing raw CRLF sequences from appearing in header values such as
<code>Set-Cookie</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/1362">#1362</a>)</p>
</li>
<li>
<p>Fixed usage of <code>proxy_ssl_context</code> with
<code>ProxyManager</code> when
<code>use_forwarding_for_https=True</code>. Passing
<code>ssl_context</code> instead of <code>proxy_ssl_context</code> for
HTTPS proxies in this configuration now emits a
<code>FutureWarning</code> and will raise an error in v3.0. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/2577">#2577</a>)</p>
</li>
<li>
<p>Changed behavior of the default <code>ConnectionPool.pool</code>
initialization. <code>LifoQueue</code> is now resolved from the
<code>queue</code> module after the <code>ConnectionPool</code> is
instantiated instead of using the default cached <code>QueueCls</code>
class property. This is done because sometimes the
<code>queue.LifoQueue</code> is monkey-patched late in the program, such
as by gevent. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/3289">#3289</a>)</p>
</li>
<li>
<p>Raised <code>UnrewindableBodyError</code> instead of
<code>ValueError</code> when retrying a request whose body had
<code>tell()</code> but not <code>seek()</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/3779">#3779</a>)</p>
</li>
<li>
<p>Decoded percent-encoded SOCKS proxy credentials before authenticating
with the proxy server. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/3785">#3785</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPResponse.drain_conn()</code> to discard unread
response data in 64 KiB chunks (same as the default <code>amt</code>
when doing <code>HTTPResponse.stream(...)</code>). (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5019">#5019</a>)</p>
</li>
<li>
<p>Fixed <code>is_ipaddress()</code> to detect non-standard IPv4 forms
accepted by <code>socket.connect</code>, such as hex
(<code>0x7f000001</code>), octal (<code>0177.0.0.1</code>), and decimal
integers (<code>2130706433</code>), ensuring SSL certificate
verification uses the correct mode for these addresses. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5029">#5029</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPConnectionPool.urlopen</code> raising a misleading
<code>FullPoolError</code> instead of <code>ValueError</code> when
called with an invalid <code>timeout</code> argument on a pool created
with <code>block=True</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5059">#5059</a>)</p>
</li>
<li>
<p>Fixed port-zero handling to preserve explicit <code>:0</code> values
instead of substituting the default ports 80 or 443 in URL parsing, pool
selection, proxy configuration, <code>connection_from_url()</code>, and
HTTP/2 request authority. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5071">#5071</a>,
<a
href="https://redirect.github.com/urllib3/urllib3/issues/5101">#5101</a>)</p>
</li>
<li>
<p>Fixed a bug where <code>PoolManager</code> passed the
<code>assert_hostname</code> and <code>assert_fingerprint</code>
parameters to HTTP connection pools. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5077">#5077</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPConnectionPool.urlopen()</code> and HTTP proxy
forwarding to strip URL fragments from absolute request targets before
sending requests. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5079">#5079</a>)</p>
</li>
<li>
<p>Added safeguards to the proxy tunneling code to prevent potential
security issues when handling invalid characters in the proxy host and
HTTP headers. This change affects users of Python 3.10, Python 3.11, and
Python 3.12 when the standard library does not contain the fix; those on
newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the
same security fixes. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5091">#5091</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPSConnection.connect()</code> overriding
<code>ProxyConfig.ssl_context</code>'s certificate policy and proxy
identity checks with the target connection's TLS settings when
forwarding through an HTTPS proxy.</p>
<p><code>HTTPSConnection</code> no longer applies target SNI,
assertions, or client credentials to forwarding proxy handshakes and
continues to use its <code>ssl_context</code> as a fallback when an
HTTPS proxy forwards an HTTP target. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5093">#5093</a>)</p>
</li>
<li>
<p>Fixed URL parsing to more strictly enforce RFC 3986 host syntax,
rejecting invalid host input such as raw spaces and control characters,
malformed percent-encodings, and percent-encoded control characters in
HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel
targets. Host normalization now also follows RFC 3986 normalization
rules for percent-encoded octets by decoding percent-encoded unreserved
characters and uppercasing the hexadecimal digits of retained
percent-encoded octets. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5095">#5095</a>)</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/urllib3/urllib3/blob/main/CHANGES.rst">urllib3's
changelog</a>.</em></p>
<blockquote>
<h1>2.8.0 (2026-09-15)</h1>
<h2>Security</h2>
<p>Fixed the following security issues:</p>
<ul>
<li>The TLS configuration for HTTPS proxies could be ignored or
overridden.
(High severity, <code>GHSA-8988-9cw3-xx77
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77&gt;</code>__)</li>
<li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code>
could buffer a chunk-size
line of unbounded length in memory. (High severity,
<code>GHSA-vxq7-64xx-v4gw
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw&gt;</code>__)</li>
<li>Chunked Deflate streaming could enter an infinite loop. (Medium
severity,
<code>GHSA-gh4c-6fx4-qh6g
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g&gt;</code>__)</li>
</ul>
<p>.. caution::</p>
<pre><code>urllib3 2.8.0 fixes HTTPS proxy TLS configuration being
ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.
<p>Configure proxy CA certificates and client certificates in
<code>proxy_ssl_context</code>, and proxy identity checks with
<code>proxy_assert_hostname</code> or
<code>proxy_assert_fingerprint</code>.
Destination client certificates and identity overrides no longer
apply to HTTPS forwarding proxy connections.
</code></pre></p>
<h2>Deprecations &amp; Removals</h2>
<ul>
<li>Deprecated using an empty collection as the <code>Retry</code>
option
<code>allowed_methods</code> to retry any verb.
(<code>[Stirling-Tools#5044](urllib3/urllib3#5044)
&lt;https://github.com/urllib3/urllib3/issues/5044&gt;</code>__)</li>
</ul>
<h2>Features</h2>
<ul>
<li>Added <code>Url.auth_decoded</code> and
<code>Url.auth_decoded_joined</code> convenience
properties to the result of <code>parse_url()</code>.
(<code>[Stirling-Tools#4945](urllib3/urllib3#4945)
&lt;https://github.com/urllib3/urllib3/issues/4945&gt;</code>__)</li>
<li>Added <code>basic_auth_encoding</code> and
<code>proxy_basic_auth_encoding</code> parameters to
<code>urllib3.util.make_headers()</code>.
(<code>[Stirling-Tools#5092](urllib3/urllib3#5092)
&lt;https://github.com/urllib3/urllib3/issues/5092&gt;</code>__)</li>
</ul>
<h2>Bugfixes</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/urllib3/urllib3/commit/b1d30ab61fe0db8f11092805e8c5ac43e091064a"><code>b1d30ab</code></a>
Release 2.8.0</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/9016d7e8afc68185496ef07f3c3a4a743d04922e"><code>9016d7e</code></a>
Skip <code>test_read_chunked_with_trailing_data_does_not_hang</code> for
brotlicffi (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5258">#5258</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/9101f581a8b3659af23b6ff335ae77200ca33533"><code>9101f58</code></a>
Fix <code>nox -s docs</code> warning (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5256">#5256</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed"><code>cd770b0</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f"><code>ea2ad7b</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/0716e31534345dc1599ea95d903c79f276239bd8"><code>0716e31</code></a>
Fix loading unencrypted client keys with a password in pyOpenSSL (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5255">#5255</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/43c68c8b43a9dcb44ed2cf4ec91384ca0d46b37d"><code>43c68c8</code></a>
Test pickling of <code>InvalidChunkLength</code> (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5247">#5247</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/308b279b3fb28e7bee952e152ec5baeb5bfd0817"><code>308b279</code></a>
Share security policy between GitHub and Read the Docs (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5253">#5253</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/53fa0731b27d4b71ab0755ea5b896422d005d706"><code>53fa073</code></a>
Add policy on duplicate pull requests (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5252">#5252</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/5f2a6a843d0100d1351c3f94d58581ca98d17267"><code>5f2a6a8</code></a>
Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5232">#5232</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/urllib3/urllib3/compare/2.7.0...2.8.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `weasyprint` from 69.0 to 70.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/Kozea/WeasyPrint/releases">weasyprint's
releases</a>.</em></p>
<blockquote>
<h2>v70.0</h2>
<p>Read about this release <a
href="https://www.courtbouillon.org/blog/00074-weasyprint-70/">on our
blog</a>.</p>
<p><strong>This is a security update (CVE-2026-55073,
GHSA-r543-q48m-4c9j).</strong></p>
<p>We strongly recommend to upgrade WeasyPrint to the latest version if
you: * embed untrusted images, or * rely on the URL fetcher to filter
metadata or stylesheets passed as Python parameters.</p>
<h2>Security</h2>
<ul>
<li>Don’t render EPS images.</li>
<li>Always use original URL fetcher when available.</li>
</ul>
<h2>Features</h2>
<ul>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2905">#2905</a>:
Add initial support of CSS Notes, with financial support from NLnet</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2731">#2731</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2781">#2781</a>:
Log an error on unknown render and write_pdf options</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2802">#2802</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2805">#2805</a>:
Create immutable releases on GitHub</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2809">#2809</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2810">#2810</a>:
Switch to MSYS2 UCRT64 environment for Windows tests and
executables</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2777">#2777</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2814">#2814</a>:
Support COLR emoji fonts</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2667">#2667</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2744">#2744</a>:
Support context paint in SVG markers</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/1862">#1862</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2844">#2844</a>:
Improve filename detection for attachments</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2816">#2816</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2827">#2827</a>:
Set SVG title as alternative text</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2718">#2718</a>:
Provide a 'onedir' Windows executable</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2863">#2863</a>:
Support box-shadow</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2755">#2755</a>:
Support RTL SVG text anchoring</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2866">#2866</a>:
Don’t use f-strings in logs</li>
</ul>
<h2>Bug fixes</h2>
<ul>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2799">#2799</a>:
Keep HarfBuzz font faces alive during PDF subsetting</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2764">#2764</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2793">#2793</a>:
Accept Path as base URL in CSS</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2800">#2800</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2801">#2801</a>:
Fix position of raster emojis</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2782">#2782</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2807">#2807</a>:
Use POSIX paths in Fontconfig</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2766">#2766</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2779">#2779</a>:
Use response bytes when image file path doesn’t exist</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2277">#2277</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2728">#2728</a>:
Honor page breaks on floated elements</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2789">#2789</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2818">#2818</a>:
Use base URL when solving pending properties</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2820">#2820</a>:
Ignore unresolvable math in image slices</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2901">#2901</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2825">#2825</a>:
Transform SVG size into CSS to apply CSS sizing algorithm</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2819">#2819</a>:
Resolve calc() division by zero to infinity</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2824">#2824</a>:
Remove old deprecation warnings</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2762">#2762</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2780">#2780</a>:
Set SVG gradient color before path construction</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2761">#2761</a>:
Handle split tables with captions</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2215">#2215</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2747">#2747</a>:
Discard broken at-rules</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2736">#2736</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2738">#2738</a>:
Apply transformations to SVG opacity groups</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2830">#2830</a>:
Use a stack to draw simple borders</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2831">#2831</a>:
Fix line_height() crash on calc() values</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2784">#2784</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2832">#2832</a>:
Set fallback font for Unicode test</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2726">#2726</a>,
<a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2881">#2881</a>:
Improve accessibility of PDF forms</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/pull/2803">#2803</a>:
Fix inline width after backtracked line breaks</li>
<li><a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2833">#2833</a>:
Store root style in anonymous style</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/Kozea/WeasyPrint/blob/main/docs/changelog.rst">weasyprint's
changelog</a>.</em></p>
<blockquote>
<h2>Version 70.0</h2>
<p>Released on 2026-09-08.</p>
<p><strong>This is a security update (CVE-2026-55073,
GHSA-r543-q48m-4c9j).</strong></p>
<p>We strongly recommend to upgrade WeasyPrint to the latest version if
you:</p>
<ul>
<li>embed untrusted images, or</li>
<li>rely on the URL fetcher to filter metadata or stylesheets passed as
Python parameters.</li>
</ul>
<p>Security:</p>
<ul>
<li>Don’t render EPS images.</li>
<li>Always use original URL fetcher when available.</li>
</ul>
<p>Features:</p>
<ul>
<li><code>[Stirling-Tools#2905](Kozea/WeasyPrint#2905)
&lt;https://github.com/Kozea/WeasyPrint/pull/2905&gt;</code>_:
Add initial support of CSS Notes, with financial support from NLnet</li>
<li><code>[Stirling-Tools#2731](Kozea/WeasyPrint#2731)
&lt;https://github.com/Kozea/WeasyPrint/issues/2731&gt;</code><em>,
<code>[Stirling-Tools#2781](Kozea/WeasyPrint#2781)
&lt;https://github.com/Kozea/WeasyPrint/pull/2781&gt;</code></em>:
Log an error on unknown render and write_pdf options</li>
<li><code>[Stirling-Tools#2802](Kozea/WeasyPrint#2802)
&lt;https://github.com/Kozea/WeasyPrint/issues/2802&gt;</code><em>,
<code>[Stirling-Tools#2805](Kozea/WeasyPrint#2805)
&lt;https://github.com/Kozea/WeasyPrint/pull/2805&gt;</code></em>:
Create immutable releases on GitHub</li>
<li><code>[Stirling-Tools#2809](Kozea/WeasyPrint#2809)
&lt;https://github.com/Kozea/WeasyPrint/issues/2809&gt;</code><em>,
<code>[Stirling-Tools#2810](Kozea/WeasyPrint#2810)
&lt;https://github.com/Kozea/WeasyPrint/pull/2810&gt;</code></em>:
Switch to MSYS2 UCRT64 environment for Windows tests and
executables</li>
<li><code>[Stirling-Tools#2777](Kozea/WeasyPrint#2777)
&lt;https://github.com/Kozea/WeasyPrint/issues/2777&gt;</code><em>,
<code>[Stirling-Tools#2814](Kozea/WeasyPrint#2814)
&lt;https://github.com/Kozea/WeasyPrint/pull/2814&gt;</code></em>:
Support COLR emoji fonts</li>
<li><code>[Stirling-Tools#2667](Kozea/WeasyPrint#2667)
&lt;https://github.com/Kozea/WeasyPrint/issues/2667&gt;</code><em>,
<code>[Stirling-Tools#2744](Kozea/WeasyPrint#2744)
&lt;https://github.com/Kozea/WeasyPrint/pull/2744&gt;</code></em>:
Support context paint in SVG markers</li>
<li><code>[Stirling-Tools#1862](Kozea/WeasyPrint#1862)
&lt;https://github.com/Kozea/WeasyPrint/issues/1862&gt;</code><em>,
<code>[Stirling-Tools#2844](Kozea/WeasyPrint#2844)
&lt;https://github.com/Kozea/WeasyPrint/pull/2844&gt;</code></em>:
Improve filename detection for attachments</li>
<li><code>[Stirling-Tools#2816](Kozea/WeasyPrint#2816)
&lt;https://github.com/Kozea/WeasyPrint/issues/2816&gt;</code><em>,
<code>[Stirling-Tools#2827](Kozea/WeasyPrint#2827)
&lt;https://github.com/Kozea/WeasyPrint/pull/2827&gt;</code></em>:
Set SVG title as alternative text</li>
<li><code>[Stirling-Tools#2718](Kozea/WeasyPrint#2718)
&lt;https://github.com/Kozea/WeasyPrint/issues/2718&gt;</code>_:
Provide a 'onedir' Windows executable</li>
<li><code>[Stirling-Tools#2863](Kozea/WeasyPrint#2863)
&lt;https://github.com/Kozea/WeasyPrint/pull/2863&gt;</code>_:
Support box-shadow</li>
<li><code>[Stirling-Tools#2755](Kozea/WeasyPrint#2755)
&lt;https://github.com/Kozea/WeasyPrint/pull/2755&gt;</code>_:
Support RTL SVG text anchoring</li>
<li><code>[Stirling-Tools#2866](Kozea/WeasyPrint#2866)
&lt;https://github.com/Kozea/WeasyPrint/issues/2866&gt;</code>_:
Don’t use f-strings in logs</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/4d3b7b6449e3494f59c7c2f36b512d129225679c"><code>4d3b7b6</code></a>
Version 70.0</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/289e278439b017cd9263b4cd4727026987f86443"><code>289e278</code></a>
Always use original URL fetcher when available</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/aeb3be74e3c904e4b772014006410e23e0512b4b"><code>aeb3be7</code></a>
Merge remote-tracking branch 'security/main'</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/48357241f949c3f6880ec1a40f56d2f5106fdef3"><code>4835724</code></a>
Merge pull request <a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2915">#2915</a>
from havelaer/fix-nested-svg-viewport-restore</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/03310511d8afac08f80939e7fa317ad6051e251f"><code>0331051</code></a>
Restore nested SVG viewport size on the SVG object, not the drawing
function</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/e4b8b45e409392197441bc449d110f323b0eeb66"><code>e4b8b45</code></a>
Add harfbuzz-vector requirement for Fedora</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/371e4debb4805fa3d5a138f2cbb044fc176284da"><code>371e4de</code></a>
Merge pull request <a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2905">#2905</a>
from Kozea/notes</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/590bf63301d77eaf6aac6b1eb3a3fbb9494e3b23"><code>590bf63</code></a>
Merge pull request <a
href="https://redirect.github.com/Kozea/WeasyPrint/issues/2913">#2913</a>
from Kozea/fast-svg-paths</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/f6570c3038b60695f715b12c7805f6933e58490a"><code>f6570c3</code></a>
Use a faster regex-based parser for SVG paths</li>
<li><a
href="https://github.com/Kozea/WeasyPrint/commit/bc0516240c5f8a1eaaf658621d52a09eebecdea9"><code>bc05162</code></a>
Use faster deque for SVG vertices</li>
<li>Additional commits viewable in <a
href="https://github.com/Kozea/WeasyPrint/compare/v69.0...v70.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `httpx2` from 2.10.0 to 2.12.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/pydantic/httpx2/releases">httpx2's
releases</a>.</em></p>
<blockquote>
<h2>v2.12.0</h2>
<h2>Highlights</h2>
<h3>🛡️ Bounded response decompression</h3>
<p><code>httpx2</code> now decodes <code>gzip</code>,
<code>deflate</code>, Brotli, and Zstandard responses incrementally.
Each decode step emits at most 1 MiB, so streaming a highly compressed
response no longer requires materializing an entire inflated network
chunk in memory (<a
href="https://redirect.github.com/pydantic/httpx2/pull/1126">pydantic/httpx2#1126</a>).</p>
<h3>📦 Shared Zstandard API</h3>
<p>Python 3.13 and earlier now use <code>backports.zstd</code>, which
provides the same bounded incremental decompression API as
<code>compression.zstd</code> on Python 3.14 and later (<a
href="https://redirect.github.com/pydantic/httpx2/pull/1146">pydantic/httpx2#1146</a>).</p>
<h2>httpx2</h2>
<h3>Changed</h3>
<ul>
<li>Use <code>backports.zstd</code> for Zstandard decoding on Python
3.13 and earlier by <a
href="https://github.com/Kludex"><code>@​Kludex</code></a> in <a
href="https://redirect.github.com/pydantic/httpx2/pull/1146">pydantic/httpx2#1146</a></li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Bound peak memory while streaming compressed responses and close
response streams when decoding fails by <a
href="https://github.com/Kludex"><code>@​Kludex</code></a> in <a
href="https://redirect.github.com/pydantic/httpx2/pull/1126">pydantic/httpx2#1126</a></li>
</ul>
<h2>httpcore2</h2>
<p>No changes since <code>2.11.0</code>. Version bumped to stay in
lockstep with <code>httpx2</code>.</p>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/pydantic/httpx2/compare/v2.11.0...v2.12.0">https://github.com/pydantic/httpx2/compare/v2.11.0...v2.12.0</a></p>
<h2>v2.11.0</h2>
<h2>Highlights</h2>
<h3>🌐 Public origin API</h3>
<p><code>httpx2</code> now includes an immutable and hashable
<code>Origin</code> value object, available through
<code>URL.origin</code>. It provides normalized scheme, host, and
effective port comparisons without including URL paths, queries,
fragments, or credentials (<a
href="https://redirect.github.com/pydantic/httpx2/pull/1134">pydantic/httpx2#1134</a>).</p>
<h3>🛠️ Request compatibility and validation</h3>
<ul>
<li>Explicit <code>Transfer-Encoding</code> headers now take precedence
over body-derived <code>Content-Length</code> headers (<a
href="https://redirect.github.com/pydantic/httpx2/pull/1137">pydantic/httpx2#1137</a>).</li>
<li>Deprecated status code aliases are available again (<a
href="https://redirect.github.com/pydantic/httpx2/pull/1135">pydantic/httpx2#1135</a>).</li>
<li>Multipart part headers are validated before serialization (<a
href="https://redirect.github.com/pydantic/httpx2/pull/1142">pydantic/httpx2#1142</a>).</li>
</ul>
<h2>httpx2</h2>
<h3>Added</h3>
<ul>
<li>Add the public <code>Origin</code> value object and
<code>URL.origin</code> property by <a
href="https://github.com/Kludex"><code>@​Kludex</code></a> in <a
href="https://redirect.github.com/pydantic/httpx2/pull/1134">pydantic/httpx2#1134</a></li>
</ul>
<h3>Changed</h3>
<ul>
<li>Require Brotli 1.2.0 or later for the <code>brotli</code> extra by
<a href="https://github.com/Kludex"><code>@​Kludex</code></a> in <a
href="https://redirect.github.com/pydantic/httpx2/pull/1141">pydantic/httpx2#1141</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/pydantic/httpx2/blob/main/src/httpx2/CHANGELOG.md">httpx2's
changelog</a>.</em></p>
<blockquote>
<h2>2.12.0 (August 18th, 2026)</h2>
<h3>Changed</h3>
<ul>
<li>Use <code>backports.zstd</code> for Zstandard decoding on Python
3.13 and earlier.
(<a
href="https://redirect.github.com/pydantic/httpx2/pull/1146">#1146</a>)</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Bound peak memory while streaming compressed responses and close
response streams when decoding fails.
(<a
href="https://redirect.github.com/pydantic/httpx2/pull/1126">#1126</a>)</li>
</ul>
<h2>2.11.0 (August 18th, 2026)</h2>
<h3>Added</h3>
<ul>
<li>Add the public <code>Origin</code> value object and
<code>URL.origin</code> property for normalized,
hashable origin comparisons. (<a
href="https://redirect.github.com/pydantic/httpx2/pull/1134">#1134</a>)</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Require Brotli 1.2.0 or later for the <code>brotli</code> extra. (<a
href="https://redirect.github.com/pydantic/httpx2/pull/1141">#1141</a>)</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Restore deprecated status code aliases. (<a
href="https://redirect.github.com/pydantic/httpx2/pull/1135">#1135</a>)</li>
<li>Extract HTTP/2 release notes from changelog headings correctly. (<a
href="https://redirect.github.com/pydantic/httpx2/pull/1136">#1136</a>)</li>
<li>Respect explicit <code>Transfer-Encoding</code> headers and expose
buffered request body lengths to WSGI applications.
(<a
href="https://redirect.github.com/pydantic/httpx2/pull/1137">#1137</a>)</li>
<li>Validate multipart part header names and values before
serialization.
(<a
href="https://redirect.github.com/pydantic/httpx2/pull/1142">#1142</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/pydantic/httpx2/commit/71ae23be5448f859c2b4e21d9972ddfa7b8d759d"><code>71ae23b</code></a>
Version 2.12.0 (<a
href="https://redirect.github.com/pydantic/httpx2/issues/1147">#1147</a>)</li>
<li><a
href="https://github.com/pydantic/httpx2/commit/4fd0c70a3f207c618b145934792f791bccfb39f8"><code>4fd0c70</code></a>
Decode compressed response bodies incrementally (<a
href="https://redirect.github.com/pydantic/httpx2/issues/1126">#1126</a>)</li>
<li><a
href="https://github.com/pydantic/httpx2/commit/d588e528a11eb20323031ee571fadc668bb81b3f"><code>d588e52</code></a>
Use <code>backports.zstd</code> on Python 3.13 and earlier (<a
href="https://redirect.github.com/pydantic/httpx2/issues/1146">#1146</a>)</li>
<li><a
href="https://github.com/pydantic/httpx2/commit/344589da2a992f7e5a0c25c68cc78c25ec6d70bd"><code>344589d</code></a>
Version 2.11.0 (<a
href="https://redirect.github.com/pydantic/httpx2/issues/1143">#1143</a>)</li>
<li><a
href="https://github.com/pydantic/httpx2/commit/de96d810ee4e309d118982fe7084a46a2bcd600d"><code>de96d81</code></a>
Validate multipart part headers (<a
href="https://redirect.github.com/pydantic/httpx2/issues/1142">#1142</a>)</li>
<li><a
href="https://github.com/pydantic/httpx2/commit/51c32698ce029140cb69a26921d017e3edda80fa"><code>51c3269</code></a>
Require brotli 1.2.0 in the brotli extra (<a
href="https://redirect.github.com/pydantic/httpx2/issues/1141">#1141</a>)</li>
<li><a
href="https://github.com/pydantic/httpx2/commit/829b93a2393212996f613e635261f777d9ec6eab"><code>829b93a</code></a>
Respect explicit Transfer-Encoding headers (<a
href="https://redirect.github.com/pydantic/httpx2/issues/1137">#1137</a>)</li>
<li><a
href="https://github.com/pydantic/httpx2/commit/4fa6c8ee96fb79035c6820e4f44a10b6262d9c9f"><code>4fa6c8e</code></a>
Fix changelog extraction regex for H2 release headings (<a
href="https://redirect.github.com/pydantic/httpx2/issues/1136">#1136</a>)</li>
<li><a
href="https://github.com/pydantic/httpx2/commit/8a6f37063514ee2a2601607c20be72667fdfa3be"><code>8a6f370</code></a>
Restore deprecated status code aliases (<a
href="https://redirect.github.com/pydantic/httpx2/issues/1135">#1135</a>)</li>
<li><a
href="https://github.com/pydantic/httpx2/commit/d03f1ec6a1a323f951a8c21cd14f9c02f2d1e855"><code>d03f1ec</code></a>
Add public Origin API (<a
href="https://redirect.github.com/pydantic/httpx2/issues/1134">#1134</a>)</li>
<li>See full diff in <a
href="https://github.com/pydantic/httpx2/compare/v2.10.0...v2.12.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `pypdf` from 6.16.1 to 6.19.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/py-pdf/pypdf/releases">pypdf's
releases</a>.</em></p>
<blockquote>
<h2>Version 6.19.0, 2026-09-16</h2>
<h2>What's new</h2>
<h3>Security (SEC)</h3>
<ul>
<li>Limit size of alphabetical page labels (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4096">#4096</a>)
by <a
href="https://github.com/stefan6419846"><code>@​stefan6419846</code></a></li>
</ul>
<h3>Deprecations (DEP)</h3>
<ul>
<li>Replace PdfWriter method add_js (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/3979">#3979</a>)
by <a href="https://github.com/j-t-1"><code>@​j-t-1</code></a></li>
</ul>
<h3>Performance Improvements (PI)</h3>
<ul>
<li>Move static value out of loop body for appearance stream data (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4087">#4087</a>)
by <a
href="https://github.com/stefan6419846"><code>@​stefan6419846</code></a></li>
<li>Reduce number of full data lookups for attachment mapping API (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4081">#4081</a>)
by <a
href="https://github.com/stefan6419846"><code>@​stefan6419846</code></a></li>
</ul>
<h3>Bug Fixes (BUG)</h3>
<ul>
<li>Do not copy unrelated pages when appending pages with non-terminal
fields (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4078">#4078</a>)
by <a
href="https://github.com/anandghegde"><code>@​anandghegde</code></a></li>
<li>Use page reference for existing internal link targets (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4076">#4076</a>)
by <a href="https://github.com/r-kamei"><code>@​r-kamei</code></a></li>
<li>Arabic-Indic digits are reversed during text extraction (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4077">#4077</a>)
by <a
href="https://github.com/Syamjith-NK"><code>@​Syamjith-NK</code></a></li>
<li>Parse a string rect for add_uri into a rectangle (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4074">#4074</a>)
by <a
href="https://github.com/RavSinghChandan"><code>@​RavSinghChandan</code></a></li>
</ul>
<p><a
href="https://github.com/py-pdf/pypdf/compare/6.18.1...6.19.0">Full
Changelog</a></p>
<h2>Version 6.18.1, 2026-09-11</h2>
<h2>What's new</h2>
<h3>Security (SEC)</h3>
<ul>
<li>Further restrict FlateDecode recovery (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4073">#4073</a>)
by <a
href="https://github.com/stefan6419846"><code>@​stefan6419846</code></a></li>
<li>Limit entry count for TrueType and Type1 font <code>/Widths</code>
(<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4072">#4072</a>)
by <a
href="https://github.com/stefan6419846"><code>@​stefan6419846</code></a></li>
<li>Limit allowed length of tokens in parse_bfchar (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4071">#4071</a>)
by <a
href="https://github.com/stefan6419846"><code>@​stefan6419846</code></a></li>
</ul>
<h3>Bug Fixes (BUG)</h3>
<ul>
<li>Use current text matrix for visitor_text (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4062">#4062</a>)
by <a href="https://github.com/r-kamei"><code>@​r-kamei</code></a></li>
<li>Repeat the letter for /S /A and /S /a page labels past Z (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4065">#4065</a>)
by <a
href="https://github.com/youdie006"><code>@​youdie006</code></a></li>
<li>Use font color for FreeText default appearance (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4051">#4051</a>)
by <a
href="https://github.com/Yuki9814"><code>@​Yuki9814</code></a></li>
</ul>
<h3>Robustness (ROB)</h3>
<ul>
<li>Fix compatibility with fonttools &lt; 4.58.0 (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4050">#4050</a>,
<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4059">#4059</a>)
by <a href="https://github.com/MeggyCal"><code>@​MeggyCal</code></a> and
<a
href="https://github.com/stefan6419846"><code>@​stefan6419846</code></a></li>
</ul>
<h3>Documentation (DOC)</h3>
<ul>
<li>Use combined matrix in visitor examples (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4066">#4066</a>)
by <a href="https://github.com/r-kamei"><code>@​r-kamei</code></a></li>
</ul>
<p><a
href="https://github.com/py-pdf/pypdf/compare/6.18.0...6.18.1">Full
Changelog</a></p>
<h2>Version 6.18.0, 2026-09-07</h2>
<h2>What's new</h2>
<p>Please note that this release requires users which previously
overwrote the default limits to migrate to the new approach: <a
href="https://pypdf.readthedocs.io/en/6.18.0/user/security.html#global">Docs</a></p>
<p>In short:</p>
<ul>
<li>Use <code>apply_configuration</code> as a context manager to
temporarily overwrite configuration values.</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/py-pdf/pypdf/blob/main/CHANGELOG.md">pypdf's
changelog</a>.</em></p>
<blockquote>
<h2>Version 6.19.0, 2026-09-16</h2>
<h3>Security (SEC)</h3>
<ul>
<li>Limit size of alphabetical page labels (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4096">#4096</a>)</li>
</ul>
<h3>Deprecations (DEP)</h3>
<ul>
<li>Replace PdfWriter method add_js (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/3979">#3979</a>)</li>
</ul>
<h3>Performance Improvements (PI)</h3>
<ul>
<li>Move static value out of loop body for appearance stream data (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4087">#4087</a>)</li>
<li>Reduce number of full data lookups for attachment mapping API (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4081">#4081</a>)</li>
</ul>
<h3>Bug Fixes (BUG)</h3>
<ul>
<li>Do not copy unrelated pages when appending pages with non-terminal
fields (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4078">#4078</a>)</li>
<li>Use page reference for existing internal link targets (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4076">#4076</a>)</li>
<li>Arabic-Indic digits are reversed during text extraction (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4077">#4077</a>)</li>
<li>Parse a string rect for add_uri into a rectangle (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4074">#4074</a>)</li>
</ul>
<p><a
href="https://github.com/py-pdf/pypdf/compare/6.18.1...6.19.0">Full
Changelog</a></p>
<h2>Version 6.18.1, 2026-09-11</h2>
<h3>Security (SEC)</h3>
<ul>
<li>Further restrict FlateDecode recovery (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4073">#4073</a>)</li>
<li>Limit entry count for TrueType and Type1 font <code>/Widths</code>
(<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4072">#4072</a>)</li>
<li>Limit allowed length of tokens in parse_bfchar (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4071">#4071</a>)</li>
</ul>
<h3>Bug Fixes (BUG)</h3>
<ul>
<li>Use current text matrix for visitor_text (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4062">#4062</a>)</li>
<li>Repeat the letter for /S /A and /S /a page labels past Z (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4065">#4065</a>)</li>
<li>Use font color for FreeText default appearance (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4051">#4051</a>)</li>
</ul>
<h3>Robustness (ROB)</h3>
<ul>
<li>Fix compatibility with fonttools &lt; 4.58.0 (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4050">#4050</a>,
<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4059">#4059</a>)</li>
</ul>
<h3>Documentation (DOC)</h3>
<ul>
<li>Use combined matrix in visitor examples (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4066">#4066</a>)</li>
</ul>
<p><a
href="https://github.com/py-pdf/pypdf/compare/6.18.0...6.18.1">Full
Changelog</a></p>
<h2>Version 6.18.0, 2026-09-07</h2>
<h3>Security (SEC)</h3>
<ul>
<li>Limit allowed length of indirect object tokens (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4055">#4055</a>)</li>
</ul>
<h3>Deprecations (DEP)</h3>
<ul>
<li>Rework configuration value handling (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4044">#4044</a>)</li>
</ul>
<h3>New Features (ENH)</h3>
<ul>
<li>Draw borders and backgrounds for appearance streams and annotations
(<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4033">#4033</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/py-pdf/pypdf/commit/d62cb58d3988b291b0435eddfd118c4f8f6b6a46"><code>d62cb58</code></a>
REL: 6.19.0</li>
<li><a
href="https://github.com/py-pdf/pypdf/commit/0d8b5a8832cde1ba308b5c27567b879b7b7eed4a"><code>0d8b5a8</code></a>
SEC: Limit size of alphabetical page labels (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4096">#4096</a>)</li>
<li><a
href="https://github.com/py-pdf/pypdf/commit/959467a9b95be83e2dc5ae873ece5f371263ede7"><code>959467a</code></a>
PI: Move static value out of loop body for appearance stream data (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4087">#4087</a>)</li>
<li><a
href="https://github.com/py-pdf/pypdf/commit/20822b263f063c96ad535405f5b8c4d81768950b"><code>20822b2</code></a>
DEV: Bump zizmorcore/zizmor-action from 0.6.3 to 0.6.4 (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4093">#4093</a>)</li>
<li><a
href="https://github.com/py-pdf/pypdf/commit/25f230191b89cdcf2b4ba3d8051d52c7392831d0"><code>25f2301</code></a>
DEP: Replace PdfWriter method add_js (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/3979">#3979</a>)</li>
<li><a
href="https://github.com/py-pdf/pypdf/commit/a92443848fda10cc2a65a7b6397fd8e1986c17d2"><code>a924438</code></a>
BUG: Do not copy unrelated pages when appending pages with non-terminal
field...</li>
<li><a
href="https://github.com/py-pdf/pypdf/commit/cf5cec2e49b9da8fae0d82a0f99f1bfe9eceb8ed"><code>cf5cec2</code></a>
BUG: Use page reference for existing internal link targets (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4076">#4076</a>)</li>
<li><a
href="https://github.com/py-pdf/pypdf/commit/96d81f05ba4b3ec9ff1b3c3e52bc71a3cdd702c7"><code>96d81f0</code></a>
BUG: Arabic-Indic digits are reversed during text extraction (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4077">#4077</a>)</li>
<li><a
href="https://github.com/py-pdf/pypdf/commit/2d219015b4cf92edcfd6d28c564295f0704fd204"><code>2d21901</code></a>
DEV: Fix Color class for latest mypy (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4082">#4082</a>)</li>
<li><a
href="https://github.com/py-pdf/pypdf/commit/893a01002aa8e23b3a61ae4b38ab74edbc904ab9"><code>893a010</code></a>
MAINT: Split PdfDocCommon._flatten (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/4070">#4070</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/py-pdf/pypdf/compare/6.16.1...6.19.0">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

feature New feature that should be supported sponsored Issues sponsored to be resolved faster

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants