Conversation
liZe
marked this pull request as ready for review
September 7, 2026 15:04
yyyyyyyan
added a commit
to percona/pmm-extensions
that referenced
this pull request
Sep 12, 2026
Bumps [weasyprint](https://github.com/Kozea/WeasyPrint) from 69.0 to 70.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/Kozea/WeasyPrint/releases">weasyprint's releases</a>.</em></p> <blockquote> <h2>v70.0</h2> <p>Read about this release <a href="https://www.courtbouillon.org/blog/00074-weasyprint-70/">on our blog</a>.</p> <p><strong>This is a security update (CVE-2026-55073, GHSA-r543-q48m-4c9j).</strong></p> <p>We strongly recommend to upgrade WeasyPrint to the latest version if you: * embed untrusted images, or * rely on the URL fetcher to filter metadata or stylesheets passed as Python parameters.</p> <h2>Security</h2> <ul> <li>Don’t render EPS images.</li> <li>Always use original URL fetcher when available.</li> </ul> <h2>Features</h2> <ul> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2905">#2905</a>: Add initial support of CSS Notes, with financial support from NLnet</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2731">#2731</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2781">#2781</a>: Log an error on unknown render and write_pdf options</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2802">#2802</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2805">#2805</a>: Create immutable releases on GitHub</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2809">#2809</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2810">#2810</a>: Switch to MSYS2 UCRT64 environment for Windows tests and executables</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2777">#2777</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2814">#2814</a>: Support COLR emoji fonts</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2667">#2667</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2744">#2744</a>: Support context paint in SVG markers</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/1862">#1862</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2844">#2844</a>: Improve filename detection for attachments</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2816">#2816</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2827">#2827</a>: Set SVG title as alternative text</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2718">#2718</a>: Provide a 'onedir' Windows executable</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2863">#2863</a>: Support box-shadow</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2755">#2755</a>: Support RTL SVG text anchoring</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2866">#2866</a>: Don’t use f-strings in logs</li> </ul> <h2>Bug fixes</h2> <ul> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2799">#2799</a>: Keep HarfBuzz font faces alive during PDF subsetting</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2764">#2764</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2793">#2793</a>: Accept Path as base URL in CSS</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2800">#2800</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2801">#2801</a>: Fix position of raster emojis</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2782">#2782</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2807">#2807</a>: Use POSIX paths in Fontconfig</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2766">#2766</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2779">#2779</a>: Use response bytes when image file path doesn’t exist</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2277">#2277</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2728">#2728</a>: Honor page breaks on floated elements</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2789">#2789</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2818">#2818</a>: Use base URL when solving pending properties</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2820">#2820</a>: Ignore unresolvable math in image slices</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2901">#2901</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2825">#2825</a>: Transform SVG size into CSS to apply CSS sizing algorithm</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2819">#2819</a>: Resolve calc() division by zero to infinity</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2824">#2824</a>: Remove old deprecation warnings</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2762">#2762</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2780">#2780</a>: Set SVG gradient color before path construction</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2761">#2761</a>: Handle split tables with captions</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2215">#2215</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2747">#2747</a>: Discard broken at-rules</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2736">#2736</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2738">#2738</a>: Apply transformations to SVG opacity groups</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2830">#2830</a>: Use a stack to draw simple borders</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2831">#2831</a>: Fix line_height() crash on calc() values</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2784">#2784</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2832">#2832</a>: Set fallback font for Unicode test</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2726">#2726</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2881">#2881</a>: Improve accessibility of PDF forms</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2803">#2803</a>: Fix inline width after backtracked line breaks</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2833">#2833</a>: Store root style in anonymous style</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/Kozea/WeasyPrint/blob/main/docs/changelog.rst">weasyprint's changelog</a>.</em></p> <blockquote> <h2>Version 70.0</h2> <p>Released on 2026-09-08.</p> <p><strong>This is a security update (CVE-2026-55073, GHSA-r543-q48m-4c9j).</strong></p> <p>We strongly recommend to upgrade WeasyPrint to the latest version if you:</p> <ul> <li>embed untrusted images, or</li> <li>rely on the URL fetcher to filter metadata or stylesheets passed as Python parameters.</li> </ul> <p>Security:</p> <ul> <li>Don’t render EPS images.</li> <li>Always use original URL fetcher when available.</li> </ul> <p>Features:</p> <ul> <li><code>[#2905](Kozea/WeasyPrint#2905) <https://github.com/Kozea/WeasyPrint/pull/2905></code>_: Add initial support of CSS Notes, with financial support from NLnet</li> <li><code>[#2731](Kozea/WeasyPrint#2731) <https://github.com/Kozea/WeasyPrint/issues/2731></code><em>, <code>[#2781](Kozea/WeasyPrint#2781) <https://github.com/Kozea/WeasyPrint/pull/2781></code></em>: Log an error on unknown render and write_pdf options</li> <li><code>[#2802](Kozea/WeasyPrint#2802) <https://github.com/Kozea/WeasyPrint/issues/2802></code><em>, <code>[#2805](Kozea/WeasyPrint#2805) <https://github.com/Kozea/WeasyPrint/pull/2805></code></em>: Create immutable releases on GitHub</li> <li><code>[#2809](Kozea/WeasyPrint#2809) <https://github.com/Kozea/WeasyPrint/issues/2809></code><em>, <code>[#2810](Kozea/WeasyPrint#2810) <https://github.com/Kozea/WeasyPrint/pull/2810></code></em>: Switch to MSYS2 UCRT64 environment for Windows tests and executables</li> <li><code>[#2777](Kozea/WeasyPrint#2777) <https://github.com/Kozea/WeasyPrint/issues/2777></code><em>, <code>[#2814](Kozea/WeasyPrint#2814) <https://github.com/Kozea/WeasyPrint/pull/2814></code></em>: Support COLR emoji fonts</li> <li><code>[#2667](Kozea/WeasyPrint#2667) <https://github.com/Kozea/WeasyPrint/issues/2667></code><em>, <code>[#2744](Kozea/WeasyPrint#2744) <https://github.com/Kozea/WeasyPrint/pull/2744></code></em>: Support context paint in SVG markers</li> <li><code>[#1862](Kozea/WeasyPrint#1862) <https://github.com/Kozea/WeasyPrint/issues/1862></code><em>, <code>[#2844](Kozea/WeasyPrint#2844) <https://github.com/Kozea/WeasyPrint/pull/2844></code></em>: Improve filename detection for attachments</li> <li><code>[#2816](Kozea/WeasyPrint#2816) <https://github.com/Kozea/WeasyPrint/issues/2816></code><em>, <code>[#2827](Kozea/WeasyPrint#2827) <https://github.com/Kozea/WeasyPrint/pull/2827></code></em>: Set SVG title as alternative text</li> <li><code>[#2718](Kozea/WeasyPrint#2718) <https://github.com/Kozea/WeasyPrint/issues/2718></code>_: Provide a 'onedir' Windows executable</li> <li><code>[#2863](Kozea/WeasyPrint#2863) <https://github.com/Kozea/WeasyPrint/pull/2863></code>_: Support box-shadow</li> <li><code>[#2755](Kozea/WeasyPrint#2755) <https://github.com/Kozea/WeasyPrint/pull/2755></code>_: Support RTL SVG text anchoring</li> <li><code>[#2866](Kozea/WeasyPrint#2866) <https://github.com/Kozea/WeasyPrint/issues/2866></code>_: Don’t use f-strings in logs</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/Kozea/WeasyPrint/commit/4d3b7b6449e3494f59c7c2f36b512d129225679c"><code>4d3b7b6</code></a> Version 70.0</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/289e278439b017cd9263b4cd4727026987f86443"><code>289e278</code></a> Always use original URL fetcher when available</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/aeb3be74e3c904e4b772014006410e23e0512b4b"><code>aeb3be7</code></a> Merge remote-tracking branch 'security/main'</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/48357241f949c3f6880ec1a40f56d2f5106fdef3"><code>4835724</code></a> Merge pull request <a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2915">#2915</a> from havelaer/fix-nested-svg-viewport-restore</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/03310511d8afac08f80939e7fa317ad6051e251f"><code>0331051</code></a> Restore nested SVG viewport size on the SVG object, not the drawing function</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/e4b8b45e409392197441bc449d110f323b0eeb66"><code>e4b8b45</code></a> Add harfbuzz-vector requirement for Fedora</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/371e4debb4805fa3d5a138f2cbb044fc176284da"><code>371e4de</code></a> Merge pull request <a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2905">#2905</a> from Kozea/notes</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/590bf63301d77eaf6aac6b1eb3a3fbb9494e3b23"><code>590bf63</code></a> Merge pull request <a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2913">#2913</a> from Kozea/fast-svg-paths</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/f6570c3038b60695f715b12c7805f6933e58490a"><code>f6570c3</code></a> Use a faster regex-based parser for SVG paths</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/bc0516240c5f8a1eaaf658621d52a09eebecdea9"><code>bc05162</code></a> Use faster deque for SVG vertices</li> <li>Additional commits viewable in <a href="https://github.com/Kozea/WeasyPrint/compare/v69.0...v70.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/percona/SEP/network/alerts). </details> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Yan Orestes <yan.orestes@percona.com>
EgorPopelyaev
pushed a commit
to paritytech/release-registry
that referenced
this pull request
Sep 15, 2026
Bumps [weasyprint](https://github.com/Kozea/WeasyPrint) from 68.0 to 70.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/Kozea/WeasyPrint/releases">weasyprint's releases</a>.</em></p> <blockquote> <h2>v70.0</h2> <p>Read about this release <a href="https://www.courtbouillon.org/blog/00074-weasyprint-70/">on our blog</a>.</p> <p><strong>This is a security update (CVE-2026-55073, GHSA-r543-q48m-4c9j).</strong></p> <p>We strongly recommend to upgrade WeasyPrint to the latest version if you: * embed untrusted images, or * rely on the URL fetcher to filter metadata or stylesheets passed as Python parameters.</p> <h2>Security</h2> <ul> <li>Don’t render EPS images.</li> <li>Always use original URL fetcher when available.</li> </ul> <h2>Features</h2> <ul> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2905">#2905</a>: Add initial support of CSS Notes, with financial support from NLnet</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2731">#2731</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2781">#2781</a>: Log an error on unknown render and write_pdf options</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2802">#2802</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2805">#2805</a>: Create immutable releases on GitHub</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2809">#2809</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2810">#2810</a>: Switch to MSYS2 UCRT64 environment for Windows tests and executables</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2777">#2777</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2814">#2814</a>: Support COLR emoji fonts</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2667">#2667</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2744">#2744</a>: Support context paint in SVG markers</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/1862">#1862</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2844">#2844</a>: Improve filename detection for attachments</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2816">#2816</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2827">#2827</a>: Set SVG title as alternative text</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2718">#2718</a>: Provide a 'onedir' Windows executable</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2863">#2863</a>: Support box-shadow</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2755">#2755</a>: Support RTL SVG text anchoring</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2866">#2866</a>: Don’t use f-strings in logs</li> </ul> <h2>Bug fixes</h2> <ul> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2799">#2799</a>: Keep HarfBuzz font faces alive during PDF subsetting</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2764">#2764</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2793">#2793</a>: Accept Path as base URL in CSS</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2800">#2800</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2801">#2801</a>: Fix position of raster emojis</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2782">#2782</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2807">#2807</a>: Use POSIX paths in Fontconfig</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2766">#2766</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2779">#2779</a>: Use response bytes when image file path doesn’t exist</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2277">#2277</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2728">#2728</a>: Honor page breaks on floated elements</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2789">#2789</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2818">#2818</a>: Use base URL when solving pending properties</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2820">#2820</a>: Ignore unresolvable math in image slices</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2901">#2901</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2825">#2825</a>: Transform SVG size into CSS to apply CSS sizing algorithm</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2819">#2819</a>: Resolve calc() division by zero to infinity</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2824">#2824</a>: Remove old deprecation warnings</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2762">#2762</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2780">#2780</a>: Set SVG gradient color before path construction</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2761">#2761</a>: Handle split tables with captions</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2215">#2215</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2747">#2747</a>: Discard broken at-rules</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2736">#2736</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2738">#2738</a>: Apply transformations to SVG opacity groups</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2830">#2830</a>: Use a stack to draw simple borders</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2831">#2831</a>: Fix line_height() crash on calc() values</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2784">#2784</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2832">#2832</a>: Set fallback font for Unicode test</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2726">#2726</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2881">#2881</a>: Improve accessibility of PDF forms</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2803">#2803</a>: Fix inline width after backtracked line breaks</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2833">#2833</a>: Store root style in anonymous style</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/Kozea/WeasyPrint/blob/main/docs/changelog.rst">weasyprint's changelog</a>.</em></p> <blockquote> <h2>Version 70.0</h2> <p>Released on 2026-09-08.</p> <p><strong>This is a security update (CVE-2026-55073, GHSA-r543-q48m-4c9j).</strong></p> <p>We strongly recommend to upgrade WeasyPrint to the latest version if you:</p> <ul> <li>embed untrusted images, or</li> <li>rely on the URL fetcher to filter metadata or stylesheets passed as Python parameters.</li> </ul> <p>Security:</p> <ul> <li>Don’t render EPS images.</li> <li>Always use original URL fetcher when available.</li> </ul> <p>Features:</p> <ul> <li><code>[#2905](Kozea/WeasyPrint#2905) <https://github.com/Kozea/WeasyPrint/pull/2905></code>_: Add initial support of CSS Notes, with financial support from NLnet</li> <li><code>[#2731](Kozea/WeasyPrint#2731) <https://github.com/Kozea/WeasyPrint/issues/2731></code><em>, <code>[#2781](Kozea/WeasyPrint#2781) <https://github.com/Kozea/WeasyPrint/pull/2781></code></em>: Log an error on unknown render and write_pdf options</li> <li><code>[#2802](Kozea/WeasyPrint#2802) <https://github.com/Kozea/WeasyPrint/issues/2802></code><em>, <code>[#2805](Kozea/WeasyPrint#2805) <https://github.com/Kozea/WeasyPrint/pull/2805></code></em>: Create immutable releases on GitHub</li> <li><code>[#2809](Kozea/WeasyPrint#2809) <https://github.com/Kozea/WeasyPrint/issues/2809></code><em>, <code>[#2810](Kozea/WeasyPrint#2810) <https://github.com/Kozea/WeasyPrint/pull/2810></code></em>: Switch to MSYS2 UCRT64 environment for Windows tests and executables</li> <li><code>[#2777](Kozea/WeasyPrint#2777) <https://github.com/Kozea/WeasyPrint/issues/2777></code><em>, <code>[#2814](Kozea/WeasyPrint#2814) <https://github.com/Kozea/WeasyPrint/pull/2814></code></em>: Support COLR emoji fonts</li> <li><code>[#2667](Kozea/WeasyPrint#2667) <https://github.com/Kozea/WeasyPrint/issues/2667></code><em>, <code>[#2744](Kozea/WeasyPrint#2744) <https://github.com/Kozea/WeasyPrint/pull/2744></code></em>: Support context paint in SVG markers</li> <li><code>[#1862](Kozea/WeasyPrint#1862) <https://github.com/Kozea/WeasyPrint/issues/1862></code><em>, <code>[#2844](Kozea/WeasyPrint#2844) <https://github.com/Kozea/WeasyPrint/pull/2844></code></em>: Improve filename detection for attachments</li> <li><code>[#2816](Kozea/WeasyPrint#2816) <https://github.com/Kozea/WeasyPrint/issues/2816></code><em>, <code>[#2827](Kozea/WeasyPrint#2827) <https://github.com/Kozea/WeasyPrint/pull/2827></code></em>: Set SVG title as alternative text</li> <li><code>[#2718](Kozea/WeasyPrint#2718) <https://github.com/Kozea/WeasyPrint/issues/2718></code>_: Provide a 'onedir' Windows executable</li> <li><code>[#2863](Kozea/WeasyPrint#2863) <https://github.com/Kozea/WeasyPrint/pull/2863></code>_: Support box-shadow</li> <li><code>[#2755](Kozea/WeasyPrint#2755) <https://github.com/Kozea/WeasyPrint/pull/2755></code>_: Support RTL SVG text anchoring</li> <li><code>[#2866](Kozea/WeasyPrint#2866) <https://github.com/Kozea/WeasyPrint/issues/2866></code>_: Don’t use f-strings in logs</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/Kozea/WeasyPrint/commit/4d3b7b6449e3494f59c7c2f36b512d129225679c"><code>4d3b7b6</code></a> Version 70.0</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/289e278439b017cd9263b4cd4727026987f86443"><code>289e278</code></a> Always use original URL fetcher when available</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/aeb3be74e3c904e4b772014006410e23e0512b4b"><code>aeb3be7</code></a> Merge remote-tracking branch 'security/main'</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/48357241f949c3f6880ec1a40f56d2f5106fdef3"><code>4835724</code></a> Merge pull request <a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2915">#2915</a> from havelaer/fix-nested-svg-viewport-restore</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/03310511d8afac08f80939e7fa317ad6051e251f"><code>0331051</code></a> Restore nested SVG viewport size on the SVG object, not the drawing function</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/e4b8b45e409392197441bc449d110f323b0eeb66"><code>e4b8b45</code></a> Add harfbuzz-vector requirement for Fedora</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/371e4debb4805fa3d5a138f2cbb044fc176284da"><code>371e4de</code></a> Merge pull request <a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2905">#2905</a> from Kozea/notes</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/590bf63301d77eaf6aac6b1eb3a3fbb9494e3b23"><code>590bf63</code></a> Merge pull request <a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2913">#2913</a> from Kozea/fast-svg-paths</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/f6570c3038b60695f715b12c7805f6933e58490a"><code>f6570c3</code></a> Use a faster regex-based parser for SVG paths</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/bc0516240c5f8a1eaaf658621d52a09eebecdea9"><code>bc05162</code></a> Use faster deque for SVG vertices</li> <li>Additional commits viewable in <a href="https://github.com/Kozea/WeasyPrint/compare/v68.0...v70.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/paritytech/release-registry/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Spigushe
added a commit
to Spigushe/barrins-project
that referenced
this pull request
Sep 17, 2026
…pdates (#152) [//]: # (dependabot-start) ⚠️ **Dependabot is rebasing this PR** ⚠️ Rebasing might not happen immediately, so don't worry if this takes some time. Note: if you make any changes to this PR yourself, they will take precedence over the rebase. --- [//]: # (dependabot-end) Bumps the all-updates group with 6 updates in the /apps/barrins_api directory: | Package | From | To | | --- | --- | --- | | [psycopg2-binary](https://github.com/psycopg/psycopg2) | `2.9.12` | `2.9.13` | | [pyjwt](https://github.com/jpadilla/pyjwt) | `2.13.0` | `2.14.0` | | [weasyprint](https://github.com/Kozea/WeasyPrint) | `69.0` | `70.0` | | [alembic](https://github.com/sqlalchemy/alembic) | `1.19.2` | `1.20.0` | | [ruff](https://github.com/astral-sh/ruff) | `0.16.6` | `0.16.7` | | [ty](https://github.com/astral-sh/ty) | `0.0.78` | `0.0.80` | Bumps the all-updates group with 5 updates in the /apps/barrins_identity directory: | Package | From | To | | --- | --- | --- | | [psycopg2-binary](https://github.com/psycopg/psycopg2) | `2.9.12` | `2.9.13` | | [pyjwt](https://github.com/jpadilla/pyjwt) | `2.13.0` | `2.14.0` | | [alembic](https://github.com/sqlalchemy/alembic) | `1.19.2` | `1.20.0` | | [ruff](https://github.com/astral-sh/ruff) | `0.16.6` | `0.16.7` | | [ty](https://github.com/astral-sh/ty) | `0.0.78` | `0.0.80` | Bumps the all-updates group with 3 updates in the /apps/barrins_scripture directory: [ruff](https://github.com/astral-sh/ruff), [ty](https://github.com/astral-sh/ty) and [selenium](https://github.com/SeleniumHQ/Selenium). Bumps the all-updates group with 5 updates in the /apps/karn_tablets directory: | Package | From | To | | --- | --- | --- | | [psycopg2-binary](https://github.com/psycopg/psycopg2) | `2.9.12` | `2.9.13` | | [ruff](https://github.com/astral-sh/ruff) | `0.16.6` | `0.16.7` | | [ty](https://github.com/astral-sh/ty) | `0.0.78` | `0.0.80` | | [numpy](https://github.com/numpy/numpy) | `2.5.2` | `2.5.3` | | [scikit-learn](https://github.com/scikit-learn/scikit-learn) | `1.9.0` | `1.9.1` | Updates `psycopg2-binary` from 2.9.12 to 2.9.13 <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/psycopg/psycopg2/blob/master/NEWS">psycopg2-binary's changelog</a>.</em></p> <blockquote> <h2>Current release</h2> <p>What's new in psycopg 2.9.13 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^</p> <ul> <li>Add support for Python 3.15 (:ticket:<code>[#1848](https://github.com/psycopg/psycopg2/issues/1848)</code>).</li> <li>Fix parsing of malformed bytea input.</li> <li>Fix parsing of malformed int64 input in arrays (:ticket:<code>[#1847](https://github.com/psycopg/psycopg2/issues/1847)</code>).</li> <li>Add a <code>pyproject.toml</code> file to declare a PEP 517 build backend (:ticket:<code>[#1788](https://github.com/psycopg/psycopg2/issues/1788)</code>).</li> <li>Drop support for Python 3.9.</li> </ul> <p>What's new in psycopg 2.9.12 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^</p> <ul> <li>Fix infinite loop with malformed interval (:ticket:<code>1835</code>).</li> </ul> <p>What's new in psycopg 2.9.11 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^</p> <ul> <li>Add support for Python 3.14.</li> <li>Avoid a segfault passing more arguments than placeholders if Python is built with assertions enabled (:ticket:<code>[#1791](https://github.com/psycopg/psycopg2/issues/1791)</code>).</li> <li>Add riscv64 platform binary packages (:ticket:<code>[#1813](https://github.com/psycopg/psycopg2/issues/1813)</code>).</li> <li><code>~psycopg2.errorcodes</code> map and <code>~psycopg2.errors</code> classes updated to PostgreSQL 18.</li> <li>Drop support for Python 3.8.</li> </ul> <p>What's new in psycopg 2.9.10 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^</p> <ul> <li>Add support for Python 3.13.</li> <li>Receive notifications on commit (:ticket:<code>[#1728](https://github.com/psycopg/psycopg2/issues/1728)</code>).</li> <li><code>~psycopg2.errorcodes</code> map and <code>~psycopg2.errors</code> classes updated to PostgreSQL 17.</li> <li>Drop support for Python 3.7.</li> </ul> <p>What's new in psycopg 2.9.9 ^^^^^^^^^^^^^^^^^^^^^^^^^^^</p> <ul> <li>Add support for Python 3.12.</li> <li>Drop support for Python 3.6.</li> </ul> <p>What's new in psycopg 2.9.8</p> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/psycopg/psycopg2/commit/f650e7afed0c94f596594e8328a0c7fa65a9d0e5"><code>f650e7a</code></a> chore: bump to release 2.9.13</li> <li><a href="https://github.com/psycopg/psycopg2/commit/368c8a1ca6d80088703a693ce64b68ad7d346698"><code>368c8a1</code></a> chore!: drop support for Python 3.9</li> <li><a href="https://github.com/psycopg/psycopg2/commit/9b39e65ab232f0a267a278cdaef1bd9975d88c65"><code>9b39e65</code></a> chore: drop scaleway build support</li> <li><a href="https://github.com/psycopg/psycopg2/commit/2ca70416be6d4d3d8170ec439876c0b3569af718"><code>2ca7041</code></a> fix: fix handling of PostgreSQL 18 exceptions</li> <li><a href="https://github.com/psycopg/psycopg2/commit/5385c027ef62ce14e57a7379e0375868507d6746"><code>5385c02</code></a> Build CPython 3.15 wheels</li> <li><a href="https://github.com/psycopg/psycopg2/commit/1d32e1f6678ffa8ab8897ca81826bf4dde6354cd"><code>1d32e1f</code></a> ci: only attempt triggering documentation refresh when pushing on main repo</li> <li><a href="https://github.com/psycopg/psycopg2/commit/433e7b77a7b700fbb1cdc6e9dca6b5948d07fc23"><code>433e7b7</code></a> chore: add pyproject.toml file to declare a PEP 517 build backend</li> <li><a href="https://github.com/psycopg/psycopg2/commit/8fb80bc3b2c358f4e3c54e33a37326d3f8b3ff6a"><code>8fb80bc</code></a> fix: fix parsing of malformed int64 input in arrays</li> <li><a href="https://github.com/psycopg/psycopg2/commit/f98014a46a1e34f024ebd6134d1d87b77490c500"><code>f98014a</code></a> fix: fix parsing of malformed bytea input</li> <li><a href="https://github.com/psycopg/psycopg2/commit/822b79cfe12ca0a04482acd382cae669a16aa789"><code>822b79c</code></a> chore: bump dependencies in binary package</li> <li>Additional commits viewable in <a href="https://github.com/psycopg/psycopg2/compare/2.9.12...2.9.13">compare view</a></li> </ul> </details> <br /> Updates `pyjwt` from 2.13.0 to 2.14.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/jpadilla/pyjwt/releases">pyjwt's releases</a>.</em></p> <blockquote> <h2>PyJWT 2.14.0</h2> <p>See the <a href="https://github.com/jpadilla/pyjwt/blob/2.14.0/CHANGELOG.rst">2.14.0 changelog</a> for the complete release details and related security advisories.</p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst">pyjwt's changelog</a>.</em></p> <blockquote> <h2><code>v2.14.0 <https://github.com/jpadilla/pyjwt/compare/2.13.0...2.14.0></code>__</h2> <p>Security</p> <pre><code> - Harden HMAC key validation against public-key material supplied as JWK, JWKS, array, encoded, BOM-prefixed, DER, or PEM input. See `GHSA-r6x4-923q-g947 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-r6x4-923q-g947>`__, `GHSA-ffc3-869f-jxw9 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-ffc3-869f-jxw9>`__, `GHSA-p4g4-x82p-q773 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-p4g4-x82p-q773>`__, and `GHSA-w2cx-738m-mc7w <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w2cx-738m-mc7w>`__. - Reject automatic redirects when ``PyJWKClient`` fetches a JWKS, preventing redirected destinations from being treated as trusted key sources. See `GHSA-9v7f-9g4p-ffgj <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-9v7f-9g4p-ffgj>`__. - Limit repeated JWKS refreshes caused by unknown key IDs while preserving normal key-rotation behavior. See `GHSA-2gx3-rcp4-g85q <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-2gx3-rcp4-g85q>`__. - Handle deeply nested and malformed JWS/JWK input without uncaught recursion errors or whole-set parsing failures. See `GHSA-8wjv-2p76-3863 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-8wjv-2p76-3863>`__ and `GHSA-w6j9-cwv2-h6wq <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w6j9-cwv2-h6wq>`__. - Enforce compact JWS encoding rules during decoding. See `GHSA-hxm8-2xgr-2p9m <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-hxm8-2xgr-2p9m>`__. - Reject detached-payload arguments for attached JWS inputs. Thanks to `@xclow3n <https://github.com/xclow3n>`__ for reporting this behavior; fixed in commit `37b54877 <https://github.com/jpadilla/pyjwt/commit/37b54877bf7bea67e8149130e96929e3ec798122>`__. <p>Fixed</p> <pre><code> - Apply HMAC key validation consistently when keys are loaded through ``PyJWK`` and ``PyJWKClient``. See `GHSA-pxh4-856f-4h89 &lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-pxh4-856f-4h89&gt;`__. - Reject empty HMAC keys when represented as JWKs. See `GHSA-pxh4-856f-4h89 &lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-pxh4-856f-4h89&gt;`__. Fixed </code></pre> <ul> <li>Raise the documented <code>PyJWTError</code> subclass instead of leaking a<br /> <code>TypeError</code> when the <code>exp</code>, <code>nbf</code>, or <code>iat</code> claim decodes to a<br /> non-numeric, non-string value such as a list, dict, or <code>null</code>.<br /> </code></pre></li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/jpadilla/pyjwt/commit/c6fe464b356ff4b1ebc9ba62172d331a40aa27df"><code>c6fe464</code></a> release: prepare v2.14.0</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/f5413029ae7a2e31b1367b5303ea86a2f54ccf42"><code>f541302</code></a> style: apply Ruff formatting</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/801cd128528c62d9b23fcd161d1a2e1c17982f95"><code>801cd12</code></a> fix: reject public JWK container HMAC keys</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/af8181ca0bec5e6b372fbba9afbe23702b787ceb"><code>af8181c</code></a> fix: reject empty HMAC keys from JWKs</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/ba4853a75fb9676362da17f67d0f64bd18afd4e1"><code>ba4853a</code></a> Throttle repeated PyJWKClient refreshes</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/2798504fa2663364573cf2d1043d8d7fef389499"><code>2798504</code></a> fix: reject DER public keys as HMAC secrets</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/8b4e233a22206b34ec1186e912e75c0b2396ac07"><code>8b4e233</code></a> fix: reject loader-accepted PEM variants</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/1f8180a211256dfe5cf32294b6753f554a5a4258"><code>1f8180a</code></a> fix: format JWS tests</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/cff1ac55fe5f1096fd05295b269fce053ee290ab"><code>cff1ac5</code></a> Fix redirect handler return annotation</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/0a795b8e1f6ef08f634aa7086fc41cc6d5ce3e56"><code>0a795b8</code></a> Reject redirects in PyJWKClient fetches</li> <li>Additional commits viewable in <a href="https://github.com/jpadilla/pyjwt/compare/2.13.0...2.14.0">compare view</a></li> </ul> </details> <br /> Updates `weasyprint` from 69.0 to 70.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/Kozea/WeasyPrint/releases">weasyprint's releases</a>.</em></p> <blockquote> <h2>v70.0</h2> <p>Read about this release <a href="https://www.courtbouillon.org/blog/00074-weasyprint-70/">on our blog</a>.</p> <p><strong>This is a security update (CVE-2026-55073, GHSA-r543-q48m-4c9j).</strong></p> <p>We strongly recommend to upgrade WeasyPrint to the latest version if you: * embed untrusted images, or * rely on the URL fetcher to filter metadata or stylesheets passed as Python parameters.</p> <h2>Security</h2> <ul> <li>Don’t render EPS images.</li> <li>Always use original URL fetcher when available.</li> </ul> <h2>Features</h2> <ul> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2905">#2905</a>: Add initial support of CSS Notes, with financial support from NLnet</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2731">#2731</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2781">#2781</a>: Log an error on unknown render and write_pdf options</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2802">#2802</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2805">#2805</a>: Create immutable releases on GitHub</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2809">#2809</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2810">#2810</a>: Switch to MSYS2 UCRT64 environment for Windows tests and executables</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2777">#2777</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2814">#2814</a>: Support COLR emoji fonts</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2667">#2667</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2744">#2744</a>: Support context paint in SVG markers</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/1862">#1862</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2844">#2844</a>: Improve filename detection for attachments</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2816">#2816</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2827">#2827</a>: Set SVG title as alternative text</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2718">#2718</a>: Provide a 'onedir' Windows executable</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2863">#2863</a>: Support box-shadow</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2755">#2755</a>: Support RTL SVG text anchoring</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2866">#2866</a>: Don’t use f-strings in logs</li> </ul> <h2>Bug fixes</h2> <ul> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2799">#2799</a>: Keep HarfBuzz font faces alive during PDF subsetting</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2764">#2764</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2793">#2793</a>: Accept Path as base URL in CSS</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2800">#2800</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2801">#2801</a>: Fix position of raster emojis</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2782">#2782</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2807">#2807</a>: Use POSIX paths in Fontconfig</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2766">#2766</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2779">#2779</a>: Use response bytes when image file path doesn’t exist</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2277">#2277</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2728">#2728</a>: Honor page breaks on floated elements</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2789">#2789</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2818">#2818</a>: Use base URL when solving pending properties</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2820">#2820</a>: Ignore unresolvable math in image slices</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2901">#2901</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2825">#2825</a>: Transform SVG size into CSS to apply CSS sizing algorithm</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2819">#2819</a>: Resolve calc() division by zero to infinity</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2824">#2824</a>: Remove old deprecation warnings</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2762">#2762</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2780">#2780</a>: Set SVG gradient color before path construction</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2761">#2761</a>: Handle split tables with captions</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2215">#2215</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2747">#2747</a>: Discard broken at-rules</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2736">#2736</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2738">#2738</a>: Apply transformations to SVG opacity groups</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2830">#2830</a>: Use a stack to draw simple borders</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2831">#2831</a>: Fix line_height() crash on calc() values</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2784">#2784</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2832">#2832</a>: Set fallback font for Unicode test</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2726">#2726</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2881">#2881</a>: Improve accessibility of PDF forms</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2803">#2803</a>: Fix inline width after backtracked line breaks</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2833">#2833</a>: Store root style in anonymous style</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/Kozea/WeasyPrint/blob/main/docs/changelog.rst">weasyprint's changelog</a>.</em></p> <blockquote> <h2>Version 70.0</h2> <p>Released on 2026-09-08.</p> <p><strong>This is a security update (CVE-2026-55073, GHSA-r543-q48m-4c9j).</strong></p> <p>We strongly recommend to upgrade WeasyPrint to the latest version if you:</p> <ul> <li>embed untrusted images, or</li> <li>rely on the URL fetcher to filter metadata or stylesheets passed as Python parameters.</li> </ul> <p>Security:</p> <ul> <li>Don’t render EPS images.</li> <li>Always use original URL fetcher when available.</li> </ul> <p>Features:</p> <ul> <li><code>[#2905](https://github.com/Kozea/WeasyPrint/issues/2905) <https://github.com/Kozea/WeasyPrint/pull/2905></code>_: Add initial support of CSS Notes, with financial support from NLnet</li> <li><code>[#2731](https://github.com/Kozea/WeasyPrint/issues/2731) <https://github.com/Kozea/WeasyPrint/issues/2731></code><em>, <code>[#2781](https://github.com/Kozea/WeasyPrint/issues/2781) <https://github.com/Kozea/WeasyPrint/pull/2781></code></em>: Log an error on unknown render and write_pdf options</li> <li><code>[#2802](https://github.com/Kozea/WeasyPrint/issues/2802) <https://github.com/Kozea/WeasyPrint/issues/2802></code><em>, <code>[#2805](https://github.com/Kozea/WeasyPrint/issues/2805) <https://github.com/Kozea/WeasyPrint/pull/2805></code></em>: Create immutable releases on GitHub</li> <li><code>[#2809](https://github.com/Kozea/WeasyPrint/issues/2809) <https://github.com/Kozea/WeasyPrint/issues/2809></code><em>, <code>[#2810](https://github.com/Kozea/WeasyPrint/issues/2810) <https://github.com/Kozea/WeasyPrint/pull/2810></code></em>: Switch to MSYS2 UCRT64 environment for Windows tests and executables</li> <li><code>[#2777](https://github.com/Kozea/WeasyPrint/issues/2777) <https://github.com/Kozea/WeasyPrint/issues/2777></code><em>, <code>[#2814](https://github.com/Kozea/WeasyPrint/issues/2814) <https://github.com/Kozea/WeasyPrint/pull/2814></code></em>: Support COLR emoji fonts</li> <li><code>[#2667](https://github.com/Kozea/WeasyPrint/issues/2667) <https://github.com/Kozea/WeasyPrint/issues/2667></code><em>, <code>[#2744](https://github.com/Kozea/WeasyPrint/issues/2744) <https://github.com/Kozea/WeasyPrint/pull/2744></code></em>: Support context paint in SVG markers</li> <li><code>[#1862](https://github.com/Kozea/WeasyPrint/issues/1862) <https://github.com/Kozea/WeasyPrint/issues/1862></code><em>, <code>[#2844](https://github.com/Kozea/WeasyPrint/issues/2844) <https://github.com/Kozea/WeasyPrint/pull/2844></code></em>: Improve filename detection for attachments</li> <li><code>[#2816](https://github.com/Kozea/WeasyPrint/issues/2816) <https://github.com/Kozea/WeasyPrint/issues/2816></code><em>, <code>[#2827](https://github.com/Kozea/WeasyPrint/issues/2827) <https://github.com/Kozea/WeasyPrint/pull/2827></code></em>: Set SVG title as alternative text</li> <li><code>[#2718](https://github.com/Kozea/WeasyPrint/issues/2718) <https://github.com/Kozea/WeasyPrint/issues/2718></code>_: Provide a 'onedir' Windows executable</li> <li><code>[#2863](https://github.com/Kozea/WeasyPrint/issues/2863) <https://github.com/Kozea/WeasyPrint/pull/2863></code>_: Support box-shadow</li> <li><code>[#2755](https://github.com/Kozea/WeasyPrint/issues/2755) <https://github.com/Kozea/WeasyPrint/pull/2755></code>_: Support RTL SVG text anchoring</li> <li><code>[#2866](https://github.com/Kozea/WeasyPrint/issues/2866) <https://github.com/Kozea/WeasyPrint/issues/2866></code>_: Don’t use f-strings in logs</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/Kozea/WeasyPrint/commit/4d3b7b6449e3494f59c7c2f36b512d129225679c"><code>4d3b7b6</code></a> Version 70.0</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/289e278439b017cd9263b4cd4727026987f86443"><code>289e278</code></a> Always use original URL fetcher when available</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/aeb3be74e3c904e4b772014006410e23e0512b4b"><code>aeb3be7</code></a> Merge remote-tracking branch 'security/main'</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/48357241f949c3f6880ec1a40f56d2f5106fdef3"><code>4835724</code></a> Merge pull request <a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2915">#2915</a> from havelaer/fix-nested-svg-viewport-restore</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/03310511d8afac08f80939e7fa317ad6051e251f"><code>0331051</code></a> Restore nested SVG viewport size on the SVG object, not the drawing function</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/e4b8b45e409392197441bc449d110f323b0eeb66"><code>e4b8b45</code></a> Add harfbuzz-vector requirement for Fedora</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/371e4debb4805fa3d5a138f2cbb044fc176284da"><code>371e4de</code></a> Merge pull request <a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2905">#2905</a> from Kozea/notes</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/590bf63301d77eaf6aac6b1eb3a3fbb9494e3b23"><code>590bf63</code></a> Merge pull request <a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2913">#2913</a> from Kozea/fast-svg-paths</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/f6570c3038b60695f715b12c7805f6933e58490a"><code>f6570c3</code></a> Use a faster regex-based parser for SVG paths</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/bc0516240c5f8a1eaaf658621d52a09eebecdea9"><code>bc05162</code></a> Use faster deque for SVG vertices</li> <li>Additional commits viewable in <a href="https://github.com/Kozea/WeasyPrint/compare/v69.0...v70.0">compare view</a></li> </ul> </details> <br /> Updates `alembic` from 1.19.2 to 1.20.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/sqlalchemy/alembic/releases">alembic's releases</a>.</em></p> <blockquote> <h1>1.20.0</h1> <p>Released: September 11, 2026</p> <h2>usecase</h2> <ul> <li> <p><strong>[usecase] [batch]</strong> Added a warning for the case where an unnamed CHECK constraint on a reflected table is omitted from a batch "recreate" operation. An unnamed CHECK constraint can't be reliably carried over in a batch recreate as it may refer to columns that are being dropped or changed. This omission was previously a silent operation. The presence of any <code>~sqlalchemy.schema.CheckConstraint</code> in <code>Operations.batch_alter_table.table_args</code> is taken to indicate that the case has been accommodated, and no warning is emitted.</p> <p>References: <a href="https://redirect.github.com/sqlalchemy/alembic/issues/1846">#1846</a></p> </li> <li> <p><strong>[usecase] [autogenerate]</strong> Autogenerate now renders a warning comment above any rendered <code>Operations.drop_constraint()</code> directive for which the constraint name is <code>None</code>, as is the case when a constraint that has no name in the model is dropped, most typically within the <code>downgrade()</code> function of a migration that adds an unnamed constraint. A warning is also emitted on the console when the migration script is generated. The directive requires a non-None name in order to be able to emit a "DROP CONSTRAINT" command.</p> <p>References: <a href="https://redirect.github.com/sqlalchemy/alembic/issues/916">#916</a></p> </li> </ul> <h2>bug</h2> <ul> <li> <p><strong>[bug] [batch]</strong> Fixed bug in batch mode where adding a column with a type that generates its own CHECK constraint, such as <code>~sqlalchemy.types.Boolean</code> or <code>~sqlalchemy.types.Enum</code> with <code>~sqlalchemy.types.Boolean.create_constraint</code> set to <code>True</code>, would emit the constraint twice when the table was recreated, once under the name generated by the naming convention in use and once under the name given to the type. The constraint is now emitted once, using the same name that would be used outside of batch mode.</p> <p>References: <a href="https://redirect.github.com/sqlalchemy/alembic/issues/1768">#1768</a></p> </li> <li> <p><strong>[bug] [batch]</strong> Fixed bug in batch mode where a CHECK constraint generated by a type such as <code>~sqlalchemy.types.Boolean</code> or <code>~sqlalchemy.types.Enum</code> would lose the name established for it by the naming convention in use when the table was recreated, as the constraint was regenerated against the temporary table used for the recreate operation. The naming convention is now resolved against the name of the table being replaced.</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li>See full diff in <a href="https://github.com/sqlalchemy/alembic/commits">compare view</a></li> </ul> </details> <br /> Updates `ruff` from 0.16.6 to 0.16.7 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/releases">ruff's releases</a>.</em></p> <blockquote> <h2>0.16.7</h2> <h2>Release Notes</h2> <p>Released on 2026-09-10.</p> <h3>Preview features</h3> <ul> <li>[<code>ruff</code>] Add rule for default values on method receivers (<code>RUF077</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/26700">#26700</a>)</li> <li>[<code>ruff</code>] Recognize <code>re.prefixmatch</code> (<code>RUF039</code>, <code>RUF055</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28311">#28311</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>Alternate nested quotes inside format spec interpolations (<a href="https://redirect.github.com/astral-sh/ruff/pull/28259">#28259</a>)</li> <li>[<code>flake8-implicit-str-concat</code>] Mark fix unsafe when it creates a docstring (<code>ISC003</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/27981">#27981</a>)</li> <li>[<code>flake8-tidy-imports</code>] Skip fixes for multi-member imports (<code>TID254</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/26584">#26584</a>)</li> <li>[<code>pylint</code>] Gate <code>ImportCycleError</code> on Python 3.15 (<code>PLW0133</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28310">#28310</a>)</li> </ul> <h3>Rule changes</h3> <ul> <li>Correct <code>D211</code> and <code>D203</code> rule conflict diagnostic (<a href="https://redirect.github.com/astral-sh/ruff/pull/28444">#28444</a>)</li> <li>Recognize <code>slice</code> and <code>frozendict</code> generics (<a href="https://redirect.github.com/astral-sh/ruff/pull/28477">#28477</a>)</li> <li>Stop defining <code>__cached__</code> for Python 3.15 (<a href="https://redirect.github.com/astral-sh/ruff/pull/28476">#28476</a>)</li> <li>[<code>pyupgrade</code>] Stop recommending removed <code>typing.no_type_check_decorator</code> (<code>UP035</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28475">#28475</a>)</li> </ul> <h3>Performance</h3> <ul> <li>Reuse parser name lookups when interning (<a href="https://redirect.github.com/astral-sh/ruff/pull/28399">#28399</a>)</li> <li>Speed up inherited configuration resolution (<a href="https://redirect.github.com/astral-sh/ruff/pull/28299">#28299</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Fix <code>line-length</code> path in <code>--config</code> example (<a href="https://redirect.github.com/astral-sh/ruff/pull/28392">#28392</a>)</li> <li>Remove the "Who’s Using Ruff?" list (<a href="https://redirect.github.com/astral-sh/ruff/pull/28455">#28455</a>)</li> </ul> <h3>Other changes</h3> <ul> <li>Embed archive checksums in the shell installer (<a href="https://redirect.github.com/astral-sh/ruff/pull/28281">#28281</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/The-Compiler"><code>@The-Compiler</code></a></li> <li><a href="https://github.com/mdiniz97"><code>@mdiniz97</code></a></li> <li><a href="https://github.com/zsol"><code>@zsol</code></a></li> <li><a href="https://github.com/gorewilliams"><code>@gorewilliams</code></a></li> <li><a href="https://github.com/RafaelJohn9"><code>@RafaelJohn9</code></a></li> <li><a href="https://github.com/qatcod"><code>@qatcod</code></a></li> <li><a href="https://github.com/zanieb"><code>@zanieb</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's changelog</a>.</em></p> <blockquote> <h2>0.16.7</h2> <p>Released on 2026-09-10.</p> <h3>Preview features</h3> <ul> <li>[<code>ruff</code>] Add rule for default values on method receivers (<code>RUF077</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/26700">#26700</a>)</li> <li>[<code>ruff</code>] Recognize <code>re.prefixmatch</code> (<code>RUF039</code>, <code>RUF055</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28311">#28311</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>Alternate nested quotes inside format spec interpolations (<a href="https://redirect.github.com/astral-sh/ruff/pull/28259">#28259</a>)</li> <li>[<code>flake8-implicit-str-concat</code>] Mark fix unsafe when it creates a docstring (<code>ISC003</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/27981">#27981</a>)</li> <li>[<code>flake8-tidy-imports</code>] Skip fixes for multi-member imports (<code>TID254</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/26584">#26584</a>)</li> <li>[<code>pylint</code>] Gate <code>ImportCycleError</code> on Python 3.15 (<code>PLW0133</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28310">#28310</a>)</li> </ul> <h3>Rule changes</h3> <ul> <li>Correct <code>D211</code> and <code>D203</code> rule conflict diagnostic (<a href="https://redirect.github.com/astral-sh/ruff/pull/28444">#28444</a>)</li> <li>Recognize <code>slice</code> and <code>frozendict</code> generics (<a href="https://redirect.github.com/astral-sh/ruff/pull/28477">#28477</a>)</li> <li>Stop defining <code>__cached__</code> for Python 3.15 (<a href="https://redirect.github.com/astral-sh/ruff/pull/28476">#28476</a>)</li> <li>[<code>pyupgrade</code>] Stop recommending removed <code>typing.no_type_check_decorator</code> (<code>UP035</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28475">#28475</a>)</li> </ul> <h3>Performance</h3> <ul> <li>Reuse parser name lookups when interning (<a href="https://redirect.github.com/astral-sh/ruff/pull/28399">#28399</a>)</li> <li>Speed up inherited configuration resolution (<a href="https://redirect.github.com/astral-sh/ruff/pull/28299">#28299</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Fix <code>line-length</code> path in <code>--config</code> example (<a href="https://redirect.github.com/astral-sh/ruff/pull/28392">#28392</a>)</li> <li>Remove the "Who’s Using Ruff?" list (<a href="https://redirect.github.com/astral-sh/ruff/pull/28455">#28455</a>)</li> </ul> <h3>Other changes</h3> <ul> <li>Embed archive checksums in the shell installer (<a href="https://redirect.github.com/astral-sh/ruff/pull/28281">#28281</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/The-Compiler"><code>@The-Compiler</code></a></li> <li><a href="https://github.com/mdiniz97"><code>@mdiniz97</code></a></li> <li><a href="https://github.com/zsol"><code>@zsol</code></a></li> <li><a href="https://github.com/gorewilliams"><code>@gorewilliams</code></a></li> <li><a href="https://github.com/RafaelJohn9"><code>@RafaelJohn9</code></a></li> <li><a href="https://github.com/qatcod"><code>@qatcod</code></a></li> <li><a href="https://github.com/zanieb"><code>@zanieb</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/nightt5879"><code>@nightt5879</code></a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/astral-sh/ruff/commit/b5dba861cc38e3f7fb4524c9ceba3e01a474ea13"><code>b5dba86</code></a> Bump version to 0.16.7 (<a href="https://redirect.github.com/astral-sh/ruff/issues/28496">#28496</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/5992d0504697d86565d8fc3a4d8245a5f4047d24"><code>5992d05</code></a> Install rustfmt before linting releases (<a href="https://redirect.github.com/astral-sh/ruff/issues/28495">#28495</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/1713a1f4325494d883a080d590a25a1946f399e8"><code>1713a1f</code></a> ensure prepare release changes pass prek (<a href="https://redirect.github.com/astral-sh/ruff/issues/28488">#28488</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/18cdbb4f3d14058794420e758864795f55336334"><code>18cdbb4</code></a> use scoped token for release workflow (<a href="https://redirect.github.com/astral-sh/ruff/issues/28484">#28484</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/c3813a501faf887fd01948c98bb8d58ad26488bd"><code>c3813a5</code></a> add a workflow for preparing releases (<a href="https://redirect.github.com/astral-sh/ruff/issues/28486">#28486</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/00948c00a671b81f5358af9f038436bcbb993b38"><code>00948c0</code></a> Remove the "Who’s Using Ruff?" list (<a href="https://redirect.github.com/astral-sh/ruff/issues/28455">#28455</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/86a2eba7b48e3c10386f7ab8a5425c7275d2b427"><code>86a2eba</code></a> [<code>pyupgrade</code>] Stop recommending removed <code>typing.no_type_check_decorator</code> (`UP...</li> <li><a href="https://github.com/astral-sh/ruff/commit/609e184aa35f0034b7ef63e3e04327081c484af6"><code>609e184</code></a> Stop defining <code>__cached__</code> for Python 3.15 (<a href="https://redirect.github.com/astral-sh/ruff/issues/28476">#28476</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/859ff2f01670c43ffff1ea597c8a2e375ada0fbe"><code>859ff2f</code></a> [ty] Track symlinked directory status in listings (<a href="https://redirect.github.com/astral-sh/ruff/issues/28482">#28482</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/77f653825800ddaf3bc221ae6db49a500e1002d5"><code>77f6538</code></a> Use paid GitHub-hosted runners for Linux (<a href="https://redirect.github.com/astral-sh/ruff/issues/28478">#28478</a>)</li> <li>Additional commits viewable in <a href="https://github.com/astral-sh/ruff/compare/0.16.6...0.16.7">compare view</a></li> </ul> </details> <br /> Updates `ty` from 0.0.78 to 0.0.80 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ty/releases">ty's releases</a>.</em></p> <blockquote> <h2>0.0.80</h2> <h2>Release Notes</h2> <p>Released on 2026-09-09.</p> <h3>Bug fixes</h3> <ul> <li>Fix <code>--force-exclude</code> for directories with an excluded ancestor (<a href="https://redirect.github.com/astral-sh/ruff/pull/28451">#28451</a>)</li> <li>Preserve metaclass candidates after conflicts (<a href="https://redirect.github.com/astral-sh/ruff/pull/28461">#28461</a>)</li> </ul> <h3>LSP server</h3> <ul> <li>Give existing autofixes descriptive titles (<a href="https://redirect.github.com/astral-sh/ruff/pull/28456">#28456</a>)</li> <li>Prevent LSP hangs during inlay hint bursts (<a href="https://redirect.github.com/astral-sh/ruff/pull/28390">#28390</a>)</li> </ul> <h3>Diagnostic improvements</h3> <ul> <li>Preserve redundant-condition diagnostics with unreachable operands (<a href="https://redirect.github.com/astral-sh/ruff/pull/28374">#28374</a>)</li> </ul> <h3>Core type checking</h3> <ul> <li>Check captured receivers when calling wrapped classmethods (<a href="https://redirect.github.com/astral-sh/ruff/pull/28467">#28467</a>)</li> <li>Fix cached classmethods on generic classes (<a href="https://redirect.github.com/astral-sh/ruff/pull/28207">#28207</a>)</li> <li>Fix disjointness of type guards and boolean literals (<a href="https://redirect.github.com/astral-sh/ruff/pull/28363">#28363</a>)</li> <li>Infer tuple variance from the full tuple spec (<a href="https://redirect.github.com/astral-sh/ruff/pull/28446">#28446</a>)</li> <li>Infer tuple variance more precisely (<a href="https://redirect.github.com/astral-sh/ruff/pull/28426">#28426</a>)</li> <li>Preserve callable identity across specialized types (<a href="https://redirect.github.com/astral-sh/ruff/pull/28409">#28409</a>)</li> <li>Preserve callback type context through ParamSpec forwarding (<a href="https://redirect.github.com/astral-sh/ruff/pull/28439">#28439</a>)</li> <li>Preserve wrapped functions in precise <code>functools.partial</code> relations (<a href="https://redirect.github.com/astral-sh/ruff/pull/28460">#28460</a>)</li> <li>Respect descriptor protocol for <code>__set__</code> itself (<a href="https://redirect.github.com/astral-sh/ruff/pull/28408">#28408</a>)</li> <li>Respect type-variable bounds in argument context (<a href="https://redirect.github.com/astral-sh/ruff/pull/28448">#28448</a>)</li> <li>Unwrap union alternatives in overload implementations (<a href="https://redirect.github.com/astral-sh/ruff/pull/28468">#28468</a>)</li> </ul> <h3>Performance</h3> <ul> <li>Distribute <code>len</code> inference over unions (<a href="https://redirect.github.com/astral-sh/ruff/pull/28470">#28470</a>)</li> <li>Fast-path concrete literal intersections (<a href="https://redirect.github.com/astral-sh/ruff/pull/28348">#28348</a>)</li> </ul> <h3>Memory usage improvements</h3> <ul> <li>Avoid excess capacity in multi-binding tables (<a href="https://redirect.github.com/astral-sh/ruff/pull/28412">#28412</a>)</li> <li>Share equivalent place tables within a file (<a href="https://redirect.github.com/astral-sh/ruff/pull/28319">#28319</a>)</li> <li>Share names in synthesized constructor parameters (<a href="https://redirect.github.com/astral-sh/ruff/pull/28398">#28398</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/sharkdp"><code>@sharkdp</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/ibraheemdev"><code>@ibraheemdev</code></a></li> <li><a href="https://github.com/AlexWaygood"><code>@AlexWaygood</code></a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ty/blob/main/CHANGELOG.md">ty's changelog</a>.</em></p> <blockquote> <h2>0.0.80</h2> <p>Released on 2026-09-09.</p> <h3>Bug fixes</h3> <ul> <li>Fix <code>--force-exclude</code> for directories with an excluded ancestor (<a href="https://redirect.github.com/astral-sh/ruff/pull/28451">#28451</a>)</li> <li>Preserve metaclass candidates after conflicts (<a href="https://redirect.github.com/astral-sh/ruff/pull/28461">#28461</a>)</li> </ul> <h3>LSP server</h3> <ul> <li>Give existing autofixes descriptive titles (<a href="https://redirect.github.com/astral-sh/ruff/pull/28456">#28456</a>)</li> <li>Prevent LSP hangs during inlay hint bursts (<a href="https://redirect.github.com/astral-sh/ruff/pull/28390">#28390</a>)</li> </ul> <h3>Diagnostic improvements</h3> <ul> <li>Preserve redundant-condition diagnostics with unreachable operands (<a href="https://redirect.github.com/astral-sh/ruff/pull/28374">#28374</a>)</li> </ul> <h3>Core type checking</h3> <ul> <li>Check captured receivers when calling wrapped classmethods (<a href="https://redirect.github.com/astral-sh/ruff/pull/28467">#28467</a>)</li> <li>Fix cached classmethods on generic classes (<a href="https://redirect.github.com/astral-sh/ruff/pull/28207">#28207</a>)</li> <li>Fix disjointness of type guards and boolean literals (<a href="https://redirect.github.com/astral-sh/ruff/pull/28363">#28363</a>)</li> <li>Infer tuple variance from the full tuple spec (<a href="https://redirect.github.com/astral-sh/ruff/pull/28446">#28446</a>)</li> <li>Infer tuple variance more precisely (<a href="https://redirect.github.com/astral-sh/ruff/pull/28426">#28426</a>)</li> <li>Preserve callable identity across specialized types (<a href="https://redirect.github.com/astral-sh/ruff/pull/28409">#28409</a>)</li> <li>Preserve callback type context through ParamSpec forwarding (<a href="https://redirect.github.com/astral-sh/ruff/pull/28439">#28439</a>)</li> <li>Preserve wrapped functions in precise <code>functools.partial</code> relations (<a href="https://redirect.github.com/astral-sh/ruff/pull/28460">#28460</a>)</li> <li>Respect descriptor protocol for <code>__set__</code> itself (<a href="https://redirect.github.com/astral-sh/ruff/pull/28408">#28408</a>)</li> <li>Respect type-variable bounds in argument context (<a href="https://redirect.github.com/astral-sh/ruff/pull/28448">#28448</a>)</li> <li>Unwrap union alternatives in overload implementations (<a href="https://redirect.github.com/astral-sh/ruff/pull/28468">#28468</a>)</li> </ul> <h3>Performance</h3> <ul> <li>Distribute <code>len</code> inference over unions (<a href="https://redirect.github.com/astral-sh/ruff/pull/28470">#28470</a>)</li> <li>Fast-path concrete literal intersections (<a href="https://redirect.github.com/astral-sh/ruff/pull/28348">#28348</a>)</li> </ul> <h3>Memory usage improvements</h3> <ul> <li>Avoid excess capacity in multi-binding tables (<a href="https://redirect.github.com/astral-sh/ruff/pull/28412">#28412</a>)</li> <li>Share equivalent place tables within a file (<a href="https://redirect.github.com/astral-sh/ruff/pull/28319">#28319</a>)</li> <li>Share names in synthesized constructor parameters (<a href="https://redirect.github.com/astral-sh/ruff/pull/28398">#28398</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/sharkdp"><code>@sharkdp</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/ibraheemdev"><code>@ibraheemdev</code></a></li> <li><a href="https://github.com/AlexWaygood"><code>@AlexWaygood</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/astral-sh/ty/commit/7fd8e15694f869200f7778082564c5968c50ce30"><code>7fd8e15</code></a> Bump version to 0.0.80 (<a href="https://redirect.github.com/astral-sh/ty/issues/4501">#4501</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/c163f21ed4be7a5608ae5791720b43040b08cf5c"><code>c163f21</code></a> Update dependency prek to v0.4.12 (<a href="https://redirect.github.com/astral-sh/ty/issues/4494">#4494</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/8ce0450332e815c0f734fb84d03d63be3eb96829"><code>8ce0450</code></a> Update prek dependencies (<a href="https://redirect.github.com/astral-sh/ty/issues/4495">#4495</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/5d0aa7a142189fc1955759c2987029b8ff8ef4a7"><code>5d0aa7a</code></a> Update actions/attest-build-provenance action to v4.2.2 (<a href="https://redirect.github.com/astral-sh/ty/issues/4497">#4497</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/e22b86b3e6d461af46b549e5ebef5474b6256783"><code>e22b86b</code></a> Update Swatinem/rust-cache action to v2.9.2 (<a href="https://redirect.github.com/astral-sh/ty/issues/4496">#4496</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/5cde40f5cb83f1cb164b91282e6a72f3dfe4580c"><code>5cde40f</code></a> Document uv integration and workspace trust settings (<a href="https://redirect.github.com/astral-sh/ty/issues/4339">#4339</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/b4cd79275b7ce22c4cf4208f8b005adb53e92523"><code>b4cd792</code></a> Bump version to 0.0.79 (<a href="https://redirect.github.com/astral-sh/ty/issues/4484">#4484</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/52f2d5b12ff4a86f1100f3b9c3e2d61b086d8a89"><code>52f2d5b</code></a> Add a GitHub repository threat model for ty (<a href="https://redirect.github.com/astral-sh/ty/issues/4481">#4481</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/fd0d789cc54f9a234da75025ef6d0777280675be"><code>fd0d789</code></a> Declare support for Python 3.15 (<a href="https://redirect.github.com/astral-sh/ty/issues/4476">#4476</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/7e7a87da9849d3f322690ae5b74b0409799668b6"><code>7e7a87d</code></a> Improve rooster-generated changelog sections (<a href="https://redirect.github.com/astral-sh/ty/issues/4473">#4473</a>)</li> <li>Additional commits viewable in <a href="https://github.com/astral-sh/ty/compare/0.0.78...0.0.80">compare view</a></li> </ul> </details> <br /> Updates `psycopg2-binary` from 2.9.12 to 2.9.13 <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/psycopg/psycopg2/blob/master/NEWS">psycopg2-binary's changelog</a>.</em></p> <blockquote> <h2>Current release</h2> <p>What's new in psycopg 2.9.13 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^</p> <ul> <li>Add support for Python 3.15 (:ticket:<code>[#1848](https://github.com/psycopg/psycopg2/issues/1848)</code>).</li> <li>Fix parsing of malformed bytea input.</li> <li>Fix parsing of malformed int64 input in arrays (:ticket:<code>[#1847](https://github.com/psycopg/psycopg2/issues/1847)</code>).</li> <li>Add a <code>pyproject.toml</code> file to declare a PEP 517 build backend (:ticket:<code>[#1788](https://github.com/psycopg/psycopg2/issues/1788)</code>).</li> <li>Drop support for Python 3.9.</li> </ul> <p>What's new in psycopg 2.9.12 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^</p> <ul> <li>Fix infinite loop with malformed interval (:ticket:<code>1835</code>).</li> </ul> <p>What's new in psycopg 2.9.11 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^</p> <ul> <li>Add support for Python 3.14.</li> <li>Avoid a segfault passing more arguments than placeholders if Python is built with assertions enabled (:ticket:<code>[#1791](https://github.com/psycopg/psycopg2/issues/1791)</code>).</li> <li>Add riscv64 platform binary packages (:ticket:<code>[#1813](https://github.com/psycopg/psycopg2/issues/1813)</code>).</li> <li><code>~psycopg2.errorcodes</code> map and <code>~psycopg2.errors</code> classes updated to PostgreSQL 18.</li> <li>Drop support for Python 3.8.</li> </ul> <p>What's new in psycopg 2.9.10 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^</p> <ul> <li>Add support for Python 3.13.</li> <li>Receive notifications on commit (:ticket:<code>[#1728](https://github.com/psycopg/psycopg2/issues/1728)</code>).</li> <li><code>~psycopg2.errorcodes</code> map and <code>~psycopg2.errors</code> classes updated to PostgreSQL 17.</li> <li>Drop support for Python 3.7.</li> </ul> <p>What's new in psycopg 2.9.9 ^^^^^^^^^^^^^^^^^^^^^^^^^^^</p> <ul> <li>Add support for Python 3.12.</li> <li>Drop support for Python 3.6.</li> </ul> <p>What's new in psycopg 2.9.8</p> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/psycopg/psycopg2/commit/f650e7afed0c94f596594e8328a0c7fa65a9d0e5"><code>f650e7a</code></a> chore: bump to release 2.9.13</li> <li><a href="https://github.com/psycopg/psycopg2/commit/368c8a1ca6d80088703a693ce64b68ad7d346698"><code>368c8a1</code></a> chore!: drop support for Python 3.9</li> <li><a href="https://github.com/psycopg/psycopg2/commit/9b39e65ab232f0a267a278cdaef1bd9975d88c65"><code>9b39e65</code></a> chore: drop scaleway build support</li> <li><a href="https://github.com/psycopg/psycopg2/commit/2ca70416be6d4d3d8170ec439876c0b3569af718"><code>2ca7041</code></a> fix: fix handling of PostgreSQL 18 exceptions</li> <li><a href="https://github.com/psycopg/psycopg2/commit/5385c027ef62ce14e57a7379e0375868507d6746"><code>5385c02</code></a> Build CPython 3.15 wheels</li> <li><a href="https://github.com/psycopg/psycopg2/commit/1d32e1f6678ffa8ab8897ca81826bf4dde6354cd"><code>1d32e1f</code></a> ci: only attempt triggering documentation refresh when pushing on main repo</li> <li><a href="https://github.com/psycopg/psycopg2/commit/433e7b77a7b700fbb1cdc6e9dca6b5948d07fc23"><code>433e7b7</code></a> chore: add pyproject.toml file to declare a PEP 517 build backend</li> <li><a href="https://github.com/psycopg/psycopg2/commit/8fb80bc3b2c358f4e3c54e33a37326d3f8b3ff6a"><code>8fb80bc</code></a> fix: fix parsing of malformed int64 input in arrays</li> <li><a href="https://github.com/psycopg/psycopg2/commit/f98014a46a1e34f024ebd6134d1d87b77490c500"><code>f98014a</code></a> fix: fix parsing of malformed bytea input</li> <li><a href="https://github.com/psycopg/psycopg2/commit/822b79cfe12ca0a04482acd382cae669a16aa789"><code>822b79c</code></a> chore: bump dependencies in binary package</li> <li>Additional commits viewable in <a href="https://github.com/psycopg/psycopg2/compare/2.9.12...2.9.13">compare view</a></li> </ul> </details> <br /> Updates `pyjwt` from 2.13.0 to 2.14.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/jpadilla/pyjwt/releases">pyjwt's releases</a>.</em></p> <blockquote> <h2>PyJWT 2.14.0</h2> <p>See the <a href="https://github.com/jpadilla/pyjwt/blob/2.14.0/CHANGELOG.rst">2.14.0 changelog</a> for the complete release details and related security advisories.</p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst">pyjwt's changelog</a>.</em></p> <blockquote> <h2><code>v2.14.0 <https://github.com/jpadilla/pyjwt/compare/2.13.0...2.14.0></code>__</h2> <p>Security</p> <pre><code> - Harden HMAC key validation against public-key material supplied as JWK, JWKS, array, encoded, BOM-prefixed, DER, or PEM input. See `GHSA-r6x4-923q-g947 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-r6x4-923q-g947>`__, `GHSA-ffc3-869f-jxw9 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-ffc3-869f-jxw9>`__, `GHSA-p4g4-x82p-q773 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-p4g4-x82p-q773>`__, and `GHSA-w2cx-738m-mc7w <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w2cx-738m-mc7w>`__. - Reject automatic redirects when ``PyJWKClient`` fetches a JWKS, preventing redirected destinations from being treated as trusted key sources. See `GHSA-9v7f-9g4p-ffgj <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-9v7f-9g4p-ffgj>`__. - Limit repeated JWKS refreshes caused by unknown key IDs while preserving normal key-rotation behavior. See `GHSA-2gx3-rcp4-g85q <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-2gx3-rcp4-g85q>`__. - Handle deeply nested and malformed JWS/JWK input without uncaught recursion errors or whole-set parsing failures. See `GHSA-8wjv-2p76-3863 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-8wjv-2p76-3863>`__ and `GHSA-w6j9-cwv2-h6wq <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w6j9-cwv2-h6wq>`__. - Enforce compact JWS encoding rules during decoding. See `GHSA-hxm8-2xgr-2p9m <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-hxm8-2xgr-2p9m>`__. - Reject detached-payload arguments for attached JWS inputs. Thanks to `@xclow3n <https://github.com/xclow3n>`__ for reporting this behavior; fixed in commit `37b54877 <https://github.com/jpadilla/pyjwt/commit/37b54877bf7bea67e8149130e96929e3ec798122>`__. <p>Fixed</p> <pre><code> - Apply HMAC key validation consistently when keys are loaded through ``PyJWK`` and ``PyJWKClient``. See `GHSA-pxh4-856f-4h89 &lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-pxh4-856f-4h89&gt;`__. - Reject empty HMAC keys when represented as JWKs. See `GHSA-pxh4-856f-4h89 &lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-pxh4-856f-4h89&gt;`__. Fixed </code></pre> <ul> <li>Raise the documented <code>PyJWTError</code> subclass instead of leaking a<br /> <code>TypeError</code> when the <code>exp</code>, <code>nbf</code>, or <code>iat</code> claim decodes to a<br /> non-numeric, non-string value such as a list, dict, or <code>null</code>.<br /> </code></pre></li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/jpadilla/pyjwt/commit/c6fe464b356ff4b1ebc9ba62172d331a40aa27df"><code>c6fe464</code></a> release: prepare v2.14.0</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/f5413029ae7a2e31b1367b5303ea86a2f54ccf42"><code>f541302</code></a> style: apply Ruff formatting</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/801cd128528c62d9b23fcd161d1a2e1c17982f95"><code>801cd12</code></a> fix: reject public JWK container HMAC keys</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/af8181ca0bec5e6b372fbba9afbe23702b787ceb"><code>af8181c</code></a> fix: reject empty HMAC keys from JWKs</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/ba4853a75fb9676362da17f67d0f64bd18afd4e1"><code>ba4853a</code></a> Throttle repeated PyJWKClient refreshes</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/2798504fa2663364573cf2d1043d8d7fef389499"><code>2798504</code></a> fix: reject DER public keys as HMAC secrets</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/8b4e233a22206b34ec1186e912e75c0b2396ac07"><code>8b4e233</code></a> fix: reject loader-accepted PEM variants</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/1f8180a211256dfe5cf32294b6753f554a5a4258"><code>1f8180a</code></a> fix: format JWS tests</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/cff1ac55fe5f1096fd05295b269fce053ee290ab"><code>cff1ac5</code></a> Fix redirect handler return annotation</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/0a795b8e1f6ef08f634aa7086fc41cc6d5ce3e56"><code>0a795b8</code></a> Reject redirects in PyJWKClient fetches</li> <li>Additional commits viewable in <a href="https://github.com/jpadilla/pyjwt/compare/2.13.0...2.14.0">compare view</a></li> </ul> </details> <br /> Updates `alembic` from 1.19.2 to 1.20.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/sqlalchemy/alembic/releases">alembic's releases</a>.</em></p> <blockquote> <h1>1.20.0</h1> <p>Released: September 11, 2026</p> <h2>usecase</h2> <ul> <li> <p><strong>[usecase] [batch]</strong> Added a warning for the case where an unnamed CHECK constraint on a reflected table is omitted from a batch "recreate" operation. An unnamed CHECK constraint can't be reliably carried over in a batch recreate as it may refer to columns that are being dropped or changed. This omission was previously a silent operation. The presence of any <code>~sqlalchemy.schema.CheckConstraint</code> in <code>Operations.batch_alter_table.table_args</code> is taken to indicate that the case has been accommodated, and no warning is emitted.</p> <p>References: <a href="https://redirect.github.com/sqlalchemy/alembic/issues/1846">#1846</a></p> </li> <li> <p><strong>[usecase] [autogenerate]</strong> Autogenerate now renders a warning comment above any rendered <code>Operations.drop_constraint()</code> directive for which the constraint name is <code>None</code>, as is the case when a constraint that has no name in the model is dropped, most typically within the <code>downgrade()</code> function of a migration that adds an unnamed constraint. A warning is also emitted on the console when the migration script is generated. The directive requires a non-None name in order to be able to emit a "DROP CONSTRAINT" command.</p> <p>References: <a href="https://redirect.github.com/sqlalchemy/alembic/issues/916">#916</a></p> </li> </ul> <h2>bug</h2> <ul> <li> <p><strong>[bug] [batch]</strong> Fixed bug in batch mode where adding a column with a type that generates its own CHECK constraint, such as <code>~sqlalchemy.types.Boolean</code> or <code>~sqlalchemy.types.Enum</code> with <code>~sqlalchemy.types.Boolean.create_constraint</code> set to <code>True</code>, would emit the constraint twice when the table was recreated, once under the name generated by the naming convention in use and once under the name given to the type. The constraint is now emitted once, using the same name that would be used outside of batch mode.</p> <p>References: <a href="https://redirect.github.com/sqlalchemy/alembic/issues/1768">#1768</a></p> </li> <li> <p><strong>[bug] [batch]</strong> Fixed bug in batch mode where a CHECK constraint generated by a type such as <code>~sqlalchemy.types.Boolean</code> or <code>~sqlalchemy.types.Enum</code> would lose the name established for it by the naming convention in use when the table was recreated, as the constraint was regenerated against the temporary table used for the recreate operation. The naming convention is now resolved against the name of the table being replaced.</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li>See full diff in <a href="https://github.com/sqlalchemy/alembic/commits">compare view</a></li> </ul> </details> <br /> Updates `ruff` from 0.16.6 to 0.16.7 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/releases">ruff's releases</a>.</em></p> <blockquote> <h2>0.16.7</h2> <h2>Release Notes</h2> <p>Released on 2026-09-10.</p> <h3>Preview features</h3> <ul> <li>[<code>ruff</code>] Add rule for default values on method receivers (<code>RUF077</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/26700">#26700</a>)</li> <li>[<code>ruff</code>] Recognize <code>re.prefixmatch</code> (<code>RUF039</code>, <code>RUF055</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28311">#28311</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>Alternate nested quotes inside format spec interpolations (<a href="https://redirect.github.com/astral-sh/ruff/pull/28259">#28259</a>)</li> <li>[<code>flake8-implicit-str-concat</code>] Mark fix unsafe when it creates a docstring (<code>ISC003</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/27981">#27981</a>)</li> <li>[<code>flake8-tidy-imports</code>] Skip fixes for multi-member imports (<code>TID254</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/26584">#26584</a>)</li> <li>[<code>pylint</code>] Gate <code>ImportCycleError</code> on Python 3.15 (<code>PLW0133</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28310">#28310</a>)</li> </ul> <h3>Rule changes</h3> <ul> <li>Correct <code>D211</code> and <code>D203</code> rule conflict diagnostic (<a href="https://redirect.github.com/astral-sh/ruff/pull/28444">#28444</a>)</li> <li>Recognize <code>slice</code> and <code>frozendict</code> generics (<a href="https://redirect.github.com/astral-sh/ruff/pull/28477">#28477</a>)</li> <li>Stop defining <code>__cached__</code> for Python 3.15 (<a href="https://redirect.github.com/astral-sh/ruff/pull/28476">#28476</a>)</li> <li>[<code>pyupgrade</code>] Stop recommending removed <code>typing.no_type_check_decorator</code> (<code>UP035</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28475">#28475</a>)</li> </ul> <h3>Performance</h3> <ul> <li>Reuse parser name lookups when interning (<a href="https://redirect.github.com/astral-sh/ruff/pull/28399">#28399</a>)</li> <li>Speed up inherited configuration resolution (<a href="https://redirect.github.com/astral-sh/ruff/pull/28299">#28299</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Fix <code>line-length</code> path in <code>--config</code> example (<a href="https://redirect.github.com/astral-sh/ruff/pull/28392">#28392</a>)</li> <li>Remove the "Who’s Using Ruff?" list (<a href="https://redirect.github.com/astral-sh/ruff/pull/28455">#28455</a>)</li> </ul> <h3>Other changes</h3> <ul> <li>Embed archive checksums in the shell installer (<a href="https://redirect.github.com/astral-sh/ruff/pull/28281">#28281</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/The-Compiler"><code>@The-Compiler</code></a></li> <li><a href="https://github.com/mdiniz97"><code>@mdiniz97</code></a></li> <li><a href="https://github.com/zsol"><code>@zsol</code></a></li> <li><a href="https://github.com/gorewilliams"><code>@gorewilliams</code></a></li> <li><a href="https://github.com/RafaelJohn9"><code>@RafaelJohn9</code></a></li> <li><a href="https://github.com/qatcod"><code>@qatcod</code></a></li> <li><a href="https://github.com/zanieb"><code>@zanieb</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's changelog</a>.</em></p> <blockquote> <h2>0.16.7</h2> <p>Released on 2026-09-10.</p> <h3>Preview features</h3> <ul> <li>[<code>ruff</code>] Add rule for default values on method receivers (<code>RUF077</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/26700">#26700</a>)</li> <li>[<code>ruff</code>] Recognize <code>re.prefixmatch</code> (<code>RUF039</code>, <code>RUF055</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28311">#28311</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>Alternate nested quotes inside format spec interpolations (<a href="https://redirect.github.com/astral-sh/ruff/pull/28259">#28259</a>)</li> <li>[<code>flake8-implicit-str-concat</code>] Mark fix unsafe when it creates a docstring (<code>ISC003</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/27981">#27981</a>)</li> <li>[<code>flake8-tidy-imports</code>] Skip fixes for multi-member imports (<code>TID254</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/26584">#26584</a>)</li> <li>[<code>pylint</code>] Gate <code>ImportCycleError</code> on Python 3.15 (<code>PLW0133</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28310">#28310</a>)</li> </ul> <h3>Rule changes</h3> <ul> <li>Correct <code>D211</code> and <code>D203</code> rule conflict diagnostic (<a href="https://redirect.github.com/astral-sh/ruff/pull/28444">#28444</a>)</li> <li>Recognize <code>slice</code> and <code>frozendict</code> generics (<a href="https://redirect.github.com/astral-sh/ruff/pull/28477">#28477</a>)</li> <li>Stop defining <code>__cached__</code> for Python 3.15 (<a href="https://redirect.github.com/astral-sh/ruff/pull/28476">#28476</a>)</li> <li>[<code>pyupgrade</code>] Stop recommending removed <code>typing.no_type_check_decorator</code> (<code>UP035</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28475">#28475</a>)</li> </ul> <h3>Performan…
Spigushe
added a commit
to Spigushe/barrins-project
that referenced
this pull request
Sep 17, 2026
…updates (#155) Bumps the all-updates group with 7 updates in the /apps/barrins_api directory: | Package | From | To | | --- | --- | --- | | [psycopg2-binary](https://github.com/psycopg/psycopg2) | `2.9.12` | `2.9.13` | | [pyjwt](https://github.com/jpadilla/pyjwt) | `2.13.0` | `2.14.0` | | [uvicorn](https://github.com/Kludex/uvicorn) | `0.52.4` | `0.53.0` | | [weasyprint](https://github.com/Kozea/WeasyPrint) | `69.0` | `70.0` | | [alembic](https://github.com/sqlalchemy/alembic) | `1.19.2` | `1.20.0` | | [ruff](https://github.com/astral-sh/ruff) | `0.16.6` | `0.16.7` | | [ty](https://github.com/astral-sh/ty) | `0.0.78` | `0.0.80` | | [psycopg2-binary](https://github.com/psycopg/psycopg2) | `2.9.12` | `2.9.13` | | [pyjwt](https://github.com/jpadilla/pyjwt) | `2.13.0` | `2.14.0` | | [uvicorn](https://github.com/Kludex/uvicorn) | `0.52.4` | `0.53.0` | | [alembic](https://github.com/sqlalchemy/alembic) | `1.19.2` | `1.20.0` | | [ruff](https://github.com/astral-sh/ruff) | `0.16.6` | `0.16.7` | | [ty](https://github.com/astral-sh/ty) | `0.0.78` | `0.0.80` | | [ruff](https://github.com/astral-sh/ruff) | `0.16.6` | `0.16.7` | | [ty](https://github.com/astral-sh/ty) | `0.0.78` | `0.0.80` | | [psycopg2-binary](https://github.com/psycopg/psycopg2) | `2.9.12` | `2.9.13` | | [ruff](https://github.com/astral-sh/ruff) | `0.16.6` | `0.16.7` | | [ty](https://github.com/astral-sh/ty) | `0.0.78` | `0.0.80` | Bumps the all-updates group with 6 updates in the /apps/barrins_identity directory: | Package | From | To | | --- | --- | --- | | [psycopg2-binary](https://github.com/psycopg/psycopg2) | `2.9.12` | `2.9.13` | | [pyjwt](https://github.com/jpadilla/pyjwt) | `2.13.0` | `2.14.0` | | [uvicorn](https://github.com/Kludex/uvicorn) | `0.52.4` | `0.53.0` | | [alembic](https://github.com/sqlalchemy/alembic) | `1.19.2` | `1.20.0` | | [ruff](https://github.com/astral-sh/ruff) | `0.16.6` | `0.16.7` | | [ty](https://github.com/astral-sh/ty) | `0.0.78` | `0.0.80` | | [psycopg2-binary](https://github.com/psycopg/psycopg2) | `2.9.12` | `2.9.13` | | [pyjwt](https://github.com/jpadilla/pyjwt) | `2.13.0` | `2.14.0` | | [uvicorn](https://github.com/Kludex/uvicorn) | `0.52.4` | `0.53.0` | | [alembic](https://github.com/sqlalchemy/alembic) | `1.19.2` | `1.20.0` | | [ruff](https://github.com/astral-sh/ruff) | `0.16.6` | `0.16.7` | | [ty](https://github.com/astral-sh/ty) | `0.0.78` | `0.0.80` | | [ruff](https://github.com/astral-sh/ruff) | `0.16.6` | `0.16.7` | | [ty](https://github.com/astral-sh/ty) | `0.0.78` | `0.0.80` | | [psycopg2-binary](https://github.com/psycopg/psycopg2) | `2.9.12` | `2.9.13` | | [ruff](https://github.com/astral-sh/ruff) | `0.16.6` | `0.16.7` | | [ty](https://github.com/astral-sh/ty) | `0.0.78` | `0.0.80` | Bumps the all-updates group with 3 updates in the /apps/barrins_scripture directory: [ruff](https://github.com/astral-sh/ruff), [ty](https://github.com/astral-sh/ty) and [selenium](https://github.com/SeleniumHQ/Selenium). Bumps the all-updates group with 5 updates in the /apps/karn_tablets directory: | Package | From | To | | --- | --- | --- | | [psycopg2-binary](https://github.com/psycopg/psycopg2) | `2.9.12` | `2.9.13` | | [ruff](https://github.com/astral-sh/ruff) | `0.16.6` | `0.16.7` | | [ty](https://github.com/astral-sh/ty) | `0.0.78` | `0.0.80` | | [psycopg2-binary](https://github.com/psycopg/psycopg2) | `2.9.12` | `2.9.13` | | [ruff](https://github.com/astral-sh/ruff) | `0.16.6` | `0.16.7` | | [ty](https://github.com/astral-sh/ty) | `0.0.78` | `0.0.80` | | [ruff](https://github.com/astral-sh/ruff) | `0.16.6` | `0.16.7` | | [ty](https://github.com/astral-sh/ty) | `0.0.78` | `0.0.80` | | [psycopg2-binary](https://github.com/psycopg/psycopg2) | `2.9.12` | `2.9.13` | | [numpy](https://github.com/numpy/numpy) | `2.5.2` | `2.5.3` | | [scikit-learn](https://github.com/scikit-learn/scikit-learn) | `1.9.0` | `1.9.1` | | [ruff](https://github.com/astral-sh/ruff) | `0.16.6` | `0.16.7` | | [ty](https://github.com/astral-sh/ty) | `0.0.78` | `0.0.80` | Updates `psycopg2-binary` from 2.9.12 to 2.9.13 <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/psycopg/psycopg2/blob/master/NEWS">psycopg2-binary's changelog</a>.</em></p> <blockquote> <h2>Current release</h2> <p>What's new in psycopg 2.9.13 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^</p> <ul> <li>Add support for Python 3.15 (:ticket:<code>[#1848](https://github.com/psycopg/psycopg2/issues/1848)</code>).</li> <li>Fix parsing of malformed bytea input.</li> <li>Fix parsing of malformed int64 input in arrays (:ticket:<code>[#1847](https://github.com/psycopg/psycopg2/issues/1847)</code>).</li> <li>Add a <code>pyproject.toml</code> file to declare a PEP 517 build backend (:ticket:<code>[#1788](https://github.com/psycopg/psycopg2/issues/1788)</code>).</li> <li>Drop support for Python 3.9.</li> </ul> <p>What's new in psycopg 2.9.12 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^</p> <ul> <li>Fix infinite loop with malformed interval (:ticket:<code>1835</code>).</li> </ul> <p>What's new in psycopg 2.9.11 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^</p> <ul> <li>Add support for Python 3.14.</li> <li>Avoid a segfault passing more arguments than placeholders if Python is built with assertions enabled (:ticket:<code>[#1791](https://github.com/psycopg/psycopg2/issues/1791)</code>).</li> <li>Add riscv64 platform binary packages (:ticket:<code>[#1813](https://github.com/psycopg/psycopg2/issues/1813)</code>).</li> <li><code>~psycopg2.errorcodes</code> map and <code>~psycopg2.errors</code> classes updated to PostgreSQL 18.</li> <li>Drop support for Python 3.8.</li> </ul> <p>What's new in psycopg 2.9.10 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^</p> <ul> <li>Add support for Python 3.13.</li> <li>Receive notifications on commit (:ticket:<code>[#1728](https://github.com/psycopg/psycopg2/issues/1728)</code>).</li> <li><code>~psycopg2.errorcodes</code> map and <code>~psycopg2.errors</code> classes updated to PostgreSQL 17.</li> <li>Drop support for Python 3.7.</li> </ul> <p>What's new in psycopg 2.9.9 ^^^^^^^^^^^^^^^^^^^^^^^^^^^</p> <ul> <li>Add support for Python 3.12.</li> <li>Drop support for Python 3.6.</li> </ul> <p>What's new in psycopg 2.9.8</p> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/psycopg/psycopg2/commit/f650e7afed0c94f596594e8328a0c7fa65a9d0e5"><code>f650e7a</code></a> chore: bump to release 2.9.13</li> <li><a href="https://github.com/psycopg/psycopg2/commit/368c8a1ca6d80088703a693ce64b68ad7d346698"><code>368c8a1</code></a> chore!: drop support for Python 3.9</li> <li><a href="https://github.com/psycopg/psycopg2/commit/9b39e65ab232f0a267a278cdaef1bd9975d88c65"><code>9b39e65</code></a> chore: drop scaleway build support</li> <li><a href="https://github.com/psycopg/psycopg2/commit/2ca70416be6d4d3d8170ec439876c0b3569af718"><code>2ca7041</code></a> fix: fix handling of PostgreSQL 18 exceptions</li> <li><a href="https://github.com/psycopg/psycopg2/commit/5385c027ef62ce14e57a7379e0375868507d6746"><code>5385c02</code></a> Build CPython 3.15 wheels</li> <li><a href="https://github.com/psycopg/psycopg2/commit/1d32e1f6678ffa8ab8897ca81826bf4dde6354cd"><code>1d32e1f</code></a> ci: only attempt triggering documentation refresh when pushing on main repo</li> <li><a href="https://github.com/psycopg/psycopg2/commit/433e7b77a7b700fbb1cdc6e9dca6b5948d07fc23"><code>433e7b7</code></a> chore: add pyproject.toml file to declare a PEP 517 build backend</li> <li><a href="https://github.com/psycopg/psycopg2/commit/8fb80bc3b2c358f4e3c54e33a37326d3f8b3ff6a"><code>8fb80bc</code></a> fix: fix parsing of malformed int64 input in arrays</li> <li><a href="https://github.com/psycopg/psycopg2/commit/f98014a46a1e34f024ebd6134d1d87b77490c500"><code>f98014a</code></a> fix: fix parsing of malformed bytea input</li> <li><a href="https://github.com/psycopg/psycopg2/commit/822b79cfe12ca0a04482acd382cae669a16aa789"><code>822b79c</code></a> chore: bump dependencies in binary package</li> <li>Additional commits viewable in <a href="https://github.com/psycopg/psycopg2/compare/2.9.12...2.9.13">compare view</a></li> </ul> </details> <br /> Updates `pyjwt` from 2.13.0 to 2.14.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/jpadilla/pyjwt/releases">pyjwt's releases</a>.</em></p> <blockquote> <h2>PyJWT 2.14.0</h2> <p>See the <a href="https://github.com/jpadilla/pyjwt/blob/2.14.0/CHANGELOG.rst">2.14.0 changelog</a> for the complete release details and related security advisories.</p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst">pyjwt's changelog</a>.</em></p> <blockquote> <h2><code>v2.14.0 <https://github.com/jpadilla/pyjwt/compare/2.13.0...2.14.0></code>__</h2> <p>Security</p> <pre><code> - Harden HMAC key validation against public-key material supplied as JWK, JWKS, array, encoded, BOM-prefixed, DER, or PEM input. See `GHSA-r6x4-923q-g947 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-r6x4-923q-g947>`__, `GHSA-ffc3-869f-jxw9 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-ffc3-869f-jxw9>`__, `GHSA-p4g4-x82p-q773 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-p4g4-x82p-q773>`__, and `GHSA-w2cx-738m-mc7w <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w2cx-738m-mc7w>`__. - Reject automatic redirects when ``PyJWKClient`` fetches a JWKS, preventing redirected destinations from being treated as trusted key sources. See `GHSA-9v7f-9g4p-ffgj <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-9v7f-9g4p-ffgj>`__. - Limit repeated JWKS refreshes caused by unknown key IDs while preserving normal key-rotation behavior. See `GHSA-2gx3-rcp4-g85q <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-2gx3-rcp4-g85q>`__. - Handle deeply nested and malformed JWS/JWK input without uncaught recursion errors or whole-set parsing failures. See `GHSA-8wjv-2p76-3863 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-8wjv-2p76-3863>`__ and `GHSA-w6j9-cwv2-h6wq <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w6j9-cwv2-h6wq>`__. - Enforce compact JWS encoding rules during decoding. See `GHSA-hxm8-2xgr-2p9m <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-hxm8-2xgr-2p9m>`__. - Reject detached-payload arguments for attached JWS inputs. Thanks to `@xclow3n <https://github.com/xclow3n>`__ for reporting this behavior; fixed in commit `37b54877 <https://github.com/jpadilla/pyjwt/commit/37b54877bf7bea67e8149130e96929e3ec798122>`__. <p>Fixed</p> <pre><code> - Apply HMAC key validation consistently when keys are loaded through ``PyJWK`` and ``PyJWKClient``. See `GHSA-pxh4-856f-4h89 &lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-pxh4-856f-4h89&gt;`__. - Reject empty HMAC keys when represented as JWKs. See `GHSA-pxh4-856f-4h89 &lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-pxh4-856f-4h89&gt;`__. Fixed </code></pre> <ul> <li>Raise the documented <code>PyJWTError</code> subclass instead of leaking a<br /> <code>TypeError</code> when the <code>exp</code>, <code>nbf</code>, or <code>iat</code> claim decodes to a<br /> non-numeric, non-string value such as a list, dict, or <code>null</code>.<br /> </code></pre></li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/jpadilla/pyjwt/commit/c6fe464b356ff4b1ebc9ba62172d331a40aa27df"><code>c6fe464</code></a> release: prepare v2.14.0</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/f5413029ae7a2e31b1367b5303ea86a2f54ccf42"><code>f541302</code></a> style: apply Ruff formatting</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/801cd128528c62d9b23fcd161d1a2e1c17982f95"><code>801cd12</code></a> fix: reject public JWK container HMAC keys</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/af8181ca0bec5e6b372fbba9afbe23702b787ceb"><code>af8181c</code></a> fix: reject empty HMAC keys from JWKs</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/ba4853a75fb9676362da17f67d0f64bd18afd4e1"><code>ba4853a</code></a> Throttle repeated PyJWKClient refreshes</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/2798504fa2663364573cf2d1043d8d7fef389499"><code>2798504</code></a> fix: reject DER public keys as HMAC secrets</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/8b4e233a22206b34ec1186e912e75c0b2396ac07"><code>8b4e233</code></a> fix: reject loader-accepted PEM variants</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/1f8180a211256dfe5cf32294b6753f554a5a4258"><code>1f8180a</code></a> fix: format JWS tests</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/cff1ac55fe5f1096fd05295b269fce053ee290ab"><code>cff1ac5</code></a> Fix redirect handler return annotation</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/0a795b8e1f6ef08f634aa7086fc41cc6d5ce3e56"><code>0a795b8</code></a> Reject redirects in PyJWKClient fetches</li> <li>Additional commits viewable in <a href="https://github.com/jpadilla/pyjwt/compare/2.13.0...2.14.0">compare view</a></li> </ul> </details> <br /> Updates `uvicorn` from 0.52.4 to 0.53.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/Kludex/uvicorn/releases">uvicorn's releases</a>.</em></p> <blockquote> <h2>Version 0.53.0</h2> <h2>🌐 Opt-in HTTP/2 support</h2> <p><code>uvicorn</code> 0.53.0 adds experimental HTTP/2 through <code>zttp</code>, alongside a new <code>zuvloop</code> integration and connection-handling improvements.</p> <pre lang="console"><code>uv add uvicorn==0.53.0 </code></pre> <ul> <li><strong>Serve HTTP/1.1 and HTTP/2 with <code>zttp</code></strong> (<a href="https://redirect.github.com/Kludex/uvicorn/pull/2982">#2982</a>, <a href="https://redirect.github.com/Kludex/uvicorn/pull/3101">#3101</a>). Install <code>zttp</code>, then enable HTTP/2 with <code>--http zttp --http2</code>. Uvicorn negotiates HTTP/2 over TLS with ALPN and supports cleartext prior knowledge.</li> <li><strong>HTTP/2 remains experimental.</strong> Upgrade-based h2c and WebSockets over HTTP/2 are not supported.</li> </ul> <h2>⚙️ More event loop choice</h2> <ul> <li><strong>Run Uvicorn with <code>zuvloop</code></strong> (<a href="https://redirect.github.com/Kludex/uvicorn/pull/3104">#3104</a>). Install <code>zuvloop</code> separately and select it explicitly with <code>--loop zuvloop</code> on CPython 3.14 or newer.</li> </ul> <h2>🛡️ More reliable connections and proxies</h2> <ul> <li><strong>Honor <code>Connection: close</code> token lists</strong> (<a href="https://redirect.github.com/Kludex/uvicorn/pull/3103">#3103</a>). Uvicorn now parses comma-separated tokens case-insensitively across HTTP implementations.</li> <li><strong>Trust IPv6 loopback proxies by default</strong> (<a href="https://redirect.github.com/Kludex/uvicorn/pull/3119">#3119</a>). The default <code>FORWARDED_ALLOW_IPS</code> value now includes <code>::1</code>.</li> <li><strong>Keep upgraded WebSockets alive</strong> (<a href="https://redirect.github.com/Kludex/uvicorn/pull/3107">#3107</a>). Uvicorn cancels the HTTP keep-alive timer when the connection becomes a WebSocket.</li> </ul> <p><strong>Full changelog:</strong> <a href="https://github.com/Kludex/uvicorn/compare/0.52.4...0.53.0">0.52.4...0.53.0</a></p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md">uvicorn's changelog</a>.</em></p> <blockquote> <h2>0.53.0 (September 14, 2026)</h2> <p>This release adds experimental HTTP/2 support through <code>zttp</code>. Enable it with <code>--http zttp --http2</code>. Upgrade-based h2c and WebSockets over HTTP/2 are not supported.</p> <h3>Added</h3> <ul> <li>Add experimental HTTP/2 support through <code>zttp</code> (<a href="https://redirect.github.com/Kludex/uvicorn/pull/2982">#2982</a>, <a href="https://redirect.github.com/Kludex/uvicorn/pull/3101">#3101</a>)</li> <li>Add support for <code>zuvloop</code> (<a href="https://redirect.github.com/Kludex/uvicorn/pull/3104">#3104</a>)</li> </ul> <h3>Fixed</h3> <ul> <li>Handle comma-separated, case-insensitive <code>Connection: close</code> tokens across HTTP implementations (<a href="https://redirect.github.com/Kludex/uvicorn/pull/3103">#3103</a>)</li> <li>Trust IPv6 loopback in the default <code>FORWARDED_ALLOW_IPS</code> value (<a href="https://redirect.github.com/Kludex/uvicorn/pull/3119">#3119</a>)</li> <li>Cancel the HTTP keep-alive timer when upgrading to WebSocket (<a href="https://redirect.github.com/Kludex/uvicorn/pull/3107">#3107</a>)</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/Kludex/uvicorn/commit/421708fbc1a704dac8bd4053a7c4c0bf4d3704ee"><code>421708f</code></a> Version 0.53.0 (<a href="https://redirect.github.com/Kludex/uvicorn/issues/3136">#3136</a>)</li> <li><a href="https://github.com/Kludex/uvicorn/commit/f1a1bff7be819f5724d6fdf86dfd448a97c62e23"><code>f1a1bff</code></a> Unset the keep-alive timer when upgrading to WebSocket (<a href="https://redirect.github.com/Kludex/uvicorn/issues/3107">#3107</a>)</li> <li><a href="https://github.com/Kludex/uvicorn/commit/63971ed952090438896e6eba7d07178b616d97cc"><code>63971ed</code></a> Document HTTP/2 support (<a href="https://redirect.github.com/Kludex/uvicorn/issues/3130">#3130</a>)</li> <li><a href="https://github.com/Kludex/uvicorn/commit/7d1a0055aee5e281accc646b559ddd147486bf8a"><code>7d1a005</code></a> Remove race from multiprocess health check test (<a href="https://redirect.github.com/Kludex/uvicorn/issues/3128">#3128</a>)</li> <li><a href="https://github.com/Kludex/uvicorn/commit/5ac6265a01ff6dcadb0e4250152c3deaf8a168a9"><code>5ac6265</code></a> Add ::1 to FORWARDED_ALLOW_IPS (<a href="https://redirect.github.com/Kludex/uvicorn/issues/3119">#3119</a>)</li> <li><a href="https://github.com/Kludex/uvicorn/commit/098b206ff7b01098561956ff4e7746d05e02acc6"><code>098b206</code></a> Remove timing race from SIGHUP supervisor test (<a href="https://redirect.github.com/Kludex/uvicorn/issues/3127">#3127</a>)</li> <li><a href="https://github.com/Kludex/uvicorn/commit/968f15e5d09df5f6b8959975f18687b9d755862d"><code>968f15e</code></a> chore(deps): bump the github-actions group with 4 updates (<a href="https://redirect.github.com/Kludex/uvicorn/issues/3113">#3113</a>)</li> <li><a href="https://github.com/Kludex/uvicorn/commit/7d4c08cce9eeabf64695c326b0e45c47c6a0337b"><code>7d4c08c</code></a> chore(deps): bump the python-packages group across 1 directory with 11 update...</li> <li><a href="https://github.com/Kludex/uvicorn/commit/fe528a480c0aec3aea3ee8ef13251b5216c47ae9"><code>fe528a4</code></a> Require explicit opt-in for zttp HTTP/2 (<a href="https://redirect.github.com/Kludex/uvicorn/issues/3101">#3101</a>)</li> <li><a href="https://github.com/Kludex/uvicorn/commit/fa324a415364563cf45908966435e2480a6b46bf"><code>fa324a4</code></a> chore(deps-dev): bump httpx2 from 2.10.0 to 2.12.0 (<a href="https://redirect.github.com/Kludex/uvicorn/issues/3121">#3121</a>)</li> <li>Additional commits viewable in <a href="https://github.com/Kludex/uvicorn/compare/0.52.4...0.53.0">compare view</a></li> </ul> </details> <br /> Updates `weasyprint` from 69.0 to 70.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/Kozea/WeasyPrint/releases">weasyprint's releases</a>.</em></p> <blockquote> <h2>v70.0</h2> <p>Read about this release <a href="https://www.courtbouillon.org/blog/00074-weasyprint-70/">on our blog</a>.</p> <p><strong>This is a security update (CVE-2026-55073, GHSA-r543-q48m-4c9j).</strong></p> <p>We strongly recommend to upgrade WeasyPrint to the latest version if you: * embed untrusted images, or * rely on the URL fetcher to filter metadata or stylesheets passed as Python parameters.</p> <h2>Security</h2> <ul> <li>Don’t render EPS images.</li> <li>Always use original URL fetcher when available.</li> </ul> <h2>Features</h2> <ul> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2905">#2905</a>: Add initial support of CSS Notes, with financial support from NLnet</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2731">#2731</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2781">#2781</a>: Log an error on unknown render and write_pdf options</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2802">#2802</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2805">#2805</a>: Create immutable releases on GitHub</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2809">#2809</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2810">#2810</a>: Switch to MSYS2 UCRT64 environment for Windows tests and executables</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2777">#2777</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2814">#2814</a>: Support COLR emoji fonts</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2667">#2667</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2744">#2744</a>: Support context paint in SVG markers</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/1862">#1862</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2844">#2844</a>: Improve filename detection for attachments</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2816">#2816</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2827">#2827</a>: Set SVG title as alternative text</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2718">#2718</a>: Provide a 'onedir' Windows executable</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2863">#2863</a>: Support box-shadow</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2755">#2755</a>: Support RTL SVG text anchoring</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2866">#2866</a>: Don’t use f-strings in logs</li> </ul> <h2>Bug fixes</h2> <ul> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2799">#2799</a>: Keep HarfBuzz font faces alive during PDF subsetting</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2764">#2764</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2793">#2793</a>: Accept Path as base URL in CSS</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2800">#2800</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2801">#2801</a>: Fix position of raster emojis</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2782">#2782</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2807">#2807</a>: Use POSIX paths in Fontconfig</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2766">#2766</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2779">#2779</a>: Use response bytes when image file path doesn’t exist</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2277">#2277</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2728">#2728</a>: Honor page breaks on floated elements</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2789">#2789</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2818">#2818</a>: Use base URL when solving pending properties</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2820">#2820</a>: Ignore unresolvable math in image slices</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2901">#2901</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2825">#2825</a>: Transform SVG size into CSS to apply CSS sizing algorithm</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2819">#2819</a>: Resolve calc() division by zero to infinity</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2824">#2824</a>: Remove old deprecation warnings</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2762">#2762</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2780">#2780</a>: Set SVG gradient color before path construction</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2761">#2761</a>: Handle split tables with captions</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2215">#2215</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2747">#2747</a>: Discard broken at-rules</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2736">#2736</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2738">#2738</a>: Apply transformations to SVG opacity groups</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2830">#2830</a>: Use a stack to draw simple borders</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2831">#2831</a>: Fix line_height() crash on calc() values</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2784">#2784</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2832">#2832</a>: Set fallback font for Unicode test</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2726">#2726</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2881">#2881</a>: Improve accessibility of PDF forms</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2803">#2803</a>: Fix inline width after backtracked line breaks</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2833">#2833</a>: Store root style in anonymous style</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/Kozea/WeasyPrint/blob/main/docs/changelog.rst">weasyprint's changelog</a>.</em></p> <blockquote> <h2>Version 70.0</h2> <p>Released on 2026-09-08.</p> <p><strong>This is a security update (CVE-2026-55073, GHSA-r543-q48m-4c9j).</strong></p> <p>We strongly recommend to upgrade WeasyPrint to the latest version if you:</p> <ul> <li>embed untrusted images, or</li> <li>rely on the URL fetcher to filter metadata or stylesheets passed as Python parameters.</li> </ul> <p>Security:</p> <ul> <li>Don’t render EPS images.</li> <li>Always use original URL fetcher when available.</li> </ul> <p>Features:</p> <ul> <li><code>[#2905](https://github.com/Kozea/WeasyPrint/issues/2905) <https://github.com/Kozea/WeasyPrint/pull/2905></code>_: Add initial support of CSS Notes, with financial support from NLnet</li> <li><code>[#2731](https://github.com/Kozea/WeasyPrint/issues/2731) <https://github.com/Kozea/WeasyPrint/issues/2731></code><em>, <code>[#2781](https://github.com/Kozea/WeasyPrint/issues/2781) <https://github.com/Kozea/WeasyPrint/pull/2781></code></em>: Log an error on unknown render and write_pdf options</li> <li><code>[#2802](https://github.com/Kozea/WeasyPrint/issues/2802) <https://github.com/Kozea/WeasyPrint/issues/2802></code><em>, <code>[#2805](https://github.com/Kozea/WeasyPrint/issues/2805) <https://github.com/Kozea/WeasyPrint/pull/2805></code></em>: Create immutable releases on GitHub</li> <li><code>[#2809](https://github.com/Kozea/WeasyPrint/issues/2809) <https://github.com/Kozea/WeasyPrint/issues/2809></code><em>, <code>[#2810](https://github.com/Kozea/WeasyPrint/issues/2810) <https://github.com/Kozea/WeasyPrint/pull/2810></code></em>: Switch to MSYS2 UCRT64 environment for Windows tests and executables</li> <li><code>[#2777](https://github.com/Kozea/WeasyPrint/issues/2777) <https://github.com/Kozea/WeasyPrint/issues/2777></code><em>, <code>[#2814](https://github.com/Kozea/WeasyPrint/issues/2814) <https://github.com/Kozea/WeasyPrint/pull/2814></code></em>: Support COLR emoji fonts</li> <li><code>[#2667](https://github.com/Kozea/WeasyPrint/issues/2667) <https://github.com/Kozea/WeasyPrint/issues/2667></code><em>, <code>[#2744](https://github.com/Kozea/WeasyPrint/issues/2744) <https://github.com/Kozea/WeasyPrint/pull/2744></code></em>: Support context paint in SVG markers</li> <li><code>[#1862](https://github.com/Kozea/WeasyPrint/issues/1862) <https://github.com/Kozea/WeasyPrint/issues/1862></code><em>, <code>[#2844](https://github.com/Kozea/WeasyPrint/issues/2844) <https://github.com/Kozea/WeasyPrint/pull/2844></code></em>: Improve filename detection for attachments</li> <li><code>[#2816](https://github.com/Kozea/WeasyPrint/issues/2816) <https://github.com/Kozea/WeasyPrint/issues/2816></code><em>, <code>[#2827](https://github.com/Kozea/WeasyPrint/issues/2827) <https://github.com/Kozea/WeasyPrint/pull/2827></code></em>: Set SVG title as alternative text</li> <li><code>[#2718](https://github.com/Kozea/WeasyPrint/issues/2718) <https://github.com/Kozea/WeasyPrint/issues/2718></code>_: Provide a 'onedir' Windows executable</li> <li><code>[#2863](https://github.com/Kozea/WeasyPrint/issues/2863) <https://github.com/Kozea/WeasyPrint/pull/2863></code>_: Support box-shadow</li> <li><code>[#2755](https://github.com/Kozea/WeasyPrint/issues/2755) <https://github.com/Kozea/WeasyPrint/pull/2755></code>_: Support RTL SVG text anchoring</li> <li><code>[#2866](https://github.com/Kozea/WeasyPrint/issues/2866) <https://github.com/Kozea/WeasyPrint/issues/2866></code>_: Don’t use f-strings in logs</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/Kozea/WeasyPrint/commit/4d3b7b6449e3494f59c7c2f36b512d129225679c"><code>4d3b7b6</code></a> Version 70.0</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/289e278439b017cd9263b4cd4727026987f86443"><code>289e278</code></a> Always use original URL fetcher when available</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/aeb3be74e3c904e4b772014006410e23e0512b4b"><code>aeb3be7</code></a> Merge remote-tracking branch 'security/main'</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/48357241f949c3f6880ec1a40f56d2f5106fdef3"><code>4835724</code></a> Merge pull request <a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2915">#2915</a> from havelaer/fix-nested-svg-viewport-restore</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/03310511d8afac08f80939e7fa317ad6051e251f"><code>0331051</code></a> Restore nested SVG viewport size on the SVG object, not the drawing function</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/e4b8b45e409392197441bc449d110f323b0eeb66"><code>e4b8b45</code></a> Add harfbuzz-vector requirement for Fedora</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/371e4debb4805fa3d5a138f2cbb044fc176284da"><code>371e4de</code></a> Merge pull request <a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2905">#2905</a> from Kozea/notes</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/590bf63301d77eaf6aac6b1eb3a3fbb9494e3b23"><code>590bf63</code></a> Merge pull request <a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2913">#2913</a> from Kozea/fast-svg-paths</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/f6570c3038b60695f715b12c7805f6933e58490a"><code>f6570c3</code></a> Use a faster regex-based parser for SVG paths</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/bc0516240c5f8a1eaaf658621d52a09eebecdea9"><code>bc05162</code></a> Use faster deque for SVG vertices</li> <li>Additional commits viewable in <a href="https://github.com/Kozea/WeasyPrint/compare/v69.0...v70.0">compare view</a></li> </ul> </details> <br /> Updates `alembic` from 1.19.2 to 1.20.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/sqlalchemy/alembic/releases">alembic's releases</a>.</em></p> <blockquote> <h1>1.20.0</h1> <p>Released: September 11, 2026</p> <h2>usecase</h2> <ul> <li> <p><strong>[usecase] [batch]</strong> Added a warning for the case where an unnamed CHECK constraint on a reflected table is omitted from a batch "recreate" operation. An unnamed CHECK constraint can't be reliably carried over in a batch recreate as it may refer to columns that are being dropped or changed. This omission was previously a silent operation. The presence of any <code>~sqlalchemy.schema.CheckConstraint</code> in <code>Operations.batch_alter_table.table_args</code> is taken to indicate that the case has been accommodated, and no warning is emitted.</p> <p>References: <a href="https://redirect.github.com/sqlalchemy/alembic/issues/1846">#1846</a></p> </li> <li> <p><strong>[usecase] [autogenerate]</strong> Autogenerate now renders a warning comment above any rendered <code>Operations.drop_constraint()</code> directive for which the constraint name is <code>None</code>, as is the case when a constraint that has no name in the model is dropped, most typically within the <code>downgrade()</code> function of a migration that adds an unnamed constraint. A warning is also emitted on the console when the migration script is generated. The directive requires a non-None name in order to be able to emit a "DROP CONSTRAINT" command.</p> <p>References: <a href="https://redirect.github.com/sqlalchemy/alembic/issues/916">#916</a></p> </li> </ul> <h2>bug</h2> <ul> <li> <p><strong>[bug] [batch]</strong> Fixed bug in batch mode where adding a column with a type that generates its own CHECK constraint, such as <code>~sqlalchemy.types.Boolean</code> or <code>~sqlalchemy.types.Enum</code> with <code>~sqlalchemy.types.Boolean.create_constraint</code> set to <code>True</code>, would emit the constraint twice when the table was recreated, once under the name generated by the naming convention in use and once under the name given to the type. The constraint is now emitted once, using the same name that would be used outside of batch mode.</p> <p>References: <a href="https://redirect.github.com/sqlalchemy/alembic/issues/1768">#1768</a></p> </li> <li> <p><strong>[bug] [batch]</strong> Fixed bug in batch mode where a CHECK constraint generated by a type such as <code>~sqlalchemy.types.Boolean</code> or <code>~sqlalchemy.types.Enum</code> would lose the name established for it by the naming convention in use when the table was recreated, as the constraint was regenerated against the temporary table used for the recreate operation. The naming convention is now resolved against the name of the table being replaced.</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li>See full diff in <a href="https://github.com/sqlalchemy/alembic/commits">compare view</a></li> </ul> </details> <br /> Updates `ruff` from 0.16.6 to 0.16.7 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/releases">ruff's releases</a>.</em></p> <blockquote> <h2>0.16.7</h2> <h2>Release Notes</h2> <p>Released on 2026-09-10.</p> <h3>Preview features</h3> <ul> <li>[<code>ruff</code>] Add rule for default values on method receivers (<code>RUF077</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/26700">#26700</a>)</li> <li>[<code>ruff</code>] Recognize <code>re.prefixmatch</code> (<code>RUF039</code>, <code>RUF055</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28311">#28311</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>Alternate nested quotes inside format spec interpolations (<a href="https://redirect.github.com/astral-sh/ruff/pull/28259">#28259</a>)</li> <li>[<code>flake8-implicit-str-concat</code>] Mark fix unsafe when it creates a docstring (<code>ISC003</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/27981">#27981</a>)</li> <li>[<code>flake8-tidy-imports</code>] Skip fixes for multi-member imports (<code>TID254</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/26584">#26584</a>)</li> <li>[<code>pylint</code>] Gate <code>ImportCycleError</code> on Python 3.15 (<code>PLW0133</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28310">#28310</a>)</li> </ul> <h3>Rule changes</h3> <ul> <li>Correct <code>D211</code> and <code>D203</code> rule conflict diagnostic (<a href="https://redirect.github.com/astral-sh/ruff/pull/28444">#28444</a>)</li> <li>Recognize <code>slice</code> and <code>frozendict</code> generics (<a href="https://redirect.github.com/astral-sh/ruff/pull/28477">#28477</a>)</li> <li>Stop defining <code>__cached__</code> for Python 3.15 (<a href="https://redirect.github.com/astral-sh/ruff/pull/28476">#28476</a>)</li> <li>[<code>pyupgrade</code>] Stop recommending removed <code>typing.no_type_check_decorator</code> (<code>UP035</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28475">#28475</a>)</li> </ul> <h3>Performance</h3> <ul> <li>Reuse parser name lookups when interning (<a href="https://redirect.github.com/astral-sh/ruff/pull/28399">#28399</a>)</li> <li>Speed up inherited configuration resolution (<a href="https://redirect.github.com/astral-sh/ruff/pull/28299">#28299</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Fix <code>line-length</code> path in <code>--config</code> example (<a href="https://redirect.github.com/astral-sh/ruff/pull/28392">#28392</a>)</li> <li>Remove the "Who’s Using Ruff?" list (<a href="https://redirect.github.com/astral-sh/ruff/pull/28455">#28455</a>)</li> </ul> <h3>Other changes</h3> <ul> <li>Embed archive checksums in the shell installer (<a href="https://redirect.github.com/astral-sh/ruff/pull/28281">#28281</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/The-Compiler"><code>@The-Compiler</code></a></li> <li><a href="https://github.com/mdiniz97"><code>@mdiniz97</code></a></li> <li><a href="https://github.com/zsol"><code>@zsol</code></a></li> <li><a href="https://github.com/gorewilliams"><code>@gorewilliams</code></a></li> <li><a href="https://github.com/RafaelJohn9"><code>@RafaelJohn9</code></a></li> <li><a href="https://github.com/qatcod"><code>@qatcod</code></a></li> <li><a href="https://github.com/zanieb"><code>@zanieb</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's changelog</a>.</em></p> <blockquote> <h2>0.16.7</h2> <p>Released on 2026-09-10.</p> <h3>Preview features</h3> <ul> <li>[<code>ruff</code>] Add rule for default values on method receivers (<code>RUF077</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/26700">#26700</a>)</li> <li>[<code>ruff</code>] Recognize <code>re.prefixmatch</code> (<code>RUF039</code>, <code>RUF055</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28311">#28311</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>Alternate nested quotes inside format spec interpolations (<a href="https://redirect.github.com/astral-sh/ruff/pull/28259">#28259</a>)</li> <li>[<code>flake8-implicit-str-concat</code>] Mark fix unsafe when it creates a docstring (<code>ISC003</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/27981">#27981</a>)</li> <li>[<code>flake8-tidy-imports</code>] Skip fixes for multi-member imports (<code>TID254</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/26584">#26584</a>)</li> <li>[<code>pylint</code>] Gate <code>ImportCycleError</code> on Python 3.15 (<code>PLW0133</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28310">#28310</a>)</li> </ul> <h3>Rule changes</h3> <ul> <li>Correct <code>D211</code> and <code>D203</code> rule conflict diagnostic (<a href="https://redirect.github.com/astral-sh/ruff/pull/28444">#28444</a>)</li> <li>Recognize <code>slice</code> and <code>frozendict</code> generics (<a href="https://redirect.github.com/astral-sh/ruff/pull/28477">#28477</a>)</li> <li>Stop defining <code>__cached__</code> for Python 3.15 (<a href="https://redirect.github.com/astral-sh/ruff/pull/28476">#28476</a>)</li> <li>[<code>pyupgrade</code>] Stop recommending removed <code>typing.no_type_check_decorator</code> (<code>UP035</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28475">#28475</a>)</li> </ul> <h3>Performance</h3> <ul> <li>Reuse parser name lookups when interning (<a href="https://redirect.github.com/astral-sh/ruff/pull/28399">#28399</a>)</li> <li>Speed up inherited configuration resolution (<a href="https://redirect.github.com/astral-sh/ruff/pull/28299">#28299</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Fix <code>line-length</code> path in <code>--config</code> example (<a href="https://redirect.github.com/astral-sh/ruff/pull/28392">#28392</a>)</li> <li>Remove the "Who’s Using Ruff?" list (<a href="https://redirect.github.com/astral-sh/ruff/pull/28455">#28455</a>)</li> </ul> <h3>Other changes</h3> <ul> <li>Embed archive checksums in the shell installer (<a href="https://redirect.github.com/astral-sh/ruff/pull/28281">#28281</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/The-Compiler"><code>@The-Compiler</code></a></li> <li><a href="https://github.com/mdiniz97"><code>@mdiniz97</code></a></li> <li><a href="https://github.com/zsol"><code>@zsol</code></a></li> <li><a href="https://github.com/gorewilliams"><code>@gorewilliams</code></a></li> <li><a href="https://github.com/RafaelJohn9"><code>@RafaelJohn9</code></a></li> <li><a href="https://github.com/qatcod"><code>@qatcod</code></a></li> <li><a href="https://github.com/zanieb"><code>@zanieb</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/nightt5879"><code>@nightt5879</code></a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/astral-sh/ruff/commit/b5dba861cc38e3f7fb4524c9ceba3e01a474ea13"><code>b5dba86</code></a> Bump version to 0.16.7 (<a href="https://redirect.github.com/astral-sh/ruff/issues/28496">#28496</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/5992d0504697d86565d8fc3a4d8245a5f4047d24"><code>5992d05</code></a> Install rustfmt before linting releases (<a href="https://redirect.github.com/astral-sh/ruff/issues/28495">#28495</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/1713a1f4325494d883a080d590a25a1946f399e8"><code>1713a1f</code></a> ensure prepare release changes pass prek (<a href="https://redirect.github.com/astral-sh/ruff/issues/28488">#28488</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/18cdbb4f3d14058794420e758864795f55336334"><code>18cdbb4</code></a> use scoped token for release workflow (<a href="https://redirect.github.com/astral-sh/ruff/issues/28484">#28484</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/c3813a501faf887fd01948c98bb8d58ad26488bd"><code>c3813a5</code></a> add a workflow for preparing releases (<a href="https://redirect.github.com/astral-sh/ruff/issues/28486">#28486</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/00948c00a671b81f5358af9f038436bcbb993b38"><code>00948c0</code></a> Remove the "Who’s Using Ruff?" list (<a href="https://redirect.github.com/astral-sh/ruff/issues/28455">#28455</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/86a2eba7b48e3c10386f7ab8a5425c7275d2b427"><code>86a2eba</code></a> [<code>pyupgrade</code>] Stop recommending removed <code>typing.no_type_check_decorator</code> (`UP...</li> <li><a href="https://github.com/astral-sh/ruff/commit/609e184aa35f0034b7ef63e3e04327081c484af6"><code>609e184</code></a> Stop defining <code>__cached__</code> for Python 3.15 (<a href="https://redirect.github.com/astral-sh/ruff/issues/28476">#28476</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/859ff2f01670c43ffff1ea597c8a2e375ada0fbe"><code>859ff2f</code></a> [ty] Track symlinked directory status in listings (<a href="https://redirect.github.com/astral-sh/ruff/issues/28482">#28482</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/77f653825800ddaf3bc221ae6db49a500e1002d5"><code>77f6538</code></a> Use paid GitHub-hosted runners for Linux (<a href="https://redirect.github.com/astral-sh/ruff/issues/28478">#28478</a>)</li> <li>Additional commits viewable in <a href="https://github.com/astral-sh/ruff/compare/0.16.6...0.16.7">compare view</a></li> </ul> </details> <br /> Updates `ty` from 0.0.78 to 0.0.80 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ty/releases">ty's releases</a>.</em></p> <blockquote> <h2>0.0.80</h2> <h2>Release Notes</h2> <p>Released on 2026-09-09.</p> <h3>Bug fixes</h3> <ul> <li>Fix <code>--force-exclude</code> for directories with an excluded ancestor (<a href="https://redirect.github.com/astral-sh/ruff/pull/28451">#28451</a>)</li> <li>Preserve metaclass candidates after conflicts (<a href="https://redirect.github.com/astral-sh/ruff/pull/28461">#28461</a>)</li> </ul> <h3>LSP server</h3> <ul> <li>Give existing autofixes descriptive titles (<a href="https://redirect.github.com/astral-sh/ruff/pull/28456">#28456</a>)</li> <li>Prevent LSP hangs during inlay hint bursts (<a href="https://redirect.github.com/astral-sh/ruff/pull/28390">#28390</a>)</li> </ul> <h3>Diagnostic improvements</h3> <ul> <li>Preserve redundant-condition diagnostics with unreachable operands (<a href="https://redirect.github.com/astral-sh/ruff/pull/28374">#28374</a>)</li> </ul> <h3>Core type checking</h3> <ul> <li>Check captured receivers when calling wrapped classmethods (<a href="https://redirect.github.com/astral-sh/ruff/pull/28467">#28467</a>)</li> <li>Fix cached classmethods on generic classes (<a href="https://redirect.github.com/astral-sh/ruff/pull/28207">#28207</a>)</li> <li>Fix disjointness of type guards and boolean literals (<a href="https://redirect.github.com/astral-sh/ruff/pull/28363">#28363</a>)</li> <li>Infer tuple variance from the full tuple spec (<a href="https://redirect.github.com/astral-sh/ruff/pull/28446">#28446</a>)</li> <li>Infer tuple variance more precisely (<a href="https://redirect.github.com/astral-sh/ruff/pull/28426">#28426</a>)</li> <li>Preserve callable identity across specialized types (<a href="https://redirect.github.com/astral-sh/ruff/pull/28409">#28409</a>)</li> <li>Preserve callback type context through ParamSpec forwarding (<a href="https://redirect.github.com/astral-sh/ruff/pull/28439">#28439</a>)</li> <li>Preserve wrapped functions in precise <code>functools.partial</code> relations (<a href="https://redirect.github.com/astral-sh/ruff/pull/28460">#28460</a>)</li> <li>Respect descriptor protocol for <code>__set__</code> itself (<a href="https://redirect.github.com/astral-sh/ruff/pull/28408">#28408</a>)</li> <li>Respect type-variable bounds in argument context (<a href="https://redirect.github.com/astral-sh/ruff/pull/28448">#28448</a>)</li> <li>Unwrap union alternatives in overload implementations (<a href="https://redirect.github.com/astral-sh/ruff/pull/28468">#28468</a>)</li> </ul> <h3>Performance</h3> <ul> <li>Distribute <code>len</code> inference over unions (<a href="https://redirect.github.com/astral-sh/ruff/pull/28470">#28470</a>)</li> <li>Fast-path concrete literal intersections (<a href="https://redirect.github.com/astral-sh/ruff/pull/28348">#28348</a>)</li> </ul> <h3>Memory usage improvements</h3> <ul> <li>Avoid excess capacity in multi-binding tables (<a href="https://redirect.github.com/astral-sh/ruff/pull/28412">#28412</a>)</li> <li>Share equivalent place tables within a file (<a href="https://redirect.github.com/astral-sh/ruff/pull/28319">#28319</a>)</li> <li>Share names in synthesized constructor parameters (<a href="https://redirect.github.com/astral-sh/ruff/pull/28398">#28398</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/sharkdp"><code>@sharkdp</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/ibraheemdev"><code>@ibraheemdev</code></a></li> <li><a href="https://github.com/AlexWaygood"><code>@AlexWaygood</code></a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ty/blob/main/CHANGELOG.md">ty's changelog</a>.</em></p> <blockquote> <h2>0.0.80</h2> <p>Released on 2026-09-09.</p> <h3>Bug fixes</h3> <ul> <li>Fix <code>--force-exclude</code> for directories with an excluded ancestor (<a href="https://redirect.github.com/astral-sh/ruff/pull/28451">#28451</a>)</li> <li>Preserve metaclass candidates after conflicts (<a href="https://redirect.github.com/astral-sh/ruff/pull/28461">#28461</a>)</li> </ul> <h3>LSP server</h3> <ul> <li>Give existing autofixes descriptive titles (<a href="https://redirect.github.com/astral-sh/ruff/pull/28456">#28456</a>)</li> <li>Prevent LSP hangs during inlay hint bursts (<a href="https://redirect.github.com/astral-sh/ruff/pull/28390">#28390</a>)</li> </ul> <h3>Diagnostic improvements</h3> <ul> <li>Preserve redundant-condition diagnostics with unreachable operands (<a href="https://redirect.github.com/astral-sh/ruff/pull/28374">#28374</a>)</li> </ul> <h3>Core type checking</h3> <ul> <li>Check captured receivers when calling wrapped classmethods (<a href="https://redirect.github.com/astral-sh/ruff/pull/28467">#28467</a>)</li> <li>Fix cached classmethods on generic classes (<a href="https://redirect.github.com/astral-sh/ruff/pull/28207">#28207</a>)</li> <li>Fix disjointness of type guards and boolean literals (<a href="https://redirect.github.com/astral-sh/ruff/pull/28363">#28363</a>)</li> <li>Infer tuple variance from the full tuple spec (<a href="https://redirect.github.com/astral-sh/ruff/pull/28446">#28446</a>)</li> <li>Infer tuple variance more precisely (<a href="https://redirect.github.com/astral-sh/ruff/pull/28426">#28426</a>)</li> <li>Preserve callable identity across specialized types (<a href="https://redirect.github.com/astral-sh/ruff/pull/28409">#28409</a>)</li> <li>Preserve callback type context through ParamSpec forwarding (<a href="https://redirect.github.com/astral-sh/ruff/pull/28439">#28439</a>)</li> <li>Preserve wrapped functions in precise <code>functools.partial</code> relations (<a href="https://redirect.github.com/astral-sh/ruff/pull/28460">#28460</a>)</li> <li>Respect descriptor protocol for <code>__set__</code> itself (<a href="https://redirect.github.com/astral-sh/ruff/pull/28408">#28408</a>)</li> <li>Respect type-variable bounds in argument context (<a href="https://redirect.github.com/astral-sh/ruff/pull/28448">#28448</a>)</li> <li>Unwrap union alternatives in overload implementations (<a href="https://redirect.github.com/astral-sh/ruff/pull/28468">#28468</a>)</li> </ul> <h3>Performance</h3> <ul> <li>Distribute <code>len</code> inference over unions (<a href="https://redirect.github.com/astral-sh/ruff/pull/28470">#28470</a>)</li> <li>Fast-path concrete literal intersections (<a href="https://redirect.github.com/astral-sh/ruff/pull/28348">#28348</a>)</li> </ul> <h3>Memory usage improvements</h3> <ul> <li>Avoid excess capacity in multi-binding tables (<a href="https://redirect.github.com/astral-sh/ruff/pull/28412">#28412</a>)</li> <li>Share equivalent place tables within a file (<a href="https://redirect.github.com/astral-sh/ruff/pull/28319">#28319</a>)</li> <li>Share names in synthesized constructor parameters (<a href="https://redirect.github.com/astral-sh/ruff/pull/28398">#28398</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/sharkdp"><code>@sharkdp</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/ibraheemdev"><code>@ibraheemdev</code></a></li> <li><a href="https://github.com/AlexWaygood"><code>@AlexWaygood</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/astral-sh/ty/commit/7fd8e15694f869200f7778082564c5968c50ce30"><code>7fd8e15</code></a> Bump version to 0.0.80 (<a href="https://redirect.github.com/astral-sh/ty/issues/4501">#4501</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/c163f21ed4be7a5608ae5791720b43040b08cf5c"><code>c163f21</code></a> Update dependency prek to v0.4.12 (<a href="https://redirect.github.com/astral-sh/ty/issues/4494">#4494</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/8ce0450332e815c0f734fb84d03d63be3eb96829"><code>8ce0450</code></a> Update prek dependencies (<a href="https://redirect.github.com/astral-sh/ty/issues/4495">#4495</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/5d0aa7a142189fc1955759c2987029b8ff8ef4a7"><code>5d0aa7a</code></a> Update actions/attest-build-provenance action to v4.2.2 (<a href="https://redirect.github.com/astral-sh/ty/issues/4497">#4497</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/e22b86b3e6d461af46b549e5ebef5474b6256783"><code>e22b86b</code></a> Update Swatinem/rust-cache action to v2.9.2 (<a href="https://redirect.github.com/astral-sh/ty/issues/4496">#4496</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/5cde40f5cb83f1cb164b91282e6a72f3dfe4580c"><code>5cde40f</code></a> Document uv integration and workspace trust settings (<a href="https://redirect.github.com/astral-sh/ty/issues/4339">#4339</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/b4cd79275b7ce22c4cf4208f8b005adb53e92523"><code>b4cd792</code></a> Bump version to 0.0.79 (<a href="https://redirect.github.com/astral-sh/ty/issues/4484">#4484</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/52f2d5b12ff4a86f1100f3b9c3e2d61b086d8a89"><code>52f2d5b</code></a> Add a GitHub repository threat model for ty (<a href="https://redirect.github.com/astral-sh/ty/issues/4481">#4481</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/fd0d789cc54f9a234da75025ef6d0777280675be"><code>fd0d789</code></a> Declare support for Python 3.15 (<a href="https://redirect.github.com/astral-sh/ty/issues/4476">#4476</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/7e7a87da9849d3f322690ae5b74b0409799668b6"><code>7e7a87d</code></a> Improve rooster-generated changelog sections (<a href="https://redirect.github.com/astral-sh/ty/issues/4473">#4473</a>)</li> <li>Additional commits viewable in <a href="https://github.com/astral-sh/ty/compare/0.0.78...0.0.80">compare view</a></li> </ul> </details> <br /> Updates `psycopg2-binary` from 2.9.12 to 2.9.13 <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/psycopg/psycopg2/blob/master/NEWS">psycopg2-binary's changelog</a>.</em></p> <blockquote> <h2>Current release</h2> <p>What's new in psycopg 2.9.13 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^</p> <ul> <li>Add support for Python 3.15 (:ticket:<code>[#1848](https://github.com/psycopg/psycopg2/issues/1848)</code>).</li> <li>Fix parsing of malformed bytea input.</li> <li>Fix parsing of malformed int64 input in arrays (:ticket:<code>[#1847](https://github.com/psycopg/psycopg2/issues/1847)</code>).</li> <li>Add a <code>pyproject.toml</code> file to declare a PEP 517 build backend (:ticket:<code>[#1788](https://github.com/psycopg/psycopg2/issues/1788)</code>).</li> <li>Drop support for Python 3.9.</li> </ul> <p>What's new in psycopg 2.9.12 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^</p> <ul> <li>Fix infinite loop with malformed interval (:ticket:<code>1835</code>).</li> </ul> <p>What's new in psycopg 2.9.11 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^</p> <ul> <li>Add support for Python 3.14.</li> <li>Avoid a segfault passing more arguments than placeholders if Python is built with assertions enabled (:ticket:<code>[#1791](https://github.com/psycopg/psycopg2/issues/1791)</code>).</li> <li>Add riscv64 platform binary packages (:ticket:<code>[#1813](https://github.com/psycopg/psycopg2/issues/1813)</code>).</li> <li><code>~psycopg2.errorcodes</code> map and <code>~psycopg2.errors</code> classes updated to PostgreSQL 18.</li> <li>Drop support for Python 3.8.</li> </ul> <p>What's new in psycopg 2.9.10 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^</p> <ul> <li>Add support for Python 3.13.</li> <li>Receive notifications on commit (:ticket:<code>[#1728](https://github.com/psycopg/psycopg2/issues/1728)</code>).</li> <li><code>~psycopg2.errorcodes</code> map and <code>~psycopg2.errors</code> classes updated to PostgreSQL 17.</li> <li>Drop support for Python 3.7.</li> </ul> <p>What's new in psycopg 2.9.9 ^^^^^^^^^^^^^^^^^^^^^^^^^^^</p> <ul> <li>Add support for Python 3.12.</li> <li>Drop support for Python 3.6.</li> </ul> <p>What's new in psycopg 2.9.8</p> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/psycopg/psycopg2/commit/f650e7afed0c94f596594e8328a0c7fa65a9d0e5"><code>f650e7a</code></a> chore: bump to release 2.9.13</li> <li><a href="https://github.com/psycopg/psycopg2/commit/368c8a1ca6d80088703a693ce64b68ad7d346698"><code>368c8a1</code></a> chore!: drop support for Python 3.9</li> <li><a href="https://github.com/psycopg/psycopg2/commit/9b39e65ab232f0a267a278cdaef1bd9975d88c65"><code>9b39e65</code></a> chore: drop scaleway build support</li> <li><a href="https://github.com/psycopg/psycopg2/commit/2ca70416be6d4d3d8170ec439876c0b3569af718"><code>2ca7041</code></a> fix: fix handling of PostgreSQL 18 exceptions</li> <li><a href="https://github.com/psycopg/psycopg2/commit/5385c027ef62ce14e57a7379e0375868507d6746"><code>5385c02</code></a> Build CPython 3.15 wheels</li> <li><a href="https://github.com/psycopg/psycopg2/commit/1d32e1f6678ffa8ab8897ca81826bf4dde6354cd"><code>1d32e1f</code></a> ci: only attempt triggering documentation refresh when pushing on main repo</li> <li><a href="https://github.com/psycopg/psycopg2/commit/433e7b77a7b700fbb1cdc6e9dca6b5948d07fc23"><code>433e7b7</code></a> chore: add pyproject.toml file to declare a PEP 517 build backend</li> <li><a href="https://github.com/psycopg/psycopg2/commit/8fb80bc3b2c358f4e3c54e33a37326d3f8b3ff6a"><code>8fb80bc</code></a> fix: fix parsing of malformed int64 input in arrays</li> <li><a href="https://github.com/psycopg/psycopg2/commit/f98014a46a1e34f024ebd6134d1d87b77490c500"><code>f98014a</code></a> fix: fix parsing of malformed bytea input</li> <li><a href="https://github.com/psycopg/psycopg2/commit/822b79cfe12ca0a04482acd382cae669a16aa789"><code>822b79c</code></a> chore: bump dependencies in binary package</li> <li>Additional commits viewable in <a href="https://github.com/psycopg/psycopg2/compare/2.9.12...2.9.13">compare view</a></li> </ul> </details> <br /> Updates `pyjwt` from 2.13.0 to 2.14.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/jpadilla/pyjwt/releases">pyjwt's releases</a>.</em></p> <blockquote> <h2>PyJWT 2.14.0</h2> <p>See the <a href="https://github.com/jpadilla/pyjwt/blob/2.14.0/CHANGELOG.rst">2.14.0 changelog</a> for the complete release details and related security advisories.</p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst">pyjwt's changelog</a>.</em></p> <blockquote> <h2><code>v2.14.0 <https://github.com/jpadilla/pyjwt/compare/2.13.0...2.14.0></code>__</h2> <p>Security</p> <pre><code> - Harden HMAC key validation against public-key material supplied as JWK, JWKS, array, encoded, BOM-prefixed, DER, or PEM input. See `GHSA-r6x4-923q-g947 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-r6x4-923q-g947>`__, `GHSA-ffc3-869f-jxw9 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-ffc3-869f-jxw9>`__, `GHSA-p4g4-x82p-q773 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-p4g4-x82p-q773>`__, and `GHSA-w2cx-738m-mc7w <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w2cx-738m-mc7w>`__. - Reject automatic redirects when ``PyJWKClient`` fetches a JWKS, preventing redirected destinations from being treated as trusted key sources. See `GHSA-9v7f-9g4p-ffgj <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-9v7f-9g4p-ffgj>`__. - Limit repeated JWKS refreshes caused by unknown key IDs while preserving normal key-rotation behavior. See `GHSA-2gx3-rcp4-g85q <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-2gx3-rcp4-g85q>`__. - Handle deeply nested and malformed JWS/JWK input without uncaught recursion errors or whole-set parsing failures. See `GHSA-8wjv-2p76-3863 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-8wjv-2p76-3863>`__ and `GHSA-w6j9-cwv2-h6wq <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w6j9-cwv2-h6wq>`__. - Enforce compact JWS encoding rules during decoding. See `GHSA-hxm8-2xgr-2p9m <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-hxm8-2xgr-2p9m>`__. - Reject detached-payload arguments for attached JWS inputs. Thanks to `@xclow3n <https://github.com/xclow3n>`__ for reporting this behavior; fixed in commit `37b54877 <https://github.com/jpadilla/pyjwt/commit/37b54877bf7bea67e8149130e96929e3ec798122>`__. <p>Fixed</p> <pre><code> - Apply HMAC key validation consistently when keys are loaded through ``PyJWK`` and ``PyJWKClient``. See `GHSA-pxh4-856f-4h89 &lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-pxh4-856f-4h89&gt;`__. - Reject empty HMAC keys when represented as JWKs. See `GHSA-pxh4-856f-4h89 &lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-pxh4-856f-4h89&gt;`__. Fixed </code></pre> <ul> <li>Raise the documented <code>PyJWTError</code> subclass instead of leaking a<br /> <code>TypeError</code> when the <code>exp</code>, <code>nbf</code>, or <code>iat</code> claim decodes to a<br /> non-numeric, non-string value such as a list, dict, or <code>null</code>.<br /> </code></pre></li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/jpadilla/pyjwt/commit/c6fe464b356ff4b1ebc9ba62172d331a40aa27df"><code>c6fe464</code></a> release: prepare v2.14.0</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/f5413029ae7a2e31b1367b5303ea86a2f54ccf42"><code>f541302</code></a> style: apply Ruff formatting</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/801cd128528c62d9b23fcd161d1a2e1c17982f95"><code>801cd12</code></a> fix: reject public JWK container HMAC keys</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/af8181ca0bec5e6b372fbba9afbe23702b787ceb"><code>af8181c</code></a> fix: reject empty HMAC keys from JWKs</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/ba4853a75fb9676362da17f67d0f64bd18afd4e1"><code>ba4853a</code></a> Throttle repeated PyJWKClient refreshes</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/2798504fa2663364573cf2d1043d8d7fef389499"><code>2798504</code></a> fix: reject DER public keys as HMAC secrets</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/8b4e233a22206b34ec1186e912e75c0b2396ac07"><code>8b4e233</code></a> fix: reject loader-accepted PEM variants</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/1f8180a211256dfe5cf32294b6753f554a5a4258"><code>1f8180a</code></a> fix: format JWS tests</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/cff1ac55fe5f1096fd05295b269fce053ee290ab"><code>cff1ac5</code></a> Fix redirect handler return annotation</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/0a795b8e1f6ef08f634aa7086fc41cc6d5ce3e56"><code>0a795b8</code></a> Reject redirects in PyJWKClient fetches</li> <li>Additional commits viewable in <a href="https://github.com/jpadilla/pyjwt/compare/2.13.0...2.14.0">compare view</a></li> </ul> </details> <br /> Updates `uvicorn` from 0.52.4 to 0.53.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/Kludex/uvicorn/releases">uvicorn's releases</a>.</em></p> <blockquote> <h2>Version 0.53.0</h2> <h2>🌐 Opt-in HTTP/2 support</h2> <p><code>uvicorn</code> 0.53.0 adds experimental HTTP/2 through <code>zttp</code>, alongside a new <code>zuvloop</code> integration and connection-handling improvements.</p> <pre lang="console"><code>uv add uvicorn==0.53.0 </code></pre> <ul> <li><strong>Serve HTTP/1.1 and HTTP/2 with <code>zttp</code></strong> (<a href="https://redirect.github.com/Kludex/uvicorn/pull/2982">#2982</a>, <a href="https://redirect.github.com/Kludex/uvicorn/pull/3101">#3101</a>). Install <code>zttp</code>, then enable HTTP/2 with <code>--http z…
chrischall
added a commit
to chrischall/outlook-to-pdf
that referenced
this pull request
Sep 18, 2026
Bumps [weasyprint](https://github.com/Kozea/WeasyPrint) from 69.0 to 70.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/Kozea/WeasyPrint/releases">weasyprint's releases</a>.</em></p> <blockquote> <h2>v70.0</h2> <p>Read about this release <a href="https://www.courtbouillon.org/blog/00074-weasyprint-70/">on our blog</a>.</p> <p><strong>This is a security update (CVE-2026-55073, GHSA-r543-q48m-4c9j).</strong></p> <p>We strongly recommend to upgrade WeasyPrint to the latest version if you: * embed untrusted images, or * rely on the URL fetcher to filter metadata or stylesheets passed as Python parameters.</p> <h2>Security</h2> <ul> <li>Don’t render EPS images.</li> <li>Always use original URL fetcher when available.</li> </ul> <h2>Features</h2> <ul> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2905">#2905</a>: Add initial support of CSS Notes, with financial support from NLnet</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2731">#2731</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2781">#2781</a>: Log an error on unknown render and write_pdf options</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2802">#2802</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2805">#2805</a>: Create immutable releases on GitHub</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2809">#2809</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2810">#2810</a>: Switch to MSYS2 UCRT64 environment for Windows tests and executables</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2777">#2777</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2814">#2814</a>: Support COLR emoji fonts</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2667">#2667</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2744">#2744</a>: Support context paint in SVG markers</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/1862">#1862</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2844">#2844</a>: Improve filename detection for attachments</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2816">#2816</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2827">#2827</a>: Set SVG title as alternative text</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2718">#2718</a>: Provide a 'onedir' Windows executable</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2863">#2863</a>: Support box-shadow</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2755">#2755</a>: Support RTL SVG text anchoring</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2866">#2866</a>: Don’t use f-strings in logs</li> </ul> <h2>Bug fixes</h2> <ul> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2799">#2799</a>: Keep HarfBuzz font faces alive during PDF subsetting</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2764">#2764</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2793">#2793</a>: Accept Path as base URL in CSS</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2800">#2800</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2801">#2801</a>: Fix position of raster emojis</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2782">#2782</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2807">#2807</a>: Use POSIX paths in Fontconfig</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2766">#2766</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2779">#2779</a>: Use response bytes when image file path doesn’t exist</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2277">#2277</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2728">#2728</a>: Honor page breaks on floated elements</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2789">#2789</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2818">#2818</a>: Use base URL when solving pending properties</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2820">#2820</a>: Ignore unresolvable math in image slices</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2901">#2901</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2825">#2825</a>: Transform SVG size into CSS to apply CSS sizing algorithm</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2819">#2819</a>: Resolve calc() division by zero to infinity</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2824">#2824</a>: Remove old deprecation warnings</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2762">#2762</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2780">#2780</a>: Set SVG gradient color before path construction</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2761">#2761</a>: Handle split tables with captions</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2215">#2215</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2747">#2747</a>: Discard broken at-rules</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2736">#2736</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2738">#2738</a>: Apply transformations to SVG opacity groups</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2830">#2830</a>: Use a stack to draw simple borders</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2831">#2831</a>: Fix line_height() crash on calc() values</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2784">#2784</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2832">#2832</a>: Set fallback font for Unicode test</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2726">#2726</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2881">#2881</a>: Improve accessibility of PDF forms</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2803">#2803</a>: Fix inline width after backtracked line breaks</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2833">#2833</a>: Store root style in anonymous style</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/Kozea/WeasyPrint/blob/main/docs/changelog.rst">weasyprint's changelog</a>.</em></p> <blockquote> <h2>Version 70.0</h2> <p>Released on 2026-09-08.</p> <p><strong>This is a security update (CVE-2026-55073, GHSA-r543-q48m-4c9j).</strong></p> <p>We strongly recommend to upgrade WeasyPrint to the latest version if you:</p> <ul> <li>embed untrusted images, or</li> <li>rely on the URL fetcher to filter metadata or stylesheets passed as Python parameters.</li> </ul> <p>Security:</p> <ul> <li>Don’t render EPS images.</li> <li>Always use original URL fetcher when available.</li> </ul> <p>Features:</p> <ul> <li><code>[#2905](Kozea/WeasyPrint#2905) <https://github.com/Kozea/WeasyPrint/pull/2905></code>_: Add initial support of CSS Notes, with financial support from NLnet</li> <li><code>[#2731](Kozea/WeasyPrint#2731) <https://github.com/Kozea/WeasyPrint/issues/2731></code><em>, <code>[#2781](Kozea/WeasyPrint#2781) <https://github.com/Kozea/WeasyPrint/pull/2781></code></em>: Log an error on unknown render and write_pdf options</li> <li><code>[#2802](Kozea/WeasyPrint#2802) <https://github.com/Kozea/WeasyPrint/issues/2802></code><em>, <code>[#2805](Kozea/WeasyPrint#2805) <https://github.com/Kozea/WeasyPrint/pull/2805></code></em>: Create immutable releases on GitHub</li> <li><code>[#2809](Kozea/WeasyPrint#2809) <https://github.com/Kozea/WeasyPrint/issues/2809></code><em>, <code>[#2810](Kozea/WeasyPrint#2810) <https://github.com/Kozea/WeasyPrint/pull/2810></code></em>: Switch to MSYS2 UCRT64 environment for Windows tests and executables</li> <li><code>[#2777](Kozea/WeasyPrint#2777) <https://github.com/Kozea/WeasyPrint/issues/2777></code><em>, <code>[#2814](Kozea/WeasyPrint#2814) <https://github.com/Kozea/WeasyPrint/pull/2814></code></em>: Support COLR emoji fonts</li> <li><code>[#2667](Kozea/WeasyPrint#2667) <https://github.com/Kozea/WeasyPrint/issues/2667></code><em>, <code>[#2744](Kozea/WeasyPrint#2744) <https://github.com/Kozea/WeasyPrint/pull/2744></code></em>: Support context paint in SVG markers</li> <li><code>[#1862](Kozea/WeasyPrint#1862) <https://github.com/Kozea/WeasyPrint/issues/1862></code><em>, <code>[#2844](Kozea/WeasyPrint#2844) <https://github.com/Kozea/WeasyPrint/pull/2844></code></em>: Improve filename detection for attachments</li> <li><code>[#2816](Kozea/WeasyPrint#2816) <https://github.com/Kozea/WeasyPrint/issues/2816></code><em>, <code>[#2827](Kozea/WeasyPrint#2827) <https://github.com/Kozea/WeasyPrint/pull/2827></code></em>: Set SVG title as alternative text</li> <li><code>[#2718](Kozea/WeasyPrint#2718) <https://github.com/Kozea/WeasyPrint/issues/2718></code>_: Provide a 'onedir' Windows executable</li> <li><code>[#2863](Kozea/WeasyPrint#2863) <https://github.com/Kozea/WeasyPrint/pull/2863></code>_: Support box-shadow</li> <li><code>[#2755](Kozea/WeasyPrint#2755) <https://github.com/Kozea/WeasyPrint/pull/2755></code>_: Support RTL SVG text anchoring</li> <li><code>[#2866](Kozea/WeasyPrint#2866) <https://github.com/Kozea/WeasyPrint/issues/2866></code>_: Don’t use f-strings in logs</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/Kozea/WeasyPrint/commit/4d3b7b6449e3494f59c7c2f36b512d129225679c"><code>4d3b7b6</code></a> Version 70.0</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/289e278439b017cd9263b4cd4727026987f86443"><code>289e278</code></a> Always use original URL fetcher when available</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/aeb3be74e3c904e4b772014006410e23e0512b4b"><code>aeb3be7</code></a> Merge remote-tracking branch 'security/main'</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/48357241f949c3f6880ec1a40f56d2f5106fdef3"><code>4835724</code></a> Merge pull request <a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2915">#2915</a> from havelaer/fix-nested-svg-viewport-restore</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/03310511d8afac08f80939e7fa317ad6051e251f"><code>0331051</code></a> Restore nested SVG viewport size on the SVG object, not the drawing function</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/e4b8b45e409392197441bc449d110f323b0eeb66"><code>e4b8b45</code></a> Add harfbuzz-vector requirement for Fedora</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/371e4debb4805fa3d5a138f2cbb044fc176284da"><code>371e4de</code></a> Merge pull request <a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2905">#2905</a> from Kozea/notes</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/590bf63301d77eaf6aac6b1eb3a3fbb9494e3b23"><code>590bf63</code></a> Merge pull request <a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2913">#2913</a> from Kozea/fast-svg-paths</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/f6570c3038b60695f715b12c7805f6933e58490a"><code>f6570c3</code></a> Use a faster regex-based parser for SVG paths</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/bc0516240c5f8a1eaaf658621d52a09eebecdea9"><code>bc05162</code></a> Use faster deque for SVG vertices</li> <li>Additional commits viewable in <a href="https://github.com/Kozea/WeasyPrint/compare/v69.0...v70.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/chrischall/outlook-to-pdf/network/alerts). </details> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Chris Hall <chris.c.hall@gmail.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
sonnyp
added a commit
to fairscope/PlanktoScope
that referenced
this pull request
Sep 22, 2026
[//]: # (dependabot-start)⚠️ **Dependabot is rebasing this PR**⚠️ Rebasing might not happen immediately, so don't worry if this takes some time. Note: if you make any changes to this PR yourself, they will take precedence over the rebase. --- [//]: # (dependabot-end) Bumps [weasyprint](https://github.com/Kozea/WeasyPrint) from 69.0 to 70.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/Kozea/WeasyPrint/releases">weasyprint's releases</a>.</em></p> <blockquote> <h2>v70.0</h2> <p>Read about this release <a href="https://www.courtbouillon.org/blog/00074-weasyprint-70/">on our blog</a>.</p> <p><strong>This is a security update (CVE-2026-55073, GHSA-r543-q48m-4c9j).</strong></p> <p>We strongly recommend to upgrade WeasyPrint to the latest version if you: * embed untrusted images, or * rely on the URL fetcher to filter metadata or stylesheets passed as Python parameters.</p> <h2>Security</h2> <ul> <li>Don’t render EPS images.</li> <li>Always use original URL fetcher when available.</li> </ul> <h2>Features</h2> <ul> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2905">#2905</a>: Add initial support of CSS Notes, with financial support from NLnet</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2731">#2731</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2781">#2781</a>: Log an error on unknown render and write_pdf options</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2802">#2802</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2805">#2805</a>: Create immutable releases on GitHub</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2809">#2809</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2810">#2810</a>: Switch to MSYS2 UCRT64 environment for Windows tests and executables</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2777">#2777</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2814">#2814</a>: Support COLR emoji fonts</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2667">#2667</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2744">#2744</a>: Support context paint in SVG markers</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/1862">#1862</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2844">#2844</a>: Improve filename detection for attachments</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2816">#2816</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2827">#2827</a>: Set SVG title as alternative text</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2718">#2718</a>: Provide a 'onedir' Windows executable</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2863">#2863</a>: Support box-shadow</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2755">#2755</a>: Support RTL SVG text anchoring</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2866">#2866</a>: Don’t use f-strings in logs</li> </ul> <h2>Bug fixes</h2> <ul> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2799">#2799</a>: Keep HarfBuzz font faces alive during PDF subsetting</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2764">#2764</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2793">#2793</a>: Accept Path as base URL in CSS</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2800">#2800</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2801">#2801</a>: Fix position of raster emojis</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2782">#2782</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2807">#2807</a>: Use POSIX paths in Fontconfig</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2766">#2766</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2779">#2779</a>: Use response bytes when image file path doesn’t exist</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2277">#2277</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2728">#2728</a>: Honor page breaks on floated elements</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2789">#2789</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2818">#2818</a>: Use base URL when solving pending properties</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2820">#2820</a>: Ignore unresolvable math in image slices</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2901">#2901</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2825">#2825</a>: Transform SVG size into CSS to apply CSS sizing algorithm</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2819">#2819</a>: Resolve calc() division by zero to infinity</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2824">#2824</a>: Remove old deprecation warnings</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2762">#2762</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2780">#2780</a>: Set SVG gradient color before path construction</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2761">#2761</a>: Handle split tables with captions</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2215">#2215</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2747">#2747</a>: Discard broken at-rules</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2736">#2736</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2738">#2738</a>: Apply transformations to SVG opacity groups</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2830">#2830</a>: Use a stack to draw simple borders</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2831">#2831</a>: Fix line_height() crash on calc() values</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2784">#2784</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2832">#2832</a>: Set fallback font for Unicode test</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2726">#2726</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2881">#2881</a>: Improve accessibility of PDF forms</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2803">#2803</a>: Fix inline width after backtracked line breaks</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2833">#2833</a>: Store root style in anonymous style</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/Kozea/WeasyPrint/blob/main/docs/changelog.rst">weasyprint's changelog</a>.</em></p> <blockquote> <h2>Version 70.0</h2> <p>Released on 2026-09-08.</p> <p><strong>This is a security update (CVE-2026-55073, GHSA-r543-q48m-4c9j).</strong></p> <p>We strongly recommend to upgrade WeasyPrint to the latest version if you:</p> <ul> <li>embed untrusted images, or</li> <li>rely on the URL fetcher to filter metadata or stylesheets passed as Python parameters.</li> </ul> <p>Security:</p> <ul> <li>Don’t render EPS images.</li> <li>Always use original URL fetcher when available.</li> </ul> <p>Features:</p> <ul> <li><code>[#2905](Kozea/WeasyPrint#2905) <https://github.com/Kozea/WeasyPrint/pull/2905></code>_: Add initial support of CSS Notes, with financial support from NLnet</li> <li><code>[#2731](Kozea/WeasyPrint#2731) <https://github.com/Kozea/WeasyPrint/issues/2731></code><em>, <code>[#2781](Kozea/WeasyPrint#2781) <https://github.com/Kozea/WeasyPrint/pull/2781></code></em>: Log an error on unknown render and write_pdf options</li> <li><code>[#2802](Kozea/WeasyPrint#2802) <https://github.com/Kozea/WeasyPrint/issues/2802></code><em>, <code>[#2805](Kozea/WeasyPrint#2805) <https://github.com/Kozea/WeasyPrint/pull/2805></code></em>: Create immutable releases on GitHub</li> <li><code>[#2809](Kozea/WeasyPrint#2809) <https://github.com/Kozea/WeasyPrint/issues/2809></code><em>, <code>[#2810](Kozea/WeasyPrint#2810) <https://github.com/Kozea/WeasyPrint/pull/2810></code></em>: Switch to MSYS2 UCRT64 environment for Windows tests and executables</li> <li><code>[#2777](Kozea/WeasyPrint#2777) <https://github.com/Kozea/WeasyPrint/issues/2777></code><em>, <code>[#2814](Kozea/WeasyPrint#2814) <https://github.com/Kozea/WeasyPrint/pull/2814></code></em>: Support COLR emoji fonts</li> <li><code>[#2667](Kozea/WeasyPrint#2667) <https://github.com/Kozea/WeasyPrint/issues/2667></code><em>, <code>[#2744](Kozea/WeasyPrint#2744) <https://github.com/Kozea/WeasyPrint/pull/2744></code></em>: Support context paint in SVG markers</li> <li><code>[#1862](Kozea/WeasyPrint#1862) <https://github.com/Kozea/WeasyPrint/issues/1862></code><em>, <code>[#2844](Kozea/WeasyPrint#2844) <https://github.com/Kozea/WeasyPrint/pull/2844></code></em>: Improve filename detection for attachments</li> <li><code>[#2816](Kozea/WeasyPrint#2816) <https://github.com/Kozea/WeasyPrint/issues/2816></code><em>, <code>[#2827](Kozea/WeasyPrint#2827) <https://github.com/Kozea/WeasyPrint/pull/2827></code></em>: Set SVG title as alternative text</li> <li><code>[#2718](Kozea/WeasyPrint#2718) <https://github.com/Kozea/WeasyPrint/issues/2718></code>_: Provide a 'onedir' Windows executable</li> <li><code>[#2863](Kozea/WeasyPrint#2863) <https://github.com/Kozea/WeasyPrint/pull/2863></code>_: Support box-shadow</li> <li><code>[#2755](Kozea/WeasyPrint#2755) <https://github.com/Kozea/WeasyPrint/pull/2755></code>_: Support RTL SVG text anchoring</li> <li><code>[#2866](Kozea/WeasyPrint#2866) <https://github.com/Kozea/WeasyPrint/issues/2866></code>_: Don’t use f-strings in logs</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/Kozea/WeasyPrint/commit/4d3b7b6449e3494f59c7c2f36b512d129225679c"><code>4d3b7b6</code></a> Version 70.0</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/289e278439b017cd9263b4cd4727026987f86443"><code>289e278</code></a> Always use original URL fetcher when available</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/aeb3be74e3c904e4b772014006410e23e0512b4b"><code>aeb3be7</code></a> Merge remote-tracking branch 'security/main'</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/48357241f949c3f6880ec1a40f56d2f5106fdef3"><code>4835724</code></a> Merge pull request <a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2915">#2915</a> from havelaer/fix-nested-svg-viewport-restore</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/03310511d8afac08f80939e7fa317ad6051e251f"><code>0331051</code></a> Restore nested SVG viewport size on the SVG object, not the drawing function</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/e4b8b45e409392197441bc449d110f323b0eeb66"><code>e4b8b45</code></a> Add harfbuzz-vector requirement for Fedora</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/371e4debb4805fa3d5a138f2cbb044fc176284da"><code>371e4de</code></a> Merge pull request <a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2905">#2905</a> from Kozea/notes</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/590bf63301d77eaf6aac6b1eb3a3fbb9494e3b23"><code>590bf63</code></a> Merge pull request <a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2913">#2913</a> from Kozea/fast-svg-paths</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/f6570c3038b60695f715b12c7805f6933e58490a"><code>f6570c3</code></a> Use a faster regex-based parser for SVG paths</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/bc0516240c5f8a1eaaf658621d52a09eebecdea9"><code>bc05162</code></a> Use faster deque for SVG vertices</li> <li>Additional commits viewable in <a href="https://github.com/Kozea/WeasyPrint/compare/v69.0...v70.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/fairscope/PlanktoScope/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Sonny Piers <sonny@fairscope.com>
glromero
pushed a commit
to BlueRingsLabs/Clinical-Deep-Research_CDR
that referenced
this pull request
Sep 30, 2026
Bumps [weasyprint](https://github.com/Kozea/WeasyPrint) from 68.1 to 70.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/Kozea/WeasyPrint/releases">weasyprint's releases</a>.</em></p> <blockquote> <h2>v70.0</h2> <p>Read about this release <a href="https://www.courtbouillon.org/blog/00074-weasyprint-70/">on our blog</a>.</p> <p><strong>This is a security update (CVE-2026-55073, GHSA-r543-q48m-4c9j).</strong></p> <p>We strongly recommend to upgrade WeasyPrint to the latest version if you: * embed untrusted images, or * rely on the URL fetcher to filter metadata or stylesheets passed as Python parameters.</p> <h2>Security</h2> <ul> <li>Don’t render EPS images.</li> <li>Always use original URL fetcher when available.</li> </ul> <h2>Features</h2> <ul> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2905">#2905</a>: Add initial support of CSS Notes, with financial support from NLnet</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2731">#2731</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2781">#2781</a>: Log an error on unknown render and write_pdf options</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2802">#2802</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2805">#2805</a>: Create immutable releases on GitHub</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2809">#2809</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2810">#2810</a>: Switch to MSYS2 UCRT64 environment for Windows tests and executables</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2777">#2777</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2814">#2814</a>: Support COLR emoji fonts</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2667">#2667</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2744">#2744</a>: Support context paint in SVG markers</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/1862">#1862</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2844">#2844</a>: Improve filename detection for attachments</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2816">#2816</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2827">#2827</a>: Set SVG title as alternative text</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2718">#2718</a>: Provide a 'onedir' Windows executable</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2863">#2863</a>: Support box-shadow</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2755">#2755</a>: Support RTL SVG text anchoring</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2866">#2866</a>: Don’t use f-strings in logs</li> </ul> <h2>Bug fixes</h2> <ul> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2799">#2799</a>: Keep HarfBuzz font faces alive during PDF subsetting</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2764">#2764</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2793">#2793</a>: Accept Path as base URL in CSS</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2800">#2800</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2801">#2801</a>: Fix position of raster emojis</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2782">#2782</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2807">#2807</a>: Use POSIX paths in Fontconfig</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2766">#2766</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2779">#2779</a>: Use response bytes when image file path doesn’t exist</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2277">#2277</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2728">#2728</a>: Honor page breaks on floated elements</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2789">#2789</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2818">#2818</a>: Use base URL when solving pending properties</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2820">#2820</a>: Ignore unresolvable math in image slices</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2901">#2901</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2825">#2825</a>: Transform SVG size into CSS to apply CSS sizing algorithm</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2819">#2819</a>: Resolve calc() division by zero to infinity</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2824">#2824</a>: Remove old deprecation warnings</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2762">#2762</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2780">#2780</a>: Set SVG gradient color before path construction</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2761">#2761</a>: Handle split tables with captions</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2215">#2215</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2747">#2747</a>: Discard broken at-rules</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2736">#2736</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2738">#2738</a>: Apply transformations to SVG opacity groups</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2830">#2830</a>: Use a stack to draw simple borders</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2831">#2831</a>: Fix line_height() crash on calc() values</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2784">#2784</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2832">#2832</a>: Set fallback font for Unicode test</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2726">#2726</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2881">#2881</a>: Improve accessibility of PDF forms</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2803">#2803</a>: Fix inline width after backtracked line breaks</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2833">#2833</a>: Store root style in anonymous style</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/Kozea/WeasyPrint/blob/main/docs/changelog.rst">weasyprint's changelog</a>.</em></p> <blockquote> <h2>Version 70.0</h2> <p>Released on 2026-09-08.</p> <p><strong>This is a security update (CVE-2026-55073, GHSA-r543-q48m-4c9j).</strong></p> <p>We strongly recommend to upgrade WeasyPrint to the latest version if you:</p> <ul> <li>embed untrusted images, or</li> <li>rely on the URL fetcher to filter metadata or stylesheets passed as Python parameters.</li> </ul> <p>Security:</p> <ul> <li>Don’t render EPS images.</li> <li>Always use original URL fetcher when available.</li> </ul> <p>Features:</p> <ul> <li><code>[#2905](Kozea/WeasyPrint#2905) <https://github.com/Kozea/WeasyPrint/pull/2905></code>_: Add initial support of CSS Notes, with financial support from NLnet</li> <li><code>[#2731](Kozea/WeasyPrint#2731) <https://github.com/Kozea/WeasyPrint/issues/2731></code><em>, <code>[#2781](Kozea/WeasyPrint#2781) <https://github.com/Kozea/WeasyPrint/pull/2781></code></em>: Log an error on unknown render and write_pdf options</li> <li><code>[#2802](Kozea/WeasyPrint#2802) <https://github.com/Kozea/WeasyPrint/issues/2802></code><em>, <code>[#2805](Kozea/WeasyPrint#2805) <https://github.com/Kozea/WeasyPrint/pull/2805></code></em>: Create immutable releases on GitHub</li> <li><code>[#2809](Kozea/WeasyPrint#2809) <https://github.com/Kozea/WeasyPrint/issues/2809></code><em>, <code>[#2810](Kozea/WeasyPrint#2810) <https://github.com/Kozea/WeasyPrint/pull/2810></code></em>: Switch to MSYS2 UCRT64 environment for Windows tests and executables</li> <li><code>[#2777](Kozea/WeasyPrint#2777) <https://github.com/Kozea/WeasyPrint/issues/2777></code><em>, <code>[#2814](Kozea/WeasyPrint#2814) <https://github.com/Kozea/WeasyPrint/pull/2814></code></em>: Support COLR emoji fonts</li> <li><code>[#2667](Kozea/WeasyPrint#2667) <https://github.com/Kozea/WeasyPrint/issues/2667></code><em>, <code>[#2744](Kozea/WeasyPrint#2744) <https://github.com/Kozea/WeasyPrint/pull/2744></code></em>: Support context paint in SVG markers</li> <li><code>[#1862](Kozea/WeasyPrint#1862) <https://github.com/Kozea/WeasyPrint/issues/1862></code><em>, <code>[#2844](Kozea/WeasyPrint#2844) <https://github.com/Kozea/WeasyPrint/pull/2844></code></em>: Improve filename detection for attachments</li> <li><code>[#2816](Kozea/WeasyPrint#2816) <https://github.com/Kozea/WeasyPrint/issues/2816></code><em>, <code>[#2827](Kozea/WeasyPrint#2827) <https://github.com/Kozea/WeasyPrint/pull/2827></code></em>: Set SVG title as alternative text</li> <li><code>[#2718](Kozea/WeasyPrint#2718) <https://github.com/Kozea/WeasyPrint/issues/2718></code>_: Provide a 'onedir' Windows executable</li> <li><code>[#2863](Kozea/WeasyPrint#2863) <https://github.com/Kozea/WeasyPrint/pull/2863></code>_: Support box-shadow</li> <li><code>[#2755](Kozea/WeasyPrint#2755) <https://github.com/Kozea/WeasyPrint/pull/2755></code>_: Support RTL SVG text anchoring</li> <li><code>[#2866](Kozea/WeasyPrint#2866) <https://github.com/Kozea/WeasyPrint/issues/2866></code>_: Don’t use f-strings in logs</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/Kozea/WeasyPrint/commit/4d3b7b6449e3494f59c7c2f36b512d129225679c"><code>4d3b7b6</code></a> Version 70.0</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/289e278439b017cd9263b4cd4727026987f86443"><code>289e278</code></a> Always use original URL fetcher when available</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/aeb3be74e3c904e4b772014006410e23e0512b4b"><code>aeb3be7</code></a> Merge remote-tracking branch 'security/main'</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/48357241f949c3f6880ec1a40f56d2f5106fdef3"><code>4835724</code></a> Merge pull request <a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2915">#2915</a> from havelaer/fix-nested-svg-viewport-restore</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/03310511d8afac08f80939e7fa317ad6051e251f"><code>0331051</code></a> Restore nested SVG viewport size on the SVG object, not the drawing function</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/e4b8b45e409392197441bc449d110f323b0eeb66"><code>e4b8b45</code></a> Add harfbuzz-vector requirement for Fedora</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/371e4debb4805fa3d5a138f2cbb044fc176284da"><code>371e4de</code></a> Merge pull request <a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2905">#2905</a> from Kozea/notes</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/590bf63301d77eaf6aac6b1eb3a3fbb9494e3b23"><code>590bf63</code></a> Merge pull request <a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2913">#2913</a> from Kozea/fast-svg-paths</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/f6570c3038b60695f715b12c7805f6933e58490a"><code>f6570c3</code></a> Use a faster regex-based parser for SVG paths</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/bc0516240c5f8a1eaaf658621d52a09eebecdea9"><code>bc05162</code></a> Use faster deque for SVG vertices</li> <li>Additional commits viewable in <a href="https://github.com/Kozea/WeasyPrint/compare/v68.1...v70.0">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
timothybrush
pushed a commit
to timothybrush/Stirling-PDF
that referenced
this pull request
Oct 5, 2026
) Bumps the uv group with 4 updates in the /engine directory: [urllib3](https://github.com/urllib3/urllib3), [weasyprint](https://github.com/Kozea/WeasyPrint), [httpx2](https://github.com/pydantic/httpx2) and [pypdf](https://github.com/py-pdf/pypdf). Updates `urllib3` from 2.7.0 to 2.8.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/urllib3/urllib3/releases">urllib3's releases</a>.</em></p> <blockquote> <h2>2.8.0</h2> <h2>🚀 urllib3 is fundraising for HTTP/2 support</h2> <p><a href="https://sethmlarson.dev/urllib3-is-fundraising-for-http2-support">urllib3 is raising ~$40,000 USD</a> to release HTTP/2 support and ensure long-term sustainable maintenance of the project. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects <a href="https://opencollective.com/urllib3">please consider contributing financially</a> to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.</p> <p>Thank you for your support.</p> <h2>Security</h2> <p>Fixed the following security issues:</p> <ul> <li>The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, GHSA-8988-9cw3-xx77)</li> <li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code> could buffer a chunk-size line of unbounded length in memory. (High severity, GHSA-vxq7-64xx-v4gw)</li> <li>Chunked Deflate streaming could enter an infinite loop. (Medium severity, GHSA-gh4c-6fx4-qh6g)</li> </ul> <blockquote> <p>[!IMPORTANT] urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes.</p> <p>Configure proxy CA certificates and client certificates in <code>proxy_ssl_context</code>, and proxy identity checks with <code>proxy_assert_hostname</code> or <code>proxy_assert_fingerprint</code>. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections.</p> </blockquote> <blockquote> <p>[!NOTE] CVE IDs had not yet been assigned to these advisories at the time of release due to a backlog at GitHub's CNA.</p> </blockquote> <h2>Deprecations & Removals</h2> <ul> <li>Deprecated using an empty collection as the <code>Retry</code> option <code>allowed_methods</code> to retry any verb. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5044">#5044</a>)</li> </ul> <h2>Features</h2> <ul> <li>Added <code>Url.auth_decoded</code> and <code>Url.auth_decoded_joined</code> convenience properties to the result of <code>parse_url()</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/4945">#4945</a>)</li> <li>Added <code>basic_auth_encoding</code> and <code>proxy_basic_auth_encoding</code> parameters to <code>urllib3.util.make_headers()</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5092">#5092</a>)</li> </ul> <h2>Bugfixes</h2> <ul> <li> <p>Fixed response header handling to replace obsolete folded header lines (<code>obs-fold</code>) with spaces in accordance with RFC 9112, preventing raw CRLF sequences from appearing in header values such as <code>Set-Cookie</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/1362">#1362</a>)</p> </li> <li> <p>Fixed usage of <code>proxy_ssl_context</code> with <code>ProxyManager</code> when <code>use_forwarding_for_https=True</code>. Passing <code>ssl_context</code> instead of <code>proxy_ssl_context</code> for HTTPS proxies in this configuration now emits a <code>FutureWarning</code> and will raise an error in v3.0. (<a href="https://redirect.github.com/urllib3/urllib3/issues/2577">#2577</a>)</p> </li> <li> <p>Changed behavior of the default <code>ConnectionPool.pool</code> initialization. <code>LifoQueue</code> is now resolved from the <code>queue</code> module after the <code>ConnectionPool</code> is instantiated instead of using the default cached <code>QueueCls</code> class property. This is done because sometimes the <code>queue.LifoQueue</code> is monkey-patched late in the program, such as by gevent. (<a href="https://redirect.github.com/urllib3/urllib3/issues/3289">#3289</a>)</p> </li> <li> <p>Raised <code>UnrewindableBodyError</code> instead of <code>ValueError</code> when retrying a request whose body had <code>tell()</code> but not <code>seek()</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/3779">#3779</a>)</p> </li> <li> <p>Decoded percent-encoded SOCKS proxy credentials before authenticating with the proxy server. (<a href="https://redirect.github.com/urllib3/urllib3/issues/3785">#3785</a>)</p> </li> <li> <p>Fixed <code>HTTPResponse.drain_conn()</code> to discard unread response data in 64 KiB chunks (same as the default <code>amt</code> when doing <code>HTTPResponse.stream(...)</code>). (<a href="https://redirect.github.com/urllib3/urllib3/issues/5019">#5019</a>)</p> </li> <li> <p>Fixed <code>is_ipaddress()</code> to detect non-standard IPv4 forms accepted by <code>socket.connect</code>, such as hex (<code>0x7f000001</code>), octal (<code>0177.0.0.1</code>), and decimal integers (<code>2130706433</code>), ensuring SSL certificate verification uses the correct mode for these addresses. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5029">#5029</a>)</p> </li> <li> <p>Fixed <code>HTTPConnectionPool.urlopen</code> raising a misleading <code>FullPoolError</code> instead of <code>ValueError</code> when called with an invalid <code>timeout</code> argument on a pool created with <code>block=True</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5059">#5059</a>)</p> </li> <li> <p>Fixed port-zero handling to preserve explicit <code>:0</code> values instead of substituting the default ports 80 or 443 in URL parsing, pool selection, proxy configuration, <code>connection_from_url()</code>, and HTTP/2 request authority. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5071">#5071</a>, <a href="https://redirect.github.com/urllib3/urllib3/issues/5101">#5101</a>)</p> </li> <li> <p>Fixed a bug where <code>PoolManager</code> passed the <code>assert_hostname</code> and <code>assert_fingerprint</code> parameters to HTTP connection pools. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5077">#5077</a>)</p> </li> <li> <p>Fixed <code>HTTPConnectionPool.urlopen()</code> and HTTP proxy forwarding to strip URL fragments from absolute request targets before sending requests. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5079">#5079</a>)</p> </li> <li> <p>Added safeguards to the proxy tunneling code to prevent potential security issues when handling invalid characters in the proxy host and HTTP headers. This change affects users of Python 3.10, Python 3.11, and Python 3.12 when the standard library does not contain the fix; those on newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5091">#5091</a>)</p> </li> <li> <p>Fixed <code>HTTPSConnection.connect()</code> overriding <code>ProxyConfig.ssl_context</code>'s certificate policy and proxy identity checks with the target connection's TLS settings when forwarding through an HTTPS proxy.</p> <p><code>HTTPSConnection</code> no longer applies target SNI, assertions, or client credentials to forwarding proxy handshakes and continues to use its <code>ssl_context</code> as a fallback when an HTTPS proxy forwards an HTTP target. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5093">#5093</a>)</p> </li> <li> <p>Fixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting invalid host input such as raw spaces and control characters, malformed percent-encodings, and percent-encoded control characters in HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host normalization now also follows RFC 3986 normalization rules for percent-encoded octets by decoding percent-encoded unreserved characters and uppercasing the hexadecimal digits of retained percent-encoded octets. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5095">#5095</a>)</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/urllib3/urllib3/blob/main/CHANGES.rst">urllib3's changelog</a>.</em></p> <blockquote> <h1>2.8.0 (2026-09-15)</h1> <h2>Security</h2> <p>Fixed the following security issues:</p> <ul> <li>The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, <code>GHSA-8988-9cw3-xx77 <https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77></code>__)</li> <li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code> could buffer a chunk-size line of unbounded length in memory. (High severity, <code>GHSA-vxq7-64xx-v4gw <https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw></code>__)</li> <li>Chunked Deflate streaming could enter an infinite loop. (Medium severity, <code>GHSA-gh4c-6fx4-qh6g <https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g></code>__)</li> </ul> <p>.. caution::</p> <pre><code>urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes. <p>Configure proxy CA certificates and client certificates in <code>proxy_ssl_context</code>, and proxy identity checks with <code>proxy_assert_hostname</code> or <code>proxy_assert_fingerprint</code>. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections. </code></pre></p> <h2>Deprecations & Removals</h2> <ul> <li>Deprecated using an empty collection as the <code>Retry</code> option <code>allowed_methods</code> to retry any verb. (<code>[Stirling-Tools#5044](urllib3/urllib3#5044) <https://github.com/urllib3/urllib3/issues/5044></code>__)</li> </ul> <h2>Features</h2> <ul> <li>Added <code>Url.auth_decoded</code> and <code>Url.auth_decoded_joined</code> convenience properties to the result of <code>parse_url()</code>. (<code>[Stirling-Tools#4945](urllib3/urllib3#4945) <https://github.com/urllib3/urllib3/issues/4945></code>__)</li> <li>Added <code>basic_auth_encoding</code> and <code>proxy_basic_auth_encoding</code> parameters to <code>urllib3.util.make_headers()</code>. (<code>[Stirling-Tools#5092](urllib3/urllib3#5092) <https://github.com/urllib3/urllib3/issues/5092></code>__)</li> </ul> <h2>Bugfixes</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/urllib3/urllib3/commit/b1d30ab61fe0db8f11092805e8c5ac43e091064a"><code>b1d30ab</code></a> Release 2.8.0</li> <li><a href="https://github.com/urllib3/urllib3/commit/9016d7e8afc68185496ef07f3c3a4a743d04922e"><code>9016d7e</code></a> Skip <code>test_read_chunked_with_trailing_data_does_not_hang</code> for brotlicffi (<a href="https://redirect.github.com/urllib3/urllib3/issues/5258">#5258</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/9101f581a8b3659af23b6ff335ae77200ca33533"><code>9101f58</code></a> Fix <code>nox -s docs</code> warning (<a href="https://redirect.github.com/urllib3/urllib3/issues/5256">#5256</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed"><code>cd770b0</code></a> Merge commit from fork</li> <li><a href="https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f"><code>ea2ad7b</code></a> Merge commit from fork</li> <li><a href="https://github.com/urllib3/urllib3/commit/0716e31534345dc1599ea95d903c79f276239bd8"><code>0716e31</code></a> Fix loading unencrypted client keys with a password in pyOpenSSL (<a href="https://redirect.github.com/urllib3/urllib3/issues/5255">#5255</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/43c68c8b43a9dcb44ed2cf4ec91384ca0d46b37d"><code>43c68c8</code></a> Test pickling of <code>InvalidChunkLength</code> (<a href="https://redirect.github.com/urllib3/urllib3/issues/5247">#5247</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/308b279b3fb28e7bee952e152ec5baeb5bfd0817"><code>308b279</code></a> Share security policy between GitHub and Read the Docs (<a href="https://redirect.github.com/urllib3/urllib3/issues/5253">#5253</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/53fa0731b27d4b71ab0755ea5b896422d005d706"><code>53fa073</code></a> Add policy on duplicate pull requests (<a href="https://redirect.github.com/urllib3/urllib3/issues/5252">#5252</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/5f2a6a843d0100d1351c3f94d58581ca98d17267"><code>5f2a6a8</code></a> Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (<a href="https://redirect.github.com/urllib3/urllib3/issues/5232">#5232</a>)</li> <li>Additional commits viewable in <a href="https://github.com/urllib3/urllib3/compare/2.7.0...2.8.0">compare view</a></li> </ul> </details> <br /> Updates `weasyprint` from 69.0 to 70.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/Kozea/WeasyPrint/releases">weasyprint's releases</a>.</em></p> <blockquote> <h2>v70.0</h2> <p>Read about this release <a href="https://www.courtbouillon.org/blog/00074-weasyprint-70/">on our blog</a>.</p> <p><strong>This is a security update (CVE-2026-55073, GHSA-r543-q48m-4c9j).</strong></p> <p>We strongly recommend to upgrade WeasyPrint to the latest version if you: * embed untrusted images, or * rely on the URL fetcher to filter metadata or stylesheets passed as Python parameters.</p> <h2>Security</h2> <ul> <li>Don’t render EPS images.</li> <li>Always use original URL fetcher when available.</li> </ul> <h2>Features</h2> <ul> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2905">#2905</a>: Add initial support of CSS Notes, with financial support from NLnet</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2731">#2731</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2781">#2781</a>: Log an error on unknown render and write_pdf options</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2802">#2802</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2805">#2805</a>: Create immutable releases on GitHub</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2809">#2809</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2810">#2810</a>: Switch to MSYS2 UCRT64 environment for Windows tests and executables</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2777">#2777</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2814">#2814</a>: Support COLR emoji fonts</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2667">#2667</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2744">#2744</a>: Support context paint in SVG markers</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/1862">#1862</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2844">#2844</a>: Improve filename detection for attachments</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2816">#2816</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2827">#2827</a>: Set SVG title as alternative text</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2718">#2718</a>: Provide a 'onedir' Windows executable</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2863">#2863</a>: Support box-shadow</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2755">#2755</a>: Support RTL SVG text anchoring</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2866">#2866</a>: Don’t use f-strings in logs</li> </ul> <h2>Bug fixes</h2> <ul> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2799">#2799</a>: Keep HarfBuzz font faces alive during PDF subsetting</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2764">#2764</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2793">#2793</a>: Accept Path as base URL in CSS</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2800">#2800</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2801">#2801</a>: Fix position of raster emojis</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2782">#2782</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2807">#2807</a>: Use POSIX paths in Fontconfig</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2766">#2766</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2779">#2779</a>: Use response bytes when image file path doesn’t exist</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2277">#2277</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2728">#2728</a>: Honor page breaks on floated elements</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2789">#2789</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2818">#2818</a>: Use base URL when solving pending properties</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2820">#2820</a>: Ignore unresolvable math in image slices</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2901">#2901</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2825">#2825</a>: Transform SVG size into CSS to apply CSS sizing algorithm</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2819">#2819</a>: Resolve calc() division by zero to infinity</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2824">#2824</a>: Remove old deprecation warnings</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2762">#2762</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2780">#2780</a>: Set SVG gradient color before path construction</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2761">#2761</a>: Handle split tables with captions</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2215">#2215</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2747">#2747</a>: Discard broken at-rules</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2736">#2736</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2738">#2738</a>: Apply transformations to SVG opacity groups</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2830">#2830</a>: Use a stack to draw simple borders</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2831">#2831</a>: Fix line_height() crash on calc() values</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2784">#2784</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2832">#2832</a>: Set fallback font for Unicode test</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2726">#2726</a>, <a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2881">#2881</a>: Improve accessibility of PDF forms</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/pull/2803">#2803</a>: Fix inline width after backtracked line breaks</li> <li><a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2833">#2833</a>: Store root style in anonymous style</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/Kozea/WeasyPrint/blob/main/docs/changelog.rst">weasyprint's changelog</a>.</em></p> <blockquote> <h2>Version 70.0</h2> <p>Released on 2026-09-08.</p> <p><strong>This is a security update (CVE-2026-55073, GHSA-r543-q48m-4c9j).</strong></p> <p>We strongly recommend to upgrade WeasyPrint to the latest version if you:</p> <ul> <li>embed untrusted images, or</li> <li>rely on the URL fetcher to filter metadata or stylesheets passed as Python parameters.</li> </ul> <p>Security:</p> <ul> <li>Don’t render EPS images.</li> <li>Always use original URL fetcher when available.</li> </ul> <p>Features:</p> <ul> <li><code>[Stirling-Tools#2905](Kozea/WeasyPrint#2905) <https://github.com/Kozea/WeasyPrint/pull/2905></code>_: Add initial support of CSS Notes, with financial support from NLnet</li> <li><code>[Stirling-Tools#2731](Kozea/WeasyPrint#2731) <https://github.com/Kozea/WeasyPrint/issues/2731></code><em>, <code>[Stirling-Tools#2781](Kozea/WeasyPrint#2781) <https://github.com/Kozea/WeasyPrint/pull/2781></code></em>: Log an error on unknown render and write_pdf options</li> <li><code>[Stirling-Tools#2802](Kozea/WeasyPrint#2802) <https://github.com/Kozea/WeasyPrint/issues/2802></code><em>, <code>[Stirling-Tools#2805](Kozea/WeasyPrint#2805) <https://github.com/Kozea/WeasyPrint/pull/2805></code></em>: Create immutable releases on GitHub</li> <li><code>[Stirling-Tools#2809](Kozea/WeasyPrint#2809) <https://github.com/Kozea/WeasyPrint/issues/2809></code><em>, <code>[Stirling-Tools#2810](Kozea/WeasyPrint#2810) <https://github.com/Kozea/WeasyPrint/pull/2810></code></em>: Switch to MSYS2 UCRT64 environment for Windows tests and executables</li> <li><code>[Stirling-Tools#2777](Kozea/WeasyPrint#2777) <https://github.com/Kozea/WeasyPrint/issues/2777></code><em>, <code>[Stirling-Tools#2814](Kozea/WeasyPrint#2814) <https://github.com/Kozea/WeasyPrint/pull/2814></code></em>: Support COLR emoji fonts</li> <li><code>[Stirling-Tools#2667](Kozea/WeasyPrint#2667) <https://github.com/Kozea/WeasyPrint/issues/2667></code><em>, <code>[Stirling-Tools#2744](Kozea/WeasyPrint#2744) <https://github.com/Kozea/WeasyPrint/pull/2744></code></em>: Support context paint in SVG markers</li> <li><code>[Stirling-Tools#1862](Kozea/WeasyPrint#1862) <https://github.com/Kozea/WeasyPrint/issues/1862></code><em>, <code>[Stirling-Tools#2844](Kozea/WeasyPrint#2844) <https://github.com/Kozea/WeasyPrint/pull/2844></code></em>: Improve filename detection for attachments</li> <li><code>[Stirling-Tools#2816](Kozea/WeasyPrint#2816) <https://github.com/Kozea/WeasyPrint/issues/2816></code><em>, <code>[Stirling-Tools#2827](Kozea/WeasyPrint#2827) <https://github.com/Kozea/WeasyPrint/pull/2827></code></em>: Set SVG title as alternative text</li> <li><code>[Stirling-Tools#2718](Kozea/WeasyPrint#2718) <https://github.com/Kozea/WeasyPrint/issues/2718></code>_: Provide a 'onedir' Windows executable</li> <li><code>[Stirling-Tools#2863](Kozea/WeasyPrint#2863) <https://github.com/Kozea/WeasyPrint/pull/2863></code>_: Support box-shadow</li> <li><code>[Stirling-Tools#2755](Kozea/WeasyPrint#2755) <https://github.com/Kozea/WeasyPrint/pull/2755></code>_: Support RTL SVG text anchoring</li> <li><code>[Stirling-Tools#2866](Kozea/WeasyPrint#2866) <https://github.com/Kozea/WeasyPrint/issues/2866></code>_: Don’t use f-strings in logs</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/Kozea/WeasyPrint/commit/4d3b7b6449e3494f59c7c2f36b512d129225679c"><code>4d3b7b6</code></a> Version 70.0</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/289e278439b017cd9263b4cd4727026987f86443"><code>289e278</code></a> Always use original URL fetcher when available</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/aeb3be74e3c904e4b772014006410e23e0512b4b"><code>aeb3be7</code></a> Merge remote-tracking branch 'security/main'</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/48357241f949c3f6880ec1a40f56d2f5106fdef3"><code>4835724</code></a> Merge pull request <a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2915">#2915</a> from havelaer/fix-nested-svg-viewport-restore</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/03310511d8afac08f80939e7fa317ad6051e251f"><code>0331051</code></a> Restore nested SVG viewport size on the SVG object, not the drawing function</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/e4b8b45e409392197441bc449d110f323b0eeb66"><code>e4b8b45</code></a> Add harfbuzz-vector requirement for Fedora</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/371e4debb4805fa3d5a138f2cbb044fc176284da"><code>371e4de</code></a> Merge pull request <a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2905">#2905</a> from Kozea/notes</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/590bf63301d77eaf6aac6b1eb3a3fbb9494e3b23"><code>590bf63</code></a> Merge pull request <a href="https://redirect.github.com/Kozea/WeasyPrint/issues/2913">#2913</a> from Kozea/fast-svg-paths</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/f6570c3038b60695f715b12c7805f6933e58490a"><code>f6570c3</code></a> Use a faster regex-based parser for SVG paths</li> <li><a href="https://github.com/Kozea/WeasyPrint/commit/bc0516240c5f8a1eaaf658621d52a09eebecdea9"><code>bc05162</code></a> Use faster deque for SVG vertices</li> <li>Additional commits viewable in <a href="https://github.com/Kozea/WeasyPrint/compare/v69.0...v70.0">compare view</a></li> </ul> </details> <br /> Updates `httpx2` from 2.10.0 to 2.12.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/pydantic/httpx2/releases">httpx2's releases</a>.</em></p> <blockquote> <h2>v2.12.0</h2> <h2>Highlights</h2> <h3>🛡️ Bounded response decompression</h3> <p><code>httpx2</code> now decodes <code>gzip</code>, <code>deflate</code>, Brotli, and Zstandard responses incrementally. Each decode step emits at most 1 MiB, so streaming a highly compressed response no longer requires materializing an entire inflated network chunk in memory (<a href="https://redirect.github.com/pydantic/httpx2/pull/1126">pydantic/httpx2#1126</a>).</p> <h3>📦 Shared Zstandard API</h3> <p>Python 3.13 and earlier now use <code>backports.zstd</code>, which provides the same bounded incremental decompression API as <code>compression.zstd</code> on Python 3.14 and later (<a href="https://redirect.github.com/pydantic/httpx2/pull/1146">pydantic/httpx2#1146</a>).</p> <h2>httpx2</h2> <h3>Changed</h3> <ul> <li>Use <code>backports.zstd</code> for Zstandard decoding on Python 3.13 and earlier by <a href="https://github.com/Kludex"><code>@Kludex</code></a> in <a href="https://redirect.github.com/pydantic/httpx2/pull/1146">pydantic/httpx2#1146</a></li> </ul> <h3>Fixed</h3> <ul> <li>Bound peak memory while streaming compressed responses and close response streams when decoding fails by <a href="https://github.com/Kludex"><code>@Kludex</code></a> in <a href="https://redirect.github.com/pydantic/httpx2/pull/1126">pydantic/httpx2#1126</a></li> </ul> <h2>httpcore2</h2> <p>No changes since <code>2.11.0</code>. Version bumped to stay in lockstep with <code>httpx2</code>.</p> <p><strong>Full Changelog</strong>: <a href="https://github.com/pydantic/httpx2/compare/v2.11.0...v2.12.0">https://github.com/pydantic/httpx2/compare/v2.11.0...v2.12.0</a></p> <h2>v2.11.0</h2> <h2>Highlights</h2> <h3>🌐 Public origin API</h3> <p><code>httpx2</code> now includes an immutable and hashable <code>Origin</code> value object, available through <code>URL.origin</code>. It provides normalized scheme, host, and effective port comparisons without including URL paths, queries, fragments, or credentials (<a href="https://redirect.github.com/pydantic/httpx2/pull/1134">pydantic/httpx2#1134</a>).</p> <h3>🛠️ Request compatibility and validation</h3> <ul> <li>Explicit <code>Transfer-Encoding</code> headers now take precedence over body-derived <code>Content-Length</code> headers (<a href="https://redirect.github.com/pydantic/httpx2/pull/1137">pydantic/httpx2#1137</a>).</li> <li>Deprecated status code aliases are available again (<a href="https://redirect.github.com/pydantic/httpx2/pull/1135">pydantic/httpx2#1135</a>).</li> <li>Multipart part headers are validated before serialization (<a href="https://redirect.github.com/pydantic/httpx2/pull/1142">pydantic/httpx2#1142</a>).</li> </ul> <h2>httpx2</h2> <h3>Added</h3> <ul> <li>Add the public <code>Origin</code> value object and <code>URL.origin</code> property by <a href="https://github.com/Kludex"><code>@Kludex</code></a> in <a href="https://redirect.github.com/pydantic/httpx2/pull/1134">pydantic/httpx2#1134</a></li> </ul> <h3>Changed</h3> <ul> <li>Require Brotli 1.2.0 or later for the <code>brotli</code> extra by <a href="https://github.com/Kludex"><code>@Kludex</code></a> in <a href="https://redirect.github.com/pydantic/httpx2/pull/1141">pydantic/httpx2#1141</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/pydantic/httpx2/blob/main/src/httpx2/CHANGELOG.md">httpx2's changelog</a>.</em></p> <blockquote> <h2>2.12.0 (August 18th, 2026)</h2> <h3>Changed</h3> <ul> <li>Use <code>backports.zstd</code> for Zstandard decoding on Python 3.13 and earlier. (<a href="https://redirect.github.com/pydantic/httpx2/pull/1146">#1146</a>)</li> </ul> <h3>Fixed</h3> <ul> <li>Bound peak memory while streaming compressed responses and close response streams when decoding fails. (<a href="https://redirect.github.com/pydantic/httpx2/pull/1126">#1126</a>)</li> </ul> <h2>2.11.0 (August 18th, 2026)</h2> <h3>Added</h3> <ul> <li>Add the public <code>Origin</code> value object and <code>URL.origin</code> property for normalized, hashable origin comparisons. (<a href="https://redirect.github.com/pydantic/httpx2/pull/1134">#1134</a>)</li> </ul> <h3>Changed</h3> <ul> <li>Require Brotli 1.2.0 or later for the <code>brotli</code> extra. (<a href="https://redirect.github.com/pydantic/httpx2/pull/1141">#1141</a>)</li> </ul> <h3>Fixed</h3> <ul> <li>Restore deprecated status code aliases. (<a href="https://redirect.github.com/pydantic/httpx2/pull/1135">#1135</a>)</li> <li>Extract HTTP/2 release notes from changelog headings correctly. (<a href="https://redirect.github.com/pydantic/httpx2/pull/1136">#1136</a>)</li> <li>Respect explicit <code>Transfer-Encoding</code> headers and expose buffered request body lengths to WSGI applications. (<a href="https://redirect.github.com/pydantic/httpx2/pull/1137">#1137</a>)</li> <li>Validate multipart part header names and values before serialization. (<a href="https://redirect.github.com/pydantic/httpx2/pull/1142">#1142</a>)</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/pydantic/httpx2/commit/71ae23be5448f859c2b4e21d9972ddfa7b8d759d"><code>71ae23b</code></a> Version 2.12.0 (<a href="https://redirect.github.com/pydantic/httpx2/issues/1147">#1147</a>)</li> <li><a href="https://github.com/pydantic/httpx2/commit/4fd0c70a3f207c618b145934792f791bccfb39f8"><code>4fd0c70</code></a> Decode compressed response bodies incrementally (<a href="https://redirect.github.com/pydantic/httpx2/issues/1126">#1126</a>)</li> <li><a href="https://github.com/pydantic/httpx2/commit/d588e528a11eb20323031ee571fadc668bb81b3f"><code>d588e52</code></a> Use <code>backports.zstd</code> on Python 3.13 and earlier (<a href="https://redirect.github.com/pydantic/httpx2/issues/1146">#1146</a>)</li> <li><a href="https://github.com/pydantic/httpx2/commit/344589da2a992f7e5a0c25c68cc78c25ec6d70bd"><code>344589d</code></a> Version 2.11.0 (<a href="https://redirect.github.com/pydantic/httpx2/issues/1143">#1143</a>)</li> <li><a href="https://github.com/pydantic/httpx2/commit/de96d810ee4e309d118982fe7084a46a2bcd600d"><code>de96d81</code></a> Validate multipart part headers (<a href="https://redirect.github.com/pydantic/httpx2/issues/1142">#1142</a>)</li> <li><a href="https://github.com/pydantic/httpx2/commit/51c32698ce029140cb69a26921d017e3edda80fa"><code>51c3269</code></a> Require brotli 1.2.0 in the brotli extra (<a href="https://redirect.github.com/pydantic/httpx2/issues/1141">#1141</a>)</li> <li><a href="https://github.com/pydantic/httpx2/commit/829b93a2393212996f613e635261f777d9ec6eab"><code>829b93a</code></a> Respect explicit Transfer-Encoding headers (<a href="https://redirect.github.com/pydantic/httpx2/issues/1137">#1137</a>)</li> <li><a href="https://github.com/pydantic/httpx2/commit/4fa6c8ee96fb79035c6820e4f44a10b6262d9c9f"><code>4fa6c8e</code></a> Fix changelog extraction regex for H2 release headings (<a href="https://redirect.github.com/pydantic/httpx2/issues/1136">#1136</a>)</li> <li><a href="https://github.com/pydantic/httpx2/commit/8a6f37063514ee2a2601607c20be72667fdfa3be"><code>8a6f370</code></a> Restore deprecated status code aliases (<a href="https://redirect.github.com/pydantic/httpx2/issues/1135">#1135</a>)</li> <li><a href="https://github.com/pydantic/httpx2/commit/d03f1ec6a1a323f951a8c21cd14f9c02f2d1e855"><code>d03f1ec</code></a> Add public Origin API (<a href="https://redirect.github.com/pydantic/httpx2/issues/1134">#1134</a>)</li> <li>See full diff in <a href="https://github.com/pydantic/httpx2/compare/v2.10.0...v2.12.0">compare view</a></li> </ul> </details> <br /> Updates `pypdf` from 6.16.1 to 6.19.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/py-pdf/pypdf/releases">pypdf's releases</a>.</em></p> <blockquote> <h2>Version 6.19.0, 2026-09-16</h2> <h2>What's new</h2> <h3>Security (SEC)</h3> <ul> <li>Limit size of alphabetical page labels (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4096">#4096</a>) by <a href="https://github.com/stefan6419846"><code>@stefan6419846</code></a></li> </ul> <h3>Deprecations (DEP)</h3> <ul> <li>Replace PdfWriter method add_js (<a href="https://redirect.github.com/py-pdf/pypdf/issues/3979">#3979</a>) by <a href="https://github.com/j-t-1"><code>@j-t-1</code></a></li> </ul> <h3>Performance Improvements (PI)</h3> <ul> <li>Move static value out of loop body for appearance stream data (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4087">#4087</a>) by <a href="https://github.com/stefan6419846"><code>@stefan6419846</code></a></li> <li>Reduce number of full data lookups for attachment mapping API (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4081">#4081</a>) by <a href="https://github.com/stefan6419846"><code>@stefan6419846</code></a></li> </ul> <h3>Bug Fixes (BUG)</h3> <ul> <li>Do not copy unrelated pages when appending pages with non-terminal fields (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4078">#4078</a>) by <a href="https://github.com/anandghegde"><code>@anandghegde</code></a></li> <li>Use page reference for existing internal link targets (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4076">#4076</a>) by <a href="https://github.com/r-kamei"><code>@r-kamei</code></a></li> <li>Arabic-Indic digits are reversed during text extraction (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4077">#4077</a>) by <a href="https://github.com/Syamjith-NK"><code>@Syamjith-NK</code></a></li> <li>Parse a string rect for add_uri into a rectangle (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4074">#4074</a>) by <a href="https://github.com/RavSinghChandan"><code>@RavSinghChandan</code></a></li> </ul> <p><a href="https://github.com/py-pdf/pypdf/compare/6.18.1...6.19.0">Full Changelog</a></p> <h2>Version 6.18.1, 2026-09-11</h2> <h2>What's new</h2> <h3>Security (SEC)</h3> <ul> <li>Further restrict FlateDecode recovery (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4073">#4073</a>) by <a href="https://github.com/stefan6419846"><code>@stefan6419846</code></a></li> <li>Limit entry count for TrueType and Type1 font <code>/Widths</code> (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4072">#4072</a>) by <a href="https://github.com/stefan6419846"><code>@stefan6419846</code></a></li> <li>Limit allowed length of tokens in parse_bfchar (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4071">#4071</a>) by <a href="https://github.com/stefan6419846"><code>@stefan6419846</code></a></li> </ul> <h3>Bug Fixes (BUG)</h3> <ul> <li>Use current text matrix for visitor_text (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4062">#4062</a>) by <a href="https://github.com/r-kamei"><code>@r-kamei</code></a></li> <li>Repeat the letter for /S /A and /S /a page labels past Z (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4065">#4065</a>) by <a href="https://github.com/youdie006"><code>@youdie006</code></a></li> <li>Use font color for FreeText default appearance (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4051">#4051</a>) by <a href="https://github.com/Yuki9814"><code>@Yuki9814</code></a></li> </ul> <h3>Robustness (ROB)</h3> <ul> <li>Fix compatibility with fonttools < 4.58.0 (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4050">#4050</a>, <a href="https://redirect.github.com/py-pdf/pypdf/issues/4059">#4059</a>) by <a href="https://github.com/MeggyCal"><code>@MeggyCal</code></a> and <a href="https://github.com/stefan6419846"><code>@stefan6419846</code></a></li> </ul> <h3>Documentation (DOC)</h3> <ul> <li>Use combined matrix in visitor examples (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4066">#4066</a>) by <a href="https://github.com/r-kamei"><code>@r-kamei</code></a></li> </ul> <p><a href="https://github.com/py-pdf/pypdf/compare/6.18.0...6.18.1">Full Changelog</a></p> <h2>Version 6.18.0, 2026-09-07</h2> <h2>What's new</h2> <p>Please note that this release requires users which previously overwrote the default limits to migrate to the new approach: <a href="https://pypdf.readthedocs.io/en/6.18.0/user/security.html#global">Docs</a></p> <p>In short:</p> <ul> <li>Use <code>apply_configuration</code> as a context manager to temporarily overwrite configuration values.</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/py-pdf/pypdf/blob/main/CHANGELOG.md">pypdf's changelog</a>.</em></p> <blockquote> <h2>Version 6.19.0, 2026-09-16</h2> <h3>Security (SEC)</h3> <ul> <li>Limit size of alphabetical page labels (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4096">#4096</a>)</li> </ul> <h3>Deprecations (DEP)</h3> <ul> <li>Replace PdfWriter method add_js (<a href="https://redirect.github.com/py-pdf/pypdf/issues/3979">#3979</a>)</li> </ul> <h3>Performance Improvements (PI)</h3> <ul> <li>Move static value out of loop body for appearance stream data (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4087">#4087</a>)</li> <li>Reduce number of full data lookups for attachment mapping API (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4081">#4081</a>)</li> </ul> <h3>Bug Fixes (BUG)</h3> <ul> <li>Do not copy unrelated pages when appending pages with non-terminal fields (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4078">#4078</a>)</li> <li>Use page reference for existing internal link targets (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4076">#4076</a>)</li> <li>Arabic-Indic digits are reversed during text extraction (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4077">#4077</a>)</li> <li>Parse a string rect for add_uri into a rectangle (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4074">#4074</a>)</li> </ul> <p><a href="https://github.com/py-pdf/pypdf/compare/6.18.1...6.19.0">Full Changelog</a></p> <h2>Version 6.18.1, 2026-09-11</h2> <h3>Security (SEC)</h3> <ul> <li>Further restrict FlateDecode recovery (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4073">#4073</a>)</li> <li>Limit entry count for TrueType and Type1 font <code>/Widths</code> (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4072">#4072</a>)</li> <li>Limit allowed length of tokens in parse_bfchar (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4071">#4071</a>)</li> </ul> <h3>Bug Fixes (BUG)</h3> <ul> <li>Use current text matrix for visitor_text (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4062">#4062</a>)</li> <li>Repeat the letter for /S /A and /S /a page labels past Z (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4065">#4065</a>)</li> <li>Use font color for FreeText default appearance (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4051">#4051</a>)</li> </ul> <h3>Robustness (ROB)</h3> <ul> <li>Fix compatibility with fonttools < 4.58.0 (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4050">#4050</a>, <a href="https://redirect.github.com/py-pdf/pypdf/issues/4059">#4059</a>)</li> </ul> <h3>Documentation (DOC)</h3> <ul> <li>Use combined matrix in visitor examples (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4066">#4066</a>)</li> </ul> <p><a href="https://github.com/py-pdf/pypdf/compare/6.18.0...6.18.1">Full Changelog</a></p> <h2>Version 6.18.0, 2026-09-07</h2> <h3>Security (SEC)</h3> <ul> <li>Limit allowed length of indirect object tokens (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4055">#4055</a>)</li> </ul> <h3>Deprecations (DEP)</h3> <ul> <li>Rework configuration value handling (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4044">#4044</a>)</li> </ul> <h3>New Features (ENH)</h3> <ul> <li>Draw borders and backgrounds for appearance streams and annotations (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4033">#4033</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/py-pdf/pypdf/commit/d62cb58d3988b291b0435eddfd118c4f8f6b6a46"><code>d62cb58</code></a> REL: 6.19.0</li> <li><a href="https://github.com/py-pdf/pypdf/commit/0d8b5a8832cde1ba308b5c27567b879b7b7eed4a"><code>0d8b5a8</code></a> SEC: Limit size of alphabetical page labels (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4096">#4096</a>)</li> <li><a href="https://github.com/py-pdf/pypdf/commit/959467a9b95be83e2dc5ae873ece5f371263ede7"><code>959467a</code></a> PI: Move static value out of loop body for appearance stream data (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4087">#4087</a>)</li> <li><a href="https://github.com/py-pdf/pypdf/commit/20822b263f063c96ad535405f5b8c4d81768950b"><code>20822b2</code></a> DEV: Bump zizmorcore/zizmor-action from 0.6.3 to 0.6.4 (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4093">#4093</a>)</li> <li><a href="https://github.com/py-pdf/pypdf/commit/25f230191b89cdcf2b4ba3d8051d52c7392831d0"><code>25f2301</code></a> DEP: Replace PdfWriter method add_js (<a href="https://redirect.github.com/py-pdf/pypdf/issues/3979">#3979</a>)</li> <li><a href="https://github.com/py-pdf/pypdf/commit/a92443848fda10cc2a65a7b6397fd8e1986c17d2"><code>a924438</code></a> BUG: Do not copy unrelated pages when appending pages with non-terminal field...</li> <li><a href="https://github.com/py-pdf/pypdf/commit/cf5cec2e49b9da8fae0d82a0f99f1bfe9eceb8ed"><code>cf5cec2</code></a> BUG: Use page reference for existing internal link targets (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4076">#4076</a>)</li> <li><a href="https://github.com/py-pdf/pypdf/commit/96d81f05ba4b3ec9ff1b3c3e52bc71a3cdd702c7"><code>96d81f0</code></a> BUG: Arabic-Indic digits are reversed during text extraction (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4077">#4077</a>)</li> <li><a href="https://github.com/py-pdf/pypdf/commit/2d219015b4cf92edcfd6d28c564295f0704fd204"><code>2d21901</code></a> DEV: Fix Color class for latest mypy (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4082">#4082</a>)</li> <li><a href="https://github.com/py-pdf/pypdf/commit/893a01002aa8e23b3a61ae4b38ab74edbc904ab9"><code>893a010</code></a> MAINT: Split PdfDocCommon._flatten (<a href="https://redirect.github.com/py-pdf/pypdf/issues/4070">#4070</a>)</li> <li>Additional commits viewable in <a href="https://github.com/py-pdf/pypdf/compare/6.16.1...6.19.0">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This pull request adds an initial support of CSS Notes, including:
@note-areaor in page margins,::note-call,::note-callbackand::note-markerpseudo-elements,note()function,all-onceparameter of theelement()function.It does not include other features, defined in this specification draft or elsewhere, including:
note-policyproperty,