Skip to content

chore(deps): update python packages - #294

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/python-packages
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/python-packages

Conversation

@renovate

@renovate renovate Bot commented Jun 20, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Update Change
Ousret/charset_normalizer minor 3.4.7 → 3.5.2
certifi/python-certifi minor 2026.05.20 → 2026.07.22
contourpy/contourpy minor v1.3.3 → v1.4.0
fonttools/fonttools minor 4.63.0 → 4.66.1
kjd/idna minor v3.17 → v3.20
matplotlib/matplotlib minor v3.10.9 → v3.11.2
nucleic/kiwi patch 1.5.0 → 1.5.1
numpy/numpy minor v2.4.6 → v2.6.0.dev0
pandas-dev/pandas minor v3.0.3 → v3.1.0.dev0
pypa/packaging minor 26.2 → 26.3
pyparsing/pyparsing patch 3.3.2 → 3.3.3
python-pillow/Pillow minor 12.2.0 → 12.3.0
scipy/scipy minor v1.17.1 → v1.18.1
urllib3/urllib3 minor 2.7.0 → 2.8.0

Release Notes

Ousret/charset_normalizer (Ousret/charset_normalizer)

v3.5.2

Compare Source

Changed
  • Raised the Cython upper bound to <3.4 for native builds. The bound remains <3.3 for
    abi3 builds to preserve compatibility with the Python 3.7 Limited API.
Fixed
  • Valid UTF-8 Chinese JSON incorrectly detected as PTCP154 due to excessive noise penalties
    for uncommon CJK characters. (#​796)
  • Supported encodings without aliases failing name resolution or being ignored in charset
    declarations. (#​800)

v3.5.1

Compare Source

Changed
  • Raised upper bound of setuptools to v84 (#​794)
  • Cache performance access optimization for our CharInfo struct (prebuilt only).
Fixed
  • No longer decoding large content when the noise detector output give a high entropy.
    Only impacted large content input >1M bytes.

v3.5.0

Compare Source

Added
  • Explicit support for Python 3.15
Fixed
  • Comparing a CharsetMatch to a non-alias encoding strings (#​773)
  • Return 0.0 CharsetMatch.multi_byte_usage for empty payloads instead of crashing (#​774)
  • A file with both a charset declaration and BOM/SIG did not verify first the BOM/SIG charset.
  • iso2022* cases misdetected due to a flaw in our multibyte chunking logic.
Changed
  • Replaced the optional mypyc build with Cython extensions while retaining the
    pure Python fallback. The previous engine (mypyc) started to hit rough limit around
    the optimization of our noise/coherence detector while Cython allows us to
    steer the engine toward the right generated optimized sources.
    This change SHOULD not impact bundler (e.g. Pyinstaller) as the module are
    immediately discoverable (i.e. not hidden import like mypyc did).
    Moreover, a long wished distribution is the abi3 wheels, this will allow us
    to no longer rush each year when a new Python interpreter is released.
    We still distribute the interpreter specific wheels for faster performance.
  • Applied micro-optimization on several utils.
  • CharsetMatches no longer sort on each match insertion.
Misc
  • Removed an old performance optimization attempt in apy.py (success_fast_tracked+payload_result_cache).

v3.4.9

Compare Source

Fixed
  • Regression in our fallback path leading to a decode error. (#​771)
    We've yanked 3.4.8 as a result of that bug.

v3.4.8

Compare Source

Fixed
  • Wall import time due to cascade codec imports for our multibyte first sort of iana supported codecs (#​742)
  • Unnecessary json import at runtime (#​753)
  • Inverse capitalization not seen by noise detector (#​731)
Changed
  • No longer holding a global cache for our noise / coherence measurements. Relax RSS memory usage.
  • Micro-optimizations in our noise / coherence measurements.
  • No longer using regex search by default for our preemptive charset mark algorithm.
  • Raised upperbound of setuptools to v83.
  • Raised upperbound of mypy(c) to v2.1.
Removed
  • Redundant UTF7 BOM marker (#​730)
certifi/python-certifi (certifi/python-certifi)

v2026.07.22

Compare Source

v2026.06.17

Compare Source

contourpy/contourpy (contourpy/contourpy)

v1.4.0: Version 1.4.0

Compare Source

ContourPy 1.4.0 introduces a new readonly property ContourGenerator.name for the algorithm name, adds support for CPython 3.15, and is the first release to upload pyodide wheels to PyPI. Support for riscv64 and iOS architectures is added but considered experimental, wheels are available from the Scientific Python Nightly Wheels service but not PyPI.

Enhancements:

  • Add ContourGenerator.name readonly property (#​566)

Compatibility:

Code improvements:

  • Remove unused ntotal argument in mpl2005 build_cntr_list_v2 (#​550)

Documentation improvements:

  • Use myst markdown for documentation instead of RST (#​551)
  • Switch docs to sphinx book theme (#​552)

Build, testing and CI improvements:

  • Switch from macos-13 to macos-15-intel github runners (#​507)
  • Fully test on python 3.14 (#​509)
  • Build intel mac wheels on macos-15-intel runner (#​513)
  • Update license metadata to use PEP 639 (#​525)
  • Update test images for bokeh 3.9.0 (#​533)
  • Remove use of cirrus CI (#​537)
  • Add zizmor to pre-commit (#​546)
  • Remove testing on python 3.13t (#​555)
  • Update test images and thresholds (#​542, #​561)
fonttools/fonttools (fonttools/fonttools)

v4.66.1

Compare Source

  • [designspaceLib] When splitting a DesignSpace v5 document with makeNames=True (as varLib.build_many does), family and style names set explicitly on an instance now take precedence over the ones computed from the STAT labels, in all languages, and a PostScript name is no longer made up from the labels for an instance that has its own style name (#​3131, #​4206, #​4208).
  • [cmap] Decompiling a format 4 subtable whose idRangeOffset points outside glyphIndexArray now raises TTLibError. A negative index used to silently map the code point to the wrong glyph, and one past the end raised a bare AssertionError (#​4209).
  • [cmap] Fix compiling a format 2 subtable when the lowest glyph ID in a lead-byte row is 32768 or higher, which failed with struct.error (#​4210).

v4.66.0

Compare Source

  • Drop support for EOL Python 3.10; fontTools now requires Python 3.11 or later. fontTools.misc.enumTools now only re-exports enum.StrEnum and is deprecated. Explicitly test and declare support for Python 3.15 (#​4183, #​4196).
  • [unicodedata] Update the bundled script, script extension, block and bidi-mirroring tables to Unicode 18.0.0, and require unicodedata2 18.0.0 when it is used (#​4192, #​4197).
  • [feaLib] Support language statements listing multiple language tags, e.g. language AZE CRT;, as Glyphs does and as proposed for the spec (adobe-type-tools/feature_file_workshops#8): the following rules and lookup references are registered under every listed language. dflt cannot be combined with other tags. LanguageStatement.language is still the first tag; all of them are in the new languages attribute (#​4201, #​4202).
  • [feaLib] Fix lookups being dropped when a script/language pair is repeated within a feature block: the repeated statement replaced the language system's lookups with a fresh copy of the default ones (#​4189).
  • [feaLib] Raise FeatureLibError instead of UnboundLocalError when a STAT table block lacks ElidedFallbackName or ElidedFallbackNameID (#​3834, #​4179).
  • [cffLib] Always recompile the CFF2 VarStore when saving. Previously the bytes compiled by an earlier save were reused, so a CFF2 variable font that was saved and then modified in place, e.g. by the instancer, was written with a stale VarStore next to its updated charstrings (#​4199).
  • [ttLib] Support static VARC fonts that omit fvar while retaining gvar or CFF2 variation data for component-internal axes: hidden axes are addressed by index and gvar can compile, decompile and round-trip through TTX without fvar, reading the axis count from a new axisCount element (#​4187, #​4188).
  • [ttLib] Fix drawing VARC components whose condition is negated (format 5), which raised AttributeError (#​4191).
  • [instancer] Fix VARC axis references left stale when removing an unrelated axis, reject pinning or restricting axes referenced by VARC components, and stop culling avar2 ranges for component-internal variations, which can reach outside the font-level ranges (#​4190, #​4193).
  • [bezierTools] Preserve exact endpoints in splitQuadraticAtT and splitCubicAtTC as well, like splitCubicAtT since 4.55.4 (#​3742, #​4194).
  • [bezierTools] Fix ZeroDivisionError in lineLineIntersections for collinear vertical lines; they are now treated as parallel like horizontal ones (#​3515, #​4181).
  • [subset] pyftsubset now preserves the input font's flavor (WOFF, WOFF2) when --flavor is omitted, instead of writing uncompressed sfnt data under the same extension; pass --flavor=none to force uncompressed output (#​3630, #​4182).
  • [merge] Report incompatible unitsPerEm values by name, with the input values, instead of a bare assertion (#​2844, #​4184).
  • [designspaceLib] Fix the type annotation and documentation of DesignSpaceDocument.default, which holds a SourceDescriptor, not a source name (#​2994, #​4186).
  • [ttLib.sfnt] Raise TTLibError instead of AssertionError for inconsistent WOFF table, metadata and private-data lengths, so the checks also hold under python -O (#​4178).
  • [misc.etree] Disable entity resolution altogether on lxml >= 5.0 as well: lxml's resolve_entities="internal" still fetched external parameter entities before lxml 6.1.3, so a crafted DTD could read local files into parsed XML content (#​4195).
  • [cmap] Bound the expansion of format 4 segments and format 12/13 groups when decompiling, like HarfBuzz does: groups are clamped to U+10FFFF, inverted or overlapping groups are skipped with a warning, and groups mapped to the missing glyph are not expanded. A crafted font could previously exhaust memory with a single group ending at 0xFFFFFFFF (#​4204).
  • [varLib.avar] Escape axis names and tags when varLib.avar.unbuild emits its designspace snippet, so a crafted font cannot inject markup (#​4203).

v4.65.0

Compare Source

  • [glyf] Add __iter__, items and values methods to the glyf table to make it more dict-like (#​4156).
  • [feaLib] Escape the anonymous block tag when scanning for its terminator, so tags containing regex metacharacters are matched literally (#​4167).
  • [varLib] Strip directory components from <variable-font name="..."/> when deriving the output filename in the varLib command line, so a designspace cannot write outside the output directory (#​4168).
  • [feaLib] Fix tracking of the current script and language across redundant script statements. Rules following a script statement that names the first declared language system no longer end up under the DFLT script, and a script statement naming the already-current script still narrows the language systems and terminates the current lookup while leaving the lookupflag alone, matching makeotf (#​1824, #​2522, #​4169).
  • [varLib.interpolatable] Escape glyph names in the HTML report (#​4172).
  • [otlLib] Fix overflow handling when building contextual lookups: offset overflows now raise OTLOffsetOverflowError instead of AttributeError so another contextual format can be tried (regression from #​3439). When all formats overflow, split the ruleset in halves until it fits (#​4171).

v4.64.0

Compare Source

  • [feaLib] Fix name-table parsing for multibyte Mac encodings (#​1196, #​4092).
  • [ttProgram] Also indent TrueType assembly following IDEF[ ], like function definitions (#​4093).
  • [subset] Keep East Asian spacing palt by default (#​4094).
  • [subset] Bug fix for MATH table in which constructions for glyphs that are only added during MATH closure were kept (#​4096).
  • [ufoLib] Make glyph-to-group construction accessible outside of lookup function (#​4102).
  • [glyf] Use reverse glyph map for O(1) __setitem__ membership (#​4103).
  • [ttLib] Fix fixLookupOverFlows() reporting success when it had not promoted any lookup to Extension, masking unresolvable overflows.
  • [ttLib] Add support for TrueType Collection version 2 (#​4100).
  • [ttLib] Pin a single head.modified timestamp across TTCollection.save (#​4111).
  • [ttLib] Give an actionable error when LookupList overflow is unrecoverable (#​4109).
  • [ttLib] Add support for the AAT bitmap tables bhed, bdat, bloc, variants of head, EBDT, EBLC used in legacy Apple bitmap-only fonts (#​4115).
  • [ttLib] Check OS/2 fsSelection/macStyle consistency against bhed as well as head (#​4118, #​4119).
  • [misc.roundTools] Add types and documentation (#​4123).
  • [varLib.instancer] Instance the BASE table (#​4137).
  • [varLib.instancer] Fix Private-dict vsindex handling in instantiateCFF2 (#​4129, #​4132).
  • [varLib.instancer] Fix crash instancing CFF2 fonts without a VariationStore (#​4130, #​4131).
  • [sfnt] Raise TTLibError instead of AssertionError or struct.error when reading a font truncated within the table directory or a table entry (#​4147, #​4149).
  • [misc.xmlWriter] Escape the ]]> terminator inside CDATA sections, so an SVG document containing it can no longer smuggle markup past a TTX round trip (#​4139).
  • [varLib.instancer] Implement avar2 partial-instancing: the avar version 2 ItemVariationStore is adjusted so that remaining axes behave the same after limiting the designspace (#​4045).
  • [feaLib] Add shorthand for the value at the default location in a variable scalar: (100 wght=900:120) means (wght=400:100 wght=900:120) when the wght default is 400 (#​4024).
  • [cmap] Raise TTLibError for a truncated or out-of-bounds cmap subtable header (#​4151).
  • [designspaceLib] Reject conflicting duplicate inputs in axis maps instead of silently keeping the last one (#​4153).
  • [designspaceLib] Read an empty <lib> element as an empty lib instead of raising IndexError (#​4142, #​4144).
  • [colorLib] Raise a legible error when a COLRv0 layer, or a COLRv1 PaintGlyph or PaintColrGlyph, references a glyph missing from the glyphMap, instead of failing obscurely later (#​2629, #​4141).
  • [cmap] Don't drop subtables in unsupported formats when compiling or dumping a font read from binary (#​4136).
  • [ttLib] Implement splitSinglePos so GPOS lookup type 1 offset overflows can be recovered by splitting the subtable (#​4091, #​4108).
  • [cmap] Round-trip empty Macintosh format 2 subtables (#​3663, #​4117).
  • [glyf] Raise TTLibError instead of RecursionError when recalcBounds() hits a composite-component reference cycle (#​3899, #​4116).
  • [svgLib] Fix crash parsing an SVG path with consecutive closepath commands (Z Z) (#​4122).
  • [ttLib] Fix DefaultTable type annotations (#​4126).
  • [ttLib] Add support for the EBSC (Embedded Bitmap Scaling) table (#​4113).
  • [svgLib] Suppress spurious close segments caused by floating-point drift in relative path commands (#​3860, #​4127).
  • [qu2cu] Fix TypeError in the Cython-compiled build when Qu2CuPen passes tuple splines (#​4160).
  • [mort] Add semantic decompilation, TTX, and compilation support for rearrangement, contextual-substitution, ligature, and insertion subtables (#​4158, #​4159, #​4161).
  • [svgLib] Start a new subpath at the just-closed subpath's initial point when a drawto command follows a closepath, per SVG spec (#​4154, #​4155).
  • [misc.filesystem] SECURITY Reject paths that resolve outside the filesystem root: a malicious UFO could read arbitrary files via .. components in contents.plist, and a crafted .ufoz could create files outside its temporary mirror (#​4124).
  • [ttLib] SECURITY Sanitise glyph names used as filenames in EBDT/CBDT ttx -z extfile export, preventing arbitrary file writes from untrusted fonts (#​4128).
  • [misc.etree] SECURITY Don't resolve external XML entities in XMLParser when lxml is used, preventing XXE file disclosure on lxml < 5.0 (#​4145).
  • [subset] Fully prune VARC auxiliary data: collect and remap variation indices referenced by condition tables when subsetting the MultiVarStore, and drop the AxisIndicesList, ConditionList, and MultiVarStore when they end up empty (#​4162).
kjd/idna (kjd/idna)

v3.20

Compare Source

  • Update to Unicode 18.0.0.
  • Better enforcement of the domain length limit in the incremental
    codec.
  • Add support for Python 3.15.

v3.19

Compare Source

  • Restore the std3_rules option, which had no effect since changes
    to UTS #​46 processing in Unicode 16. Note that uts46_remap()
    defaults to enabling STD3 rules, so direct callers will see input
    containing non-LDH ASCII characters rejected again.
  • Performance improvements to UTS #​46 mapping, particularly for
    ASCII-only domains.
  • Test on free-threaded CPython with the GIL disabled and document
    thread safety.
  • Expose the Unicode version of the generated tables as
    idna.unicode_version, and show it in idna --version.
  • Add code, text, codepoint and position attributes to
    IDNAError so that the failed rule and the offending character can
    be identified without parsing the exception message.
  • The deprecated transitional argument to encode() and
    uts46_remap() is now completely ignored, and gives a deprecation warning
    for the latter.
  • Reject A-labels that are not the canonical Punycode encoding of
    their U-label.
  • Fix CONTEXTJ violations raising IDNAError instead of
    InvalidCodepointContext.
  • Consistently raise IDNAError for empty labels and non-ASCII bytes
    passed to label helper functions and the incremental codec.
  • Add property-based tests, extended fuzzing targets, coverage
    measurement, and CI checks that the data tables match the generator
    output.
  • Various code quality and tooling improvements.

Thanks to stefan6419846, LouieLuNZ, and Salvatore Corvaglia for
contributions to this release.

v3.18

Compare Source

matplotlib/matplotlib (matplotlib/matplotlib)

v3.11.2: REL: v3.11.2

Compare Source

This is the second bugfix release of the 3.11.x series.

This release contains several bug-fixes and adjustments:

  • Speed up RGBA-stage image resampling
  • Fix hexbin clipping in PDF output
  • Fix \text with internal braces
  • Fix some crashes and make some checks more robust to unlikely cases
  • Fix frame skew when saving GIF animations with PillowWriter
  • Fix HiDPI handling in Qt toolbar and WebAgg embeddings
  • Fix ResizeEvent handling for TextBox
  • Fix bug with PGF hatch linewidth and color
  • Fix a bug with drawing an empty Collection
  • Fix incorrect glyphs in Cairo backends
  • Improve build system to prevent conflicts between wheels and system libraries

v3.11.1: REL: v3.11.1

Compare Source

This is the first bugfix release of the 3.11.x series.

This release contains several bug-fixes and adjustments:

  • Fix tight layout of multiple subplots with sharey=True
  • Fix NoNorm cursor formatting for uint8 images
  • Fix occasional misalignment in reported mouse position (also fix a bug with canvas height)
  • Fix clipped Axis labels on 3D plots with tight layout
  • Fix inverted Axis on 3D plots
  • Fix restoring 'auto' aspect in 3D axes after switching from 'equal'
  • Fix missing glyphs when subsetting Type 1 fonts in PDF
  • Fix oversized embedding of Type 42 fonts in PDF/PostScript files

As well as several documentation and typing improvements and corrections.

v3.11.0: REL: v3.11.0

Compare Source

The largest change within this release is a complete overhaul of text and font processing. Through the use of libraqm, HarfBuzz, SheenBidi, and an updated release of FreeType, all text should now support modern font features, enabling full internationalization in all languages. Not all features of these libraries are supported yet, but we expect this work to enable further improvements in an easier manner.

Outside of text handling, there are several improvements to 3D Axes, performance, new accessible colour sequences, flexible figure management, and more. See the release notes for more information.

v3.11.0rc2: REL: v3.11.0rc2

Compare Source

This is the second release candidate for the meso release 3.11.0.

This release candidate fixes some problems with downstream packages, removes some missed deprecations, and corrects some additional minor bugs.

v3.11.0rc1: REL: v3.11.0rc1

Compare Source

After an extended development stretch, we are pleased to announce the first release candidate of Matplotlib 3.11.0.

The largest change within this release is a complete overhaul of text and font processing. Through the use of libraqm, HarfBuzz, SheenBidi, and an updated release of FreeType, all text should now support modern font features, enabling full internationalization in all languages. Not all features of these libraries are supported yet, but we expect this work to enable further improvements in an easier manner. Due to the update to the font rendering stack, we cannot guarantee that text will be bit-for-bit perfect with previous releases, so if you are using Matplotlib for testing, it may be necessary to introduce/raise a tolerance within your tests.

Outside of text handling, there are several improvements to 3D Axes, performance, new accessible colour sequences, flexible figure management, and more. Final release notes are still being curated, but you may browse the list of new features, API changes, and all issues/pull requests on the milestone.

As a note for downstream packagers, the font libraries have only been tested against the versions bundled with the wheels. It may be possible to expand the range of requirements, or that a requirement is too broad. Please report any issues you have building against external dependencies.

nucleic/kiwi (nucleic/kiwi)

v1.5.1

Compare Source

  • add support for Python 3.15 PR #​243
  • fix bad version reported in C++ code PR #​243
numpy/numpy (numpy/numpy)

v2.6.0.dev0

Compare Source

v2.5.3: (Sep 6, 2026)

Compare Source

NumPy 2.5.3 Release Notes

The NumPy 2.5.3 is a patch release that fixes bugs discovered after the 2.5.2
release. Apart from the usual bug and maintenance work, there are a number of
StringDType related fixes for problems discovered during the ongoing string
work in the main branch.

This release supports Python versions 3.12-3.15

Changes

  • Casting a fixed-width byte string array (np.bytes_) to StringDType
    now raises TypeError when the bytes are not valid UTF-8. Previously the
    invalid bytes were stored as-is and later caused undefined behavior in
    string operations.

    (gh-32296)

  • MaskedArray._fill_value would become stale when ufuncs that change dtype
    left the result holding a fill_value typed for the old dtype. The mismatch
    was silent until something later called _check_fill_value, such as
    .view(), and then a TypeError would be raised. Now, when the copied
    fill_value is no longer valid for the new dtype, fall back to the
    default fill_value for that dtype instead of propagating the stale value.
    This may raise a ComplexWarning if the fill_value is complex and the
    new dtype is real.

    (gh-32423)

Contributors

A total of 9 people contributed to this release. People with a "+" by their
names contributed a patch for the first time.

  • Charles Harris
  • Iason Krommydas
  • James Davies +
  • Joren Hammudoglu
  • Maanas Arora
  • Matti Picus
  • Nathan Goldbaum
  • Shikhar Goel +
  • Yeonho Kim +

Pull requests merged

A total of 27 pull requests were merged for this release.

  • #​32235: MAINT: Prepare 2.5.x for further development
  • #​32289: BUG: raise ValueError when reading into record array with references...
  • #​32290: BUG: avoid uninitialized memory access / NULL-pointer deref in...
  • #​32291: TYP: fix np.random.{get,set}_bit_generator implicit re-exports...
  • #​32292: BUG: don't assume strides are a multiple of itemsize in stringdtype...
  • #​32293: CI: fix ccache CC override, add CXX in mac Conda CI (#​32285)
  • #​32303: BUG: Fix ref leak in [convert_from_type]{#convert_from_type} for custom scalar types...
  • #​32304: BUG: fix a number of issues around iterators and StringDType...
  • #​32326: TST: avoid allocating huge tuple of arrays in concatenate test...
  • #​32338: BUG: avoid possible UB in 'safe' multiplication helpers (#​32294)
  • #​32339: MAINT: use PyObject_ functions instead of raw PyArray_ ones (#​32331)
  • #​32378: BUG: validate UTF-8 and harden StringDType bounds handling (#​32296)
  • #​32380: BUG: fix two error handling mistakes in stringdtype replace loop...
  • #​32381: BUG: fix visibility annotations for functions in StringDType...
  • #​32384: MAINT: Update ml_dtypes pin to 8/21/2026.
  • #​32385: MAINT: Update numpy/_core/src/umath/svml
  • #​32410: MAINT: skip failing cython limited API tests on Cython 3.3.0...
  • #​32427: BUG: close duplicated file descriptor if fdopen fails (#​32386)
  • #​32428: MAINT: add missing space in warning and error messages (#​32405)
  • #​32430: BUG: fix error handling in StringDType to fixed-width bytes case...
  • #​32441: MAINT: Only run nightly BLAS tests on main.
  • #​32471: BUG: fix memory leak in StringDType creation error path (#​32470)
  • #​32477: BUG: fix stale fill_value after ufuncs change MaskedArray dtype...
  • #​32478: MAINT: exit deadlock tests quickly on slow hardware (#​32466)
  • #​32481: BUG: Backport StringDType byteorder fixes
  • #​32506: DOC: use static scipy doc site for intershpinx (#​32503)
  • #​32509: BUG: fix crash in ufunc.resolve_dtypes with a Python scalar type...

v2.5.2: (Aug 9, 2026)

Compare Source

NumPy 2.5.2 Release Notes

The NumPy 2.5.2 is a patch release that fixes bugs discovered after the 2.5.1
release. The big news is that it includes wheels for the newly released
Python 3.15.0rc1.

This release supports Python versions 3.12-3.15

C API changes

PyArray_StringDTypeObject is opaque under the abi3t stable ABI

The PyArray_StringDTypeObject was accidentally exposed in NumPy
2.5 when targeting the free-threading-compatible stable ABI
(Py_TARGET_ABI3T). PyArray_StringDTypeObject is now an opaque
struct: extensions compiled that way cannot access its fields, since
the struct layout depends on the size of the object header. Any code
that accessed PyArray_StringDTypeObject fields in an abi3t build
would have crashed, so we are making this API change in a bugfix
release.

The NpyString allocator API remains usable by passing the
descriptor object pointer, e.g.
NpyString_acquire_allocator((PyArray_StringDTypeObject *)descr).

(gh-31771)

Contributors

A total of 16 people contributed to this release. People with a "+" by their
names contributed a patch for the first time.

  • Abhijeetsingh Meena +
  • Charalampos Stratakis
  • Charles Harris
  • Chris Ninham +
  • David Woods
  • Geonho +
  • Gopu Yeshwanth Reddy +
  • Iason Krommydas
  • Ijtihed Kilani
  • Jelle Zijlstra +
  • Joren Hammudoglu
  • Kumar Aditya
  • Mike Boyle
  • Nathan Goldbaum
  • Raghuveer Devulapalli
  • Sebastian Berg

Pull requests merged

A total of 28 pull requests were merged for this release.

  • #​31864: MAINT: Prepare 2.5.x for further development
  • #​31889: TYP: Backport multiple static typing fixes 1.
  • #​31900: TST: add tests for stable ABI numpy extensions (#​31822)
  • #​31901: BUG: fix StringDType coerce flag in binary ufunc promotion...
  • #​31902: BLD: fix meson deprecation warnings (#​31892)
  • #​31921: TYP: Backport multiple typing fixes 2.
  • #​31947: MAINT: Update x86-simd-sort subproject (5adb334 → fa944ef) (#​31908)
  • #​31949: BUG: fix crash on 32 bit systems using abi3t (#​31771)
  • #​31950: MNT: remove some obsolete string to bool workarounds (#​31859)
  • #​31952: BUG: centralized helper for output coerce and na_object in stringdtype...
  • #​31953: BUG: fix CPU feature env diagnostic buffer overruns (#​31905)
  • #​31954: BUG: restore ndarray.conjugate() for legacy user-defined dtypes...
  • #​31955: TYP: Avoid shadowed dtype annotations
  • #​32077: MAINT: Update verdored-meson/meson to match main.
  • #​32114: BUG: fix refcount leak on overlapping copyto with where=False
  • #​32115: BUG: fix swallowed cast error in fancy indexing assignment (#​31975)
  • #​32116: BUG: Fix buffered iterator stride after removing multi-index
  • #​32117: BUG: fix np.fromiter corruption when reusing a StringDType...
  • #​32119: BUG: add a special case for StringDType in np.isdtype (#​32030)
  • #​32121: BUG: reference leak in simd_sequence_from_iterable (#​32038)
  • #​32122: BUG: ensure lock is held when accessing or writing to RNG state...
  • #​32123: BUG: fully reset cached RNG state for non-MT19937 RNGs (#​32062)
  • #​32135: TYP: type capabilities max dimensions
  • #​32158: BUG: avoid possible stack overflow in arraydescr_dealloc (#​32133)
  • #​32206: MAINT: Update cibuildwheel to v4.2.0
  • #​32214: MAINT: Skip limited_api tests on some platforms.
  • #​32220: TYP: isclose shape-typing fix for 2d array-likes (#​32205)
  • #​32221: BUG: avoid segfaults when legacy copyswap slot is not defined...

v2.5.1: (July 4, 2026)

Compare Source

NumPy 2.5.1 Release Notes

The NumPy 2.5.1 is a patch release that fixes bugs discovered after the 2.5.0
release. The most noticeable is the fix is to the numpy datetime cython API
which should allow downstream to support NumPy versions older than 2.5.
Preparation for Python 3.15 continues along with typing improvements.

This release supports Python versions 3.12-3.14

Changes

  • The minimum supported GCC version has been updated from 9.3.0 to 10.3.0

    (gh-31843)

Contributors

A total of 10 people contributed to this release. People with a "+" by their
names contributed a patch for the first time.

  • Adhyan Gupta +
  • Ankit Ahlawat
  • Charles Harris
  • Iason Krommydas
  • Joren Hammudoglu
  • Kumar Aditya
  • Nathan Goldbaum
  • Sebastian Berg
  • Ties Jan Hefting +
  • Vineet Kumar

Pull requests merged

A total of 20 pull requests were merged for this release.

  • #​31707: MAINT: Prepare 2.5.x for further development
  • #​31721: CI: fix new cython-lint errors (#​31711)
  • #​31723: MAINT: Update meson to match main
  • #​31729: TST: use setup-sde instead of curl to get SDE binaries (#​31727)
  • #​31829: BUG: Relax finfo to be easier accessible for all user dtypes...
  • #​31831: TYP: Fix flatiter.__next__ return type for object_ and...
  • #​31832: BUG: avoid deadlocks using NpyString API (#​31682)
  • #​31833: BUG: fix out array leak in reduceat and accumulate when dtype...
  • #​31835: BUG: fix numpy datetime cython APIs to be compatible with older...
  • #​31836: TYP: Fix incorrect dtype inference of asarray([]) (#​31732)
  • #​31837: TYP: Fix np.ma.masked_array 2.5.0 regression
  • #​31838: FIX: Refactor error handling in array_setstate to prevent typecode...
  • #​31839: TST: xfail multithreaded BLAS test more generously
  • #​31840: MAINT: Rename subroutine for crackfortran tests
  • #​31842: BUG: fix leak in reductions when a ufunc override errors or is...
  • #​31849: BLD: set minimum required gcc version to 10.3 (#​31843)
  • #​31855: CI: fix hangs on MacOS ASan CI (#​31853)
  • #​31856: BUG: fix several bugs in StringDType operations (#​31846)
  • #​31857: BUG: Fix segfault in MT19937 by preventing recursive seed lists...
  • #​31858: BUG: Fix signed integer overflow in datetime.c (#​31688)

v2.5.0: (June 21, 2026)

Compare Source

NumPy 2.5.0 Release Notes

Numpy 2.5.0 is a transitional release. It drops support for Python 3.11,
marking the end of distutils, and expires a large number of deprecations made
in the 2.0.x release. It also improves free threading and brings sorting into
compliance with the array-api standard with the addition of descending sorts.
There is also a fair amount of preparation for Python 3.15, which will be
supported starting with the first rc.

This release supports Python versions 3.12-3.14.

Highlights

  • Distutils has been removed,
  • Many expired deprecations, see below,
  • Many new deprecations, see below,
  • Many static typing improvements.
  • Improved support for free threading,
  • Support for descending sorts,

See New Features below for other additions.

Deprecations

  • numpy.char.chararray is deprecated. Use an ndarray with a string or bytes dtype instead.

    (gh-30605)

  • numpy.take now correctly checks if the result can be cast to the provided
    out=out under the same-kind rule. A DeprecationWarning is given now
    when this check fails. Previously, take incorrectly checked if out
    could be cast to the result (the wrong direction). This deprecation also
    affects compress and possibly other functions. (Future versions of NumPy
    may tighten the casting check further.)

    (gh-30615)

  • The numpy.char.[as]array functions are deprecated. Use an
    numpy.[as]array with a string or bytes dtype instead.

    (gh-30802)

  • Setting the dtype attribute is deprecated because mutating an array is unsafe
    if an array is shared, especially by multiple threads. As an alternative,
    you can create a view with a new dtype via array.view(dtype=new_dtype).

    (gh-29244)

  • Setting the shape attribute is deprecated because mutating an array is
    unsafe if an array is shared, especially by multiple threads. As an
    alternative, you can create a new view via np.reshape or
    np.ndarray.reshape. For example: x = np.arange(15); x = np.reshape(x, (3, 5)).
    To ensure no copy is made from the data, one can use np.reshape(..., copy=False).

    While setting the shape on an array is discouraged, for cases where it is
    difficult to work around, e.g., in __array_finalize__, it is possible
    with the private method np.ndarray._set_shape.

    (gh-29536)

  • Using the generic unit in numpy.timedelta64 is deprecated since this
    can lead to unexpected behavior such as non-transitive comparison, see
    gh-28287 for details. As
    an alternative, specify an explicit unit such as 's' (seconds) or 'D'
    (days) when constructing numpy.timedelta64. Due to this change, operations
    that implicitly rely on the generic unit are also deprecated. For
    example:

    arr = np.array([1, 2, 3], dtype="m8[s]")
    

1 is implicitly converted to generic timedelta64

  arr + 1

(gh-29619)

  • Resizing a Numpy array in place is deprecated since mutating an array is
    unsafe if an array is shared, especially by multiple threads. As an
    alternative, you can create a resized array via np.resize.

    (gh-30181)

  • numpy.fix is deprecated, use numpy.trunc instead. It is faster and
    follows the Array API standard. Both functions provide identical
    functionality: rounding array elements towards zero.

    (gh-30644)

  • numpy.ma.round_ is deprecated. numpy.ma.round can be used as a
    replacement.

    (gh-30738)

  • numpy.typename is deprecated because the names returned by it were
    outdated and

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "every weekend"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/python-packages branch 4 times, most recently from 0078737 to 06fe35c Compare July 6, 2026 06:12
@renovate
renovate Bot force-pushed the renovate/python-packages branch 2 times, most recently from 4315066 to c0c82b5 Compare July 10, 2026 11:42
@renovate
renovate Bot force-pushed the renovate/python-packages branch 5 times, most recently from 8bbaa4e to b58208f Compare July 23, 2026 09:09
@renovate
renovate Bot force-pushed the renovate/python-packages branch from b58208f to 14cc605 Compare August 3, 2026 21:12
@renovate
renovate Bot force-pushed the renovate/python-packages branch from 14cc605 to 22d1a0a Compare August 12, 2026 19:42
@github-actions

github-actions Bot commented Aug 12, 2026 •

Copy link
Copy Markdown

✅ commit messages pass

@renovate
renovate Bot force-pushed the renovate/python-packages branch 4 times, most recently from e79d16a to 009dd24 Compare August 21, 2026 22:31
@renovate
renovate Bot force-pushed the renovate/python-packages branch 2 times, most recently from 97ee002 to 391abb6 Compare August 31, 2026 16:41
@renovate
renovate Bot force-pushed the renovate/python-packages branch from 391abb6 to 9f1dd13 Compare September 10, 2026 15:43
@coderabbitai

coderabbitai Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: b8365704-997c-48cd-802c-b6dadeb5431e

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@renovate
renovate Bot force-pushed the renovate/python-packages branch 4 times, most recently from 4aec909 to 5d6e38d Compare September 17, 2026 21:38
@renovate
renovate Bot force-pushed the renovate/python-packages branch 2 times, most recently from 4a14045 to b43a02b Compare September 23, 2026 19:54
@renovate
renovate Bot force-pushed the renovate/python-packages branch from b43a02b to ed09f38 Compare September 29, 2026 18:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants