chore(deps): update python packages - #294
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/python-packages
branch
4 times, most recently
from
July 6, 2026 06:12
0078737 to
06fe35c
Compare
renovate
Bot
force-pushed
the
renovate/python-packages
branch
2 times, most recently
from
July 10, 2026 11:42
4315066 to
c0c82b5
Compare
renovate
Bot
force-pushed
the
renovate/python-packages
branch
5 times, most recently
from
July 23, 2026 09:09
8bbaa4e to
b58208f
Compare
renovate
Bot
force-pushed
the
renovate/python-packages
branch
from
August 3, 2026 21:12
b58208f to
14cc605
Compare
renovate
Bot
force-pushed
the
renovate/python-packages
branch
from
August 12, 2026 19:42
14cc605 to
22d1a0a
Compare
✅ commit messages pass |
renovate
Bot
force-pushed
the
renovate/python-packages
branch
4 times, most recently
from
August 21, 2026 22:31
e79d16a to
009dd24
Compare
renovate
Bot
force-pushed
the
renovate/python-packages
branch
2 times, most recently
from
August 31, 2026 16:41
97ee002 to
391abb6
Compare
renovate
Bot
force-pushed
the
renovate/python-packages
branch
from
September 10, 2026 15:43
391abb6 to
9f1dd13
Compare
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
renovate
Bot
force-pushed
the
renovate/python-packages
branch
4 times, most recently
from
September 17, 2026 21:38
4aec909 to
5d6e38d
Compare
renovate
Bot
force-pushed
the
renovate/python-packages
branch
2 times, most recently
from
September 23, 2026 19:54
4a14045 to
b43a02b
Compare
renovate
Bot
force-pushed
the
renovate/python-packages
branch
from
September 29, 2026 18:49
b43a02b to
ed09f38
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
3.4.7→3.5.22026.05.20→2026.07.22v1.3.3→v1.4.04.63.0→4.66.1v3.17→v3.20v3.10.9→v3.11.21.5.0→1.5.1v2.4.6→v2.6.0.dev0v3.0.3→v3.1.0.dev026.2→26.33.3.2→3.3.312.2.0→12.3.0v1.17.1→v1.18.12.7.0→2.8.0Release Notes
Ousret/charset_normalizer (Ousret/charset_normalizer)
v3.5.2Compare Source
Changed
<3.4for native builds. The bound remains<3.3forabi3builds to preserve compatibility with the Python 3.7 Limited API.Fixed
for uncommon CJK characters. (#796)
declarations. (#800)
v3.5.1Compare Source
Changed
Fixed
Only impacted large content input >1M bytes.
v3.5.0Compare Source
Added
Fixed
Changed
pure Python fallback. The previous engine (mypyc) started to hit rough limit around
the optimization of our noise/coherence detector while Cython allows us to
steer the engine toward the right generated optimized sources.
This change SHOULD not impact bundler (e.g. Pyinstaller) as the module are
immediately discoverable (i.e. not hidden import like mypyc did).
Moreover, a long wished distribution is the abi3 wheels, this will allow us
to no longer rush each year when a new Python interpreter is released.
We still distribute the interpreter specific wheels for faster performance.
Misc
v3.4.9Compare Source
Fixed
We've yanked 3.4.8 as a result of that bug.
v3.4.8Compare Source
Fixed
Changed
Removed
certifi/python-certifi (certifi/python-certifi)
v2026.07.22Compare Source
v2026.06.17Compare Source
contourpy/contourpy (contourpy/contourpy)
v1.4.0: Version 1.4.0Compare Source
ContourPy 1.4.0 introduces a new readonly property
ContourGenerator.namefor the algorithm name, adds support for CPython 3.15, and is the first release to uploadpyodidewheels to PyPI. Support forriscv64andiOSarchitectures is added but considered experimental, wheels are available from the Scientific Python Nightly Wheels service but not PyPI.Enhancements:
ContourGenerator.namereadonly property (#566)Compatibility:
Code improvements:
ntotalargument in mpl2005build_cntr_list_v2(#550)Documentation improvements:
Build, testing and CI improvements:
macos-13tomacos-15-intelgithub runners (#507)macos-15-intelrunner (#513)bokeh3.9.0 (#533)zizmortopre-commit(#546)fonttools/fonttools (fonttools/fonttools)
v4.66.1Compare Source
makeNames=True(asvarLib.build_manydoes), family and style names set explicitly on an instance now take precedence over the ones computed from the STAT labels, in all languages, and a PostScript name is no longer made up from the labels for an instance that has its own style name (#3131, #4206, #4208).idRangeOffsetpoints outsideglyphIndexArraynow raisesTTLibError. A negative index used to silently map the code point to the wrong glyph, and one past the end raised a bareAssertionError(#4209).struct.error(#4210).v4.66.0Compare Source
fontTools.misc.enumToolsnow only re-exportsenum.StrEnumand is deprecated. Explicitly test and declare support for Python 3.15 (#4183, #4196).unicodedata218.0.0 when it is used (#4192, #4197).languagestatements listing multiple language tags, e.g.language AZE CRT;, as Glyphs does and as proposed for the spec (adobe-type-tools/feature_file_workshops#8): the following rules and lookup references are registered under every listed language.dfltcannot be combined with other tags.LanguageStatement.languageis still the first tag; all of them are in the newlanguagesattribute (#4201, #4202).script/languagepair is repeated within a feature block: the repeated statement replaced the language system's lookups with a fresh copy of the default ones (#4189).FeatureLibErrorinstead ofUnboundLocalErrorwhen aSTATtable block lacksElidedFallbackNameorElidedFallbackNameID(#3834, #4179).VarStorewhen saving. Previously the bytes compiled by an earlier save were reused, so a CFF2 variable font that was saved and then modified in place, e.g. by the instancer, was written with a staleVarStorenext to its updated charstrings (#4199).VARCfonts that omitfvarwhile retaininggvaror CFF2 variation data for component-internal axes: hidden axes are addressed by index andgvarcan compile, decompile and round-trip through TTX withoutfvar, reading the axis count from a newaxisCountelement (#4187, #4188).VARCcomponents whose condition is negated (format 5), which raisedAttributeError(#4191).VARCaxis references left stale when removing an unrelated axis, reject pinning or restricting axes referenced byVARCcomponents, and stop culling avar2 ranges for component-internal variations, which can reach outside the font-level ranges (#4190, #4193).splitQuadraticAtTandsplitCubicAtTCas well, likesplitCubicAtTsince 4.55.4 (#3742, #4194).ZeroDivisionErrorinlineLineIntersectionsfor collinear vertical lines; they are now treated as parallel like horizontal ones (#3515, #4181).pyftsubsetnow preserves the input font's flavor (WOFF, WOFF2) when--flavoris omitted, instead of writing uncompressed sfnt data under the same extension; pass--flavor=noneto force uncompressed output (#3630, #4182).unitsPerEmvalues by name, with the input values, instead of a bare assertion (#2844, #4184).DesignSpaceDocument.default, which holds aSourceDescriptor, not a source name (#2994, #4186).TTLibErrorinstead ofAssertionErrorfor inconsistent WOFF table, metadata and private-data lengths, so the checks also hold underpython -O(#4178).resolve_entities="internal"still fetched external parameter entities before lxml 6.1.3, so a crafted DTD could read local files into parsed XML content (#4195).varLib.avar.unbuildemits its designspace snippet, so a crafted font cannot inject markup (#4203).v4.65.0Compare Source
__iter__,itemsandvaluesmethods to theglyftable to make it more dict-like (#4156).<variable-font name="..."/>when deriving the output filename in thevarLibcommand line, so a designspace cannot write outside the output directory (#4168).scriptstatements. Rules following ascriptstatement that names the first declared language system no longer end up under theDFLTscript, and ascriptstatement naming the already-current script still narrows the language systems and terminates the current lookup while leaving thelookupflagalone, matching makeotf (#1824, #2522, #4169).OTLOffsetOverflowErrorinstead ofAttributeErrorso another contextual format can be tried (regression from #3439). When all formats overflow, split the ruleset in halves until it fits (#4171).v4.64.0Compare Source
IDEF[ ], like function definitions (#4093).paltby default (#4094).__setitem__membership (#4103).fixLookupOverFlows()reporting success when it had not promoted any lookup to Extension, masking unresolvable overflows.TTCollection.save(#4111).bhed,bdat,bloc, variants ofhead,EBDT,EBLCused in legacy Apple bitmap-only fonts (#4115).OS/2fsSelection/macStyle consistency againstbhedas well ashead(#4118, #4119).BASEtable (#4137).vsindexhandling ininstantiateCFF2(#4129, #4132).TTLibErrorinstead ofAssertionErrororstruct.errorwhen reading a font truncated within the table directory or a table entry (#4147, #4149).]]>terminator inside CDATA sections, so an SVG document containing it can no longer smuggle markup past a TTX round trip (#4139).(100 wght=900:120)means(wght=400:100 wght=900:120)when the wght default is 400 (#4024).TTLibErrorfor a truncated or out-of-bounds cmap subtable header (#4151).<lib>element as an empty lib instead of raisingIndexError(#4142, #4144).splitSinglePosso GPOS lookup type 1 offset overflows can be recovered by splitting the subtable (#4091, #4108).TTLibErrorinstead ofRecursionErrorwhenrecalcBounds()hits a composite-component reference cycle (#3899, #4116).Z Z) (#4122).DefaultTabletype annotations (#4126).EBSC(Embedded Bitmap Scaling) table (#4113).TypeErrorin the Cython-compiled build whenQu2CuPenpasses tuple splines (#4160)...components incontents.plist, and a crafted.ufozcould create files outside its temporary mirror (#4124).ttx -z extfileexport, preventing arbitrary file writes from untrusted fonts (#4128).XMLParserwhen lxml is used, preventing XXE file disclosure on lxml < 5.0 (#4145).VARCauxiliary data: collect and remap variation indices referenced by condition tables when subsetting theMultiVarStore, and drop theAxisIndicesList,ConditionList, andMultiVarStorewhen they end up empty (#4162).kjd/idna (kjd/idna)
v3.20Compare Source
codec.
v3.19Compare Source
std3_rulesoption, which had no effect since changesto UTS #46 processing in Unicode 16. Note that
uts46_remap()defaults to enabling STD3 rules, so direct callers will see input
containing non-LDH ASCII characters rejected again.
ASCII-only domains.
thread safety.
idna.unicode_version, and show it inidna --version.code,text,codepointandpositionattributes toIDNAErrorso that the failed rule and the offending character canbe identified without parsing the exception message.
transitionalargument toencode()anduts46_remap()is now completely ignored, and gives a deprecation warningfor the latter.
their U-label.
IDNAErrorinstead ofInvalidCodepointContext.IDNAErrorfor empty labels and non-ASCII bytespassed to label helper functions and the incremental codec.
measurement, and CI checks that the data tables match the generator
output.
Thanks to stefan6419846, LouieLuNZ, and Salvatore Corvaglia for
contributions to this release.
v3.18Compare Source
matplotlib/matplotlib (matplotlib/matplotlib)
v3.11.2: REL: v3.11.2Compare Source
This is the second bugfix release of the 3.11.x series.
This release contains several bug-fixes and adjustments:
hexbinclipping in PDF output\textwith internal bracesPillowWriterResizeEventhandling forTextBoxv3.11.1: REL: v3.11.1Compare Source
This is the first bugfix release of the 3.11.x series.
This release contains several bug-fixes and adjustments:
sharey=TrueNoNormcursor formatting foruint8imagesAs well as several documentation and typing improvements and corrections.
v3.11.0: REL: v3.11.0Compare Source
The largest change within this release is a complete overhaul of text and font processing. Through the use of libraqm, HarfBuzz, SheenBidi, and an updated release of FreeType, all text should now support modern font features, enabling full internationalization in all languages. Not all features of these libraries are supported yet, but we expect this work to enable further improvements in an easier manner.
Outside of text handling, there are several improvements to 3D Axes, performance, new accessible colour sequences, flexible figure management, and more. See the release notes for more information.
v3.11.0rc2: REL: v3.11.0rc2Compare Source
This is the second release candidate for the meso release 3.11.0.
This release candidate fixes some problems with downstream packages, removes some missed deprecations, and corrects some additional minor bugs.
v3.11.0rc1: REL: v3.11.0rc1Compare Source
After an extended development stretch, we are pleased to announce the first release candidate of Matplotlib 3.11.0.
The largest change within this release is a complete overhaul of text and font processing. Through the use of libraqm, HarfBuzz, SheenBidi, and an updated release of FreeType, all text should now support modern font features, enabling full internationalization in all languages. Not all features of these libraries are supported yet, but we expect this work to enable further improvements in an easier manner. Due to the update to the font rendering stack, we cannot guarantee that text will be bit-for-bit perfect with previous releases, so if you are using Matplotlib for testing, it may be necessary to introduce/raise a tolerance within your tests.
Outside of text handling, there are several improvements to 3D Axes, performance, new accessible colour sequences, flexible figure management, and more. Final release notes are still being curated, but you may browse the list of new features, API changes, and all issues/pull requests on the milestone.
As a note for downstream packagers, the font libraries have only been tested against the versions bundled with the wheels. It may be possible to expand the range of requirements, or that a requirement is too broad. Please report any issues you have building against external dependencies.
nucleic/kiwi (nucleic/kiwi)
v1.5.1Compare Source
numpy/numpy (numpy/numpy)
v2.6.0.dev0Compare Source
v2.5.3: (Sep 6, 2026)Compare Source
NumPy 2.5.3 Release Notes
The NumPy 2.5.3 is a patch release that fixes bugs discovered after the 2.5.2
release. Apart from the usual bug and maintenance work, there are a number of
StringDType related fixes for problems discovered during the ongoing string
work in the main branch.
This release supports Python versions 3.12-3.15
Changes
Casting a fixed-width byte string array (
np.bytes_) toStringDTypenow raises
TypeErrorwhen the bytes are not valid UTF-8. Previously theinvalid bytes were stored as-is and later caused undefined behavior in
string operations.
(gh-32296)
MaskedArray._fill_valuewould become stale when ufuncs that change dtypeleft the result holding a fill_value typed for the old dtype. The mismatch
was silent until something later called
_check_fill_value, such as.view(), and then aTypeErrorwould be raised. Now, when the copiedfill_value is no longer valid for the new dtype, fall back to the
default fill_value for that dtype instead of propagating the stale value.
This may raise a
ComplexWarningif the fill_value is complex and thenew dtype is real.
(gh-32423)
Contributors
A total of 9 people contributed to this release. People with a "+" by their
names contributed a patch for the first time.
Pull requests merged
A total of 27 pull requests were merged for this release.
np.random.{get,set}_bit_generatorimplicit re-exports...PyObject_functions instead of rawPyArray_ ones(#32331)v2.5.2: (Aug 9, 2026)Compare Source
NumPy 2.5.2 Release Notes
The NumPy 2.5.2 is a patch release that fixes bugs discovered after the 2.5.1
release. The big news is that it includes wheels for the newly released
Python 3.15.0rc1.
This release supports Python versions 3.12-3.15
C API changes
PyArray_StringDTypeObjectis opaque under the abi3t stable ABIThe
PyArray_StringDTypeObjectwas accidentally exposed in NumPy2.5 when targeting the free-threading-compatible stable ABI
(
Py_TARGET_ABI3T).PyArray_StringDTypeObjectis now an opaquestruct: extensions compiled that way cannot access its fields, since
the struct layout depends on the size of the object header. Any code
that accessed
PyArray_StringDTypeObjectfields in an abi3t buildwould have crashed, so we are making this API change in a bugfix
release.
The
NpyStringallocator API remains usable by passing thedescriptor object pointer, e.g.
NpyString_acquire_allocator((PyArray_StringDTypeObject *)descr).(gh-31771)
Contributors
A total of 16 people contributed to this release. People with a "+" by their
names contributed a patch for the first time.
Pull requests merged
A total of 28 pull requests were merged for this release.
StringDTypecoerce flag in binary ufunc promotion...5adb334→fa944ef) (#31908)np.fromitercorruption when reusing aStringDType...simd_sequence_from_iterable(#32038)iscloseshape-typing fix for 2d array-likes (#32205)v2.5.1: (July 4, 2026)Compare Source
NumPy 2.5.1 Release Notes
The NumPy 2.5.1 is a patch release that fixes bugs discovered after the 2.5.0
release. The most noticeable is the fix is to the numpy datetime cython API
which should allow downstream to support NumPy versions older than 2.5.
Preparation for Python 3.15 continues along with typing improvements.
This release supports Python versions 3.12-3.14
Changes
The minimum supported GCC version has been updated from 9.3.0 to 10.3.0
(gh-31843)
Contributors
A total of 10 people contributed to this release. People with a "+" by their
names contributed a patch for the first time.
Pull requests merged
A total of 20 pull requests were merged for this release.
cython-linterrors (#31711)flatiter.__next__return type forobject_and...asarray([])(#31732)np.ma.masked_array2.5.0 regressionv2.5.0: (June 21, 2026)Compare Source
NumPy 2.5.0 Release Notes
Numpy 2.5.0 is a transitional release. It drops support for Python 3.11,
marking the end of distutils, and expires a large number of deprecations made
in the 2.0.x release. It also improves free threading and brings sorting into
compliance with the array-api standard with the addition of descending sorts.
There is also a fair amount of preparation for Python 3.15, which will be
supported starting with the first rc.
This release supports Python versions 3.12-3.14.
Highlights
See New Features below for other additions.
Deprecations
numpy.char.chararrayis deprecated. Use anndarraywith a string or bytes dtype instead.(gh-30605)
numpy.takenow correctly checks if the result can be cast to the providedout=outunder the same-kind rule. ADeprecationWarningis given nowwhen this check fails. Previously,
takeincorrectly checked ifoutcould be cast to the result (the wrong direction). This deprecation also
affects
compressand possibly other functions. (Future versions of NumPymay tighten the casting check further.)
(gh-30615)
The
numpy.char.[as]arrayfunctions are deprecated. Use annumpy.[as]arraywith a string or bytes dtype instead.(gh-30802)
Setting the dtype attribute is deprecated because mutating an array is unsafe
if an array is shared, especially by multiple threads. As an alternative,
you can create a view with a new dtype via
array.view(dtype=new_dtype).(gh-29244)
Setting the
shapeattribute is deprecated because mutating an array isunsafe if an array is shared, especially by multiple threads. As an
alternative, you can create a new view via
np.reshapeornp.ndarray.reshape. For example:x = np.arange(15); x = np.reshape(x, (3, 5)).To ensure no copy is made from the data, one can use
np.reshape(..., copy=False).While setting the shape on an array is discouraged, for cases where it is
difficult to work around, e.g., in
__array_finalize__, it is possiblewith the private method
np.ndarray._set_shape.(gh-29536)
Using the
genericunit innumpy.timedelta64is deprecated since thiscan lead to unexpected behavior such as non-transitive comparison, see
gh-28287 for details. As
an alternative, specify an explicit unit such as
's'(seconds) or'D'(days) when constructing
numpy.timedelta64. Due to this change, operationsthat implicitly rely on the
genericunit are also deprecated. Forexample:
1is implicitly converted to generic timedelta64(gh-29619)
Resizing a Numpy array in place is deprecated since mutating an array is
unsafe if an array is shared, especially by multiple threads. As an
alternative, you can create a resized array via
np.resize.(gh-30181)
numpy.fixis deprecated, usenumpy.truncinstead. It is faster andfollows the Array API standard. Both functions provide identical
functionality: rounding array elements towards zero.
(gh-30644)
numpy.ma.round_is deprecated.numpy.ma.roundcan be used as areplacement.
(gh-30738)
numpy.typenameis deprecated because the names returned by it wereoutdated and
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.