Skip to content

chore(deps): bump the python-dependencies group with 11 updates - #98

Merged
xxg1413 merged 1 commit into
masterfrom
dependabot/pip/python-dependencies-e8addec0a6
Oct 4, 2026
Merged

xxg1413 merged 1 commit into
masterfrom
dependabot/pip/python-dependencies-e8addec0a6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 4, 2026

Copy link
Copy Markdown
Contributor

Updates the requirements on requests, urllib3, mypy, types-pyyaml, types-requests, charset-normalizer, idna, fonttools, pyparsing, pytz and tzdata to permit the latest version.
Updates requests from 2.32.5 to 2.34.2

Release notes

Sourced from requests's releases.

v2.34.2

2.34.2 (2026-05-14)

  • Moved headers input type back to Mapping to avoid invariance issues with MutableMapping and inferred dict types. Users calling Request.headers.update() may need to narrow typing in their code. (#7441)

Full Changelog: https://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14

v2.34.1

2.34.1 (2026-05-13)

Bugfixes

  • Widened json input type from dict and list to Mapping and Sequence. (#7436)
  • Changed headers input type to MutableMapping and removed None from Request.headers typing to improve handling for users. (#7431)
  • Response.reason moved from str | None to str to improve handling for users. (#7437)
  • Fixed a bug where some bodies with custom __getattr__ implementations weren't being properly detected as Iterables. (#7433)

New Contributors

Full Changelog: https://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13

v2.34.0

2.34.0 (2026-05-11)

Announcements

  • Requests 2.34.0 introduces inline types, replacing those provided by typeshed. Public API types should be fully compatible with mypy, pyright, and ty. We believe types are comprehensive but if you find issues, please report them to the pinned tracking issue.

    Special thanks to @​bastimeyer, @​cthoyt, @​edgarrmondragon, and @​srittau for helping review and test the types ahead of the release. (#7272)

Improvements

  • Digest Auth hashing algorithms have added usedforsecurity=False to clarify security considerations. (#7310)
  • Requests added support for Python 3.15 based on beta1. Downstream projects should be able to start testing prior to its release in October. (#7422)
  • Requests added support for Python 3.14t. (#7419)

Bugfixes

  • Response.history no longer contains a reference to itself, preventing accidental looping when traversing the history list. (#7328)
  • Requests no longer performs greedy matching on no_proxy domains. The

... (truncated)

Changelog

Sourced from requests's changelog.

2.34.2 (2026-05-14)

  • Moved headers input type back to Mapping to avoid invariance issues with MutableMapping and inferred dict types. Users calling Request.headers.update() may need to narrow typing in their code. (#7441)

2.34.1 (2026-05-13)

Bugfixes

  • Widened json input type from dict and list to Mapping and Sequence. (#7436)
  • Changed headers input type to MutableMapping and removed None from Request.headers typing to improve handling for users. (#7431)
  • Response.reason moved from str | None to str to improve handling for users. (#7437)
  • Fixed a bug where some bodies with custom __getattr__ implementations weren't being properly detected as Iterables. (#7433)

2.34.0 (2026-05-11)

Announcements

  • Requests 2.34.0 introduces inline types, replacing those provided by typeshed. Public API types should be fully compatible with mypy, pyright, and ty. We believe types are comprehensive but if you find issues, please report them to the pinned tracking issue.

    Special thanks to @​bastimeyer, @​cthoyt, @​edgarrmondragon, and @​srittau for helping review and test the types ahead of the release. (#7272)

Improvements

  • Digest Auth hashing algorithms have added usedforsecurity=False to clarify security considerations. (#7310)
  • Requests added support for Python 3.15 based on beta1. Downstream projects should be able to start testing prior to its release in October. (#7422)
  • Requests added support for Python 3.14t. (#7419)

Bugfixes

  • Response.history no longer contains a reference to itself, preventing accidental looping when traversing the history list. (#7328)
  • Requests no longer performs greedy matching on no_proxy domains. The proxy_bypass implementation has been updated with CPython's fix from bpo-39057. (#7427)
  • Requests no longer incorrectly strips duplicate leading slashes in URI paths. This should address user issues with specific presigned URLs. Note the full fix requires urllib3 2.7.0+. (#7315)

... (truncated)

Commits

Updates urllib3 from 2.6.3 to 2.8.0

Release notes

Sourced from urllib3's releases.

2.8.0

🚀 urllib3 is fundraising for HTTP/2 support

urllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects please consider contributing financially to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.

Thank you for your support.

Security

Fixed the following security issues:

  • The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, GHSA-8988-9cw3-xx77)
  • HTTPResponse.stream() and read_chunked() could buffer a chunk-size line of unbounded length in memory. (High severity, GHSA-vxq7-64xx-v4gw)
  • Chunked Deflate streaming could enter an infinite loop. (Medium severity, GHSA-gh4c-6fx4-qh6g)

[!IMPORTANT] urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes.

Configure proxy CA certificates and client certificates in proxy_ssl_context, and proxy identity checks with proxy_assert_hostname or proxy_assert_fingerprint. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections.

[!NOTE] CVE IDs had not yet been assigned to these advisories at the time of release due to a backlog at GitHub's CNA.

Deprecations & Removals

  • Deprecated using an empty collection as the Retry option allowed_methods to retry any verb. (#5044)

Features

  • Added Url.auth_decoded and Url.auth_decoded_joined convenience properties to the result of parse_url(). (#4945)
  • Added basic_auth_encoding and proxy_basic_auth_encoding parameters to urllib3.util.make_headers(). (#5092)

Bugfixes

  • Fixed response header handling to replace obsolete folded header lines (obs-fold) with spaces in accordance with RFC 9112, preventing raw CRLF sequences from appearing in header values such as Set-Cookie. (#1362)

  • Fixed usage of proxy_ssl_context with ProxyManager when use_forwarding_for_https=True. Passing ssl_context instead of proxy_ssl_context for HTTPS proxies in this configuration now emits a FutureWarning and will raise an error in v3.0. (#2577)

  • Changed behavior of the default ConnectionPool.pool initialization. LifoQueue is now resolved from the queue module after the ConnectionPool is instantiated instead of using the default cached QueueCls class property. This is done because sometimes the queue.LifoQueue is monkey-patched late in the program, such as by gevent. (#3289)

  • Raised UnrewindableBodyError instead of ValueError when retrying a request whose body had tell() but not seek(). (#3779)

  • Decoded percent-encoded SOCKS proxy credentials before authenticating with the proxy server. (#3785)

  • Fixed HTTPResponse.drain_conn() to discard unread response data in 64 KiB chunks (same as the default amt when doing HTTPResponse.stream(...)). (#5019)

  • Fixed is_ipaddress() to detect non-standard IPv4 forms accepted by socket.connect, such as hex (0x7f000001), octal (0177.0.0.1), and decimal integers (2130706433), ensuring SSL certificate verification uses the correct mode for these addresses. (#5029)

  • Fixed HTTPConnectionPool.urlopen raising a misleading FullPoolError instead of ValueError when called with an invalid timeout argument on a pool created with block=True. (#5059)

  • Fixed port-zero handling to preserve explicit :0 values instead of substituting the default ports 80 or 443 in URL parsing, pool selection, proxy configuration, connection_from_url(), and HTTP/2 request authority. (#5071, #5101)

  • Fixed a bug where PoolManager passed the assert_hostname and assert_fingerprint parameters to HTTP connection pools. (#5077)

  • Fixed HTTPConnectionPool.urlopen() and HTTP proxy forwarding to strip URL fragments from absolute request targets before sending requests. (#5079)

  • Added safeguards to the proxy tunneling code to prevent potential security issues when handling invalid characters in the proxy host and HTTP headers. This change affects users of Python 3.10, Python 3.11, and Python 3.12 when the standard library does not contain the fix; those on newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes. (#5091)

  • Fixed HTTPSConnection.connect() overriding ProxyConfig.ssl_context's certificate policy and proxy identity checks with the target connection's TLS settings when forwarding through an HTTPS proxy.

    HTTPSConnection no longer applies target SNI, assertions, or client credentials to forwarding proxy handshakes and continues to use its ssl_context as a fallback when an HTTPS proxy forwards an HTTP target. (#5093)

  • Fixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting invalid host input such as raw spaces and control characters, malformed percent-encodings, and percent-encoded control characters in HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host normalization now also follows RFC 3986 normalization rules for percent-encoded octets by decoding percent-encoded unreserved characters and uppercasing the hexadecimal digits of retained percent-encoded octets. (#5095)

... (truncated)

Changelog

Sourced from urllib3's changelog.

2.8.0 (2026-09-15)

Security

Fixed the following security issues:

  • The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, GHSA-8988-9cw3-xx77 <https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77>__)
  • HTTPResponse.stream() and read_chunked() could buffer a chunk-size line of unbounded length in memory. (High severity, GHSA-vxq7-64xx-v4gw <https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw>__)
  • Chunked Deflate streaming could enter an infinite loop. (Medium severity, GHSA-gh4c-6fx4-qh6g <https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g>__)

.. caution::

urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.

Configure proxy CA certificates and client certificates in proxy_ssl_context, and proxy identity checks with proxy_assert_hostname or proxy_assert_fingerprint. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections.

Deprecations & Removals

  • Deprecated using an empty collection as the Retry option allowed_methods to retry any verb. ([#5044](https://github.com/urllib3/urllib3/issues/5044) <https://github.com/urllib3/urllib3/issues/5044>__)

Features

  • Added Url.auth_decoded and Url.auth_decoded_joined convenience properties to the result of parse_url(). ([#4945](https://github.com/urllib3/urllib3/issues/4945) <https://github.com/urllib3/urllib3/issues/4945>__)
  • Added basic_auth_encoding and proxy_basic_auth_encoding parameters to urllib3.util.make_headers(). ([#5092](https://github.com/urllib3/urllib3/issues/5092) <https://github.com/urllib3/urllib3/issues/5092>__)

Bugfixes

... (truncated)

Commits
  • b1d30ab Release 2.8.0
  • 9016d7e Skip test_read_chunked_with_trailing_data_does_not_hang for brotlicffi (#5258)
  • 9101f58 Fix nox -s docs warning (#5256)
  • cd770b0 Merge commit from fork
  • ea2ad7b Merge commit from fork
  • 0716e31 Fix loading unencrypted client keys with a password in pyOpenSSL (#5255)
  • 43c68c8 Test pickling of InvalidChunkLength (#5247)
  • 308b279 Share security policy between GitHub and Read the Docs (#5253)
  • 53fa073 Add policy on duplicate pull requests (#5252)
  • 5f2a6a8 Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (#5232)
  • Additional commits viewable in compare view

Updates mypy to 2.3.1

Changelog

Sourced from mypy's changelog.

Mypy 2.3.1

  • Fix mypyc crash on double yielding Iterators (Daniël van Noord, PR 21826)
  • Fix mypyc default_factory for inherited dataclass (Daniël van Noord, PR 21785)
  • Clear mypyc coroutine env on coroutine completion (Piotr Sawicki, PR 21734)
  • Fix crash when unpacking return value from overload (Shantanu, PR 21830)

Acknowledgements

Thanks to all mypy contributors who contributed to this release:

  • Agriya Khetarpal
  • Ethan Sarp
  • Ivan Levkivskyi
  • Jingchen Ye
  • Jukka Lehtosalo
  • Piotr Sawicki
  • Shantanu
  • Tom Bannink
  • Viktor Szépe
  • ygale

I'd also like to thank my employer, Dropbox, for supporting mypy development.

Mypy 2.2

We've just uploaded mypy 2.2.0 to the Python Package Index (PyPI). Mypy is a static type checker for Python. This release includes new features, performance improvements and bug fixes. You can install it as follows:

python3 -m pip install -U mypy

You can read the full documentation for this release on Read the Docs.

Support for Closed TypedDicts (PEP 728)

Mypy now supports closed TypedDicts as specified in PEP 728. A closed TypedDict cannot have extra keys beyond those explicitly defined. This allows the type checker to determine that certain operations are safe when they otherwise wouldn't be due to the potential presence of unknown keys.

You can use the closed keyword argument with TypedDict:

HasName = TypedDict("HasName", {"name": str})
HasOnlyName = TypedDict("HasOnlyName", {"name": str}, closed=True)
Movie = TypedDict("Movie", {"name": str, "year": int})
movie: Movie = {"name": "Nimona", "year": 2023}
has_name: HasName = movie  # OK: HasName is open (default)
has_only_name: HasOnlyName = movie  # Error: HasOnlyName is closed and Movie has extra "year" key
</tr></table>

... (truncated)

Commits
  • d642c44 Bump version to 2.3.1
  • a392429 [mypyc] Fix crash on double yielding Iterators (#21826)
  • 4843e77 [mypyc] Fix default_factory for inherited dataclass (#21785)
  • 14f5df9 [mypyc] Clear coroutine env on coroutine completion (#21734)
  • 6dfa06d Fix crash when unpacking return value from overload (#21830)
  • a385746 Bump version to 2.3.1+dev
  • 8aabf84 Drop +dev from version
  • 4d8ad2a Update changelog for 2.3 release (#21728)
  • 2c21546 [mypyc] Update documentation of race conditions under free threading (#21726)
  • a9f62a3 [mypyc] Make attribute access memory safe on free-threaded builds (#21705)
  • Additional commits viewable in compare view

Updates types-pyyaml to 6.0.12.20260906

Commits

Updates types-requests to 2.33.0.20260906

Commits

Updates charset-normalizer from 3.5.1 to 3.5.2

Release notes

Sourced from charset-normalizer's releases.

Version 3.5.2

3.5.2 (2026-09-29)

Changed

  • Raised the Cython upper bound to <3.4 for native builds. The bound remains <3.3 for abi3 builds to preserve compatibility with the Python 3.7 Limited API.

Fixed

  • Valid UTF-8 Chinese JSON incorrectly detected as PTCP154 due to excessive noise penalties for uncommon CJK characters. (#796)
  • Supported encodings without aliases failing name resolution or being ignored in charset declarations. (#800)
Changelog

Sourced from charset-normalizer's changelog.

3.5.2 (2026-09-29)

Changed

  • Raised the Cython upper bound to <3.4 for native builds. The bound remains <3.3 for abi3 builds to preserve compatibility with the Python 3.7 Limited API.

Fixed

  • Valid UTF-8 Chinese JSON incorrectly detected as PTCP154 due to excessive noise penalties for uncommon CJK characters. (#796)
  • Supported encodings without aliases failing name resolution or being ignored in charset declarations. (#800)
Commits
  • 935c29a Release 3.5.2 (#805)
  • 9d3238a test: disable traefik in downstream niquests
  • b4c0368 docs: write changelog entry for 3.5.2
  • 717da31 chore: bump version to 3.5.2
  • 264895d chore: update pypa/cibuildwheel and pypa/gh-action-pypi-publish
  • 41e28b6 chore: raise Cython upper bound to 3.3
  • b130b7d Fix valid UTF-8 Chinese JSON misdetected as PTCP154 (#796)
  • f6afd31 Make the IANA_NO_ALIASES encodings resolvable by name (#800)
  • See full diff in compare view

Updates idna from 3.19 to 3.20

Release notes

Sourced from idna's releases.

v3.20

  • Update to Unicode 18.0.0.
  • Better enforcement of the domain length limit in the incremental codec.
  • Add support for Python 3.15.
Changelog

Sourced from idna's changelog.

3.20 (2026-09-17)

  • Update to Unicode 18.0.0.
  • Better enforcement of the domain length limit in the incremental codec.
  • Add support for Python 3.15.
Commits
  • d55e65e Release 3.20
  • 0c0824a Pre-release 3.20rc0
  • bd7c316 Note Python 3.15 support in the 3.20 changelog
  • b6cce85 Merge pull request #276 from kjd/unicode-18
  • 9a4bc59 Update to Unicode 18.0.0
  • dfab5a0 Merge branch 'python-3.15'
  • 417c354 Read the latest Unicode version from the DerivedAge.txt header instead of the...
  • cd17392 Merge pull request #274 from kjd/fix-decode-length-check
  • c5796d7 Skip the decode round-trip check for domains past encode's length limit
  • d6ee690 Update to Python 3.15 release candidate in CI and add trove classifier
  • Additional commits viewable in compare view

Updates fonttools from 4.65.0 to 4.66.1

Release notes

Sourced from fonttools's releases.

4.66.1

  • [designspaceLib] When splitting a DesignSpace v5 document with makeNames=True (as varLib.build_many does), family and style names set explicitly on an instance now take precedence over the ones computed from the STAT labels, in all languages, and a PostScript name is no longer made up from the labels for an instance that has its own style name (#3131, #4206, #4208).
  • [cmap] Decompiling a format 4 subtable whose idRangeOffset points outside glyphIndexArray now raises TTLibError. A negative index used to silently map the code point to the wrong glyph, and one past the end raised a bare AssertionError (#4209).
  • [cmap] Fix compiling a format 2 subtable when the lowest glyph ID in a lead-byte row is 32768 or higher, which failed with struct.error (#4210).

4.66.0

  • Drop support for EOL Python 3.10; fontTools now requires Python 3.11 or later. fontTools.misc.enumTools now only re-exports enum.StrEnum and is deprecated. Explicitly test and declare support for Python 3.15 (#4183, #4196).
  • [unicodedata] Update the bundled script, script extension, block and bidi-mirroring tables to Unicode 18.0.0, and require unicodedata2 18.0.0 when it is used (#4192, #4197).
  • [feaLib] Support language statements listing multiple language tags, e.g. language AZE CRT;adobe-type-tools/feature_file_workshops#8dflt cannot be combined with other tags. LanguageStatement.language is still the first tag; all of them are in the new languages attribute (#4201, #4202).
  • [feaLib] Fix lookups being dropped when a script/language pair is repeated within a feature block: the repeated statement replaced the language system's lookups with a fresh copy of the default ones (#4189).
  • [feaLib] Raise FeatureLibError instead of UnboundLocalError when a STAT table block lacks ElidedFallbackName or ElidedFallbackNameID (#3834, #4179).
  • [cffLib] Always recompile the CFF2 VarStore when saving. Previously the bytes compiled by an earlier save were reused, so a CFF2 variable font that was saved and then modified in place, e.g. by the instancer, was written with a stale VarStore next to its updated charstrings (#4199).
  • [ttLib] Support static VARC fonts that omit fvar while retaining gvar or CFF2 variation data for component-internal axes: hidden axes are addressed by index and gvar can compile, decompile and round-trip through TTX without fvar, reading the axis count from a new axisCount element (#4187, #4188).
  • [ttLib] Fix drawing VARC components whose condition is negated (format 5), which raised AttributeError (#4191).
  • [instancer] Fix VARC axis references left stale when removing an unrelated axis, reject pinning or restricting axes referenced by VARC components, and stop culling avar2 ranges for component-internal variations, which can reach outside the font-level ranges (#4190, #4193).
  • [bezierTools] Preserve exact endpoints in splitQuadraticAtT and splitCubicAtTC as well, like splitCubicAtT since 4.55.4 (#3742, #4194).
  • [bezierTools] Fix ZeroDivisionError in lineLineIntersections for collinear vertical lines; they are now treated as parallel like horizontal ones (#3515, #4181).
  • [subset] pyftsubset now preserves the input font's flavor (WOFF, WOFF2) when --flavor is omitted, instead of writing uncompressed sfnt data under the same extension; pass --flavor=none to force uncompressed output (#3630, #4182).
  • [merge] Report incompatible unitsPerEm values by name, with the input values, instead of a bare assertion (#2844, #4184).
  • [designspaceLib] Fix the type annotation and documentation of DesignSpaceDocument.default, which holds a SourceDescriptor, not a source name (#2994, #4186).
  • [ttLib.sfnt] Raise TTLibError instead of AssertionError for inconsistent WOFF table, metadata and private-data lengths, so the checks also hold under python -O (#4178).
  • [misc.etree] Disable entity resolution altogether on lxml >= 5.0 as well: lxml's resolve_entities="internal" still fetched external parameter entities before lxml 6.1.3, so a crafted DTD could read local files into parsed XML content (#4195).
  • [cmap] Bound the expansion of format 4 segments and format 12/13 groups when decompiling, like HarfBuzz does: groups are clamped to U+10FFFF, inverted or overlapping groups are skipped with a warning, and groups mapped to the missing glyph are not expanded. A crafted font could previously exhaust memory with a single group ending at 0xFFFFFFFF (#4204).
  • [varLib.avar] Escape axis names and tags when varLib.avar.unbuild emits its designspace snippet, so a crafted font cannot inject markup (#4203).
Changelog

Sourced from fonttools's changelog.

4.66.1 (released 2026-09-29)

  • [designspaceLib] When splitting a DesignSpace v5 document with makeNames=True (as varLib.build_many does), family and style names set explicitly on an instance now take precedence over the ones computed from the STAT labels, in all languages, and a PostScript name is no longer made up from the labels for an instance that has its own style name (#3131, #4206, #4208).
  • [cmap] Decompiling a format 4 subtable whose idRangeOffset points outside glyphIndexArray now raises TTLibError. A negative index used to silently map the code point to the wrong glyph, and one past the end raised a bare AssertionError (#4209).
  • [cmap] Fix compiling a format 2 subtable when the lowest glyph ID in a lead-byte row is 32768 or higher, which failed with struct.error (#4210).

4.66.0 (released 2026-09-23)

  • Drop support for EOL Python 3.10; fontTools now requires Python 3.11 or later. fontTools.misc.enumTools now only re-exports enum.StrEnum and is deprecated. Explicitly test and declare support for Python 3.15 (#4183, #4196).
  • [unicodedata] Update the bundled script, script extension, block and bidi-mirroring tables to Unicode 18.0.0, and require unicodedata2 18.0.0 when it is used (#4192, #4197).
  • [feaLib] Support language statements listing multiple language tags, e.g. language AZE CRT;, as Glyphs does and as proposed for the spec adobe-type-tools/feature_file_workshops#8 references are registered under every listed language. dflt cannot be combined with other tags. LanguageStatement.language is still the first tag; all of them are in the new languages attribute (#4201, #4202).
  • [feaLib] Fix lookups being dropped when a script/language pair is repeated within a feature block: the repeated statement replaced the language system's lookups with a fresh copy of the default ones (#4189).
  • [feaLib] Raise FeatureLibError instead of UnboundLocalError when a STAT table block lacks ElidedFallbackName or ElidedFallbackNameID (#3834, #4179).
  • [cffLib] Always recompile the CFF2 VarStore when saving. Previously the bytes compiled by an earlier save were reused, so a CFF2 variable font that was saved and then modified in place, e.g. by the instancer, was written with a stale VarStore next to its updated charstrings (#4199).
  • [ttLib] Support static VARC fonts that omit fvar while retaining gvar or CFF2 variation data for component-internal axes: hidden axes are addressed by index and gvar can compile, decompile and round-trip through TTX without fvar, reading the axis count from a new axisCount element (#4187, #4188).
  • [ttLib] Fix drawing VARC components whose condition is negated (format 5), which raised AttributeError (#4191).
  • [instancer] Fix VARC axis references left stale when removing an unrelated axis, reject pinning or restricting axes referenced by VARC components, and stop culling avar2 ranges for component-internal variations,

... (truncated)

Commits
  • 9e95795 Release 4.66.1
  • 8fc91fb Update NEWS.rst [skip ci]
  • 82dc507 Merge pull request #4209 from insaf021/cmap4-idrangeoffset-bounds
  • a83553e trim comments
  • 85049d3 Merge pull request #4208 from fonttools/fix-split-stat-names-override
  • 1ad111d Merge pull request #4210 from youdie006/cmap-format2-high-gids
  • c9e9d68 [cmap] fix format 2 compile for glyph IDs above 32767
  • 85625c5 raise TTLibError for out-of-range glyphIndexArray offset in cmap format 4
  • 879173e [designspaceLib] Let explicit instance names win over STAT labels when splitting
  • 718b61b Bump version: 4.66.0 → 4.66.1.dev0
  • Additional commits viewable in compare view

Updates pyparsing from 3.3.2 to 3.3.3

Changelog

Sourced from pyparsing's changelog.

Version 3.3.3 - in development

  • Added support for Python 3.15.

  • Parse actions that return a tuple value for a named expression formerly saved just the first value of the tuple. Now they return the entire tuple. Partially fixes Issue #401, PR #640 submitted by Vincent Gao et AI.

  • Fixed CI unit test jobs selecting a tox environment with no test commands. The matrix and fallback now select py-unit, as diagnosed and proposed by glaziermag in issue #662; submitted by Neal Lin et AI.

  • Fixed Dict returning an empty nested ParseResults.as_dict() as [] instead of {}. Incorporates partial solution submitted in PR #635 submitted by Leo Ji.

    Additional fixes found as part of this work:

    • Removed vestigial unused ParseResults._modal attribute.

    • Fixed incidental bug when Dict tries to create a dict with a ParseResults value for a key (not hashable).

  • Fixed Word(..., max=n) raising instead of matching up to max characters when the character set contained whitespace - Word(nums, max=3) and Word(nums + " ", max=3) gave opposite results on the same input. Now both forms match up to max and leave the rest for the next parser. PR #646 submitted by Andrew Chen et AI.

  • Fixed QuotedString stripping whitespace that is part of a multi-character quote delimiter, e.g. the leading newline in QuotedString("\n;", multiline=True). The delimiter was silently collapsed to ";", so the newline was ignored when matching. QuotedString now only rejects quote_char/end_quote_char values that are empty or entirely whitespace, and preserves any surrounding whitespace that is part of a valid delimiter. Reported in issue #492.

  • Fixed pyparsing_common.as_datetime raising Invalid date/time: microsecond must be in 0..999999 for valid ISO-8601 timestamps whose fractional seconds round up to a full second (e.g. 2021-06-15T12:30:59.9999995, common in nanosecond-precision timestamps). The rounded microseconds are now added via timedelta so the value carries into the next second instead of overflowing the datetime microsecond argument. PR submitted by Andrew Chen et AI.

  • Fixed debug output corruption when a parsed line contains a carriage return or other control character. set_debug() printed the source line verbatim, so a stray \r returned the terminal cursor to column 0 and overwrote the "Match ... at loc" text. Control characters in the debug line are now shown escaped, and the marker caret stays aligned with the match location. Issue #496, reported by Matthew Rowles.

... (truncated)

Commits
  • d90d38b Update flit version and exclusion of generated railroad diagrams from source ...
  • 4220992 Updated CI to execute unit tests, PR #663; update test_unit.py to add test ca...
  • e266043 Reworked internal recursive implementations to use local stack vars or iterat...
  • See full diff in compare view

Updates pytz from 2026.3.post1 to 2026.4

Commits
  • 1ac6e51 Bump version numbers to 2026.4 (2026d)
  • 1672798 IANA 2026d
  • 0b5995b Squashed 'tz/' changes from 71f28b9ab3..bac9223f4b
  • e96461b Make deprecation notice louder
  • 3c7af58 Merge branch 'nicoleman0-fix/timezone-non-string-input' into 2026d
  • 234a247 Merge branch 'nicoleman0-fix/fixedoffset-basetzinfo' into 2026d
  • 8f8a588 Raise UnknownTimeZoneError for non-string zone arguments
  • 1f0f27e Make _FixedOffset a BaseTzInfo exposing _utcoffset
  • See full diff in compare view

Updates tzdata from 2026.3 to 2026.4

Release notes

Sourced from tzdata's releases.

2026.4: Release of upstream tzdata 2026d

Version 2026.4

Upstream version 2026d released 2026-09-11T22:21:07+00:00

Briefly:

Canada’s Northwest Territories moved to permanent -06 on 2026-08-21. Obsolescent settings like TZ="EST5EDT" now conform better to POSIX. Fix security, performance and porting bugs in zic and localtime.

Changes to future timestamps

Canada’s Northwest Territories will not fall back on 2026-11-01 and will stay on -06 year-round, matching Alberta’s recent change. Model this with its traditional abbreviation CST. Although the change to permanent -06 legally took place on 2026-08-21, temporarily model the change to occur on 2026-11-01 at 02:00 for the same reason as other recent temporary hacks. (Caution: see “NOTE FOR 2026b TEMPORARY HACK FOR CLDR AND CANADA” below.) This affects only America/Inuvik as the rest of the territory is covered by America/Edmonton, for which the equivalent change was released in 2026c.

Changes to past timestamps

Colombia’s 1992-05-02 spring forward was at 00:00, not 24:00.

Iran’s 1979-05-26 spring forward was at 00:00, not 24:00. (Thanks to N.F. Hase.)

The backward-compatibility names EST5EDT, CST6CDT, MST7MDT, and PST8PDT now conform better to POSIX. For example, EST5EDT now always uses the abbreviation "EST" for standard time (now always 5 hours behind UT) and "EDT" for daylight saving time, whereas it formerly had different UT offsets before standard time was introduced and sometimes used abbreviations like "LMT", "EWT" and "EPT", all contrary to POSIX. Also, though not required by POSIX these names now use US federal rules rather than rules of places like New York, reverting to 2024a behavior. This change affects only timestamps before 1966-10-30 at 01:00 standard time.

Other data changes

The temporary hacks used for North American timekeeping changes now work around a libstdc++ std::chrono bug in GCC 14.1-14.4, 15.1-15.2, and 16.1; see GCC bug 124851. This data change does not affect TZif files or timestamps. The change does not work around the related but less serious GCC bugs 116110 and 124513. These GCC bugs are all fixed in GCC 16.2.

Changes to documentation

URLs for release tarballs in tz-link.html have been updated to reflect their new canonical URLs on data.iana.org.

Changelog

Sourced from tzdata's changelog.

Version 2026.4

Upstream version 2026d released 2026-09-11T22:21:07+00:00

Briefly:

Canada’s Northwest Territories moved to permanent -06 on 2026-08-21. Obsolescent settings like TZ="EST5EDT" now conform better to POSIX. Fix security, performance and porting bugs in zic and localtime.

Changes to future timestamps

Canada’s Northwest Territories will not fall back on 2026-11-01 and will stay on -06 year-round, matching Alberta’s recent change. Model this with its traditional abbreviation CST. Although the change to permanent -06 legally took place on 2026-08-21, temporarily model the change to occur on 2026-11-01 at 02:00 for the same reason as other recent temporary hacks. (Caution: see “NOTE FOR 2026b TEMPORARY HACK FOR CLDR AND CANADA” below.) This affects only America/Inuvik as the rest of the territory is covered by America/Edmonton, for which the equivalent change was released in 2026c.

Changes to past timestamps

Colombia’s 1992-05-02 spring forward was at 00:00, not 24:00.

Iran’s 1979-05-26 spring forward was at 00:00, not 24:00. (Thanks to N.F. Hase.)

The backward-compatibility names EST5EDT, CST6CDT, MST7MDT, and PST8PDT now conform better to POSIX. For example, EST5EDT now always uses the abbreviation "EST" for standard time (now always 5 hours behind UT) and "EDT" for daylight saving time, whereas it formerly had different UT offsets before standard time was introduced and sometimes used abbreviations like "LMT", "EWT" and "EPT", all contrary to POSIX. Also, though not required by POSIX these names now use US federal rules rather than rules of places like New York, reverting to 2024a behavior. This change affects only timestamps before 1966-10-30 at 01:00 standard time.

Other data changes

The temporary hacks used for North American timekeeping changes now work around a libstdc++ std::chrono bug in GCC 14.1-14.4, 15.1-15.2, and 16.1; see GCC bug 124851. This data change does not affect TZif files or timestamps. The change does not work around the related but less serious GCC bugs 116110 and 124513. These GCC bugs are all fixed in GCC 16.2.

Changes to documentation

URLs for release tarballs in tz-link.html have been updated to reflect their new canonical URLs on data.iana.org.


Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close t...

Description has been truncated

Updates the requirements on [requests](https://github.com/psf/requests), [urllib3](https://github.com/urllib3/urllib3), [mypy](https://github.com/python/mypy), [types-pyyaml](https://github.com/python/typeshed), [types-requests](https://github.com/python/typeshed), [charset-normalizer](https://github.com/jawah/charset_normalizer), [idna](https://github.com/kjd/idna), [fonttools](https://github.com/fonttools/fonttools), [pyparsing](https://github.com/pyparsing/pyparsing), [pytz](https://github.com/stub42/pytz) and [tzdata](https://github.com/python/tzdata) to permit the latest version.

Updates `requests` from 2.32.5 to 2.34.2
- [Release notes](https://github.com/psf/requests/releases)
- [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md)
- [Commits](psf/requests@v2.32.5...v2.34.2)

Updates `urllib3` from 2.6.3 to 2.8.0
- [Release notes](https://github.com/urllib3/urllib3/releases)
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst)
- [Commits](urllib3/urllib3@2.6.3...2.8.0)

Updates `mypy` to 2.3.1
- [Changelog](https://github.com/python/mypy/blob/master/CHANGELOG.md)
- [Commits](python/mypy@v1.14.0...v2.3.1)

Updates `types-pyyaml` to 6.0.12.20260906
- [Commits](https://github.com/python/typeshed/commits)

Updates `types-requests` to 2.33.0.20260906
- [Commits](https://github.com/python/typeshed/commits)

Updates `charset-normalizer` from 3.5.1 to 3.5.2
- [Release notes](https://github.com/jawah/charset_normalizer/releases)
- [Changelog](https://github.com/jawah/charset_normalizer/blob/master/CHANGELOG.md)
- [Commits](jawah/charset_normalizer@3.5.1...3.5.2)

Updates `idna` from 3.19 to 3.20
- [Release notes](https://github.com/kjd/idna/releases)
- [Changelog](https://github.com/kjd/idna/blob/master/HISTORY.md)
- [Commits](kjd/idna@v3.19...v3.20)

Updates `fonttools` from 4.65.0 to 4.66.1
- [Release notes](https://github.com/fonttools/fonttools/releases)
- [Changelog](https://github.com/fonttools/fonttools/blob/main/NEWS.rst)
- [Commits](fonttools/fonttools@4.65.0...4.66.1)

Updates `pyparsing` from 3.3.2 to 3.3.3
- [Release notes](https://github.com/pyparsing/pyparsing/releases)
- [Changelog](https://github.com/pyparsing/pyparsing/blob/master/CHANGES)
- [Commits](pyparsing/pyparsing@3.3.2...3.3.3)

Updates `pytz` from 2026.3.post1 to 2026.4
- [Release notes](https://github.com/stub42/pytz/releases)
- [Commits](stub42/pytz@release_2026.3.post1...release_2026.4)

Updates `tzdata` from 2026.3 to 2026.4
- [Release notes](https://github.com/python/tzdata/releases)
- [Changelog](https://github.com/python/tzdata/blob/master/NEWS.md)
- [Commits](python/tzdata@2026.3...2026.4)

---
updated-dependencies:
- dependency-name: requests
  dependency-version: 2.34.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: urllib3
  dependency-version: 2.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: mypy
  dependency-version: 2.3.1
  dependency-type: direct:development
  dependency-group: python-dependencies
- dependency-name: types-pyyaml
  dependency-version: 6.0.12.20260906
  dependency-type: direct:development
  dependency-group: python-dependencies
- dependency-name: types-requests
  dependency-version: 2.33.0.20260906
  dependency-type: direct:development
  dependency-group: python-dependencies
- dependency-name: charset-normalizer
  dependency-version: 3.5.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: idna
  dependency-version: '3.20'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: fonttools
  dependency-version: 4.66.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: pyparsing
  dependency-version: 3.3.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: pytz
  dependency-version: '2026.4'
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: tzdata
  dependency-version: '2026.4'
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Oct 4, 2026
@dependabot
dependabot Bot requested a review from xxg1413 as a code owner October 4, 2026 08:00
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Oct 4, 2026
@xxg1413
xxg1413 merged commit cc156d8 into master Oct 4, 2026
3 checks passed
@xxg1413
xxg1413 deleted the dependabot/pip/python-dependencies-e8addec0a6 branch October 4, 2026 08:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant