Skip to content

Scheduled weekly dependency update for week 36 - #458

Closed
pyup-bot wants to merge 14 commits into
mainfrom
pyup-scheduled-update-2026-09-07
Closed

pyup-bot wants to merge 14 commits into
mainfrom
pyup-scheduled-update-2026-09-07

Conversation

@pyup-bot

@pyup-bot pyup-bot commented Sep 7, 2026

Copy link
Copy Markdown
Collaborator

Update cattrs from 26.1.0 to 26.2.0.

Changelog

26.2.0

- Fix the `msgpack` and `cbor2` converters unstructuring naive datetimes as local time, which made the serialized value depend on the timezone of the machine doing the unstructuring; naive datetimes are now assumed to be UTC, matching what the structure hooks already read back.
([774](https://github.com/python-attrs/cattrs/issues/774) [#775](https://github.com/python-attrs/cattrs/pull/775))
- Fix `override(rename=...)` targets containing a quote (or other characters not safe in a bare string literal) crashing code generation with `SyntaxError`; the rename key is now embedded with `repr`.
([771](https://github.com/python-attrs/cattrs/pull/771))
- Fix `Counter` keys not being unstructured with the key type's own hook; the single-type-arg branch passed the whole type-args tuple to the key hook lookup instead of the key type.
([768](https://github.com/python-attrs/cattrs/pull/768))
- Fix `create_default_dis_func <cattrs.disambiguators.create_default_dis_func>` (aka `create_uniq_field_dis_func`) failing to disambiguate valid unions depending on the order of the member classes; unique fields are now resolved iteratively to a fixpoint.
([230](https://github.com/python-attrs/cattrs/issues/230) [#765](https://github.com/python-attrs/cattrs/pull/765))
- Support more recursive types on 3.14+ with specialized factories for [`annotationlib.ForwardRef`](https://docs.python.org/3/library/annotationlib.html#annotationlib.ForwardRef).
([740](https://github.com/python-attrs/cattrs/issues/740) [#741](https://github.com/python-attrs/cattrs/pull/741))
- `Converter <cattrs.Converter>` now uses specialized hook factories to generate hooks for tuples, increasing speed.
([737](https://github.com/python-attrs/cattrs/pull/737))
- Fix an `AttributeError` in `cattrs` internals that could be triggered by using the `include_subclasses` strategy in a `structure_hook_factory`
([721](https://github.com/python-attrs/cattrs/issues/721), [#722](https://github.com/python-attrs/cattrs/pull/722))
- Fix TypedDict codegen when keys contain single quotes.
([769](https://github.com/python-attrs/cattrs/pull/769))
- Add `CattrsError` exception type: all exceptions raised by `cattrs` inherit from this. 
Literal and date-time validation raise this directly, instead of `Exception`.
([728](https://github.com/python-attrs/cattrs/pull/728))
- Fix the `detailed_validation` parameter being passed under the wrong name in {func}`namedtuple_dict_structure_factory <cattrs.cols.namedtuple_dict_structure_factory>`, causing it to be silently ignored.
([723](https://github.com/python-attrs/cattrs/pull/723))
- _cattrs_ is now autoformatted using Ruff.
([732](https://github.com/python-attrs/cattrs/pull/732))
- Support running the test suite without `cbor2` installed.
([748](https://github.com/python-attrs/cattrs/pull/748))
- The [union passthrough strategy](https://catt.rs/en/stable/strategies.html#union-passthrough) now supports PEP 695 type aliases as union members.
([753](https://github.com/python-attrs/cattrs/pull/753))
- {meth}`BaseConverter.register_structure_hook_factory` and {meth}`BaseConverter.register_unstructure_hook_factory` now properly return the factory when used as decorators.
([724](https://github.com/python-attrs/cattrs/pull/724))
- The {mod}`msgspec <cattrs.preconf.msgspec>` preconf converter now properly handles recursive classes on Python 3.14+.
([757](https://github.com/python-attrs/cattrs/pull/757))
Links

Update fonttools from 4.63.0 to 4.64.0.

Changelog

4.64.0

----------------------------

- [feaLib] Fix name-table parsing for multibyte Mac encodings (1196, 4092).
- [ttProgram] Also indent TrueType assembly following ``IDEF[ ]``, like function
definitions (4093).
- [subset] Keep East Asian spacing ``palt`` by default (4094).
- [subset] Bug fix for MATH table in which constructions for glyphs that are only
added during MATH closure were kept (4096).
- [ufoLib] Make glyph-to-group construction accessible outside of lookup function
(4102).
- [glyf] Use reverse glyph map for O(1) ``__setitem__`` membership (4103).
- [ttLib] Fix ``fixLookupOverFlows()`` reporting success when it had not promoted
any lookup to Extension, masking unresolvable overflows.
- [ttLib] Add support for TrueType Collection version 2 (4100).
- [ttLib] Pin a single head.modified timestamp across ``TTCollection.save`` (4111).
- [ttLib] Give an actionable error when LookupList overflow is unrecoverable (4109).
- [ttLib] Add support for the AAT bitmap tables ``bhed``, ``bdat``, ``bloc``,
variants of ``head``, ``EBDT``, ``EBLC`` used in legacy Apple bitmap-only fonts
(4115).
- [ttLib] Check ``OS/2`` fsSelection/macStyle consistency against ``bhed`` as well
as ``head`` (4118, 4119).
- [misc.roundTools] Add types and documentation (4123).
- [varLib.instancer] Instance the ``BASE`` table (4137).
- [varLib.instancer] Fix Private-dict ``vsindex`` handling in ``instantiateCFF2``
(4129, 4132).
- [varLib.instancer] Fix crash instancing CFF2 fonts without a VariationStore
(4130, 4131).
- [sfnt] Raise ``TTLibError`` instead of ``AssertionError`` or ``struct.error``
when reading a font truncated within the table directory or a table entry
(4147, 4149).
- [misc.xmlWriter] Escape the ``]]>`` terminator inside CDATA sections, so an SVG
document containing it can no longer smuggle markup past a TTX round trip
(4139).
- [varLib.instancer] Implement avar2 partial-instancing: the avar version 2
ItemVariationStore is adjusted so that remaining axes behave the same after
limiting the designspace (4045).
- [feaLib] Add shorthand for the value at the default location in a variable
scalar: ``(100 wght=900:120)`` means ``(wght=400:100 wght=900:120)`` when the
wght default is 400 (4024).
- [cmap] Raise ``TTLibError`` for a truncated or out-of-bounds cmap subtable
header (4151).
- [designspaceLib] Reject conflicting duplicate inputs in axis maps instead of
silently keeping the last one (4153).
- [designspaceLib] Read an empty ``<lib>`` element as an empty lib instead of
raising ``IndexError`` (4142, 4144).
- [colorLib] Raise a legible error when a COLRv0 layer, or a COLRv1 PaintGlyph or
PaintColrGlyph, references a glyph missing from the glyphMap, instead of failing
obscurely later (2629, 4141).
- [cmap] Don't drop subtables in unsupported formats when compiling or dumping a
font read from binary (4136).
- [ttLib] Implement ``splitSinglePos`` so GPOS lookup type 1 offset overflows can
be recovered by splitting the subtable (4091, 4108).
- [cmap] Round-trip empty Macintosh format 2 subtables (3663, 4117).
- [glyf] Raise ``TTLibError`` instead of ``RecursionError`` when ``recalcBounds()``
hits a composite-component reference cycle (3899, 4116).
- [svgLib] Fix crash parsing an SVG path with consecutive closepath commands
(``Z Z``) (4122).
- [ttLib] Fix ``DefaultTable`` type annotations (4126).
- [ttLib] Add support for the ``EBSC`` (Embedded Bitmap Scaling) table (4113).
- [svgLib] Suppress spurious close segments caused by floating-point drift in
relative path commands (3860, 4127).
- [qu2cu] Fix ``TypeError`` in the Cython-compiled build when ``Qu2CuPen`` passes
tuple splines (4160).
- [mort] Add semantic decompilation, TTX, and compilation support for
rearrangement, contextual-substitution, ligature, and insertion subtables
(4158, 4159, 4161).
- [svgLib] Start a new subpath at the just-closed subpath's initial point when a
drawto command follows a closepath, per SVG spec (4154, 4155).
- [misc.filesystem] **SECURITY** Reject paths that resolve outside the filesystem
root: a malicious UFO could read arbitrary files via ``..`` components in
``contents.plist``, and a crafted ``.ufoz`` could create files outside its
temporary mirror (4124).
- [ttLib] **SECURITY** Sanitise glyph names used as filenames in EBDT/CBDT
``ttx -z extfile`` export, preventing arbitrary file writes from untrusted
fonts (4128).
- [misc.etree] **SECURITY** Don't resolve external XML entities in ``XMLParser``
when lxml is used, preventing XXE file disclosure on lxml < 5.0 (4145).
- [subset] Fully prune ``VARC`` auxiliary data: collect and remap variation
indices referenced by condition tables when subsetting the ``MultiVarStore``,
and drop the ``AxisIndicesList``, ``ConditionList``, and ``MultiVarStore``
when they end up empty (4162).
Links

Update lxml from 6.1.1 to 6.1.3.

Changelog

6.1.2

==================

* GH526: Some build files were missing in the sdist.
Patch by Nicola Soranzo.

* Some minor corrections for error handling cases.

Other changes
-------------

* Built with Cython 3.2.9.
Links

Update msgpack from 1.2.1 to 1.2.2.

The bot wasn't able to find a changelog for this release. Got an idea?

Links

Update orjson from 3.11.9 to 3.12.0.

Changelog

3.12.0

Changed

- Serialization implementation substantially rewritten.
- Publish PyPI wheels for Python 3.15. For Python 3.15 and later,
`manylinux_2_39` (2024) is targeted instead of `manylinux_2_17` (2012).
- No longer publish PyPI wheels for ppc64le and s390x.
Links

Update ast-serialize from 0.6.0 to 0.10.0.

The bot wasn't able to find a changelog for this release. Got an idea?

Links

Update click from 8.4.2 to 8.5.0.

Changelog

8.5.0

Released 2026-08-24

- Add built-in shell completion support for PowerShell (Windows PowerShell
5.1+ and pwsh 7+) alongside the existing `bash`, `zsh`, and `fish`
completers. Use `_FOO_BAR_COMPLETE=powershell_source foo-bar` to generate
the completion script. {issue}`2672` {pr}`3637`
- Supported versions of Windows enable ANSI terminal styles by default.
Colorama is no longer a dependency and is not used. {issue}`2986` {pr}`3505`
- {class}`Argument` accepts a `help` parameter, and help output includes
a `Positional arguments` section when argument help is available. {issue}`2983` {pr}`3473`
- `confirm()` and `prompt()` strip ANSI color and style codes from the
prompt when the output stream does not support them, matching `echo()`.
This stripping was lost in `8.4.0` when {pr}`2969` began writing the
prompt with `input()` directly. {issue}`3572` {pr}`3653`
- Fix test failures when using pytest >= 9.1. {pr}`3656`
- {class}`Path` with `allow_dash=True` no longer triggers a `BytesWarning`,
an error under `python -bb`, when checking a value against the `-`
convention. {issue}`2877` {pr}`3642`
- Add {func}`custom_version_option`, a `--version` option whose output is
produced by a callback, covering cases {func}`version_option` intentionally
does not. The feature set of {func}`version_option` is now frozen; see
[discussion 3527](https://github.com/pallets/click/discussions/3527). {pr}`3581`
- `style()` and `secho()` no longer silently drop the 256-color index `0`
(black) passed as `fg` or `bg`, and now validate color arguments. Invalid
colors raise a `ValueError` instead of a `TypeError`. {pr}`3677`
- The automatic help option stores its value under the reserved name
`_click_default_help` instead of `help`, so a parameter named `help` no
longer breaks parsing. The new name is visible in
{meth}`Command.to_info_dict` output. Parameters that overwrite each other's
value trigger a warning: an argument sharing its name with another
parameter, or any parameter claiming the reserved name. Options may still
share a name to compete for the same value (feature switches).
{issue}`2819` {pr}`3678`
- `unstyle` and the ANSI handling behind help-text wrapping now strip the full
CSI escape-sequence grammar. {pr}`3681`
- Streamline `Option` flag handling: the flag-kind, type, lazy-default and
validation steps in `Option.__init__` move into focused helpers, and
`flag_value` and `default` keep their unset sentinel at construction
(resolved lazily on read) so `is UNSET` reliably tells a user-supplied value
from an auto-derived one. Runtime behavior is unchanged, but
{meth}`Parameter.to_info_dict` now resolves `default=True` on a feature
switch to its `flag_value`, matching what the function receives at call
time. {pr}`3641`
- {func}`get_binary_stream` and {func}`get_text_stream` are deprecated and
will be removed in Click 9.0. {issue}`3481` {pr}`3695`
- The following `click.utils` names were never intentionally public and are
now private (`_`-prefixed). The old names remain available with a
`DeprecationWarning` until Click 9.0: `LazyFile`, `KeepOpenFile`,
`make_default_short_help`, `PacifyFlushWrapper`, and `safecall`.
{issue}`3099` {pr}`3695`
- Deprecate {meth}`CliRunner.isolated_filesystem`. It relies on
{func}`os.chdir`, which mutates process-global state and is not
thread-safe. The helper predates Python 3 and modern pytest: use a
temporary directory ({class}`tempfile.TemporaryDirectory` or pytest's
`tmp_path` fixture) with absolute paths instead. For running tests in
parallel, use process-based isolation (such as `pytest-xdist`) rather
than threads, since {meth}`CliRunner.invoke` also redirects the
process-global standard streams. {issue}`3501` {issue}`3700` {pr}`3704`
- `prompt()` is now generically typed and returns the type produced by
`type`, `value_proc`, or a matching `default` instead of `Any`.
{class}`ParamType` takes a second optional type parameter describing the
input value it accepts (`ParamType[int, str]` for a type converting
strings to integers), defaulting to `Any`. {pr}`3407`
- {meth}`Command.get_help_option_names` returns the help option names in the
order they were declared. {pr}`3728`
- {func}`get_pager_file` yields a text stream on Windows again. The temporary
file backend opened its file in binary mode, so writing a `str` to the pager
raised `TypeError: a bytes-like object is required, not 'str'`, and the
`color` argument was ignored on that path. Regression introduced in `8.4.0`
by {pr}`1572`. {issue}`3731` {issue}`3732` {issue}`3740` {pr}`3739`
- {func}`progressbar` settles on its final position when `update_min_steps`
does not divide the total. Steps below that threshold are applied when the
bar finishes, so `show_pos` renders `20/20` rather than the last multiple
it reached. {issue}`3571` {pr}`3769`
- An error raised while writing to the pager no longer gets replaced by
`PermissionError: [WinError 32]` on Windows. The temporary file backend
unlinked its file without closing it first, and Windows refuses to remove a
file the process still holds open, so the cleanup failure masked the real
exception. {issue}`3731` {pr}`3764`
- The temporary file the pager writes to on Windows is opened with the encoding
{func}`get_pager_file` picked for the output stream, and with
`errors="replace"` to match the pipe backend. Any text stdout can encode
reaches the pager.
- The temporary file pager backend forwards any parameters the user set in
`PAGER` to the pager command instead of silently dropping them. On Windows,
`PAGER="less -R"` now invokes `less -R` on the temporary file rather than
bare `less`. {pr}`3777`
- Improve raw mode detection by parsing the option tokens. {issue}`3416`
{pr}`3777`
- {func}`edit` accepts `os.PathLike` values for `filename`, in addition to
strings. {issue}`2869` {pr}`3781`
Links

Update coverage from 7.15.2 to 7.16.0.

Changelog

7.16.0

---------------------------

- When combining files, now path separator slashes will automatically be
converted to the local file system style. This makes it less necessary to
define ``[paths]`` configuration to combine data across operating systems.
Fixes `issue 2266`_.

- The :meth:`.Coverage.switch_context` method now returns the previous context.

- Fix: previously, a ``[paths]`` pattern would be replaced everywhere in a file
path when it was only meant to be replaced once, in the leading portion of
the path. This is now fixed, in `pull 2268`_.

- Fixes to validation of options and configuration settings:

- Negative precision settings now always cause useful error messages (`pull
 2261`_).

- An invalid regex in the ``--contexts`` option (or the ``[report]
 contexts`` setting) reported a confusing "Couldn't use data file ...:
 user-defined function raised exception" error. Now it raises a proper
 configuration error naming the bad regex, like other regex settings do
 (`pull 2262`_).

- Non-string values in TOML configuration settings now produce a helpful
 error message instead of a traceback.  This affects list settings whose
 elements aren't strings (like ``omit``, ``exclude_lines``, or a ``[paths]``
 entry), file settings like ``data_file``, and any wrong-typed value in the
 ``[paths]`` section (`pull 2263`_).

- ``coverage run`` refuses run-affecting command-line options like
 ``--branch`` alongside ``--concurrency=multiprocessing``, since they can't
 reach the subprocesses.  The check only recognized ``multiprocessing`` as
 the entire option value, so ``--concurrency=multiprocessing,thread``
 slipped through and failed later with "Can't combine statement coverage
 data with branch data".  Each named concurrency library is now properly
 considered (`pull 2270`_).

- Fix: ``coverage annotate -d DIR`` raised an ``AssertionError`` if any
measured file had an extension other than ``.py``, such as a ``.pyw`` file on
Windows.  The original extension is now restored on the annotated copy (`pull
2265`_).

.. _pull 2261: https://github.com/coveragepy/coveragepy/pull/2261
.. _pull 2262: https://github.com/coveragepy/coveragepy/pull/2262
.. _pull 2263: https://github.com/coveragepy/coveragepy/pull/2263
.. _pull 2265: https://github.com/coveragepy/coveragepy/pull/2265
.. _issue 2266: https://github.com/coveragepy/coveragepy/issues/2266
.. _pull 2268: https://github.com/coveragepy/coveragepy/pull/2268
.. _pull 2270: https://github.com/coveragepy/coveragepy/pull/2270


.. _changes_7-15-4:

7.15.4

---------------------------

- Fix: in the HTML report, a source file name containing a double quote (legal
on POSIX) wasn't escaped where it's dropped into the ``href`` of the index
and prev/next links, so it could close the attribute early and inject markup.
Page URLs are now escaped. Thanks, `Rajath Mohare <pull 2227_>`_.

- Fix: the LCOV report wrote file names and other fields into its
line-oriented records without neutralizing control characters. A measured
file whose name contained a newline (legal on POSIX) could forge extra
records, inflating the coverage seen by tools that read the report. Control
characters in a field are now replaced. Thanks, `Rajath Mohare <pull
2226_>`_.

- Wheels are now provided for Python 3.15.

.. _pull 2226: https://github.com/coveragepy/coveragepy/pull/2226
.. _pull 2227: https://github.com/coveragepy/coveragepy/pull/2227


.. _changes_7-15-3:

7.15.3

---------------------------

- Fix: the sysmon core is incompatible with dynamic contexts. Previously, the
combination would be prevented when read from the coverage.py configuration.
But using the context API as pytest-cov does, contexts would be silently
dropped. Now a warning is issued, thanks to `Jisang Han <pull 2234_>`_.
Closes `issue 2200`_.

- A performance improvement in the low-level line number bookkeeping when
combining data files, thanks to `Kevin Turcios <pull 2239_>`_.

- Performance improvement in HTML reporting by reducing the number of times
files have to be parsed, thanks to `Kevin Turcios <pull 2240_>`_.

.. _issue 2200: https://github.com/coveragepy/coveragepy/issues/2200
.. _pull 2234: https://github.com/coveragepy/coveragepy/pull/2234
.. _pull 2239: https://github.com/coveragepy/coveragepy/pull/2239
.. _pull 2240: https://github.com/coveragepy/coveragepy/pull/2240


.. _changes_7-15-2:
Links

Update isort from 8.0.1 to 9.0.1.

Changelog

9.0.0

- Remove logic for deprecated options (2498) DanielNoord
- Sort lazy import statements (2503) DanielNoord
- Add initial support for Python 3.15 (2466) DanielNoord
- Compile with `mypyc` by DanielNoord in https://github.com/PyCQA/isort/pull/2586
- Cache calls to `posixpath.abspath` by DanielNoord in https://github.com/PyCQA/isort/pull/2606
- Consider private `stdlib` modules to be `stdlib` (2295) devdanzin
- Add CLI Flag for --forced-separate (https://github.com/PyCQA/isort/pull/2367) hirak99
- Add separate_packages option (2313) alex-liang3
- Fix inline comment duplication across merged `from X import` lines (2499) copilot-swe-agent
- Fix src glob patterns passed via CLI (2497) ReinerBRO
- Fix opening-line comment moving to alias attribute line on wrapped imports (2491) copilot-swe-agent
- Fix multi_line_output=3/5 ignored when wrapping single imports with inline comments (2474) copilot-swe-agent
- Fix false positive in `check_code` when using `float_to_top` + `add_imports` (2492) copilot-swe-agent
- Fix: preserve bare `` inline comments on imports (2488) copilot-swe-agent
- Fix grouping of non-aliased imports when mixed with aliased imports from the same module (2470) copilot-swe-agent
- Fix https://github.com/PyCQA/isort/issues/2500: trusted publishing by staticdev in https://github.com/PyCQA/isort/pull/2521
- Fix git_hook lazy=True option by sparrowt in https://github.com/PyCQA/isort/pull/2542
- Honor ` isort: off/on/split` during `float_to_top` preprocessing with CRLF input by DanielNoord with Copilot in https://github.com/PyCQA/isort/pull/2553
- Fix --sort-reexports crash with non-seekable streams (e.g. stdin) by Abdu-Ahmed in https://github.com/PyCQA/isort/pull/2547
- Fix non-idempotent output with split_on_trailing_comma and a non-default wrap mode by sarathfrancis90 in https://github.com/PyCQA/isort/pull/2554
- Fix non-idempotent NOQA wrap mode with imports that carry their own comment by sarathfrancis90 in https://github.com/PyCQA/isort/pull/2556
- Fix NOQA wrap mode accumulating spaces before the comment on each run by sarathfrancis90 in https://github.com/PyCQA/isort/pull/2558
- Fix NOQA not added to long imports in several output paths by urayoru113 in https://github.com/PyCQA/isort/pull/2568
- Honor ` isort: skip` when a `__future__` import is present (2092) by apoorvdarshan in https://github.com/PyCQA/isort/pull/2574
- fix: make sorted `__all__` and literals black-compatible (2280) by lord-haffi in https://github.com/PyCQA/isort/pull/2576
- Honor skip comments when sorting reexports by sakshichitnis27 in https://github.com/PyCQA/isort/pull/2581
- Keep aliased import when the plain name carries a comment by sarathfrancis90 in https://github.com/PyCQA/isort/pull/2567
- fix: don't crash on --config-root without --resolve-all-configs by Gooh456 in https://github.com/PyCQA/isort/pull/2597
- fix: check_code misses lines_before_imports-only changes (2242) by gaoflow in https://github.com/PyCQA/isort/pull/2563
- Fix preservation of form-feed blank lines by utkarshalpha in https://github.com/PyCQA/isort/pull/2599
- Small clean up and fix inconsistency in handling of `*` imports by DanielNoord in https://github.com/PyCQA/isort/pull/2619
- Fix word-wrapping of 'from ... import *' into invalid Python (2267) by sudorm-rf0 in https://github.com/PyCQA/isort/pull/2624
- Fix pylint disable-next comments at the start of imports by Neallin-917 in https://github.com/PyCQA/isort/pull/2628
- Keep add_imports below a prefixed module docstring by Eljees in https://github.com/PyCQA/isort/pull/2626
- Add read the docs configuration (2504) DanielNoord
- Remove unused and broken dependencies (2517) DanielNoord
- Remove `Any` from `parse.py` (2516) DanielNoord
- Bring documentation in line with old documentation (2507) DanielNoord
- Sync profile docs with implementation (2495) copilot-swe-agent
- Fix the playground (2494) DanielNoord7) hirak99
- Remove unused _ENCODING_PATTERN regex and re import by duriantaco in https://github.com/PyCQA/isort/pull/2525
- Remove references to defunct `git_ignore` config by sparrowt in https://github.com/PyCQA/isort/pull/2531
- Fix broken relative links in README and CHANGELOG for both GitHub and Sphinx by rohitshinde08 in https://github.com/PyCQA/isort/pull/2530
- Bump vendored `tomli` by DanielNoord in https://github.com/PyCQA/isort/pull/2579
- Document temporary .isorted files by sapunyangkut in https://github.com/PyCQA/isort/pull/2580
- Remove `cruft` by DanielNoord in https://github.com/PyCQA/isort/pull/2610
- Small fixes in preparation for `mypyc` compiled wheels by DanielNoord in https://github.com/PyCQA/isort/pull/2623
- Small fixes in preparation for compiling with `mypyc` by DanielNoord in https://github.com/PyCQA/isort/pull/2625
- Fix `test_importable` for local dev by DanielNoord in https://github.com/PyCQA/isort/pull/2635
Links

Update librt from 0.13.0 to 0.15.0.

The bot wasn't able to find a changelog for this release. Got an idea?

Links

Update mypy from 2.3.0 to 2.3.1.

Changelog

2.3.1

- Fix mypyc crash on double yielding Iterators (Daniël van Noord, PR [21826](https://github.com/python/mypy/pull/21826))
- Fix mypyc `default_factory` for inherited dataclass (Daniël van Noord, PR [21785](https://github.com/python/mypy/pull/21785))
- Clear mypyc coroutine env on coroutine completion (Piotr Sawicki, PR [21734](https://github.com/python/mypy/pull/21734))
- Fix crash when unpacking return value from overload (Shantanu, PR [21830](https://github.com/python/mypy/pull/21830))

Acknowledgements

Thanks to all mypy contributors who contributed to this release:

- Agriya Khetarpal
- Ethan Sarp
- Ivan Levkivskyi
- Jingchen Ye
- Jukka Lehtosalo
- Piotr Sawicki
- Shantanu
- Tom Bannink
- Viktor Szépe
- ygale

I'd also like to thank my employer, Dropbox, for supporting mypy development.
Links

Update packaging from 26.2 to 26.3.

Changelog

26.3

~~~~~~~~~~~~~~~~~

Features:

* Add a public :class:`~packaging.ranges.VersionRange` API and
:meth:`SpecifierSet.to_range() <packaging.specifiers.SpecifierSet.to_range>`,
representing the versions a specifier set accepts as an interval set that
supports intersection, union, difference, complement, set relations,
membership tests, and filtering.
:meth:`~packaging.ranges.VersionRange.to_specifier_set` converts a range back
to a :class:`~packaging.specifiers.SpecifierSet` where a PEP 440 form exists.
(:pull:`1267`, :pull:`1270`, :pull:`1298`)
* PEP 808: accept ``Metadata-Version: 2.6``. (:pull:`1194`)
* Add a ``limit`` argument to ``parse_tag()`` for compressed tag sets.
(:issue:`1220`)
* Add a ``prefer_sdist_predicate`` argument to ``Pylock.select()`` to prefer
source distributions over wheels for selected packages. (:pull:`1334`)
* Add :func:`~packaging.tags.pure_python_tags` to generate the pure-Python
tags for a Python version without touching the running platform.
(:pull:`1346`)
* Add :meth:`SpecifierSet.is_subset()
<packaging.specifiers.SpecifierSet.is_subset>`, :meth:`~packaging.specifiers.SpecifierSet.is_superset`,
and :meth:`~packaging.specifiers.SpecifierSet.is_disjoint`, which compare the
versions two specifier sets accept. (:pull:`1313`)

Behavior adaptations:

* Drop support for Python 3.8; packaging now requires Python 3.9 or later.
(:pull:`1157`)
* Prefer native ``linux_*`` platform tags over ``manylinux`` and ``musllinux``
tags on Linux. (:issue:`160`)

Fixes for versions and specifiers:

* Raise ``InvalidVersion`` instead of ``TypeError`` when ``Version`` is given a
non-string. (:pull:`1319`)
* Raise ``InvalidVersion`` for non-string pre-release letters passed to
``Version.from_parts``. (:pull:`1241`)
* Fix an ``AttributeError`` when hashing internally trimmed versions.
(:pull:`1242`)
* Fix ``SpecifierSet.is_unsatisfiable`` for post-release boundary
intersections. (:pull:`1257`)

Fixes for requirements and markers:

* Make ``Requirement.__hash__`` consistent with ``__eq__`` for
trailing-zero-equivalent specifiers (e.g. ``foo==1.0.0`` and
``foo==1.0.0.0``), so equal requirements hash equal and deduplicate in
sets and dicts. (:pull:`1232`)
* Normalize requested extra names before comparing or hashing requirements.
(:issue:`644`)
* Preserve a ``Requirement``'s specifier ``prereleases`` override across a
pickle round trip. (:issue:`1204`)
* Raise ``InvalidRequirement`` instead of ``InvalidSpecifier`` when a
requirement contains an invalid specifier. (:pull:`1332`)
* Clarify the error for post-release prefix wildcards like ``==1.0.post1.*``.
(:pull:`1299`)
* Preserve quoting semantics when serializing marker values, so round-tripped
markers parse back to the same marker. (:pull:`1213`)
* Keep the parentheses of a nested group when serializing markers.
(:pull:`1316`)
* Normalize ``extra`` and ``dependency_groups`` values in nested markers at
parse time. (:pull:`1246`, :pull:`1310`)
* Raise ``UndefinedComparison`` when a set-valued variable like ``extras`` is
used outside the membership form. (:pull:`1265`)
* Raise ``UndefinedEnvironmentName`` (a ``KeyError`` subclass) for missing
environment keys during marker evaluation. (:pull:`1276`)
* Wrap malformed string literal errors in ``InvalidMarker`` /
``InvalidRequirement`` instead of leaking a low-level error. (:pull:`1249`)
* Reject requirements and markers with a trailing line break. (:pull:`1345`)

Fixes for metadata and licenses:

* Collect all ``from_email`` validation errors into one ``ExceptionGroup``
instead of raising the first. (:pull:`1268`)
* Accept the UTF-8 charset case-insensitively in email payloads.
(:pull:`1330`)
* Reject malformed ``Description-Content-Type`` values. (:pull:`1329`)
* Don't rewrite user values that contain ``{field}`` placeholders in error
messages. (:pull:`1327`)
* Route multipart email payloads to ``unparsed`` instead of asserting.
(:pull:`1247`)
* Make ``InvalidMetadata`` and ``CyclicDependencyGroup`` picklable.
(:pull:`1328`)
* Fold every line boundary ``str.splitlines`` recognizes when writing a header
with :class:`~packaging.metadata.RFC822Message`. (:pull:`1356`)
* Raise ``InvalidLicenseExpression`` for misplaced ``WITH`` clauses and empty
``LicenseRef-`` names. (:pull:`1266`)
* Raise ``InvalidLicenseExpression`` instead of ``KeyError`` for a
``LicenseRef-`` with a ``+`` suffix. (:pull:`1219`)

Fixes for tags and filenames:

* Raise ``InvalidTag`` from ``parse_tag()`` for tags with the wrong number of
components. (:pull:`1238`)
* Reject empty tag components in ``parse_wheel_filename()`` and
``parse_tag()``. (:pull:`1234`)
* Reject an empty project name in the wheel and sdist filename parsers.
(:pull:`1305`)
* Reject wheel filenames with a trailing newline. (:pull:`1341`)
* Reject wheel tags whose interpreter component is not an identifier.
(:issue:`577`)
* ``is_normalized_name`` now rejects names with collapsed double hyphens like
``a--b``. (:pull:`1230`)
* Fix duplicate explicit ``abi3t`` tags. (:pull:`1245`)
* Forward the ``warn`` argument to ``generic_tags()`` in ``sys_tags()``.
(:pull:`1264`)
* Raise ``SystemError`` for an empty or malformed CPython ``EXT_SUFFIX``.
(:pull:`1271`, :pull:`1301`)
* Fix a typo in the macOS ``fat3`` architecture name (was ``fat32``).
(:pull:`1199`)

Fixes for pylock, direct URLs, and dependency groups:

* Percent-decode ``pylock`` artifact file names derived from a ``url`` so that
local versions (e.g. a wheel with ``2.12.1+cu130`` encoded as ``2.12.1%2Bcu130``)
yield a valid file name. (:pull:`1314`)
* Use an explicitly empty ``tags`` sequence in ``Pylock.select()`` instead of
falling back to ``sys_tags()``. (:pull:`1349`)
* Fix ``Pylock.select()`` on Python builds that report a non-PEP 440
``python_full_version`` (e.g. ``3.15.0+``). (:pull:`1179`)
* Reject TOML booleans where integers are expected in ``pylock`` files.
(:pull:`1244`)
* Add ``PylockSelectError`` to ``packaging.pylock.__all__``. (:pull:`1202`)
* Fix ``DirectUrl`` credential stripping for passwords containing `.
(:pull:`1218`)
* Parse the URL scheme case-insensitively when checking for file URLs in
``direct_url``. (:pull:`1240`)
* Require absolute file URLs for local directories in ``direct_url``.
(:pull:`1297`)
* Collect ``InvalidRequirement`` errors while resolving dependency groups
instead of leaking them. (:pull:`1302`)
* Don't cache malformed dependency group parses. (:pull:`1248`)

Performance:

* Implement ``Specifier`` and ``SpecifierSet`` filtering with the new range
engine. (:pull:`1120`, :pull:`1259`)
* Cache the default marker environment. (:pull:`1250`)
* Cache the ``_manylinux`` module lookup process-wide. (:pull:`1254`)
* Add ``__slots__`` to ``Requirement`` and the token classes. (:pull:`1320`,
:pull:`1258`)
* Keep range caches across canonicalization, precompile the wheel project-name
pattern, simplify ``parse_tag()``, and skip ``platform.mac_ver()`` when the
version and arch are given. (:pull:`1253`, :pull:`1256`, :pull:`1236`,
:pull:`1255`)

Documentation:

* Describe the validation scope of ``packaging.pylock``. (:pull:`1339`)
* Explain which ``packaging.metadata`` fields are validated. (:pull:`1342`)
* Document ``RFC822Policy`` in the low-level ``packaging.metadata`` interface.
(:pull:`1222`)
* Enable nitpicky mode and render missing classes and fields in the API
reference. (:pull:`1196`, :pull:`1225`, :pull:`1277`)
* Add missing ``versionadded`` / ``versionchanged`` directives and many small
docstring fixes across the API reference. (:pull:`1205`, :pull:`1207`,
:pull:`1208`, :pull:`1209`, :pull:`1211`, :pull:`1216`, :pull:`1217`,
:pull:`1223`, :pull:`1272`, :pull:`1273`, :pull:`1274`, :pull:`1291`,
:pull:`1300`, :pull:`1303`, :pull:`1317`, :pull:`1344`)

Internal:

* Add Python 3.15 to the test matrix. (:pull:`1190`)
* Add a musl/Alpine test job and make the test suite pass on musl.
(:pull:`1226`, :pull:`1227`)
* Expand the downstream test matrix by ten projects. (:pull:`1261`)
* Update to mypy 2. (:pull:`1191`)
* Use nox's uv integration. (:pull:`1057`)
Links

Update platformdirs from 4.11.0 to 4.11.7.

The bot wasn't able to find a changelog for this release. Got an idea?

Links

Update pygments from 2.20.0 to 2.21.0.

The bot wasn't able to find a changelog for this release. Got an idea?

Links

@pyup-bot

Copy link
Copy Markdown
Collaborator Author

Closing this in favor of #459

@pyup-bot pyup-bot closed this Sep 14, 2026
@madig
madig deleted the pyup-scheduled-update-2026-09-07 branch September 14, 2026 16:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant