Skip to content

fix(deps): update pypi group#118

Merged
ChipWolf merged 1 commit into
mainfrom
renovate/pypi
May 9, 2026
Merged

fix(deps): update pypi group#118
ChipWolf merged 1 commit into
mainfrom
renovate/pypi

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Apr 21, 2026

This PR contains the following updates:

Package Change Age Confidence
certifi 2026.2.252026.4.22 age confidence
idna (changelog) 3.113.13 age confidence
poetry-core 2.3.22.4.0 age confidence
urllib3 (changelog) 2.6.32.7.0 age confidence

Release Notes

certifi/python-certifi (certifi)

v2026.4.22

Compare Source

kjd/idna (idna)

v3.13

Compare Source

v3.12

Compare Source

python-poetry/poetry-core (poetry-core)

v2.4.0

Compare Source

Changed
  • Update list of supported licenses (#​935).
Vendoring
urllib3/urllib3 (urllib3)

v2.7.0

Compare Source

=======================

Security

Addressed high-severity security issues.
Impact was limited to specific use cases detailed in the accompanying
advisories; overall user exposure was estimated to be marginal.

  • Decompression-bomb safeguards of the streaming API were bypassed:

    1. When HTTPResponse.drain_conn() was called after the response had been
      read and decompressed partially.
    2. During the second HTTPResponse.read(amt=N) or
      HTTPResponse.stream(amt=N) call when the response was decompressed
      using the official Brotli <https://pypi.org/project/brotli/>__ library.

    See GHSA-mf9v-mfxr-j63j <https://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j>__
    for details.

  • HTTP pools created using ProxyManager.connection_from_url did not strip
    sensitive headers specified in Retry.remove_headers_on_redirect when
    redirecting to a different host.
    (GHSA-qccp-gfcp-xxvc <https://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc>__)

Deprecations and Removals

  • Used FutureWarning instead of DeprecationWarning for better
    visibility of existing deprecation notices. Rescheduled the removal of
    deprecated features to version 3.0.
    (#&#8203;3764 <https://github.com/urllib3/urllib3/issues/3764>__)
  • Removed support for end-of-life Python 3.9.
    (#&#8203;3720 <https://github.com/urllib3/urllib3/issues/3720>__)
  • Removed support for end-of-life PyPy3.10.
    (#&#8203;4979 <https://github.com/urllib3/urllib3/issues/4979>__)
  • Bumped the minimum supported pyOpenSSL version to 19.0.0.
    (#&#8203;3777 <https://github.com/urllib3/urllib3/issues/3777>__)

Bugfixes

  • Fixed a bug where HTTPResponse.read(amt=None) was ignoring decompressed
    data buffered from previous partial reads.
    (#&#8203;3636 <https://github.com/urllib3/urllib3/issues/3636>__)
  • Fixed a bug where HTTPResponse.read() could cache only part of the
    response after a partial read when cache_content=True.
    (#&#8203;4967 <https://github.com/urllib3/urllib3/issues/4967>__)
  • Fixed HTTPResponse.stream() and HTTPResponse.read_chunked() to handle
    amt=0.
    (#&#8203;3793 <https://github.com/urllib3/urllib3/issues/3793>__)
  • Updated _TYPE_BODY type alias to include missing Iterable[str],
    matching the documented and runtime behavior of chunked request bodies.
    (#&#8203;3798 <https://github.com/urllib3/urllib3/issues/3798>__)
  • Fixed LocationParseError when paths resembling schemeless URIs were
    passed to HTTPConnectionPool.urlopen().
    (#&#8203;3352 <https://github.com/urllib3/urllib3/issues/3352>__)
  • Fixed BaseHTTPResponse.readinto() type annotation to accept
    memoryview in addition to bytearray, matching the
    io.RawIOBase.readinto contract and enabling use with
    io.BufferedReader without type errors.
    (#&#8203;3764 <https://github.com/urllib3/urllib3/issues/3764>__)

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the type/minor label Apr 21, 2026
@github-actions
Copy link
Copy Markdown
Contributor

🏷️ Test Badge Generation (Shields.io)

hilbert

Gutenberg The North Face /e/ BadgeSort Conekta SymPy Caterpillar Weights & Biases Alibaba Cloud Swift Allegro Zapier BuzzFeed Leader Price Lemmy Adobe After Effects Plesk Pop!_OS YOLO Photopea pr.co gitignore.io WordPress EDEKA Oxygen Datadog

hsv

Gutenberg The North Face /e/ BadgeSort Lemmy BuzzFeed Swift Zapier Allegro Alibaba Cloud Weights & Biases Caterpillar SymPy Photopea YOLO Pop!_OS Plesk WordPress pr.co EDEKA Conekta gitignore.io Adobe After Effects Oxygen Datadog Leader Price

step

Gutenberg The North Face /e/ BadgeSort BuzzFeed Zapier Swift Allegro Alibaba Cloud Weights & Biases Lemmy Caterpillar SymPy Photopea Conekta gitignore.io EDEKA WordPress pr.co Pop!_OS Plesk YOLO Oxygen Datadog Adobe After Effects Leader Price

step_invert

Gutenberg The North Face /e/ BadgeSort BuzzFeed Zapier Swift Allegro Alibaba Cloud Weights & Biases Lemmy Caterpillar SymPy Photopea Conekta gitignore.io EDEKA WordPress pr.co Pop!_OS Plesk YOLO Adobe After Effects Datadog Oxygen Leader Price

luminance

Gutenberg The North Face /e/ BadgeSort Conekta Oxygen Leader Price Datadog SymPy gitignore.io EDEKA BuzzFeed WordPress pr.co Zapier Swift Allegro Photopea Alibaba Cloud Pop!_OS Adobe After Effects Plesk Weights & Biases YOLO Caterpillar Lemmy

@github-actions
Copy link
Copy Markdown
Contributor

🏷️ Test Badge Generation (Badgen.net)

hilbert

Gutenberg The North Face /e/ BadgeSort Conekta SymPy Caterpillar Weights & Biases Alibaba Cloud Swift Allegro Zapier BuzzFeed Leader Price Lemmy Adobe After Effects Plesk Pop!_OS YOLO Photopea pr.co gitignore.io WordPress EDEKA Oxygen Datadog

@renovate renovate Bot changed the title fix(deps): update idna to 3.12 fix(deps): update pypi group Apr 22, 2026
@renovate renovate Bot force-pushed the renovate/pypi branch from a2c20b2 to b5a0b22 Compare April 22, 2026 18:53
@github-actions
Copy link
Copy Markdown
Contributor

🏷️ Test Badge Generation (Shields.io)

hilbert

Wacom Tidal BBC Bun BadgeSort Shadow Dataverse ZincSearch OpenAPI Initiative Vitess Git LFS FACEIT Air Canada Facepunch Huawei Yamaha Motor Corporation FITE dbt Amazon SQS IcoMoon egghead Mercurial Electron Elm Zalo iFixit

hsv

Wacom Tidal BBC Bun BadgeSort Mercurial FITE Huawei Git LFS dbt Vitess FACEIT egghead OpenAPI Initiative Dataverse ZincSearch Electron Shadow Elm iFixit Zalo IcoMoon Amazon SQS Air Canada Yamaha Motor Corporation Facepunch

step

Wacom Tidal BBC Bun BadgeSort FITE Huawei Git LFS FACEIT Vitess dbt Mercurial egghead OpenAPI Initiative Dataverse ZincSearch Shadow Zalo iFixit Electron Elm IcoMoon Yamaha Motor Corporation Air Canada Facepunch Amazon SQS

step_invert

Wacom Tidal BBC Bun BadgeSort FITE Huawei Git LFS FACEIT Vitess dbt Mercurial egghead OpenAPI Initiative ZincSearch Dataverse Shadow Zalo iFixit Electron Elm IcoMoon Amazon SQS Facepunch Air Canada Yamaha Motor Corporation

luminance

Wacom Tidal BBC Bun BadgeSort Shadow FITE Yamaha Motor Corporation Huawei Air Canada Facepunch Zalo iFixit Dataverse IcoMoon Git LFS Electron FACEIT Elm Amazon SQS Vitess dbt ZincSearch OpenAPI Initiative Mercurial egghead

@github-actions
Copy link
Copy Markdown
Contributor

🏷️ Test Badge Generation (Badgen.net)

hilbert

Wacom Tidal BBC Bun BadgeSort Shadow Dataverse ZincSearch OpenAPI Initiative Vitess Git LFS FACEIT Air Canada Facepunch Huawei Yamaha Motor Corporation FITE dbt Amazon SQS IcoMoon egghead Mercurial Electron Elm Zalo iFixit

@renovate renovate Bot force-pushed the renovate/pypi branch from b5a0b22 to 870a24d Compare May 3, 2026 16:42
@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented May 3, 2026

🏷️ Test Badge Generation (Shields.io)

hilbert

WWE BadgeSort Drone Homebridge Beats Max-Planck-Gesellschaft Audiomack KinoPoisk Blender Laravel Nissan Steinberg Pinterest Turborepo Plurk BBC iPlayer IPFS ImageJ ICON Wish Alipay Apache NetBeans IDE Terraform Lidl Major League Hacking Bit

hsv

WWE BadgeSort Drone Turborepo Plurk Laravel Blender KinoPoisk Audiomack Max-Planck-Gesellschaft ICON ImageJ IPFS Beats Wish Alipay Major League Hacking Lidl Apache NetBeans IDE Terraform Bit Homebridge BBC iPlayer Nissan Steinberg Pinterest

step

WWE BadgeSort Drone Laravel Turborepo Plurk KinoPoisk Blender Audiomack Max-Planck-Gesellschaft Beats Lidl Major League Hacking Apache NetBeans IDE Alipay ICON Wish ImageJ IPFS Terraform Homebridge Bit Nissan Pinterest Steinberg BBC iPlayer

step_invert

WWE BadgeSort Drone Laravel Turborepo Plurk KinoPoisk Blender Audiomack Max-Planck-Gesellschaft Beats Lidl Major League Hacking Apache NetBeans IDE Alipay ICON Wish ImageJ IPFS Terraform Homebridge Bit BBC iPlayer Steinberg Pinterest Nissan

luminance

WWE BadgeSort Drone Homebridge Nissan Pinterest Steinberg Beats Lidl Bit Major League Hacking Max-Planck-Gesellschaft Terraform Apache NetBeans IDE Laravel Turborepo BBC iPlayer Plurk Alipay KinoPoisk Blender ICON Wish ImageJ IPFS Audiomack

@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented May 3, 2026

🏷️ Test Badge Generation (Badgen.net)

hilbert

WWE BadgeSort Drone Homebridge Beats Max-Planck-Gesellschaft Audiomack KinoPoisk Blender Laravel Nissan Steinberg Pinterest Turborepo Plurk BBC iPlayer IPFS ImageJ ICON Wish Alipay Apache NetBeans IDE Terraform Lidl Major League Hacking Bit

@renovate renovate Bot force-pushed the renovate/pypi branch from 870a24d to 15858d3 Compare May 7, 2026 20:26
@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented May 7, 2026

🏷️ Test Badge Generation (Shields.io)

hilbert

Deno Treyarch EyeEm Claris WebStorm BadgeSort stylelint Apache Kafka STMicroelectronics Verdaccio CiviCRM Lamborghini smart XAMPP Informatica Tencent QQ Netflix Klarna Google Maps Supabase Pexels Stripe Go Pandora Yahoo! Dacia

hsv

Deno Treyarch EyeEm Claris WebStorm BadgeSort Informatica XAMPP smart Lamborghini CiviCRM Verdaccio Supabase Pexels Go stylelint Stripe STMicroelectronics Google Maps Pandora Dacia Yahoo! Klarna Apache Kafka Netflix Tencent QQ

step

Deno Treyarch EyeEm Claris WebStorm BadgeSort Informatica XAMPP smart Lamborghini Verdaccio CiviCRM Pexels Supabase STMicroelectronics stylelint Pandora Stripe Google Maps Go Yahoo! Dacia Apache Kafka Netflix Tencent QQ Klarna

step_invert

Deno Treyarch EyeEm Claris WebStorm BadgeSort Informatica XAMPP smart Lamborghini Verdaccio CiviCRM Supabase Pexels STMicroelectronics stylelint Pandora Stripe Google Maps Go Dacia Yahoo! Klarna Tencent QQ Netflix Apache Kafka

luminance

Deno Treyarch EyeEm Claris WebStorm BadgeSort STMicroelectronics Apache Kafka Yahoo! stylelint Dacia Netflix Pandora Tencent QQ Verdaccio Stripe Informatica Pexels Google Maps Go XAMPP Supabase CiviCRM Lamborghini smart Klarna

@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented May 7, 2026

🏷️ Test Badge Generation (Badgen.net)

hilbert

Deno Treyarch EyeEm Claris WebStorm BadgeSort stylelint Apache Kafka STMicroelectronics Verdaccio CiviCRM Lamborghini smart XAMPP Informatica Tencent QQ Netflix Klarna Google Maps Supabase Pexels Stripe Go Pandora Yahoo! Dacia

@ChipWolf ChipWolf merged commit c94b51e into main May 9, 2026
4 checks passed
@ChipWolf ChipWolf deleted the renovate/pypi branch May 9, 2026 18:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant