Closed dependabot[bot] closed 2 years ago
@dependabot ignore this major version
OK, I won't notify you about version 4.x.x again, unless you re-open this PR or update to a 4.x.x release yourself.
@dependabot merge
On Wed, Jul 6, 2022 at 5:22 PM dependabot[bot] @.***> wrote:
This automated pull request fixes a security vulnerability https://github.com/freelawproject/eyecite/security/dependabot/2 (moderate severity).
Learn more about Dependabot security updates https://docs.github.com/github/managing-security-vulnerabilities/configuring-dependabot-security-updates.
Bumps lxml https://github.com/lxml/lxml from 4.6.5 to 4.9.1. Changelog
Sourced from lxml's changelog https://github.com/lxml/lxml/blob/master/CHANGES.txt.
4.9.1 (2022-07-01) Bugs fixed
- A crash was resolved when using iterwalk() (or canonicalize()) after parsing certain incorrect input. Note that iterwalk() can crash on valid input parsed with the same parser after failing to parse the incorrect input.
4.9.0 (2022-06-01) Bugs fixed
- GH#341: The mixin inheritance order in lxml.html was corrected. Patch by xmo-odoo.
Other changes
-
Built with Cython 0.29.30 to adapt to changes in Python 3.11 and 3.12.
Wheels include zlib 1.2.12, libxml2 2.9.14 and libxslt 1.1.35 (libxml2 2.9.12+ and libxslt 1.1.34 on Windows).
GH#343: Windows-AArch64 build support in Visual Studio. Patch by Steve Dower.
4.8.0 (2022-02-17) Features added
-
GH#337: Path-like objects are now supported throughout the API instead of just strings. Patch by Henning Janssen.
The ElementMaker now supports QName values as tags, which always override the default namespace of the factory.
Bugs fixed
- GH#338: In lxml.objectify, the XSI float annotation "nan" and "inf" were spelled in lower case, whereas XML Schema datatypes define them as "NaN" and "INF" respectively.
... (truncated) Commits
- d01872c https://github.com/lxml/lxml/commit/d01872ccdf7e1e5e825b6c6292b43e7d27ae5fc4 Prevent parse failure in new test from leaking into later test runs.
- d65e632 https://github.com/lxml/lxml/commit/d65e63229e8958bc08344a85cd3f09ceeef933c3 Prepare release of lxml 4.9.1.
- 86368e9 https://github.com/lxml/lxml/commit/86368e9cf70a0ad23cccd5ee32de847149af0c6f Fix a crash when incorrect parser input occurs together with usages of iterwa...
- 50c2764 https://github.com/lxml/lxml/commit/50c276412880c1a3dde8a6d6c909e3ed8ef47e43 Delete unused Travis CI config and reference in docs (GH-345 https://github-redirect.dependabot.com/lxml/lxml/issues/345)
- 8f0bf2d https://github.com/lxml/lxml/commit/8f0bf2d158f2dd3f98d410c8a38fcd536fd11b53 Try to speed up the musllinux AArch64 build by splitting the different CPytho...
- b9f7074 https://github.com/lxml/lxml/commit/b9f7074430594b95824059eef931dfbb27a7645e Remove debug print from test.
- b224e0f https://github.com/lxml/lxml/commit/b224e0f69dde58425d1077e07d193d19d3f803a9 Try to install 'xz' in wheel builds, if available, since it's now needed to e...
- 897ebfa https://github.com/lxml/lxml/commit/897ebfa002fe5ec773ffe8851721047fedcc6928 Update macOS deployment target version from 10.14 to 10.15 since 10.14 starts...
- 853c9e9 https://github.com/lxml/lxml/commit/853c9e9cbf1c82d1ad3c096362372a048108905e Prepare release of 4.9.0.
- d3f77e6 https://github.com/lxml/lxml/commit/d3f77e678a8394559331d27257714e8aa4b082f2 Add a test for https://bugs.launchpad.net/lxml/+bug/1965070 leaving out the a...
- Additional commits viewable in compare view https://github.com/lxml/lxml/compare/lxml-4.6.5...lxml-4.9.1
[image: Dependabot compatibility score] https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- @dependabot rebase will rebase this PR
- @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
- @dependabot merge will merge this PR after your CI passes on it
- @dependabot squash and merge will squash and merge this PR after your CI passes on it
- @dependabot cancel merge will cancel a previously requested merge and block automerging
- @dependabot reopen will reopen this PR if it is closed
- @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page https://github.com/freelawproject/eyecite/network/alerts.
You can view, comment on, or merge this pull request online at:
https://github.com/freelawproject/eyecite/pull/115 Commit Summary
- bb70de5 https://github.com/freelawproject/eyecite/pull/115/commits/bb70de5215a749d450e648d1e64a4e8331f68bbd build(deps): bump lxml from 4.6.5 to 4.9.1
File Changes
(1 file https://github.com/freelawproject/eyecite/pull/115/files)
- M poetry.lock https://github.com/freelawproject/eyecite/pull/115/files#diff-f53a023eedfa3fbf2925ec7dc76eecdc954ea94b7e47065393dbad519613dc89 (133)
Patch Links:
- https://github.com/freelawproject/eyecite/pull/115.patch
- https://github.com/freelawproject/eyecite/pull/115.diff
— Reply to this email directly, view it on GitHub https://github.com/freelawproject/eyecite/pull/115, or unsubscribe https://github.com/notifications/unsubscribe-auth/AABZ3KU2QAJV6CYAI2I4MYDVSX2I7ANCNFSM523F6LSA . You are receiving this because you are subscribed to this thread.Message ID: @.***>
-- Mike Lissner Executive Director Free Law Project https://free.law
This PR is closed - you'll need to reopen it before merging.
Bumps lxml from 4.6.5 to 4.9.1.
Changelog
Sourced from lxml's changelog.
... (truncated)
Commits
d01872c
Prevent parse failure in new test from leaking into later test runs.d65e632
Prepare release of lxml 4.9.1.86368e9
Fix a crash when incorrect parser input occurs together with usages of iterwa...50c2764
Delete unused Travis CI config and reference in docs (GH-345)8f0bf2d
Try to speed up the musllinux AArch64 build by splitting the different CPytho...b9f7074
Remove debug print from test.b224e0f
Try to install 'xz' in wheel builds, if available, since it's now needed to e...897ebfa
Update macOS deployment target version from 10.14 to 10.15 since 10.14 starts...853c9e9
Prepare release of 4.9.0.d3f77e6
Add a test for https://bugs.launchpad.net/lxml/+bug/1965070 leaving out the a...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/freelawproject/eyecite/network/alerts).