chore(deps): update all non-major dependencies #124

Open
renovate[bot] wants to merge 1 commit from renovate/all-minor-patch into main
renovate[bot] commented 2026-09-21 22:06:15 +00:00 (Migrated from github.com)

This PR contains the following updates:

Package Change Age Confidence
aiohttp ==3.14.3 → ==3.14.4 age confidence
cachetools (changelog) ==7.2.0 → ==7.2.1 age confidence
charset-normalizer (changelog) ==3.5.1 → ==3.5.2 age confidence
cryptography (changelog) ==50.0.1 → ==50.0.2 age confidence
multidict ==6.9.0 → ==6.9.1 age confidence
python-dotenv ==1.2.3 → ==1.2.4 age confidence
pytz (source) ==2026.3.post1 → ==2026.5 age confidence
soupsieve ==2.9.2 → ==2.10 age confidence
svglib ==2.2.0 → ==2.3.0 age confidence

Release Notes

aio-libs/aiohttp (aiohttp)

v3.14.4

Compare Source

===================

Features

  • Added :class:aiohttp.UploadTracker for observing a client request's upload progress -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:13579.

  • Switched application/x-www-form-urlencoded parsing in
    :meth:~aiohttp.web.BaseRequest.post to the faster :func:yarl.query_to_pairs
    parser and added the client_max_fields argument to
    :class:~aiohttp.web.Application (default 1000) to cap the number of form
    fields accepted by :meth:~aiohttp.web.BaseRequest.post. Forms with more
    than 1000 fields now receive a 413 response unless the cap is raised;
    0 disables it -- by :user:bdraco.

    Related issues and pull requests on GitHub:
    :issue:13738.

  • Added constants to aiohttp.hdrs for widely used headers: those that
    browsers send on every request (Sec-Fetch-*, Sec-CH-UA*,
    Sec-GPC, Upgrade-Insecure-Requests, Priority), W3C trace context
    (traceparent, tracestate, baggage), response security, reporting
    and caching headers, the remaining RFC 9110 and RFC 9530 fields,
    Content-ID and common de facto proxy and application headers, and
    grouped the constants by where the header is defined. The C parser returns
    these names as the shared :class:~multidict.istr constants instead of new
    :class:str objects, which made parsing a typical browser request about
    9% cheaper -- by :user:asvetlov.

    Related issues and pull requests on GitHub:
    :issue:13886.

Bug fixes

  • Remove overlapping slots in RequestHandler,
    fix broken slots inheritance in :py:class:~aiohttp.web.StreamResponse.

    Related issues and pull requests on GitHub:
    :issue:6547.

  • Fixed a segmentation fault in the C HTTP parser on Python 3.12 and newer when payload decompression raised an error while pending decompressed data was being drained, as seen with brotlicffi 1.2 -- by :user:bdraco.

    Related issues and pull requests on GitHub:
    :issue:13203, :issue:13249.

  • Rejected control characters in the request target in the pure-Python HTTP parser,
    matching the llhttp-backed parser, which already refuses them
    -- by :user:arshsmith1.

    Related issues and pull requests on GitHub:
    :issue:13212.

  • Stripped the trailing whitespace from header values in the C HTTP parser,
    so that it matches the pure-Python parser and :rfc:9110#section-5.5
    -- by :user:LuShadowX.

    Related issues and pull requests on GitHub:
    :issue:13246.

  • Fixed the WebSocket reader rejecting a compressed data frame with close code 1002 when a control frame arrived before the first data frame (regression in 3.14.2) -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:13274.

  • Fixed internally retried requests sending a truncated body when the request
    data was a file object.

    Related issues and pull requests on GitHub:
    :issue:13329, :issue:13330.

  • Fixed event loop state possibly being corrupted on Python 3.12+ -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:13346.

  • Fixed the HTTP parser raising :exc:~aiohttp.ClientPayloadError when a fully received Content-Length body was pending completion -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:13348.

  • Bounded the per-read object overhead the WebSocket reader retains while reassembling a frame delivered across many small reads; the reads are joined once when the frame completes, and folded into a single buffer if they exceed a fragment cap, so a frame dribbled in tiny reads cannot pin unbounded per-read overhead -- by :user:Dreamsorcerer and :user:bdraco.

    Related issues and pull requests on GitHub:
    :issue:13352, :issue:13488.

  • Fixed requests pipelined behind a request whose upgrade the handler declined
    going unanswered once there were more of them than the per-connection queue
    holds. With the pure-Python parser the same requests were also served more
    than once -- by :user:rodrigobnogueira.

    Related issues and pull requests on GitHub:
    :issue:13356.

  • Reduced CPU consumption when encountering many concatenated members in a compressed payload and rejected large amounts of members -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:13362.

  • Fixed excessive memory consumption with small WebSocket messages -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:13393.

  • Fixed an integer overflow on too large messages -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:13415.

  • Switched multipart handling to use spooled temporary files to reduce number of file descriptors needed -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:13426.

  • Fixed a limit on message tail after an upgrade request -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:13501.

  • Fixed some edge case handling in multipart parts using base 64 encoding -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:13509.

  • Fixed Cython 3.3.0 failing to compile the WebSocket reader: dropped the
    Final[...] annotation from ALLOWED_CLOSE_CODES and the int
    annotation from the local start_pos in WebSocketReader._feed_data,
    both of which conflicted with declarations in reader_c.pxd under
    Cython 3.3.0 -- by :user:Georgefifth.

    Related issues and pull requests on GitHub:
    :issue:13520.

  • Fixed the WebSocket reader accepting a new data frame injected between the
    fragments of an in-progress message; per :rfc:6455#section-5.4 every frame
    after the first fragment and before the FIN must be a continuation, and
    such a stream is now rejected as a protocol error -- by :user:arshsmith1.

    Related issues and pull requests on GitHub:
    :issue:13553.

  • Fixed a connection being eligible for reuse after its request was cancelled
    or failed while waiting for a 100 Continue response or finalizing the
    body; the request headers were already sent, so reusing the connection
    corrupted the next request on it -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:13579.

  • Fixed BaseRequest.http_range not accepting case-insensitive range units -- by :user:Manny7717.

    Related issues and pull requests on GitHub:
    :issue:13580, :issue:13581.

  • Fixed CookieJar.update_cookies() to copy user-passed mutable Morsel objects -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:13637.

  • Fixed unbounded memory growth on a client WebSocket connection. A frame
    protocol error detaches the reader but leaves the connection upgraded, so a
    peer could stream unlimited data into an internal buffer when the application
    never called :meth:~aiohttp.ClientWebSocketResponse.receive; that data is
    now discarded, since nothing can parse it. Data arriving before the reader is
    installed is bounded by read_bufsize, which now applies to this buffer as
    well as to :attr:~aiohttp.ClientResponse.content
    -- by :user:bdraco.

    Related issues and pull requests on GitHub:
    :issue:13655, :issue:13743.

  • Fixed pure-Python request parser not reading a body in a HEAD request -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:13671.

  • Fixed host-only cookie state being lost on expiration -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:13674.

  • Fixed a possible OverflowError on cookies and a connection not being closed properly -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:13677.

  • The first-request deadline now also closes connections whose first request body stalls, while a body that is still arriving extends the deadline instead of being interrupted -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:13681.

  • Fixed idle connections not being closed if no request was received -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:13681.

  • Fixed :meth:~aiohttp.web.Application.add_domain not routing a request to
    its domain application when the Host header carried a port and the
    domain was registered without one, or, for a wildcard domain, uppercase
    letters -- by :user:rodrigobnogueira.

    Related issues and pull requests on GitHub:
    :issue:13693.

  • Added empty __slots__ to AbstractRouteDef so that RouteDef and
    StaticDef instances no longer carry an unused __dict__.

    Related issues and pull requests on GitHub:
    :issue:13716.

  • Fixed BaseConnector(keepalive_timeout=None) crashing on the second request to the same host with TypeError: '<=' not supported between instances of 'float' and 'NoneType' -- by :user:ishan-1010.

    Related issues and pull requests on GitHub:
    :issue:13756, :issue:13757.

  • Fixed a crash in :meth:~aiohttp.BodyPartReader.read_chunk on a body part
    with an explicit Content-Length: 0: the part fell through to the
    streaming read strategy, whose minimum chunk size assertion then failed for
    chunk sizes below the boundary length. Such parts now yield an immediate
    empty chunk, like any other part with a known length
    -- by :user:istoolsfox.

    Related issues and pull requests on GitHub:
    :issue:13758, :issue:13760.

  • Fixed Set-Cookie parsing treating unrecognized attributes as additional
    cookies. Each Set-Cookie header now sets exactly one cookie and
    unrecognized attributes are ignored, per :rfc:6265#section-5.2, preventing
    a malicious server from creating an attacker-selected number of cookie
    objects (and correspondingly large outgoing Cookie headers) from a
    bounded amount of response data. DummyCookieJar, and CookieJar in
    safe mode for IP-address origins, no longer parse Set-Cookie headers at
    all -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:13800.

  • Fixed the web server trusting the scheme of an absolute-form request-target -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:13821.

  • Fixed CookieJar.filter_cookies() sending shared cookies (cookies without a Domain attribute) marked Secure over unencrypted connections -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:13830.

  • Fixed per-request cookies (the cookies argument of a request method) marked Secure not being sent to origins listed in CookieJar's treat_as_secure_origin -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:13833.

  • Fixed the connection to an HTTP proxy staying open until garbage collection, and being reported as Unclosed connection, when sending the CONNECT request for an HTTPS tunnel failed -- by :user:Garbsener.

    Related issues and pull requests on GitHub:
    :issue:13841.

  • Resolved a redirect Location with the scheme of the current URL but
    without //, such as http:/path or http:path, against the
    current URL, as browsers do, instead of treating it as an absolute URL
    without a host
    -- by :user:asvetlov.

    Related issues and pull requests on GitHub:
    :issue:13855.

  • Rejected absolute-form request targets without // or with an empty
    host, such as http:/example.com/ or http:///example.com/, before
    parsing them with yarl, which reads a host from them in its WHATWG mode;
    RFC 9110 requires a host for http and https. The invalid URL test
    data no longer uses http:///example.com, which such a yarl version
    parses as http://example.com/, as browsers do
    -- by :user:asvetlov.

    Related issues and pull requests on GitHub:
    :issue:13858.

  • Fixed :py:meth:~aiohttp.StreamReader.readuntil not finding a multi-byte
    separator whose bytes arrived in different chunks, which made it return data
    past the separator -- by :user:andrewstellman.

    Related issues and pull requests on GitHub:
    :issue:13870.

  • Fixed mixed-case Content-Encoding values (for example Gzip)
    being accepted by the parser but failing decompression, a regression
    from the CVE-2025-69224 hardening -- by :user:muhammad-a-dev.

    Related issues and pull requests on GitHub:
    :issue:13894.

  • Added limits to client cookie parsing, :class:~aiohttp.CookieJar storage and
    generated Cookie headers, with Firefox-style eviction, and fixed a replaced cookie
    keeping the previous cookie's expiry when the new cookie has none
    -- by :user:iamibi and :user:bdraco.

    Related issues and pull requests on GitHub:
    :issue:13930.

  • Improved performance in domain matching with Application.add_domain() -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:13943.

Deprecations (removal in next major release)

  • Deprecated ClientResponse.output_size and ClientResponse.upload_complete;
    use aiohttp.UploadTracker instead -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:13579.

Removals and backward incompatible breaking changes

  • The WebSocket receive queue now only holds a weak reference to the WebSocketReader while parsing is stalled; code constructing a reader directly and passing it to set_parser() must keep its own strong reference to it, or frames the reader stopped short of parsing are lost with it -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:13393.

  • Removed the internal writer proxy used for upload progress accounting.
    AbstractStreamWriter gained an optional on_body_write callback that
    write() / write_eof() implementations must invoke with each accepted
    body chunk's byte length; custom writer implementations that do not call it
    will report Payload.bytes_written as 0 -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:13436.

  • Increased minimum yarl version to 1.25.1 -- by :user:bdraco.

    Related issues and pull requests on GitHub:
    :issue:13734.

  • Changed Set-Cookie parsing to create exactly one cookie per field, as RFC 6265
    and browsers do. Later name=value pairs and unknown attributes no longer create
    extra cookies, a leading pair such as Path=/ or $Version=1 is the cookie itself,
    and legacy $Path and $Domain attributes are ignored -- by :user:iamibi.

    Related issues and pull requests on GitHub:
    :issue:13930.

Improved documentation

  • Documented valid request URL forms when using :class:~aiohttp.UnixConnector, including base_url with an HTTP host -- by :user:muhammad-a-dev.

    Related issues and pull requests on GitHub:
    :issue:11324, :issue:13781.

  • Corrected the documented signature of :meth:~aiohttp.StreamReader.read_nowait,
    whose n parameter defaults to -1 rather than the None that was
    previously documented -- by :user:LALITH0110.

    Related issues and pull requests on GitHub:
    :issue:13295.

  • Added interlock-cb, an aiohttp client circuit breaker middleware, to the
    third-party libraries page -- by :user:bagowix.

    Related issues and pull requests on GitHub:
    :issue:13336.

  • Documented that max_redirects=0 means no limit and that allow_redirects=False disables redirects -- by :user:monasco.

    Related issues and pull requests on GitHub:
    :issue:13658.

  • Corrected the documented signature of :py:meth:~aiohttp.StreamReader.readuntil, which
    showed a str separator although the method takes bytes, and documented its
    keyword-only max_size argument -- by :user:hxperl.

    Related issues and pull requests on GitHub:
    :issue:13686.

  • Replaced most of the sphinx.ext.extlinks-based roles in the documentation
    with :pypi:sphinx-issues, which ships the
    :issue:, :pr:, :commit: and :user: roles out of the box.
    Pull request references are now captioned #N instead of PR #N, and
    commit references as abbreviated, @-prefixed hashes
    -- by :user:aiolibsbot.

    Related issues and pull requests on GitHub:
    :issue:13752.

  • Fixed the Content-ID example in the multipart docs, which used a
    constant missing from aiohttp.hdrs and a value that is not a valid
    message ID -- by :user:asvetlov.

    Related issues and pull requests on GitHub:
    :issue:13886.

Packaging updates and notes for downstreams

  • Started publishing an additional pure-Python wheel alongside the existing
    per-platform binary wheels and the sdist -- by :user:webknjaz.

    This gives users on platforms without a working C compiler, or without a
    matching pre-built wheel, an installable fallback that does not require
    compilation.

    Related issues and pull requests on GitHub:
    :issue:7632, :issue:13388.

  • Removed the aiohttp/_websocket/reader_c.py symlink from the source tree; the aiohttp._websocket.reader_c extension is now compiled directly from reader_py.py using cython --module-name, so distributions no longer include a reader_c.py file that showed up as an uncovered module in coverage reports -- by :user:bdraco.

    Related issues and pull requests on GitHub:
    :issue:13457.

  • Adopted :pep:639 license metadata -- the license is now declared as the
    SPDX expression Apache-2.0 AND MIT and license-files moved to the
    [project] table, which raises the build-time requirement to
    setuptools >= 77.0. Built distributions now carry
    License-Expression instead of the legacy License field
    -- by :user:aiolibsbot.

    Related issues and pull requests on GitHub:
    :issue:13891.

Contributor-facing changes

  • The CI/CD is now in sync with the rest of the projects in terms of where
    the cibuildwheel workflow lives -- by :user:webknjaz.

    Related commits on GitHub:
    :commit:59c0123d.

  • Moved the pytest configuration from :file:setup.cfg to a dedicated
    :file:pytest.ini that follows the layout shared with propcache and
    other aio-libs projects. Compared to the old configuration,
    minversion is raised from 3.8.2 to 8.4; pytest-xdist
    (--numprocesses=auto) and pytest-cov (--cov,
    --cov-context=test, --no-cov-on-fail) are enabled by default
    again, so pass --numprocesses=0 and/or --no-cov to opt out, as
    the :file:Makefile targets and CI jobs now do where needed;
    --doctest-modules, --strict-markers and
    faulthandler_timeout = 30 are enabled; -v is no longer added;
    empty parameter sets are marked xfail instead of skipped;
    --junitxml reports use xunit1 with captured output and
    call-only durations; and norecursedirs skips more directories,
    including :file:tests/isolated/
    -- by :user:aiolibsbot.

    Related issues and pull requests on GitHub:
    :issue:12620, :issue:12621.

  • Added check that change fragment matches PR number -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:12788.

  • CI now builds the sdist (and a pure-Python wheel) once, in a new
    build-pure-python-dists job, and shares that build across test,
    autobahn, benchmark, build-wheels, test-mobile and the
    sdist-based half of linting, instead of every one of those jobs
    checking out the repository and running make cythonize on its own
    -- by :user:webknjaz.

    Linting is also now split into lint-from-git (the
    :file:requirements/runtime-deps.in sync check and docs spell-checking,
    which need real Git history) and lint-from-sdist (mypy,
    slotscheck, the changelog fragment check, and twine check, which
    build from the shared artifact instead), since an sdist tarball never
    contains :file:.git.

    Related issues and pull requests on GitHub:
    :issue:13363, :issue:13388.

  • Synchronized the coverage.py configuration (:file:.coveragerc.toml and
    :file:.coveragerc-cython.toml) with the pattern already established in
    :external+yarl:doc:yarl <index>, :external+multidict:doc:multidict <index>, frozenlist and other sibling projects
    -- by :user:webknjaz.

    Both files now anchor package discovery through source_pkgs instead of
    relying on a same-named directory happening to exist relative to the
    working directory, and add a [paths] mapping so coverage recorded
    against an installed copy of aiohttp still combines correctly with
    coverage recorded from the Git checkout. CI now lets pytest-cov write
    coverage.xml directly via --cov-report=xml instead of a separate
    coverage xml step, and the Autobahn testsuite's subprocess-based
    coverage collection (which uses coverage run --append, incompatible
    with parallel mode) now opts out per-invocation via a
    COVERAGE_PARALLEL_MODE environment variable instead of trying to
    override it on the command line.

    Related issues and pull requests on GitHub:
    :issue:13422.

  • Stopped the benchmark CI job from hanging in the CodSpeed runner's apt
    install by installing libc6-dbg up front with a bounded retry, and raised
    the job timeout from 15 to 30 minutes -- by :user:bdraco.

    Related issues and pull requests on GitHub:
    :issue:13489.

  • Added benchmarks for reading masked WebSocket messages and fixed the
    existing read benchmarks, which stopped measuring the parser after the
    eighth large frame due to the queue limit -- by :user:bdraco.

    Related issues and pull requests on GitHub:
    :issue:13561.

  • Removed stale filterwarnings ignores from the pytest configuration
    that are no longer triggered by aiohttp, the supported Python versions
    or the pinned test dependencies -- by :user:aiolibsbot.

    Related issues and pull requests on GitHub:
    :issue:13717.

  • Dropped the leftover PIP_USER setting and the pip --user PATH
    prefix from the CI workflow; both became dead once the test jobs started
    provisioning Python via astral-sh/setup-uv
    -- by :user:aiolibsbot.

    Related issues and pull requests on GitHub:
    :issue:13718, :issue:13721.

  • Changed the long host in the Host header tests to one that is not made
    only of digits, since yarl now parses such a host as an IP address in its
    default mode and rejects this one as out of range
    -- by :user:asvetlov.

    Related issues and pull requests on GitHub:
    :issue:13861.

  • Fixed tools/gen.py dropping a header name from the generated C lookup
    when two names shared a prefix that differed only in letter case, such as
    Accept-CH and Accept-Charset, and made the generated code compile
    without warnings -- by :user:asvetlov.

    Related issues and pull requests on GitHub:
    :issue:13886.

Miscellaneous internal changes

  • Avoided formatting an unused fallback Date header value when the response
    already has one -- by :user:marcus-campbell.

    Related issues and pull requests on GitHub:
    :issue:13299.

  • Improved header parsing performance in the C HTTP parser by reusing the
    :class:~multidict.istr built for a header name missing from
    aiohttp.hdrs the next time the same name arrives, from a bounded
    cache of up to 512 names of at most 64 bytes -- by :user:asvetlov.

    Related issues and pull requests on GitHub:
    :issue:13887.


tkem/cachetools (cachetools)

v7.2.1

Compare Source

===================

  • Improve error handling for RRCache.popitem() when the cache is
    empty.

  • Minor style and documentation improvements.

  • Update CI environment.

jawah/charset_normalizer (charset-normalizer)

v3.5.2

Compare Source

Changed
  • Raised the Cython upper bound to <3.4 for native builds. The bound remains <3.3 for
    abi3 builds to preserve compatibility with the Python 3.7 Limited API.
Fixed
  • Valid UTF-8 Chinese JSON incorrectly detected as PTCP154 due to excessive noise penalties
    for uncommon CJK characters. (#​796)
  • Supported encodings without aliases failing name resolution or being ignored in charset
    declarations. (#​800)
pyca/cryptography (cryptography)

v50.0.2

Compare Source

aio-libs/multidict (multidict)

v6.9.1

Compare Source

=====

(2026-09-21)

Bug fixes

  • Fixed the C extension reading freed memory on free-threaded builds when a
    list handed to :py:meth:~multidict.MultiDict.update,
    :py:meth:~multidict.MultiDict.extend, :py:meth:~multidict.MultiDict.merge
    or the :py:class:~multidict.MultiDict and :py:class:~multidict.CIMultiDict
    constructors, a [key, value] item inside any iterable handed to them, or a
    list tested with in against :py:meth:~multidict.MultiDict.items, is
    changed by another thread; a call that catches the list shrinking under it
    now raises :py:exc:RuntimeError -- by :user:rodrigobnogueira.

    Related issues and pull requests on GitHub:
    :issue:1437.

  • Fixed a data race on the free-threaded build where a retired hash table's
    reader count used relaxed atomics, letting a lock-free get()/getone()/
    __getitem__() read race a concurrent free of that table. The reader-exit
    decrement and the drain's free check now use release/acquire ordering
    instead -- by :user:asvetlov.

    Related issues and pull requests on GitHub:
    :issue:1481.

  • Fixed a free-threaded build bug where two threads calling update(),
    merge(), or __setitem__() on the same key at the same time could lose
    the key entirely instead of just racing on which value wins. A decref of the
    replaced value could transiently suspend the writer's critical section,
    letting a second writer for the same key observe the first writer's
    in-progress entry as absent and, once both settled, mistake it for a stale
    duplicate and delete it. Every such decref is now deferred until the writer
    has released its critical section, so the window can no longer open.
    setdefault() had an unrelated instance of the same blind spot (it could
    insert a duplicate rather than recognizing an in-flight key), fixed alongside
    it -- by :user:asvetlov.

    Related issues and pull requests on GitHub:
    :issue:1483.

  • Fixed a free-threaded build bug where getall() and the items()/
    keys()/values() equality path could raise KeyError or report a
    present, never-deleted key as missing. A concurrent update()/extend()/
    __setitem__() call can have its critical section transiently suspended
    (a decref triggering a blocking allocator call) while an entry is marked as
    part of its own bookkeeping; a reader landing in that window used to treat
    the mark as "not found" instead of "still there, in flight" -- by
    :user:asvetlov.

    Related issues and pull requests on GitHub:
    :issue:1484.

  • Fixed a reference leak in the C extension where operand | md.items()
    and md.items() - operand leaked one key and one value reference per
    element of operand, letting a large operand grow memory without bound
    (:gh:GHSA-54p9-h82j-f925 <aio-libs/multidict/security/advisories/GHSA-54p9-h82j-f925>)
    -- by :user:asvetlov.

    The issue was reported by :user:waydeshi.

    Related commits on GitHub:
    :commit:350b4a0.

  • Fixed a segmentation fault on the standard (non-free-threaded) C extension
    build when a value type's __del__ released the GIL (for example by
    calling time.sleep()) while update(), merge(), __setitem__(),
    __delitem__(), pop(), popone(), or popall() was dropping a
    replaced or removed value. Py_BEGIN_CRITICAL_SECTION compiles to a no-op
    on this build, so nothing else was stopping a second thread from mutating the
    very same MultiDict concurrently once the GIL was released mid-mutation.
    Every such decref is now deferred until the mutation has fully finished, the
    same technique already used to close the analogous free-threaded-build race
    -- by :user:asvetlov.

    Related issues and pull requests on GitHub:
    :issue:1489.

  • Fixed the C extension reading freed memory while iterating a
    :py:class:~multidict.CIMultiDict whose keys are plain :py:class:str.
    Converting such a key to :py:class:~multidict.istr could run Python code
    (a :py:class:str subclass's __str__ or __del__) or, on free-threaded
    builds, suspend the iterator's critical section, after which the iterator read
    the entry again even though a concurrent mutation could already have freed it.
    As part of the fix, :py:meth:~multidict.MultiDict.copy and re-initializing
    from another multidict now assign a new version in the C extension instead of
    reusing the source's, matching the pure Python implementation
    -- by :user:asvetlov.

    Related issues and pull requests on GitHub:
    :issue:1496.

  • Fixed a use-after-free on the free-threaded build where a lock-free
    get(), [] or in could read a hash table that a concurrent
    resize had just retired and another reader was freeing
    -- by :user:asvetlov.

    Related issues and pull requests on GitHub:
    :issue:1497.

Contributor-facing changes

  • Removed a redundant include and a duplicated exclude line from
    MANIFEST.in; sdist contents are unchanged -- by :user:asvetlov.

    Related issues and pull requests on GitHub:
    :issue:1478.

  • Added .claudeignore file -- by :user:asvetlov

    Related issues and pull requests on GitHub:
    :issue:1479.

  • Scaled up the pure-Python pop(), popitem(), __delitem__(),
    add() and item-insertion benchmarks to do more work per measurement.
    Repeated CodSpeed runs on the same commit showed these particular
    benchmarks flagged as dominated by syscalls, understating their real
    cost and adding noise to the reported values; a larger working set
    amortizes that overhead -- by :user:asvetlov.

    Related issues and pull requests on GitHub:
    :issue:1485.

  • Replaced deprecated instrumentation codspeed mode with simulation -- by :user:asvetlov

    Related issues and pull requests on GitHub:
    :issue:1493.

  • Reorganized the mutating benchmarks (item insertion, update(),
    add() of the same key, pop(), popitem(), clear(),
    __delitem__() and __setitem__()) to copy a fresh multidict and
    apply the operation in a loop, like the add() and extend()
    benchmarks already do. The insertion, update() and clear()
    benchmarks previously mutated a single multidict shared across
    rounds, so only the first round measured the intended operation; the
    rest did a single copy per round, letting per-round overhead dominate
    -- by :user:asvetlov.

    Related issues and pull requests on GitHub:
    :issue:1494.

  • The repr() and view inequality benchmarks were updated to repeat their
    operation in a loop, like the other benchmarks, and the CodSpeed benchmark
    job was moved to Python 3.14 -- by :user:asvetlov.

    Related issues and pull requests on GitHub:
    :issue:1498.

  • Dropped -I from the AddressSanitizer test command in AGENTS.md
    and in the CI job. It implies -E, which made Python ignore
    PYTHONMALLOC=malloc, so small hash tables were still served from
    pymalloc arenas where use-after-free went undetected
    -- by :user:asvetlov.

    Related issues and pull requests on GitHub:
    :issue:1499.

  • The CI/CD workflow was updated to stop superseded runs of the same pull request
    when a new commit is pushed; runs on master, release branches, tags,
    the merge queue, and the daily schedule are never interrupted
    -- by :user:asvetlov.

    Related issues and pull requests on GitHub:
    :issue:1500.

  • The release job was changed to upload distributions and their signatures
    to the GitHub Release one file at a time, skipping assets that were
    already attached and retrying after a pause, so that a parallel upload
    burst no longer tripped the GitHub secondary rate limit
    -- by :user:asvetlov.

    Related issues and pull requests on GitHub:
    :issue:1503.

Miscellaneous internal changes

  • Corrected several comments in the free-threaded C extension that
    attributed critical-section suspension to a blocking PyMem_Malloc()
    call; allocation alone never suspends an acquired critical section, and
    the real risk at those sites is a decref running
    a finalizer or weakref callback. Also dropped a retry loop in
    md_clone_from_ht() that guarded against the same, non-existent
    allocation-triggered suspension -- by :user:asvetlov.

    Related issues and pull requests on GitHub:
    :issue:1486.

  • Changed the free-threaded build's deferred decref buffer, used by
    update() and __setitem__(), to a chain of fixed-size blocks
    with a large inline first block instead of a small inline array that
    was reallocated on growth -- by :user:asvetlov.

    Related issues and pull requests on GitHub:
    :issue:1501.


theskumar/python-dotenv (python-dotenv)

v1.2.4

Compare Source

Fixed
  • dotenv get no longer exits with code 1 for empty string values (KEY=) by [@​ShamikOfficial] in [#​700]
  • An unquoted empty value followed by an inline comment (e.g. KEY= # comment) is now parsed as an empty string instead of the comment text by [@​Noethix55555] in [#​663]
  • dotenv run --no-override now expands variable references with the same precedence as load_dotenv(override=False), so a value like ${BASE}/suffix uses the existing BASE from the environment instead of the one from the .env file by [@​ROTl24] in [#​698]
stub42/pytz (pytz)

v2026.5

Compare Source

v2026.4

Compare Source

facelessuser/soupsieve (soupsieve)

v2.10

Compare Source

2.10

  • NEW: Support Python 3.15.
  • NEW: Add new ignore option to API methods that allows the specification of specific pseudo-classes to be
    ignored.
  • NEW: Tighten restrictions such that namespaces and custom objects must always be a Mapping, previously lists
    of tuples were also allowed.
  • NEW: Use a singleton for null selectors internally via called Null of type SelectorNull.
  • NEW: For performance, Soup Sieve will no longer try and coerce bad attribute values to useable strings.
  • NEW: Add NOCACHE flag that can be used to disable caching optimizations selectors and possibly other future
    caching optimizations. Provided for disabling and also disabling if issues are found with the new caching approach.
  • FIX: Improve performance of ~ for various cases by employing caching.
  • FIX: Improve performance of nth-* family of selectors in certain scenarios by employing caching.
  • FIX: Ensure custom is properly passed down from API functions to compilation.
deeplook/svglib (svglib)

v2.3.0

Compare Source

Security
  • External <image>/<use> references can no longer escape the document's own
    directory. xlink_href_target() joined the reference onto the source
    directory and only checked os.access(), so an absolute reference discarded
    that directory and .. climbed above it, letting an untrusted SVG name any
    file the process could read (CWE-22, GHSA-2p5c-8vcc-4rcw). Absolute
    references are now refused, and the new opt-in external_reference_root on
    svg2rlg()/SvgRenderer confines resolution to a trusted directory,
    propagated into nested external-SVG renderers. Relative references, including
    .., keep working by default.

  • The svg2pdf command line tool now sets external_reference_root to the
    input file's own directory, since a file converted from the command line is
    routinely one the user did not author. Pass -R/--external-root with a
    parent directory to allow shared assets, or / to allow any relative
    reference. Library callers are unaffected: the default stays None.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [aiohttp](https://redirect.github.com/aio-libs/aiohttp) | `==3.14.3` → `==3.14.4` | ![age](https://developer.mend.io/api/mc/badges/age/pypi/aiohttp/3.14.4?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/pypi/aiohttp/3.14.3/3.14.4?slim=true) | | [cachetools](https://redirect.github.com/tkem/cachetools) ([changelog](https://redirect.github.com/tkem/cachetools/blob/master/CHANGELOG.rst)) | `==7.2.0` → `==7.2.1` | ![age](https://developer.mend.io/api/mc/badges/age/pypi/cachetools/7.2.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/pypi/cachetools/7.2.0/7.2.1?slim=true) | | [charset-normalizer](https://redirect.github.com/jawah/charset_normalizer) ([changelog](https://redirect.github.com/jawah/charset_normalizer/blob/master/CHANGELOG.md)) | `==3.5.1` → `==3.5.2` | ![age](https://developer.mend.io/api/mc/badges/age/pypi/charset-normalizer/3.5.2?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/pypi/charset-normalizer/3.5.1/3.5.2?slim=true) | | [cryptography](https://redirect.github.com/pyca/cryptography) ([changelog](https://cryptography.io/en/latest/changelog/)) | `==50.0.1` → `==50.0.2` | ![age](https://developer.mend.io/api/mc/badges/age/pypi/cryptography/50.0.2?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/pypi/cryptography/50.0.1/50.0.2?slim=true) | | [multidict](https://redirect.github.com/aio-libs/multidict) | `==6.9.0` → `==6.9.1` | ![age](https://developer.mend.io/api/mc/badges/age/pypi/multidict/6.9.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/pypi/multidict/6.9.0/6.9.1?slim=true) | | [python-dotenv](https://redirect.github.com/theskumar/python-dotenv) | `==1.2.3` → `==1.2.4` | ![age](https://developer.mend.io/api/mc/badges/age/pypi/python-dotenv/1.2.4?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/pypi/python-dotenv/1.2.3/1.2.4?slim=true) | | [pytz](http://pythonhosted.org/pytz) ([source](https://redirect.github.com/stub42/pytz)) | `==2026.3.post1` → `==2026.5` | ![age](https://developer.mend.io/api/mc/badges/age/pypi/pytz/2026.5?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/pypi/pytz/2026.3.post1/2026.5?slim=true) | | [soupsieve](https://redirect.github.com/facelessuser/soupsieve) | `==2.9.2` → `==2.10` | ![age](https://developer.mend.io/api/mc/badges/age/pypi/soupsieve/2.10?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/pypi/soupsieve/2.9.2/2.10?slim=true) | | [svglib](https://redirect.github.com/deeplook/svglib) | `==2.2.0` → `==2.3.0` | ![age](https://developer.mend.io/api/mc/badges/age/pypi/svglib/2.3.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/pypi/svglib/2.2.0/2.3.0?slim=true) | --- ### Release Notes <details> <summary>aio-libs/aiohttp (aiohttp)</summary> ### [`v3.14.4`](https://redirect.github.com/aio-libs/aiohttp/blob/HEAD/CHANGES.rst#3144-2026-10-04) [Compare Source](https://redirect.github.com/aio-libs/aiohttp/compare/v3.14.3...v3.14.4) \=================== ## Features - Added :class:`aiohttp.UploadTracker` for observing a client request's upload progress -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`13579`. - Switched `application/x-www-form-urlencoded` parsing in :meth:`~aiohttp.web.BaseRequest.post` to the faster :func:`yarl.query_to_pairs` parser and added the `client_max_fields` argument to :class:`~aiohttp.web.Application` (default `1000`) to cap the number of form fields accepted by :meth:`~aiohttp.web.BaseRequest.post`. Forms with more than 1000 fields now receive a `413` response unless the cap is raised; `0` disables it -- by :user:`bdraco`. *Related issues and pull requests on GitHub:* :issue:`13738`. - Added constants to `aiohttp.hdrs` for widely used headers: those that browsers send on every request (`Sec-Fetch-*`, `Sec-CH-UA*`, `Sec-GPC`, `Upgrade-Insecure-Requests`, `Priority`), W3C trace context (`traceparent`, `tracestate`, `baggage`), response security, reporting and caching headers, the remaining RFC 9110 and RFC 9530 fields, `Content-ID` and common de facto proxy and application headers, and grouped the constants by where the header is defined. The C parser returns these names as the shared :class:`~multidict.istr` constants instead of new :class:`str` objects, which made parsing a typical browser request about 9% cheaper -- by :user:`asvetlov`. *Related issues and pull requests on GitHub:* :issue:`13886`. ## Bug fixes - Remove overlapping slots in `RequestHandler`, fix broken slots inheritance in :py:class:`~aiohttp.web.StreamResponse`. *Related issues and pull requests on GitHub:* :issue:`6547`. - Fixed a segmentation fault in the C HTTP parser on Python 3.12 and newer when payload decompression raised an error while pending decompressed data was being drained, as seen with `brotlicffi` 1.2 -- by :user:`bdraco`. *Related issues and pull requests on GitHub:* :issue:`13203`, :issue:`13249`. - Rejected control characters in the request target in the pure-Python HTTP parser, matching the llhttp-backed parser, which already refuses them \-- by :user:`arshsmith1`. *Related issues and pull requests on GitHub:* :issue:`13212`. - Stripped the trailing whitespace from header values in the C HTTP parser, so that it matches the pure-Python parser and :rfc:`9110#section-5.5` \-- by :user:`LuShadowX`. *Related issues and pull requests on GitHub:* :issue:`13246`. - Fixed the WebSocket reader rejecting a compressed data frame with close code 1002 when a control frame arrived before the first data frame (regression in 3.14.2) -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`13274`. - Fixed internally retried requests sending a truncated body when the request data was a file object. *Related issues and pull requests on GitHub:* :issue:`13329`, :issue:`13330`. - Fixed event loop state possibly being corrupted on Python 3.12+ -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`13346`. - Fixed the HTTP parser raising :exc:`~aiohttp.ClientPayloadError` when a fully received `Content-Length` body was pending completion -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`13348`. - Bounded the per-read object overhead the WebSocket reader retains while reassembling a frame delivered across many small reads; the reads are joined once when the frame completes, and folded into a single buffer if they exceed a fragment cap, so a frame dribbled in tiny reads cannot pin unbounded per-read overhead -- by :user:`Dreamsorcerer` and :user:`bdraco`. *Related issues and pull requests on GitHub:* :issue:`13352`, :issue:`13488`. - Fixed requests pipelined behind a request whose upgrade the handler declined going unanswered once there were more of them than the per-connection queue holds. With the pure-Python parser the same requests were also served more than once -- by :user:`rodrigobnogueira`. *Related issues and pull requests on GitHub:* :issue:`13356`. - Reduced CPU consumption when encountering many concatenated members in a compressed payload and rejected large amounts of members -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`13362`. - Fixed excessive memory consumption with small WebSocket messages -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`13393`. - Fixed an integer overflow on too large messages -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`13415`. - Switched multipart handling to use spooled temporary files to reduce number of file descriptors needed -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`13426`. - Fixed a limit on message tail after an upgrade request -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`13501`. - Fixed some edge case handling in multipart parts using base 64 encoding -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`13509`. - Fixed Cython 3.3.0 failing to compile the WebSocket reader: dropped the `Final[...]` annotation from `ALLOWED_CLOSE_CODES` and the `int` annotation from the local `start_pos` in `WebSocketReader._feed_data`, both of which conflicted with declarations in `reader_c.pxd` under Cython 3.3.0 -- by :user:`Georgefifth`. *Related issues and pull requests on GitHub:* :issue:`13520`. - Fixed the WebSocket reader accepting a new data frame injected between the fragments of an in-progress message; per :rfc:`6455#section-5.4` every frame after the first fragment and before the `FIN` must be a continuation, and such a stream is now rejected as a protocol error -- by :user:`arshsmith1`. *Related issues and pull requests on GitHub:* :issue:`13553`. - Fixed a connection being eligible for reuse after its request was cancelled or failed while waiting for a `100 Continue` response or finalizing the body; the request headers were already sent, so reusing the connection corrupted the next request on it -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`13579`. - Fixed `BaseRequest.http_range` not accepting case-insensitive range units -- by :user:`Manny7717`. *Related issues and pull requests on GitHub:* :issue:`13580`, :issue:`13581`. - Fixed `CookieJar.update_cookies()` to copy user-passed mutable `Morsel` objects -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`13637`. - Fixed unbounded memory growth on a client WebSocket connection. A frame protocol error detaches the reader but leaves the connection upgraded, so a peer could stream unlimited data into an internal buffer when the application never called :meth:`~aiohttp.ClientWebSocketResponse.receive`; that data is now discarded, since nothing can parse it. Data arriving before the reader is installed is bounded by `read_bufsize`, which now applies to this buffer as well as to :attr:`~aiohttp.ClientResponse.content` \-- by :user:`bdraco`. *Related issues and pull requests on GitHub:* :issue:`13655`, :issue:`13743`. - Fixed pure-Python request parser not reading a body in a `HEAD` request -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`13671`. - Fixed host-only cookie state being lost on expiration -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`13674`. - Fixed a possible `OverflowError` on cookies and a connection not being closed properly -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`13677`. - The first-request deadline now also closes connections whose first request body stalls, while a body that is still arriving extends the deadline instead of being interrupted -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`13681`. - Fixed idle connections not being closed if no request was received -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`13681`. - Fixed :meth:`~aiohttp.web.Application.add_domain` not routing a request to its domain application when the `Host` header carried a port and the domain was registered without one, or, for a wildcard domain, uppercase letters -- by :user:`rodrigobnogueira`. *Related issues and pull requests on GitHub:* :issue:`13693`. - Added empty `__slots__` to `AbstractRouteDef` so that `RouteDef` and `StaticDef` instances no longer carry an unused `__dict__`. *Related issues and pull requests on GitHub:* :issue:`13716`. - Fixed `BaseConnector(keepalive_timeout=None)` crashing on the second request to the same host with `TypeError: '<=' not supported between instances of 'float' and 'NoneType'` -- by :user:`ishan-1010`. *Related issues and pull requests on GitHub:* :issue:`13756`, :issue:`13757`. - Fixed a crash in :meth:`~aiohttp.BodyPartReader.read_chunk` on a body part with an explicit `Content-Length: 0`: the part fell through to the streaming read strategy, whose minimum chunk size assertion then failed for chunk sizes below the boundary length. Such parts now yield an immediate empty chunk, like any other part with a known length \-- by :user:`istoolsfox`. *Related issues and pull requests on GitHub:* :issue:`13758`, :issue:`13760`. - Fixed `Set-Cookie` parsing treating unrecognized attributes as additional cookies. Each `Set-Cookie` header now sets exactly one cookie and unrecognized attributes are ignored, per :rfc:`6265#section-5.2`, preventing a malicious server from creating an attacker-selected number of cookie objects (and correspondingly large outgoing `Cookie` headers) from a bounded amount of response data. `DummyCookieJar`, and `CookieJar` in safe mode for IP-address origins, no longer parse `Set-Cookie` headers at all -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`13800`. - Fixed the web server trusting the scheme of an absolute-form request-target -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`13821`. - Fixed `CookieJar.filter_cookies()` sending shared cookies (cookies without a `Domain` attribute) marked `Secure` over unencrypted connections -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`13830`. - Fixed per-request cookies (the `cookies` argument of a request method) marked `Secure` not being sent to origins listed in `CookieJar`'s `treat_as_secure_origin` -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`13833`. - Fixed the connection to an HTTP proxy staying open until garbage collection, and being reported as `Unclosed connection`, when sending the `CONNECT` request for an HTTPS tunnel failed -- by :user:`Garbsener`. *Related issues and pull requests on GitHub:* :issue:`13841`. - Resolved a redirect `Location` with the scheme of the current URL but without `//`, such as `http:/path` or `http:path`, against the current URL, as browsers do, instead of treating it as an absolute URL without a host \-- by :user:`asvetlov`. *Related issues and pull requests on GitHub:* :issue:`13855`. - Rejected absolute-form request targets without `//` or with an empty host, such as `http:/example.com/` or `http:///example.com/`, before parsing them with yarl, which reads a host from them in its WHATWG mode; RFC 9110 requires a host for `http` and `https`. The invalid URL test data no longer uses `http:///example.com`, which such a yarl version parses as `http://example.com/`, as browsers do \-- by :user:`asvetlov`. *Related issues and pull requests on GitHub:* :issue:`13858`. - Fixed :py:meth:`~aiohttp.StreamReader.readuntil` not finding a multi-byte separator whose bytes arrived in different chunks, which made it return data past the separator -- by :user:`andrewstellman`. *Related issues and pull requests on GitHub:* :issue:`13870`. - Fixed mixed-case `Content-Encoding` values (for example `Gzip`) being accepted by the parser but failing decompression, a regression from the CVE-2025-69224 hardening -- by :user:`muhammad-a-dev`. *Related issues and pull requests on GitHub:* :issue:`13894`. - Added limits to client cookie parsing, :class:`~aiohttp.CookieJar` storage and generated `Cookie` headers, with Firefox-style eviction, and fixed a replaced cookie keeping the previous cookie's expiry when the new cookie has none \-- by :user:`iamibi` and :user:`bdraco`. *Related issues and pull requests on GitHub:* :issue:`13930`. - Improved performance in domain matching with `Application.add_domain()` -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`13943`. ## Deprecations (removal in next major release) - Deprecated `ClientResponse.output_size` and `ClientResponse.upload_complete`; use `aiohttp.UploadTracker` instead -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`13579`. ## Removals and backward incompatible breaking changes - The WebSocket receive queue now only holds a weak reference to the `WebSocketReader` while parsing is stalled; code constructing a reader directly and passing it to `set_parser()` must keep its own strong reference to it, or frames the reader stopped short of parsing are lost with it -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`13393`. - Removed the internal writer proxy used for upload progress accounting. `AbstractStreamWriter` gained an optional `on_body_write` callback that `write()` / `write_eof()` implementations must invoke with each accepted body chunk's byte length; custom writer implementations that do not call it will report `Payload.bytes_written` as `0` -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`13436`. - Increased minimum yarl version to 1.25.1 -- by :user:`bdraco`. *Related issues and pull requests on GitHub:* :issue:`13734`. - Changed `Set-Cookie` parsing to create exactly one cookie per field, as RFC 6265 and browsers do. Later `name=value` pairs and unknown attributes no longer create extra cookies, a leading pair such as `Path=/` or `$Version=1` is the cookie itself, and legacy `$Path` and `$Domain` attributes are ignored -- by :user:`iamibi`. *Related issues and pull requests on GitHub:* :issue:`13930`. ## Improved documentation - Documented valid request URL forms when using :class:`~aiohttp.UnixConnector`, including `base_url` with an HTTP host -- by :user:`muhammad-a-dev`. *Related issues and pull requests on GitHub:* :issue:`11324`, :issue:`13781`. - Corrected the documented signature of :meth:`~aiohttp.StreamReader.read_nowait`, whose `n` parameter defaults to `-1` rather than the `None` that was previously documented -- by :user:`LALITH0110`. *Related issues and pull requests on GitHub:* :issue:`13295`. - Added `interlock-cb`, an aiohttp client circuit breaker middleware, to the third-party libraries page -- by :user:`bagowix`. *Related issues and pull requests on GitHub:* :issue:`13336`. - Documented that `max_redirects=0` means no limit and that `allow_redirects=False` disables redirects -- by :user:`monasco`. *Related issues and pull requests on GitHub:* :issue:`13658`. - Corrected the documented signature of :py:meth:`~aiohttp.StreamReader.readuntil`, which showed a `str` separator although the method takes `bytes`, and documented its keyword-only `max_size` argument -- by :user:`hxperl`. *Related issues and pull requests on GitHub:* :issue:`13686`. - Replaced most of the `sphinx.ext.extlinks`-based roles in the documentation with :pypi:`sphinx-issues`, which ships the `:issue:`, `:pr:`, `:commit:` and `:user:` roles out of the box. Pull request references are now captioned `#N` instead of `PR #N`, and commit references as abbreviated, `@`-prefixed hashes \-- by :user:`aiolibsbot`. *Related issues and pull requests on GitHub:* :issue:`13752`. - Fixed the `Content-ID` example in the multipart docs, which used a constant missing from `aiohttp.hdrs` and a value that is not a valid message ID -- by :user:`asvetlov`. *Related issues and pull requests on GitHub:* :issue:`13886`. ## Packaging updates and notes for downstreams - Started publishing an additional pure-Python wheel alongside the existing per-platform binary wheels and the `sdist` -- by :user:`webknjaz`. This gives users on platforms without a working C compiler, or without a matching pre-built wheel, an installable fallback that does not require compilation. *Related issues and pull requests on GitHub:* :issue:`7632`, :issue:`13388`. - Removed the `aiohttp/_websocket/reader_c.py` symlink from the source tree; the `aiohttp._websocket.reader_c` extension is now compiled directly from `reader_py.py` using `cython --module-name`, so distributions no longer include a `reader_c.py` file that showed up as an uncovered module in coverage reports -- by :user:`bdraco`. *Related issues and pull requests on GitHub:* :issue:`13457`. - Adopted :pep:`639` license metadata -- the license is now declared as the SPDX expression `Apache-2.0 AND MIT` and `license-files` moved to the `[project]` table, which raises the build-time requirement to `setuptools >= 77.0`. Built distributions now carry `License-Expression` instead of the legacy `License` field \-- by :user:`aiolibsbot`. *Related issues and pull requests on GitHub:* :issue:`13891`. ## Contributor-facing changes - The CI/CD is now in sync with the rest of the projects in terms of where the `cibuildwheel` workflow lives -- by :user:`webknjaz`. *Related commits on GitHub:* :commit:`59c0123d`. - Moved the pytest configuration from :file:`setup.cfg` to a dedicated :file:`pytest.ini` that follows the layout shared with `propcache` and other `aio-libs` projects. Compared to the old configuration, `minversion` is raised from `3.8.2` to `8.4`; `pytest-xdist` (`--numprocesses=auto`) and `pytest-cov` (`--cov`, `--cov-context=test`, `--no-cov-on-fail`) are enabled by default again, so pass `--numprocesses=0` and/or `--no-cov` to opt out, as the :file:`Makefile` targets and CI jobs now do where needed; `--doctest-modules`, `--strict-markers` and `faulthandler_timeout = 30` are enabled; `-v` is no longer added; empty parameter sets are marked `xfail` instead of skipped; `--junitxml` reports use `xunit1` with captured output and call-only durations; and `norecursedirs` skips more directories, including :file:`tests/isolated/` \-- by :user:`aiolibsbot`. *Related issues and pull requests on GitHub:* :issue:`12620`, :issue:`12621`. - Added check that change fragment matches PR number -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`12788`. - CI now builds the `sdist` (and a pure-Python wheel) once, in a new `build-pure-python-dists` job, and shares that build across `test`, `autobahn`, `benchmark`, `build-wheels`, `test-mobile` and the `sdist`-based half of linting, instead of every one of those jobs checking out the repository and running `make cythonize` on its own \-- by :user:`webknjaz`. Linting is also now split into `lint-from-git` (the :file:`requirements/runtime-deps.in` sync check and docs spell-checking, which need real Git history) and `lint-from-sdist` (`mypy`, `slotscheck`, the changelog fragment check, and `twine check`, which build from the shared artifact instead), since an `sdist` tarball never contains :file:`.git`. *Related issues and pull requests on GitHub:* :issue:`13363`, :issue:`13388`. - Synchronized the `coverage.py` configuration (:file:`.coveragerc.toml` and :file:`.coveragerc-cython.toml`) with the pattern already established in :external+yarl:doc:`yarl <index>`, :external+multidict:doc:`multidict <index>`, `frozenlist` and other sibling projects \-- by :user:`webknjaz`. Both files now anchor package discovery through `source_pkgs` instead of relying on a same-named directory happening to exist relative to the working directory, and add a `[paths]` mapping so coverage recorded against an installed copy of `aiohttp` still combines correctly with coverage recorded from the Git checkout. CI now lets `pytest-cov` write `coverage.xml` directly via `--cov-report=xml` instead of a separate `coverage xml` step, and the Autobahn testsuite's subprocess-based coverage collection (which uses `coverage run --append`, incompatible with parallel mode) now opts out per-invocation via a `COVERAGE_PARALLEL_MODE` environment variable instead of trying to override it on the command line. *Related issues and pull requests on GitHub:* :issue:`13422`. - Stopped the benchmark CI job from hanging in the CodSpeed runner's apt install by installing `libc6-dbg` up front with a bounded retry, and raised the job timeout from 15 to 30 minutes -- by :user:`bdraco`. *Related issues and pull requests on GitHub:* :issue:`13489`. - Added benchmarks for reading masked WebSocket messages and fixed the existing read benchmarks, which stopped measuring the parser after the eighth large frame due to the queue limit -- by :user:`bdraco`. *Related issues and pull requests on GitHub:* :issue:`13561`. - Removed stale `filterwarnings` ignores from the pytest configuration that are no longer triggered by aiohttp, the supported Python versions or the pinned test dependencies -- by :user:`aiolibsbot`. *Related issues and pull requests on GitHub:* :issue:`13717`. - Dropped the leftover `PIP_USER` setting and the `pip --user` `PATH` prefix from the CI workflow; both became dead once the test jobs started provisioning Python via `astral-sh/setup-uv` \-- by :user:`aiolibsbot`. *Related issues and pull requests on GitHub:* :issue:`13718`, :issue:`13721`. - Changed the long host in the `Host` header tests to one that is not made only of digits, since yarl now parses such a host as an IP address in its default mode and rejects this one as out of range \-- by :user:`asvetlov`. *Related issues and pull requests on GitHub:* :issue:`13861`. - Fixed `tools/gen.py` dropping a header name from the generated C lookup when two names shared a prefix that differed only in letter case, such as `Accept-CH` and `Accept-Charset`, and made the generated code compile without warnings -- by :user:`asvetlov`. *Related issues and pull requests on GitHub:* :issue:`13886`. ## Miscellaneous internal changes - Avoided formatting an unused fallback `Date` header value when the response already has one -- by :user:`marcus-campbell`. *Related issues and pull requests on GitHub:* :issue:`13299`. - Improved header parsing performance in the C HTTP parser by reusing the :class:`~multidict.istr` built for a header name missing from `aiohttp.hdrs` the next time the same name arrives, from a bounded cache of up to 512 names of at most 64 bytes -- by :user:`asvetlov`. *Related issues and pull requests on GitHub:* :issue:`13887`. *** </details> <details> <summary>tkem/cachetools (cachetools)</summary> ### [`v7.2.1`](https://redirect.github.com/tkem/cachetools/blob/HEAD/CHANGELOG.rst#v721-2026-10-05) [Compare Source](https://redirect.github.com/tkem/cachetools/compare/v7.2.0...v7.2.1) \=================== - Improve error handling for `RRCache.popitem()` when the cache is empty. - Minor style and documentation improvements. - Update CI environment. </details> <details> <summary>jawah/charset_normalizer (charset-normalizer)</summary> ### [`v3.5.2`](https://redirect.github.com/jawah/charset_normalizer/blob/HEAD/CHANGELOG.md#352-2026-09-29) [Compare Source](https://redirect.github.com/jawah/charset_normalizer/compare/3.5.1...3.5.2) ##### Changed - Raised the Cython upper bound to `<3.4` for native builds. The bound remains `<3.3` for `abi3` builds to preserve compatibility with the Python 3.7 Limited API. ##### Fixed - Valid UTF-8 Chinese JSON incorrectly detected as PTCP154 due to excessive noise penalties for uncommon CJK characters. ([#&#8203;796](https://redirect.github.com/jawah/charset_normalizer/issues/796)) - Supported encodings without aliases failing name resolution or being ignored in charset declarations. ([#&#8203;800](https://redirect.github.com/jawah/charset_normalizer/issues/800)) </details> <details> <summary>pyca/cryptography (cryptography)</summary> ### [`v50.0.2`](https://redirect.github.com/pyca/cryptography/compare/50.0.1...50.0.2) [Compare Source](https://redirect.github.com/pyca/cryptography/compare/50.0.1...50.0.2) </details> <details> <summary>aio-libs/multidict (multidict)</summary> ### [`v6.9.1`](https://redirect.github.com/aio-libs/multidict/blob/HEAD/CHANGES.rst#691) [Compare Source](https://redirect.github.com/aio-libs/multidict/compare/v6.9.0...v6.9.1) \===== *(2026-09-21)* ## Bug fixes - Fixed the C extension reading freed memory on free-threaded builds when a list handed to :py:meth:`~multidict.MultiDict.update`, :py:meth:`~multidict.MultiDict.extend`, :py:meth:`~multidict.MultiDict.merge` or the :py:class:`~multidict.MultiDict` and :py:class:`~multidict.CIMultiDict` constructors, a `[key, value]` item inside any iterable handed to them, or a list tested with `in` against :py:meth:`~multidict.MultiDict.items`, is changed by another thread; a call that catches the list shrinking under it now raises :py:exc:`RuntimeError` -- by :user:`rodrigobnogueira`. *Related issues and pull requests on GitHub:* :issue:`1437`. - Fixed a data race on the free-threaded build where a retired hash table's reader count used relaxed atomics, letting a lock-free `get()`/`getone()`/ `__getitem__()` read race a concurrent free of that table. The reader-exit decrement and the drain's free check now use release/acquire ordering instead -- by :user:`asvetlov`. *Related issues and pull requests on GitHub:* :issue:`1481`. - Fixed a free-threaded build bug where two threads calling `update()`, `merge()`, or `__setitem__()` on the same key at the same time could lose the key entirely instead of just racing on which value wins. A decref of the replaced value could transiently suspend the writer's critical section, letting a second writer for the same key observe the first writer's in-progress entry as absent and, once both settled, mistake it for a stale duplicate and delete it. Every such decref is now deferred until the writer has released its critical section, so the window can no longer open. `setdefault()` had an unrelated instance of the same blind spot (it could insert a duplicate rather than recognizing an in-flight key), fixed alongside it -- by :user:`asvetlov`. *Related issues and pull requests on GitHub:* :issue:`1483`. - Fixed a free-threaded build bug where `getall()` and the `items()`/ `keys()`/`values()` equality path could raise `KeyError` or report a present, never-deleted key as missing. A concurrent `update()`/`extend()`/ `__setitem__()` call can have its critical section transiently suspended (a decref triggering a blocking allocator call) while an entry is marked as part of its own bookkeeping; a reader landing in that window used to treat the mark as "not found" instead of "still there, in flight" -- by :user:`asvetlov`. *Related issues and pull requests on GitHub:* :issue:`1484`. - Fixed a reference leak in the C extension where `operand | md.items()` and `md.items() - operand` leaked one key and one value reference per element of `operand`, letting a large operand grow memory without bound (:gh:`GHSA-54p9-h82j-f925 <aio-libs/multidict/security/advisories/GHSA-54p9-h82j-f925>`) \-- by :user:`asvetlov`. The issue was reported by :user:`waydeshi`. *Related commits on GitHub:* :commit:`350b4a0`. - Fixed a segmentation fault on the standard (non-free-threaded) C extension build when a value type's `__del__` released the GIL (for example by calling `time.sleep()`) while `update()`, `merge()`, `__setitem__()`, `__delitem__()`, `pop()`, `popone()`, or `popall()` was dropping a replaced or removed value. `Py_BEGIN_CRITICAL_SECTION` compiles to a no-op on this build, so nothing else was stopping a second thread from mutating the very same `MultiDict` concurrently once the GIL was released mid-mutation. Every such decref is now deferred until the mutation has fully finished, the same technique already used to close the analogous free-threaded-build race \-- by :user:`asvetlov`. *Related issues and pull requests on GitHub:* :issue:`1489`. - Fixed the C extension reading freed memory while iterating a :py:class:`~multidict.CIMultiDict` whose keys are plain :py:class:`str`. Converting such a key to :py:class:`~multidict.istr` could run Python code (a :py:class:`str` subclass's `__str__` or `__del__`) or, on free-threaded builds, suspend the iterator's critical section, after which the iterator read the entry again even though a concurrent mutation could already have freed it. As part of the fix, :py:meth:`~multidict.MultiDict.copy` and re-initializing from another multidict now assign a new version in the C extension instead of reusing the source's, matching the pure Python implementation \-- by :user:`asvetlov`. *Related issues and pull requests on GitHub:* :issue:`1496`. - Fixed a use-after-free on the free-threaded build where a lock-free `get()`, `[]` or `in` could read a hash table that a concurrent resize had just retired and another reader was freeing \-- by :user:`asvetlov`. *Related issues and pull requests on GitHub:* :issue:`1497`. ## Contributor-facing changes - Removed a redundant `include` and a duplicated `exclude` line from `MANIFEST.in`; sdist contents are unchanged -- by :user:`asvetlov`. *Related issues and pull requests on GitHub:* :issue:`1478`. - Added `.claudeignore` file -- by :user:`asvetlov` *Related issues and pull requests on GitHub:* :issue:`1479`. - Scaled up the pure-Python `pop()`, `popitem()`, `__delitem__()`, `add()` and item-insertion benchmarks to do more work per measurement. Repeated CodSpeed runs on the same commit showed these particular benchmarks flagged as dominated by syscalls, understating their real cost and adding noise to the reported values; a larger working set amortizes that overhead -- by :user:`asvetlov`. *Related issues and pull requests on GitHub:* :issue:`1485`. - Replaced deprecated *instrumentation* codspeed mode with *simulation* -- by :user:`asvetlov` *Related issues and pull requests on GitHub:* :issue:`1493`. - Reorganized the mutating benchmarks (item insertion, `update()`, `add()` of the same key, `pop()`, `popitem()`, `clear()`, `__delitem__()` and `__setitem__()`) to copy a fresh multidict and apply the operation in a loop, like the `add()` and `extend()` benchmarks already do. The insertion, `update()` and `clear()` benchmarks previously mutated a single multidict shared across rounds, so only the first round measured the intended operation; the rest did a single copy per round, letting per-round overhead dominate \-- by :user:`asvetlov`. *Related issues and pull requests on GitHub:* :issue:`1494`. - The `repr()` and view inequality benchmarks were updated to repeat their operation in a loop, like the other benchmarks, and the CodSpeed benchmark job was moved to Python 3.14 -- by :user:`asvetlov`. *Related issues and pull requests on GitHub:* :issue:`1498`. - Dropped `-I` from the AddressSanitizer test command in `AGENTS.md` and in the CI job. It implies `-E`, which made Python ignore `PYTHONMALLOC=malloc`, so small hash tables were still served from `pymalloc` arenas where use-after-free went undetected \-- by :user:`asvetlov`. *Related issues and pull requests on GitHub:* :issue:`1499`. - The CI/CD workflow was updated to stop superseded runs of the same pull request when a new commit is pushed; runs on `master`, release branches, tags, the merge queue, and the daily schedule are never interrupted \-- by :user:`asvetlov`. *Related issues and pull requests on GitHub:* :issue:`1500`. - The release job was changed to upload distributions and their signatures to the GitHub Release one file at a time, skipping assets that were already attached and retrying after a pause, so that a parallel upload burst no longer tripped the GitHub secondary rate limit \-- by :user:`asvetlov`. *Related issues and pull requests on GitHub:* :issue:`1503`. ## Miscellaneous internal changes - Corrected several comments in the free-threaded C extension that attributed critical-section suspension to a blocking `PyMem_Malloc()` call; allocation alone never suspends an acquired critical section, and the real risk at those sites is a decref running a finalizer or weakref callback. Also dropped a retry loop in `md_clone_from_ht()` that guarded against the same, non-existent allocation-triggered suspension -- by :user:`asvetlov`. *Related issues and pull requests on GitHub:* :issue:`1486`. - Changed the free-threaded build's deferred decref buffer, used by `update()` and `__setitem__()`, to a chain of fixed-size blocks with a large inline first block instead of a small inline array that was reallocated on growth -- by :user:`asvetlov`. *Related issues and pull requests on GitHub:* :issue:`1501`. *** </details> <details> <summary>theskumar/python-dotenv (python-dotenv)</summary> ### [`v1.2.4`](https://redirect.github.com/theskumar/python-dotenv/blob/HEAD/CHANGELOG.md#124---2026-10-01) [Compare Source](https://redirect.github.com/theskumar/python-dotenv/compare/v1.2.3...v1.2.4) ##### Fixed - `dotenv get` no longer exits with code 1 for empty string values (`KEY=`) by \[[@&#8203;ShamikOfficial](https://redirect.github.com/ShamikOfficial)] in \[[#&#8203;700](https://redirect.github.com/theskumar/python-dotenv/issues/700)] - An unquoted empty value followed by an inline comment (e.g. `KEY= # comment`) is now parsed as an empty string instead of the comment text by \[[@&#8203;Noethix55555](https://redirect.github.com/Noethix55555)] in \[[#&#8203;663](https://redirect.github.com/theskumar/python-dotenv/issues/663)] - `dotenv run --no-override` now expands variable references with the same precedence as `load_dotenv(override=False)`, so a value like `${BASE}/suffix` uses the existing `BASE` from the environment instead of the one from the `.env` file by \[[@&#8203;ROTl24](https://redirect.github.com/ROTl24)] in \[[#&#8203;698](https://redirect.github.com/theskumar/python-dotenv/issues/698)] </details> <details> <summary>stub42/pytz (pytz)</summary> ### [`v2026.5`](https://redirect.github.com/stub42/pytz/compare/release_2026.4...release_2026.5) [Compare Source](https://redirect.github.com/stub42/pytz/compare/release_2026.4...release_2026.5) ### [`v2026.4`](https://redirect.github.com/stub42/pytz/compare/release_2026.3.post1...release_2026.4) [Compare Source](https://redirect.github.com/stub42/pytz/compare/release_2026.3.post1...release_2026.4) </details> <details> <summary>facelessuser/soupsieve (soupsieve)</summary> ### [`v2.10`](https://redirect.github.com/facelessuser/soupsieve/releases/tag/2.10) [Compare Source](https://redirect.github.com/facelessuser/soupsieve/compare/2.9.2...2.10) #### 2.10 - **NEW**: Support Python 3.15. - **NEW**: Add new `ignore` option to API methods that allows the specification of specific pseudo-classes to be ignored. - **NEW**: Tighten restrictions such that `namespaces` and `custom` objects must always be a Mapping, previously lists of tuples were also allowed. - **NEW**: Use a singleton for null selectors internally via called `Null` of type `SelectorNull`. - **NEW**: For performance, Soup Sieve will no longer try and coerce bad attribute values to useable strings. - **NEW**: Add `NOCACHE` flag that can be used to disable caching optimizations selectors and possibly other future caching optimizations. Provided for disabling and also disabling if issues are found with the new caching approach. - **FIX**: Improve performance of `~` for various cases by employing caching. - **FIX**: Improve performance of `nth-*` family of selectors in certain scenarios by employing caching. - **FIX**: Ensure `custom` is properly passed down from API functions to compilation. </details> <details> <summary>deeplook/svglib (svglib)</summary> ### [`v2.3.0`](https://redirect.github.com/deeplook/svglib/blob/HEAD/CHANGELOG.md#230-2026-10-05) [Compare Source](https://redirect.github.com/deeplook/svglib/compare/v2.2.0...v2.3.0) ##### Security - External `<image>`/`<use>` references can no longer escape the document's own directory. `xlink_href_target()` joined the reference onto the source directory and only checked `os.access()`, so an absolute reference discarded that directory and `..` climbed above it, letting an untrusted SVG name any file the process could read (CWE-22, GHSA-2p5c-8vcc-4rcw). Absolute references are now refused, and the new opt-in `external_reference_root` on `svg2rlg()`/`SvgRenderer` confines resolution to a trusted directory, propagated into nested external-SVG renderers. Relative references, including `..`, keep working by default. - The `svg2pdf` command line tool now sets `external_reference_root` to the input file's own directory, since a file converted from the command line is routinely one the user did not author. Pass `-R`/`--external-root` with a parent directory to allow shared assets, or `/` to allow any relative reference. Library callers are unaffected: the default stays `None`. </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://redirect.github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/sarumaj/schulportal-telegram-bot). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMDMuMCIsInVwZGF0ZWRJblZlciI6IjQ0LjEzNC4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
This pull request can be merged automatically.
This branch is out-of-date with the base branch
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin renovate/all-minor-patch:renovate/all-minor-patch
git switch renovate/all-minor-patch

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch main
git merge --no-ff renovate/all-minor-patch
git switch renovate/all-minor-patch
git rebase main
git switch main
git merge --ff-only renovate/all-minor-patch
git switch renovate/all-minor-patch
git rebase main
git switch main
git merge --no-ff renovate/all-minor-patch
git switch main
git merge --squash renovate/all-minor-patch
git switch main
git merge --ff-only renovate/all-minor-patch
git switch main
git merge renovate/all-minor-patch
git push origin main
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
dawid/schulportal-telegram-bot!124
No description provided.