Skip to content

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Sep 13, 2024

This PR contains the following updates:

Package Change Age Confidence
lxml (source, changelog) 5.2.2 -> 5.4.0 age confidence

Release Notes

lxml/lxml (lxml)

v5.4.0

Compare Source

==================

Bugs fixed

  • LP#2107279: Binary wheels use libxml2 2.13.8 and libxslt 1.1.43 to resolve several CVEs.
    (Binary wheels for Windows continue to use a patched libxml2 2.11.9 and libxslt 1.1.39.)
    Issue found by Anatoly Katyushin.

v5.3.2

Compare Source

==================

This release resolves CVE-2025-24928 as described in
https://gitlab.gnome.org/GNOME/libxml2/-/issues/847

Bugs fixed

  • Binary wheels use libxml2 2.12.10 and libxslt 1.1.42.

  • Binary wheels for Windows use a patched libxml2 2.11.9 and libxslt 1.1.39.

v5.3.1

Compare Source

==================

Bugs fixed

  • GH#440: Some tests were adapted for libxml2 2.14.0.
    Patch by Nick Wellnhofer.

  • LP#2097175: DTD(external_id="…") erroneously required a byte string as ID value.

  • GH#450: iterparse() internally triggered the `DeprecationWarning`` added in lxml 5.3.0 when parsing HTML.

Other changes

  • GH#442: Binary wheels for macOS no longer use the linker flag -flat_namespace.

v5.3.0

Compare Source

==================

Bugs fixed

  • GH#440: Some tests were adapted for libxml2 2.14.0.
    Patch by Nick Wellnhofer.

  • LP#2097175: DTD(external_id="…") erroneously required a byte string as ID value.

  • GH#450: iterparse() internally triggered the `DeprecationWarning`` added in lxml 5.3.0 when parsing HTML.

Other changes

  • GH#442: Binary wheels for macOS no longer use the linker flag -flat_namespace.

Configuration

📅 Schedule: Branch creation - "every weekend" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the dependencies Pull requests that update a dependency file label Sep 13, 2024
@renovate renovate bot force-pushed the renovate/lxml-5.x-lockfile branch 13 times, most recently from 73884be to 71d22b3 Compare September 21, 2024 04:48
@renovate renovate bot force-pushed the renovate/lxml-5.x-lockfile branch 16 times, most recently from 3b06cef to 1fa69ff Compare September 25, 2024 22:54
@renovate renovate bot force-pushed the renovate/lxml-5.x-lockfile branch 13 times, most recently from 06797fc to 76eaa70 Compare May 15, 2025 04:25
@renovate renovate bot force-pushed the renovate/lxml-5.x-lockfile branch 11 times, most recently from 8eeaa35 to 0d85767 Compare May 23, 2025 04:23
@renovate renovate bot force-pushed the renovate/lxml-5.x-lockfile branch from 0d85767 to 2cf4660 Compare August 10, 2025 12:42
@renovate renovate bot force-pushed the renovate/lxml-5.x-lockfile branch from 2cf4660 to 358cb4e Compare August 19, 2025 12:34
@renovate renovate bot changed the title fix(deps): update dependency lxml to v5.4.0 fix(deps): update dependency lxml to v5.4.0 - autoclosed Aug 20, 2025
@renovate renovate bot closed this Aug 20, 2025
@renovate renovate bot deleted the renovate/lxml-5.x-lockfile branch August 20, 2025 22:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants