chore(deps): update dependency lxml to v5.4.0 #44

Open
renovate-bot wants to merge 1 commit from renovate/lxml-5.x into master
Member

This PR contains the following updates:

Package Change Age Confidence
lxml (source, changelog) ==5.3.0 -> ==5.4.0 age confidence

Release Notes

lxml/lxml (lxml)

v5.4.0

Compare Source

==================

Bugs fixed

  • LP#2107279: Binary wheels use libxml2 2.13.8 and libxslt 1.1.43 to resolve several CVEs.
    (Binary wheels for Windows continue to use a patched libxml2 2.11.9 and libxslt 1.1.39.)
    Issue found by Anatoly Katyushin.

v5.3.2

Compare Source

==================

This release resolves CVE-2025-24928 as described in
https://gitlab.gnome.org/GNOME/libxml2/-/issues/847

Bugs fixed

  • Binary wheels use libxml2 2.12.10 and libxslt 1.1.42.

  • Binary wheels for Windows use a patched libxml2 2.11.9 and libxslt 1.1.39.

v5.3.1

Compare Source

==================

Bugs fixed

  • GH#440: Some tests were adapted for libxml2 2.14.0.
    Patch by Nick Wellnhofer.

  • LP#2097175: DTD(external_id="…") erroneously required a byte string as ID value.

  • GH#450: iterparse() internally triggered the `DeprecationWarning`` added in lxml 5.3.0 when parsing HTML.

Other changes

  • GH#442: Binary wheels for macOS no longer use the linker flag -flat_namespace.

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

This PR contains the following updates: | Package | Change | Age | Confidence | |---|---|---|---| | [lxml](https://lxml.de/) ([source](https://github.com/lxml/lxml), [changelog](https://git.launchpad.net/lxml/plain/CHANGES.txt)) | `==5.3.0` -> `==5.4.0` | [![age](https://developer.mend.io/api/mc/badges/age/pypi/lxml/5.4.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/pypi/lxml/5.3.0/5.4.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) | --- ### Release Notes <details> <summary>lxml/lxml (lxml)</summary> ### [`v5.4.0`](https://github.com/lxml/lxml/blob/HEAD/CHANGES.txt#540-2025-04-22) [Compare Source](https://github.com/lxml/lxml/compare/lxml-5.3.2...lxml-5.4.0) \================== ## Bugs fixed - [LP#2107279](https://github.com/LP/lxml/issues/2107279): Binary wheels use libxml2 2.13.8 and libxslt 1.1.43 to resolve several CVEs. (Binary wheels for Windows continue to use a patched libxml2 2.11.9 and libxslt 1.1.39.) Issue found by Anatoly Katyushin. ### [`v5.3.2`](https://github.com/lxml/lxml/blob/HEAD/CHANGES.txt#532-2025-04-05) [Compare Source](https://github.com/lxml/lxml/compare/lxml-5.3.1...lxml-5.3.2) \================== This release resolves CVE-2025-24928 as described in https://gitlab.gnome.org/GNOME/libxml2/-/issues/847 ## Bugs fixed - Binary wheels use libxml2 2.12.10 and libxslt 1.1.42. - Binary wheels for Windows use a patched libxml2 2.11.9 and libxslt 1.1.39. ### [`v5.3.1`](https://github.com/lxml/lxml/blob/HEAD/CHANGES.txt#531-2025-02-09) [Compare Source](https://github.com/lxml/lxml/compare/lxml-5.3.0...lxml-5.3.1) \================== ## Bugs fixed - [GH#440](https://github.com/GH/lxml/issues/440): Some tests were adapted for libxml2 2.14.0. Patch by Nick Wellnhofer. - [LP#2097175](https://github.com/LP/lxml/issues/2097175): `DTD(external_id="…")` erroneously required a byte string as ID value. - [GH#450](https://github.com/GH/lxml/issues/450): `iterparse()` internally triggered the \`DeprecationWarning\`\` added in lxml 5.3.0 when parsing HTML. ## Other changes - [GH#442](https://github.com/GH/lxml/issues/442): Binary wheels for macOS no longer use the linker flag `-flat_namespace`. </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS4yMTIuMCIsInVwZGF0ZWRJblZlciI6IjQxLjEuNCIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJyZW5vdmF0ZS1ib3QiXX0=-->
renovate-bot added the
renovate-bot
label 2025-03-24 05:21:16 +05:30
renovate-bot force-pushed renovate/lxml-5.x from 4e53a1b50b to a14a9c9c03 2025-04-07 05:18:24 +05:30 Compare
renovate-bot changed title from chore(deps): update dependency lxml to v5.3.1 to chore(deps): update dependency lxml to v5.3.2 2025-04-07 05:18:25 +05:30
renovate-bot force-pushed renovate/lxml-5.x from a14a9c9c03 to 4874b49f4c 2025-04-28 05:21:16 +05:30 Compare
renovate-bot changed title from chore(deps): update dependency lxml to v5.3.2 to chore(deps): update dependency lxml to v5.4.0 2025-04-28 05:21:17 +05:30
This pull request can be merged automatically.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin renovate/lxml-5.x:renovate/lxml-5.x
git checkout renovate/lxml-5.x

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git checkout master
git merge --no-ff renovate/lxml-5.x
git checkout renovate/lxml-5.x
git rebase master
git checkout master
git merge --ff-only renovate/lxml-5.x
git checkout renovate/lxml-5.x
git rebase master
git checkout master
git merge --no-ff renovate/lxml-5.x
git checkout master
git merge --squash renovate/lxml-5.x
git checkout master
git merge --ff-only renovate/lxml-5.x
git checkout master
git merge renovate/lxml-5.x
git push origin master
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: ForgeFlux/nodeinfo-test#44
No description provided.