Bump lxml from 4.8.0 to 4.9.2
Bumps lxml from 4.8.0 to 4.9.2.
Changelog
Sourced from lxml's changelog.
4.9.2 (2022-12-13)
Bugs fixed
- CVE-2022-2309: A Bug in libxml2 2.9.1[0-4] could let namespace declarations from a failed parser run leak into later parser runs. This bug was worked around in lxml and resolved in libxml2 2.10.0. https://gitlab.gnome.org/GNOME/libxml2/-/issues/378
Other changes
LP#1981760:
Element.attribnow registers ascollections.abc.MutableMapping.lxml now has a static build setup for macOS on ARM64 machines (not used for building wheels). Patch by Quentin Leffray.
4.9.1 (2022-07-01)
Bugs fixed
- A crash was resolved when using
iterwalk()(orcanonicalize()) after parsing certain incorrect input. Note thatiterwalk()can crash on valid input parsed with the same parser after failing to parse the incorrect input.4.9.0 (2022-06-01)
Bugs fixed
- GH#341: The mixin inheritance order in
lxml.htmlwas corrected. Patch by xmo-odoo.Other changes
Built with Cython 0.29.30 to adapt to changes in Python 3.11 and 3.12.
Wheels include zlib 1.2.12, libxml2 2.9.14 and libxslt 1.1.35 (libxml2 2.9.12+ and libxslt 1.1.34 on Windows).
GH#343: Windows-AArch64 build support in Visual Studio.
... (truncated)
Commits
c17c1caUse same naming for Python version matrix variable in wheel workflow as in CI...fc2f7eaUse windows-2016 image instead of windows-2019 to fix the Py2.7 build.98224b3Install more recent library versions for the wheel build.ce4e5bcFix release date.cece238Add PyPy-3.8 CI target.2c2308eTry to add a Windows CI build for Py2.7.0b0b2b9Exclude missing Python versions from CI jobs.b848b82Try to fix CI "setup.py install" in Py3.11.487a194CI: exclude non-static Windows jobs.fc53d6fShow executed commands in CI runs.- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)