Bump lxml from 4.8.0 to 4.9.3
Bumps lxml from 4.8.0 to 4.9.3.
Changelog
Sourced from lxml's changelog.
4.9.3 (2023-07-05)
Bugs fixed
lxml.objectifyaccepted non-decimal numbers like²²²as integers.A memory leak in
lxml.html.cleanwas resolved by switching to Cython 0.29.34+.GH#348: URL checking in the HTML cleaner was improved. Patch by Tim McCormack.
GH#371, GH#373: Some regex strings were changed to raw strings to fix Python warnings. Patches by Jakub Wilk and Anthony Sottile.
Other changes
Wheels include zlib 1.2.13, libxml2 2.10.3 and libxslt 1.1.38 (zlib 1.2.12, libxml2 2.10.3 and libxslt 1.1.37 on Windows).
Built with Cython 0.29.36 to adapt to changes in Python 3.12.
4.9.2 (2022-12-13)
Bugs fixed
- CVE-2022-2309: A Bug in libxml2 2.9.1[0-4] could let namespace declarations from a failed parser run leak into later parser runs. This bug was worked around in lxml and resolved in libxml2 2.10.0. https://gitlab.gnome.org/GNOME/libxml2/-/issues/378
Other changes
LP#1981760:
Element.attribnow registers ascollections.abc.MutableMapping.lxml now has a static build setup for macOS on ARM64 machines (not used for building wheels). Patch by Quentin Leffray.
4.9.1 (2022-07-01)
Bugs fixed
... (truncated)
Commits
15936e9Build: Fix wheel target split for aarch64.1226a23Build: Fix wheel target for i686 since manylinux-2.28 does not support it any...9f05e26Build: Use newer Docker images to (hopefully) include Py3.12.b218465Fix release date.994001eBuild: Fix PyPy wheel build by actually installing it.86cebbdBuild: Use system Py2.7 on macOS since the "setup-python" action has removed ...8a55066Build: Install library dependencies for sdist build.fffb658Build: Build the sdist without compiling the external libraries, in a separat...794beddBuild: Avoid building the sdist before the wheel because it lacks the proper ...c4693f3Build: Upgrade to newer PyPy-3.9 version to work around C-API issues.- Additional commits viewable in compare view
You can trigger a rebase of this PR by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Note Automatic rebases have been disabled on this pull request as it has been open for over 30 days.
@Evidlo you should probably look into this PR since it fixes the 3.11 dependency issue.
@dependabot rebase
Looks like lxml is no longer a dependency, so this is no longer needed.