Skip to content

chore(deps): weekly safe pypi updates · 6 packages - #227

Closed
mendral-app[bot] wants to merge 1 commit into
mainfrom
mendral/deps/weekly-safe-pypi-20260615
Closed

chore(deps): weekly safe pypi updates · 6 packages#227
mendral-app[bot] wants to merge 1 commit into
mainfrom
mendral/deps/weekly-safe-pypi-20260615

Conversation

@mendral-app

@mendral-app mendral-app Bot commented Jun 15, 2026

Copy link
Copy Markdown
Contributor

Packages bumped

Package Old New File
joblib 1.5.0 1.5.3 hub/jupyter-server/requirements.txt
nltk 3.9.1 3.9.4 hub/jupyter-server/requirements.txt
spacy 3.8.2 3.8.14 hub/jupyter-server/requirements.txt
xlrd 2.0.1 2.0.2 hub/jupyter-server/requirements.txt
pytz 2025.2 2026.2 hub/jupyter-server/requirements.txt
requests 2.32.4 2.34.2 both requirements files
Per-package detail

joblib 1.5.0 → 1.5.3

  • Patch releases with bug fixes and internal improvements
  • Impact: Used by scikit-learn for parallel computation. Patch-only, no API changes.

nltk 3.9.1 → 3.9.4

  • Patch releases with bug fixes
  • Impact: NLP toolkit used in data science template. Patch-only, no behavioral changes.

spacy 3.8.2 → 3.8.14

  • Patch releases within the 3.8.x series (stays compatible with constraint noted in requirements)
  • Impact: NLP library. Stays within 3.8.x constraint that avoids 3.13.x Python issues. Bug fixes only.

xlrd 2.0.1 → 2.0.2

  • Patch release with minor fixes
  • Impact: Excel file reader. Minimal usage surface, patch-only.

pytz 2025.2 → 2026.2

  • Updated IANA timezone database (2026b release)
  • Impact: Timezone data update. Always safe — contains updated timezone definitions from IANA.

requests 2.32.4 → 2.34.2

  • Minor releases with improvements to connection handling, urllib3 compatibility updates
  • No breaking API changes in the 2.x series
  • Impact: HTTP client used in server and data science templates. Stable library with excellent backward compatibility.

Files modified

  • hub/jupyter-server/requirements.txt
  • hub/jupyter-server/server/requirements.txt
Skipped this ecosystem
Package Current Reason
numpy 1.26.4 Blocked by gensim compatibility (documented constraint)
scipy 1.13.1 Blocked by gensim compatibility (documented constraint)
gensim 4.3.3 Unmaintained; no safe upgrade path
pandas 2.2.3 3.0.x is major; ecosystem compatibility unclear with gensim constraint
ipykernel 6.29.5 7.x is major version bump
fastapi 0.111.0 Latest 0.137.0 published 2026-06-14 (cooldown)
httpx 0.27.0 0.28.x may have breaking changes (pre-1.0 semver)
pydantic 2.9.1 2.13.x is many minor versions; needs separate evaluation
uvicorn 0.30.1 0.49.x is many minor versions; needs separate evaluation
websockets 12.0 16.x is major version bump
bokeh 3.7.3 4.x is major version bump
imageio 2.37.0 3.x is major version bump
numba 0.61.2 0.65.x needs numpy compatibility verification
matplotlib 3.10.3 Latest 3.11.0 published 2026-06-12 (cooldown)
pytest 8.3.5 Latest 9.1.0 published 2026-06-13 (cooldown)
tornado 6.5.1 Latest 6.5.7 published 2026-06-08 (borderline cooldown)
scikit-learn 1.6.1 1.9.0 is 3 minor versions ahead; needs evaluation
opencv-python 4.11.0.86 4.13.x needs separate evaluation
jupyter-server 2.16.0 2.19.0 is 3 minor versions; needs evaluation
ipython 9.2.0 9.14.x is many minor versions; needs evaluation

Note

Created by Mendral. Tag @mendral-app with feedback or questions.

Bump:
- joblib 1.5.0 → 1.5.3
- nltk 3.9.1 → 3.9.4
- spacy 3.8.2 → 3.8.14
- xlrd 2.0.1 → 2.0.2
- pytz 2025.2 → 2026.2
- requests 2.32.4 → 2.34.2
@mendral-app
mendral-app Bot requested a review from a team June 15, 2026 09:22
@cploujoux

Copy link
Copy Markdown
Contributor

Closing as stale.

This PR has been in merge conflict and unreviewed for a long time. Checked before closing: none of the packages it bumps has an open Dependabot alert on this repo today — so it is not holding back any security fix, it is only adding noise to the review queue.

Where a real vulnerability does remain open, it is being handled by a dedicated remediation PR instead of a stale bulk update.

@cploujoux cploujoux closed this Aug 14, 2026
@cploujoux
cploujoux deleted the mendral/deps/weekly-safe-pypi-20260615 branch August 14, 2026 22:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant