Skip to content

chore(deps): weekly safe pypi updates · 9 packages - #244

Open
mendral-app[bot] wants to merge 1 commit into
mainfrom
mendral/deps/weekly-safe-pypi-20260706
Open

chore(deps): weekly safe pypi updates · 9 packages#244
mendral-app[bot] wants to merge 1 commit into
mainfrom
mendral/deps/weekly-safe-pypi-20260706

Conversation

@mendral-app

@mendral-app mendral-app Bot commented Jul 6, 2026

Copy link
Copy Markdown
Contributor

Packages bumped

Package Old New Published
tornado 6.5.1 6.5.7 2026-06-08
urllib3 2.5.0 2.7.0 2026-05-07
nltk 3.9.1 3.9.4 2026-03-24
ipython 9.2.0 9.15.0 2026-06-26
imageio 2.37.0 2.37.3 2026-03-09
joblib 1.5.0 1.5.3 2025-12-15
python-docx 1.1.2 1.2.0 2025-06-16
pytz 2025.2 2026.2 2026-05-04
soundfile 0.13.1 0.14.0 2026-06-06
Per-package detail

tornado 6.5.1 → 6.5.7 ⚠️ Security

  • v6.5.6: Cross-origin redirect header stripping (CVE-2026-49853), decompressed response size enforcement (CVE-2026-49855), buffer overflow fix (CVE-2026-49854)
  • v6.5.5: Multipart form-data limited to 100 parts, cookie validation, carriage return rejection
  • v6.5.3: DoS fixes for multipart/form-data and header parsing (CVE-2025-67726, CVE-2025-67725, CVE-2025-67724)
  • Used as dependency of jupyter-server — no API changes, security patches only

urllib3 2.5.0 → 2.7.0 ⚠️ Security

  • v2.6.0: CVE-2025-66471 & CVE-2025-66418 (decompression bombs, Content-Encoding DoS)
  • v2.7.0: Decompression-bomb safeguard fixes, redirect header stripping for credentials, pyOpenSSL ≥ 19.0.0 required
  • Drops Python 3.9 (image uses 3.12 ✓)
  • Used transitively via requests/aiohttp — no code changes needed

nltk 3.9.1 → 3.9.4 ⚠️ Security

  • v3.9.3: CVE-2025-14009 (secure ZIP extraction), path traversal and arbitrary reads blocking
  • v3.9.4: Python 3.14 support, Levenshtein/Jaro similarity fixes
  • Used as NLP toolkit in template — no API changes

ipython 9.2.0 → 9.15.0

  • New %xmode Doctest traceback mode, Python 3.15 debugger fixes
  • %run glob expansion: quoted arguments no longer expand (matches shell behavior)
  • IPython.utils.generics.inspect_object deprecated
  • SQLite history fallback for concurrent access
  • Used as Jupyter kernel backend — behavioral change only affects %run with quoted globs, unlikely to affect template users

imageio 2.37.0 → 2.37.3

  • Fixed invalid EXIF orientation in Pillow plugin
  • Fixed OverflowError in pyav plugin
  • Added fsspec dependency, fixed ffmpeg caret handling
  • Patch fixes only, no impact on template usage

joblib 1.5.0 → 1.5.3

  • Maintenance/bug fix releases
  • Used by scikit-learn internally — no user-facing changes

python-docx 1.1.2 → 1.2.0

  • Minor feature release
  • Used as document generation library in template — additive changes only

pytz 2025.2 → 2026.2

  • Timezone database update (2026 DST rules)
  • No code changes, data-only update

soundfile 0.14.0

  • Type annotations added, race condition fix for concurrent file opens
  • ARM64 Windows support added
  • Drops Python ≤ 3.9 (image uses 3.12 ✓)
  • Used for audio I/O in template — no breaking API changes

Files modified

  • hub/jupyter-server/requirements.txt
Skipped this ecosystem
Package Current Reason
jupyter-server 2.16.0 Covered by open PR #236 (→ 2.20.0)
orjson 3.10.18 Covered by open PR #236 (→ 3.11.9)
matplotlib 3.10.3 Covered by open PR #236 (→ 3.11.0)
aiohttp 3.12.14 Covered by open PR #236 (→ 3.14.1)
beautifulsoup4 4.13.4 Covered by open PR #236 (→ 4.15.0)
bokeh 3.7.3 Covered by open PR #236 (→ 3.9.1)
opencv-python 4.11.0.86 Covered by open PR #236 (→ 4.13.0.92)
plotly 6.0.1 Covered by open PR #236 (→ 6.8.0)
kaleido 1.0.0 Covered by open PR #236 (→ 1.3.0)
requests 2.32.4 Covered by open PR #236 (→ 2.34.2)
scikit-learn 1.6.1 Covered by open PR #236 (→ 1.9.0)
spacy 3.8.2 Covered by open PR #236 (→ 3.8.14)
fastapi 0.111.0 Covered by open PR #236 (→ 0.138.0)
httpx 0.27.0 Covered by open PR #236 (→ 0.28.1)
pydantic 2.9.1 Covered by open PR #236 (→ 2.13.4)
numpy 1.26.4 Pinned — blocked by gensim (unmaintained)
scipy 1.13.1 Pinned — blocked by gensim (unmaintained)
pandas 2.2.3 Major bump (→ 3.x) requires numpy 2, blocked by gensim
gensim 4.3.3 Unmaintained, no newer release
numba 0.61.2 Latest (0.66.0) within 7-day cooldown; fallback 0.65.1 may conflict with pinned numpy 1.26
pillow 12.2.0 Latest (12.3.0) within 7-day cooldown, no eligible fallback
ipykernel 6.29.5 Major bump (→ 7.x), deferred for separate risky PR
pytest 8.3.5 Major bump (→ 9.x), deferred for separate risky PR
websockets 12.0 Major bump (→ 16.0), deferred for separate risky PR
uvicorn 0.30.1 Latest (0.50.1) within cooldown; fallback 0.49.0 is a large jump, deferred
scikit-image 0.25.2 Minor bump (→ 0.26.0) but may require newer scipy, blocked by gensim chain
openpyxl 3.1.5 Already at latest
seaborn 0.13.2 Already at latest
xarray 2025.4.0 Already at latest
xlrd 2.0.1 Already at latest
sympy 1.14.0 Already at latest
textblob 0.19.0 Already at latest
librosa 0.11.0 Already at latest

Note

Created by Mendral. Tag @mendral-app with feedback or questions.

Bump imageio, joblib, nltk, python-docx, pytz, soundfile, tornado, urllib3, ipython
@mendral-app
mendral-app Bot requested a review from a team July 6, 2026 09:16
@mendral-app
mendral-app Bot marked this pull request as ready for review July 6, 2026 09:36
@cursor

cursor Bot commented Jul 6, 2026

Copy link
Copy Markdown

Bugbot is not enabled for this team, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants