Skip to content

deps: Update weasyprint requirement from <70,>=69.0 to >=70.0,<71 - #191

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/weasyprint-gte-70.0-and-lt-71
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/weasyprint-gte-70.0-and-lt-71

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Updates the requirements on weasyprint to permit the latest version.

Release notes

Sourced from weasyprint's releases.

v70.0

Read about this release on our blog.

This is a security update (CVE-2026-55073, GHSA-r543-q48m-4c9j).

We strongly recommend to upgrade WeasyPrint to the latest version if you: * embed untrusted images, or * rely on the URL fetcher to filter metadata or stylesheets passed as Python parameters.

Security

  • Don’t render EPS images.
  • Always use original URL fetcher when available.

Features

  • #2905: Add initial support of CSS Notes, with financial support from NLnet
  • #2731, #2781: Log an error on unknown render and write_pdf options
  • #2802, #2805: Create immutable releases on GitHub
  • #2809, #2810: Switch to MSYS2 UCRT64 environment for Windows tests and executables
  • #2777, #2814: Support COLR emoji fonts
  • #2667, #2744: Support context paint in SVG markers
  • #1862, #2844: Improve filename detection for attachments
  • #2816, #2827: Set SVG title as alternative text
  • #2718: Provide a 'onedir' Windows executable
  • #2863: Support box-shadow
  • #2755: Support RTL SVG text anchoring
  • #2866: Don’t use f-strings in logs

Bug fixes

  • #2799: Keep HarfBuzz font faces alive during PDF subsetting
  • #2764, #2793: Accept Path as base URL in CSS
  • #2800, #2801: Fix position of raster emojis
  • #2782, #2807: Use POSIX paths in Fontconfig
  • #2766, #2779: Use response bytes when image file path doesn’t exist
  • #2277, #2728: Honor page breaks on floated elements
  • #2789, #2818: Use base URL when solving pending properties
  • #2820: Ignore unresolvable math in image slices
  • #2901, #2825: Transform SVG size into CSS to apply CSS sizing algorithm
  • #2819: Resolve calc() division by zero to infinity
  • #2824: Remove old deprecation warnings
  • #2762, #2780: Set SVG gradient color before path construction
  • #2761: Handle split tables with captions
  • #2215, #2747: Discard broken at-rules
  • #2736, #2738: Apply transformations to SVG opacity groups
  • #2830: Use a stack to draw simple borders
  • #2831: Fix line_height() crash on calc() values
  • #2784, #2832: Set fallback font for Unicode test
  • #2726, #2881: Improve accessibility of PDF forms
  • #2803: Fix inline width after backtracked line breaks
  • #2833: Store root style in anonymous style

... (truncated)

Changelog

Sourced from weasyprint's changelog.

Version 70.0

Released on 2026-09-08.

This is a security update (CVE-2026-55073, GHSA-r543-q48m-4c9j).

We strongly recommend to upgrade WeasyPrint to the latest version if you:

  • embed untrusted images, or
  • rely on the URL fetcher to filter metadata or stylesheets passed as Python parameters.

Security:

  • Don’t render EPS images.
  • Always use original URL fetcher when available.

Features:

  • [#2905](https://github.com/Kozea/WeasyPrint/issues/2905) <https://github.com/Kozea/WeasyPrint/pull/2905>_: Add initial support of CSS Notes, with financial support from NLnet
  • [#2731](https://github.com/Kozea/WeasyPrint/issues/2731) <https://github.com/Kozea/WeasyPrint/issues/2731>, [#2781](https://github.com/Kozea/WeasyPrint/issues/2781) <https://github.com/Kozea/WeasyPrint/pull/2781>: Log an error on unknown render and write_pdf options
  • [#2802](https://github.com/Kozea/WeasyPrint/issues/2802) <https://github.com/Kozea/WeasyPrint/issues/2802>, [#2805](https://github.com/Kozea/WeasyPrint/issues/2805) <https://github.com/Kozea/WeasyPrint/pull/2805>: Create immutable releases on GitHub
  • [#2809](https://github.com/Kozea/WeasyPrint/issues/2809) <https://github.com/Kozea/WeasyPrint/issues/2809>, [#2810](https://github.com/Kozea/WeasyPrint/issues/2810) <https://github.com/Kozea/WeasyPrint/pull/2810>: Switch to MSYS2 UCRT64 environment for Windows tests and executables
  • [#2777](https://github.com/Kozea/WeasyPrint/issues/2777) <https://github.com/Kozea/WeasyPrint/issues/2777>, [#2814](https://github.com/Kozea/WeasyPrint/issues/2814) <https://github.com/Kozea/WeasyPrint/pull/2814>: Support COLR emoji fonts
  • [#2667](https://github.com/Kozea/WeasyPrint/issues/2667) <https://github.com/Kozea/WeasyPrint/issues/2667>, [#2744](https://github.com/Kozea/WeasyPrint/issues/2744) <https://github.com/Kozea/WeasyPrint/pull/2744>: Support context paint in SVG markers
  • [#1862](https://github.com/Kozea/WeasyPrint/issues/1862) <https://github.com/Kozea/WeasyPrint/issues/1862>, [#2844](https://github.com/Kozea/WeasyPrint/issues/2844) <https://github.com/Kozea/WeasyPrint/pull/2844>: Improve filename detection for attachments
  • [#2816](https://github.com/Kozea/WeasyPrint/issues/2816) <https://github.com/Kozea/WeasyPrint/issues/2816>, [#2827](https://github.com/Kozea/WeasyPrint/issues/2827) <https://github.com/Kozea/WeasyPrint/pull/2827>: Set SVG title as alternative text
  • [#2718](https://github.com/Kozea/WeasyPrint/issues/2718) <https://github.com/Kozea/WeasyPrint/issues/2718>_: Provide a 'onedir' Windows executable
  • [#2863](https://github.com/Kozea/WeasyPrint/issues/2863) <https://github.com/Kozea/WeasyPrint/pull/2863>_: Support box-shadow
  • [#2755](https://github.com/Kozea/WeasyPrint/issues/2755) <https://github.com/Kozea/WeasyPrint/pull/2755>_: Support RTL SVG text anchoring
  • [#2866](https://github.com/Kozea/WeasyPrint/issues/2866) <https://github.com/Kozea/WeasyPrint/issues/2866>_: Don’t use f-strings in logs

... (truncated)

Commits
  • 4d3b7b6 Version 70.0
  • 289e278 Always use original URL fetcher when available
  • aeb3be7 Merge remote-tracking branch 'security/main'
  • 4835724 Merge pull request #2915 from havelaer/fix-nested-svg-viewport-restore
  • 0331051 Restore nested SVG viewport size on the SVG object, not the drawing function
  • e4b8b45 Add harfbuzz-vector requirement for Fedora
  • 371e4de Merge pull request #2905 from Kozea/notes
  • 590bf63 Merge pull request #2913 from Kozea/fast-svg-paths
  • f6570c3 Use a faster regex-based parser for SVG paths
  • bc05162 Use faster deque for SVG vertices
  • Additional commits viewable in compare view

@dependabot @github

dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

MrChengLen added a commit that referenced this pull request Oct 6, 2026
…n and dead triggers gone

An analysis of all ten workflows found that pytest runs once per PR
(lint-and-test). The other PR checks do different jobs: image smoke tests,
external PDF/A validation, secret and scope scans. Three things were real
duplication:

- veraPDF: verapdf.yml rebuilt the environment lint-and-test already had (41
  of its 49 s), and no ruleset required it, although the README and the
  pricing page call it a CI gate. Its steps (fixture via
  scripts/verapdf_check.py, the digest-pinned verapdf/cli run, artifact
  upload) now follow the test run in lint-and-test, a required check, so a
  PDF/A-2b regression blocks the merge. The container now runs with
  `--network none` and a read-only mount, and the upload uses
  `if: ${{ !cancelled() }}`. verapdf.yml is gone.
  test_verapdf_gate_is_part_of_the_required_lint_and_test_job pins both gate
  steps in that job: no step- or job-level `if:` or `continue-on-error`,
  `--flavour 2b`, and no `|| true`.
- sbom.yml built the same SBOM on every main push as docker.yml's `sbom` job,
  which also attests it to the images. The 90-day artifact had no reader.
  sbom.yml keeps workflow_dispatch as the rehearsal for the SBOM steps.
- `develop` triggers in ci.yml and scope-guard.yml: no such branch exists.

Dependabot: Dependabot gives requirements.txt floor raises (`>=a` -> `>=b`)
no update type, so the minor/patch group never caught them. #191-#195 arrived
one by one, and four of them sat red until a lockfile recompile. The pip
group is now `python-all` (patterns: *): one PR a week, one lockfile pass,
after a 3-day cooldown. WeasyPrint stays out of the group (held below 70
until the SSRF url_fetcher guard is ported; it keeps arriving as its own
reminder PR). cyclonedx-bom (>=6) and pikepdf (>=11) are ignored by version
range, because `update-types` cannot match range requirements.

Not consolidated, on purpose: secret-scan and scope-check (two required
contexts, different jobs), lockfile-drift (non-required by design),
deps-latest (weekly unpinned early warning), docker-pr (token isolation from
the push build), the post-merge CI run on main (with non-strict checks, the
only test of the merge result).

Verified on main 93c6ff1: full suite 1663 passed / 80 skipped; workflow guard
tests and the changelog-fragment guard green; YAML parses; ruff clean;
gitleaks and the pre-commit scope guard clean. Security and code review
(commit-review gate) done; their findings are in.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@dependabot dependabot Bot changed the title deps: update weasyprint requirement from <70,>=69.0 to >=70.0,<71 deps: Update weasyprint requirement from <70,>=69.0 to >=70.0,<71 Oct 8, 2026
@dependabot
dependabot Bot force-pushed the dependabot/pip/weasyprint-gte-70.0-and-lt-71 branch from afc7dcd to b51281d Compare October 8, 2026 08:43
Updates the requirements on [weasyprint](https://github.com/Kozea/WeasyPrint) to permit the latest version.
- [Release notes](https://github.com/Kozea/WeasyPrint/releases)
- [Changelog](https://github.com/Kozea/WeasyPrint/blob/main/docs/changelog.rst)
- [Commits](Kozea/WeasyPrint@v69.0...v70.0)

---
updated-dependencies:
- dependency-name: weasyprint
  dependency-version: '70.0'
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/pip/weasyprint-gte-70.0-and-lt-71 branch from b51281d to b93ce4c Compare October 8, 2026 08:51
MrChengLen added a commit that referenced this pull request Oct 8, 2026
…ntil their ports

Both majors need code changes first: WeasyPrint 70 reworks the url_fetcher
interface the SSRF guard relies on, and stripe 16 pins an API version that
rejects payment_method_types on Checkout session creation. Excluded from the
python-all group, they arrived as standalone PRs (#191, #204) that could only
sit red. Like the existing cyclonedx-bom and pikepdf caps, they are now
`ignore`d by version range (>=70, >=16); Dependabot raises floors below a cap
and keeps the cap (seen with b75b56c on pikepdf/cyclonedx-bom). Patch and minor
releases below the caps now come in the weekly batch.

New guard test_dependabot_ignores_sit_on_live_caps: every pip ignore range
must match a cap in requirements*.txt, so a port that lifts a cap but forgets
the ignore fails CI instead of freezing the package silently (mutation-
checked). requirements.txt's cap comments say so too. Two earlier unreleased
fragments and the dependabot.yml header are corrected for the new behaviour.

Dependabot security updates and alerts are off on this repo, so the ignores
suppress nothing security-wise; pip-audit on requirements.lock stays the
CVE gate.

Verified: full suite 1734 passed / 123 skipped; ruff clean; gitleaks and the
pre-commit scope guard clean. Code review done, findings applied.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@MrChengLen

Copy link
Copy Markdown
Owner

Closing: WeasyPrint stays below 70 until the url_fetcher-based SSRF guard is ported to WeasyPrint 70's fetcher API. Since #205, Dependabot ignores weasyprint >=70 until that port lands. The port lifts the cap in requirements.txt and the ignore together; tests/test_supply_chain_hygiene.py::test_dependabot_ignores_sit_on_live_caps keeps the two in step.

@dependabot @github

dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

Looks like weasyprint is no longer being updated by Dependabot, so this is no longer needed.

@MrChengLen MrChengLen closed this Oct 8, 2026
@dependabot
dependabot Bot deleted the dependabot/pip/weasyprint-gte-70.0-and-lt-71 branch October 8, 2026 09:14
@dependabot @github

dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant