py-interface-meta: added version 2.0.1
interface_meta provides a convenient way to expose an extensible API with
enforced method signatures and consistent documentation.
py-autobahn: updated to 26.7.1
26.7.1
------
**Security**
* Fix WebSocket ``maxMessagePayloadSize`` being enforced against the compressed on-the-wire frame length instead of the uncompressed reassembled message size when permessage-compress (deflate/bzip2/snappy/brotli) is negotiated. A small compressed frame could inflate far beyond the configured limit and be delivered to the application (a decompression-bomb style denial-of-service; security advisory GHSA-hxp9-w8x3-p566, same class as CVE-2016-10544). The limit is now re-checked at the inflation site against the running uncompressed message size, and the connection is failed with close code 1009 (message too big) before delivery — for both the whole-message and streaming receive APIs and every compression backend. Behaviour change: a compressed message that inflates past ``maxMessagePayloadSize`` is now rejected where it previously passed; uncompressed traffic and the per-frame ``maxFramePayloadSize`` wire guard are unaffected
* Fix the permessage-deflate ``max_message_size`` receive cap silently truncating an over-limit message and raising a zlib error instead of cleanly rejecting it: the bounded ``decompress(…, max_length)`` left the remaining input in ``unconsumed_tail`` undrained, so the message was corrupted rather than reported. Decompression is now bounded cumulatively across frames and raises ``PayloadExceededError`` as soon as the uncompressed size would exceed the cap
* Make bounded decompression backend-agnostic: ``decompress_message_data()`` gains an optional ``max_output_len`` argument (documented on the ``PerMessageCompress`` base class) and every permessage-compress backend now honours it. deflate and bzip2 stop inflating once the limit is reached (native incremental cap); snappy and brotli, whose libraries expose no output-length argument, inflate the frame (already bounded on the wire by ``maxFramePayloadSize``) and then reject — a weaker but still clean per-frame guarantee. The WebSocket receive path passes the remaining ``maxMessagePayloadSize`` budget so a compressed frame no longer expands unbounded into memory before the size check; the previous post-inflation check
* Make the asyncio RawSocket receive size limit configurable, at parity with the Twisted backend. The asyncio ``WampRawSocketFactory`` now exposes ``setProtocolOptions(maxMessagePayloadSize=...)`` / ``resetProtocolOptions()`` (bounds ``[512, 2**24]``, default 16 MB), and the configured value drives both the advertised handshake length exponent and the enforced receive cap (rounded up to the next power of two), matching the Twisted factory. Previously the asyncio receive limit was hardwired to 16 MB (a dead ``max_size=None`` branch), so an asyncio WAMP peer could not tighten its RawSocket receive limit for DoS hardening and Crossbar's RawSocket ``max_message_size`` had no effect on the asyncio path
**FlatBuffers**
* Fix ``check_zlmdb_flatbuffers_version_in_sync()`` comparing the build-time ``version()`` (which is ``(0, 0, 0, None, None)`` on installed wheels, where the vendored FlatBuffers ``__git_version__`` is unstamped) — it now compares the reliably-stamped ``__version__`` and returns a version string. Added regression tests
* Make ``autobahn.flatbuffers.version()`` reliable on installed wheels: when the build-time ``__git_version__`` is a bare commit hash or ``"unknown"`` (shallow clone / submodule absent from the sdist), ``version()`` now falls back to parsing the static vendored ``__version__`` and returns ``(major, minor, patch, None, None)`` instead of ``(0, 0, 0, None, None)``; rich ``git describe`` detail is still returned on genuine dev/git builds. Also hardened ``hatch_build.py`` so it never stamps a non-parseable ``__git_version__``. Return shape is unchanged (5-tuple); no API break
**Build & CI/CD**
[5 lines not shown]
py-twine: updated to 7.0.0
twine 7.0.0 (2026-07-27)
Bugfixes
- Specify UTF-8 encoding when reading ``.pypirc`` files.
- Add missing subdependencies to ``--version`` output.
- The dependency on ``rich`` has been bumped to avoid a hang in some environments.
- Indices that respond with non-standard HTTP codes are now handled more gracefully.
Deprecations and Removals
- Fix uploading packages with metadata version 2.5. The fix no longer allows metadata version 2.0, which was never officially standardised.
py-anyio: updated to 4.15.0
4.15.0
- Added support for the newer keyword-only arguments on ``anyio.Path`` methods to match
the standard library ``pathlib.Path``:
* ``follow_symlinks`` on ``exists()`` (Python 3.12+)
* ``follow_symlinks`` on ``is_dir()`` (Python 3.13+)
* ``follow_symlinks`` on ``is_file()`` (Python 3.13+)
* ``follow_symlinks`` on ``owner()`` (Python 3.13+)
* ``follow_symlinks`` on ``group()`` (Python 3.13+)
* ``newline`` on ``read_text()`` (Python 3.13+)
- Added ``amap``, ``gather``, and ``as_completed`` utility functions to simplify common
patterns
- Added ``--anyio-mode`` command-line option as an alternative to the ``anyio_mode``
ini setting, and fix the pytest plugin's auto mode detection to recognize the mode
when set via either mechanism(e.g: ``pytest_asyncio``).
[73 lines not shown]
py-joblib: updated to 1.6.0
1.6.0
Fix caching of functions whose source cannot be retrieved, such as functions defined in a notebook cell. Their identity fell back to str(hash(func.__code__)), which is salted by PYTHONHASHSEED and so differed between processes. A worker reading the func_code.py written by another one concluded that the function had changed and wiped the whole cache directory for it, discarding results computed by its peers. func_code.py is also no longer rewritten in place, so a reader can no longer catch it half-written and draw the same conclusion.
Drop python 3.9 support. The oldest supported Python version is now Python 3.10.
Fix eval_expr (used to evaluate the pre_dispatch argument of Parallel) to raise a ValueError as documented instead of leaking a ZeroDivisionError for expressions that divide or take a modulo by zero.
MemorizedResult now forwards mmap_mode to its store backend, so a cached array reconstructed from a location is memory-mapped as requested instead of being loaded fully into memory.
Unvendor cloudpickle to more quickly benefit from maintenance releases of cloudpickle
Fix Memory.cache for functions with a keyword-only argument that has a default declared before a keyword-only argument without a default.
Fix behavior of filter_args on some precise cases.
Fix a concurrency error that could happen with unordered generator.
Fix: dump() now accepts any input os.PathLike object to be consistent with load.
The documentation now uses pydata sphinx theme. Furthermore, optional dependencies test and docs have been added to pyproject.toml.
Vendor loky 3.6.0
py-vdirsyncer: updated to 0.21.0
0.21.0
- Implement retrying for ``google`` storage type when a rate limit is reached.
- ``tenacity`` is now a required dependency.
- Drop support for Python 3.8.
- Retry transient network errors for nullipotent requests.
- Add support for Python 3.14.
py-setuptools_scm: updated to 10.2.3
10.2.3 (2026-09-03)
Miscellaneous
- Do not run the xmlsec download regression test on Python 3.8, where no lxml wheel exists and `--no-build-isolation` leaves pip without a build toolchain for the lxml sdist.
py-vcs-versioning: updated to 2.3.4
2.3.4 (2026-09-03)
Fixed
- Ensure the vcs-versioning testsuite passes without setuptools-scm installed; the egg-info vs PKG-INFO discovery priority test moved to the setuptools-scm testsuite, which owns the egg-info entry point it needs.
2.3.3 (2026-09-03)
Fixed
- The `semver-pep440` and `semver-pep440-release-branch` version schemes now keep the PEP 440 epoch of the tag they are derived from, instead of emitting a version that sorts below it.
py-cachelib: updated to 0.17.0
0.17.0
- Timeout now also accepts a ``datetime.timedelta`` in addition to int. :pr:`510`
- Float timeouts are deprecated and now rounded up to whole seconds, so
backends with integer-second APIs (e.g. memcached) no longer fail with
a confusing ``TypeError``. Passing a float will raise a ``TypeError``
in a future release; timeouts of any other unsupported type raise
``TypeError`` immediately. :pr:`510`
- Add ``memcache_client_lib`` parameter to ``MemcachedCache`` to select which
memcache client library to use (``pylibmc``, ``google``, ``memcache``, or
``libmc``). When not set, the library is auto-detected as before. :pr:`511`
jj: updated to 0.45.1
0.45.1 - 2026-09-03
This release fixes an error that prevented the new jj-core crate from being
published.
Fixed bugs
* Building without `Cargo.lock` (e.g. `cargo install jj-cli`) works again
after all versions of the `bisync` crate, a transitive dependency of gix,
were yanked.
* Signatures on commits in SHA-256 Git repositories are now stored under the
`gpgsig-sha256` header, as Git does, so Git recognizes them as signed and
jj can read them back.
openvpn: updated to 2.7.7
Overview of changes in 2.7.7
Security fixes
- reliability layer: Avoid unbounded reliable TLS timeout (CVE-2026-84732)
- reliability layer: Ignore acks for packets that cannot be outstanding
(CVE-2026-84732)
- Windows: fix ``CreateProcess()`` command line quoting for characters that
are special to ``cmd.exe`` and where a combination of validation script
plus rogue CA could lead to misbehavior (CVE-2026-84256)
- Windows: fix ``tapctl`` to always call ``netsh.exe`` with full path
(as we do elsewhere) (CVE-2026-84226)
- Windows: don't use NULL DACL with system objects, namely the
[77 lines not shown]
powerdns-recursor: Update to 5.4.6
Released: 3rd of September 2026
Improvements
Skip unexpected tags when deserializing protobuf messages
References: #17869, pull request 17967
Store scope zero replies in packetcache and modify on retrieval.
References: #17897, pull request 17968, pull request 17983
Update our Rust deps.
References: #17696, pull request 17969
Make getOpenFileDescriptors fast under Linux.
M
M
References: #17973, pull request 17996
openjdk8: Restore SunOS support.
Add a big XXX comment to patch-common_autoconf_generated-configure.sh
explaining why generation for it is currently broken.
dnscontrol: Update to 5.0.3
Changelog
Provider-specific changes:
c1ebdb1: BIND: BUGFIX: SOA not incrementing on the existing zone (fixes #4840) (#4842) (@TomOnTime)
90984bb: BUNNY_DNS: Fix TXT record creation (#4839) (@TomOnTime)
c798fcb: LINODE: Add support for TTLs of 30s and 120s (#4835) (@dairiki)
f96fde4: LINODE: BUGFIX: too picky about hyphens in names of SRV records (#4828) (@TomOnTime)
Dependencies:
b6ce13f: CHORE: Update dependencies (#4843) (@TomOnTime)
Other changes and improvements:
34db875: BUG: SPF flattening removes redirect= modifiers that an "all" mechanism ignores (#4634) (@shuvamk)
0d6fe4b: CHORE: Upgrade to glob v1 (#4841) (@TomOnTime)
162a39b: Potential fix for code scanning alert no. 50: Cache Poisoning via execution of untrusted code (#4837) (@TomOnTime)
5196387: Release v5.0.3 (#4844) (@TomOnTime)