sem: update to 0.21.1.
### Fixed
- **Building a graph over Svelte components no longer crashes
(SIGSEGV) on Linux/glibc.** `sem graph`/`context`/`orient` over
`.svelte` files deterministically exited 139 from an invalid free
in the `tree-sitter-htmlx-svelte` 0.1.8 grammar's scanner, hit
during parallel graph construction (macOS's allocator tolerated
the bad free, so it only showed on Linux). Bumped the grammar to
0.1.16, which carries the scanner fixes; the existing version
constraint already permitted it, so this is a lock-only dependency
update. Added a parallel-Svelte-graph regression test. Thanks @XF-FW
for the exhaustive isolation and the verified fix (#471).
rspamd: update to 4.1.5.
4.1.5: 14 Aug 2026
** Incompatible changes **
* [Rework] gpt: Return only a boolean from the condition callback (request content generation moved into gpt_check)
* [Conf] Ship explicit allow_file_and_shm_inputs = true defaults for the normal, controller and proxy workers (the default becomes false in the next major release)
** Features **
* [Feature] fuzzy: Share sender facts (SPF, DKIM, DMARC, PTR state, recipient bucket, TLS) with storages over encrypted rules
* [Feature] mime: Decode PDF simple font text via the font's /Encoding (Annex D base encodings and /Differences overrides)
* [Feature] mime: Parse PDF /ToUnicode CMaps and decode composite (Type0) fonts
* [Feature] elastic: Structured fuzzy match results and message size in the schema
** Bug fixes **
* [CritFix] protocol: Gate File/Path/Shm message sources behind allow_file_and_shm_inputs (any TCP client could have arbitrary files parsed)
* [Fix] controller: Rate limit authentication failures per source (max_auth_failures)
* [Fix] fuzzy: Per-key forbidden_ids replaces the default set instead of adding to it
* [Fix] fuzzy: Apply the per-key ACL to delayed v1 replies
[22 lines not shown]
py-webencodings: update to 0.6.1.
0.6.1
Packaging
Update links on PyPI.
0.6.0
Dependencies
Support Python 3.10, 3.11, 3.12, 3.13, 3.14.
Drop support of Python 2.6, 2.7, 3.3, 3.4, 3.5, 3.6, 3.7, 3.8 and 3.9.
Packaging
Include license file in packages.
[10 lines not shown]
py-platformdirs: update to 4.11.3.
📄 docs: publish llms.txt from the docs build by @gaborbernat in #522
fix: don't crash when an XDG dirs variable holds only separators by @darrenhuai in #523
py-pdf: update to 6.16.1.
6.16.1
Security (SEC)
Limit iterations for outline retrieval and XForm text extraction (#3966) by @stefan6419846
6.16.0
Security (SEC)
Detect cycles in TreeObject.insert_child (#3964) by @stefan6419846
New Features (ENH)
AppearanceStream: Allow arbitrary rotations and apply rotations for annotation appearance streams (#3917) by @PJBrs
AppearanceStream: Consider more encodings for Type1 core fonts (#3905) by @PJBrs
[24 lines not shown]
py-orjson: update to 3.12.0.
## 3.12.0 - 2026-08-14
### Changed
- Serialization implementation substantially rewritten.
- Publish PyPI wheels for Python 3.15. For Python 3.15 and later,
`manylinux_2_39` (2024) is targeted instead of `manylinux_2_17` (2012).
- No longer publish PyPI wheels for ppc64le and s390x.
py-httpx2: update to 2.10.0.
Added
Add support for running on WebAssembly / Emscripten via Pyodide by @hoodmane in #1119
Add max_event_size to cap SSE event buffering by @Kludex in #1071
Add RFC 9110 status code constants by @mbeijen in #1069
Add support for Python 3.15 by @hugovk in #1090
Changed
Improve SSE chunk buffering performance by @Kludex in #1117
Skip cookie extraction without Set-Cookie by @Kludex in #1107
Return str | None instead of Any from Headers.get by @ItsDrike in #1121
Fixed
Enforce WebSocket max message size across fragments by @Kludex in #1085
Ignore unsolicited and duplicate Pong frames by @Kludex in #1122
py-httpcore2: update to 2.10.0.
Added
Add support for Python 3.15 by @hugovk in #1090
Changed
Avoid quadratic copying when sending large HTTP/2 request bodies by @Kludex in #1127
Fixed
Propagate the original exception instead of raising KeyError when an HTTP/2 stream fails by @yhay81 in #1093
Start TLS for the wss scheme in SOCKS5 proxy connections by @Kludex in #1104
py-filelock: update to 3.32.3.
🧪 test(strict): deflake close-fault injections on graalpy by @gaborbernat in #697
📄 docs: publish llms.txt from the docs build by @gaborbernat in #700
🐛 fix(fork): survive audit events during interpreter shutdown by @gaborbernat in #703
py-charset-normalizer: update to 3.5.1.
## [3.5.1](https://github.com/Ousret/charset_normalizer/compare/3.5.0...3.5.1) (2026-08-15)
### Changed
- Raised upper bound of setuptools to v84 (#794)
- Cache performance access optimization for our CharInfo struct (prebuilt only).
### Fixed
- No longer decoding large content when the noise detector output give a high entropy.
Only impacted large content input >1M bytes.
## [3.5.0](https://github.com/Ousret/charset_normalizer/compare/3.4.9...3.5.0) (2026-08-12)
### Added
- Explicit support for Python 3.15
### Fixed
- Comparing a CharsetMatch to a non-alias encoding strings (#773)
[19 lines not shown]
moor: update to 2.17.0.
v2.17.0: Report loading progress to your terminal Latest
With this release, moor reports to the terminal when it's busy loading,
using the OSC 9;4 progress protocol supported by terminals such as
iTerm2.
Also in this release:
Fixed a data loss bug where two moor instances sharing a search
history file could silently overwrite each other's committed
searches
Pressing 'n'/'N' with no active search now resumes the most recently
used search history entry instead of doing nothing. Thanks @knirch
for #455!
Fixed the status bar missing its separator between the filename and
the percentage while the reader was still paused during initial
loading
[40 lines not shown]
libpsl: update to 0.23.3.
14.08.2026 Release V0.23.3
* meson: make copyright_prog work for cross builds
10.08.2026 Release V0.23.2
* meson: Use compatible C code instead of 'date'
* configure.ac: Fix typo that broke SOURCE_DATE_EPOCH for COPYRIGHT_YEAR