Skip to content

chore(deps): update dependency lxml to <=5.4.0 - autoclosed#369

Closed
renovate[bot] wants to merge 1 commit intomainfrom
renovate/lxml-5.x
Closed

chore(deps): update dependency lxml to <=5.4.0 - autoclosed#369
renovate[bot] wants to merge 1 commit intomainfrom
renovate/lxml-5.x

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Dec 6, 2025

This PR contains the following updates:

Package Change Age Confidence
lxml (source, changelog) <=5.3.2<=5.4.0 age confidence

Release Notes

lxml/lxml (lxml)

v5.4.0

Compare Source

==================

Bugs fixed

  • LP#2107279: Binary wheels use libxml2 2.13.8 and libxslt 1.1.43 to resolve several CVEs.
    (Binary wheels for Windows continue to use a patched libxml2 2.11.9 and libxslt 1.1.39.)
    Issue found by Anatoly Katyushin.

v5.3.2

Compare Source

==================

This release resolves CVE-2025-24928 as described in
https://gitlab.gnome.org/GNOME/libxml2/-/issues/847

Bugs fixed

  • Binary wheels use libxml2 2.12.10 and libxslt 1.1.42.

  • Binary wheels for Windows use a patched libxml2 2.11.9 and libxslt 1.1.39.


Configuration

📅 Schedule: (in timezone US/Eastern)

  • Branch creation
    • "every weekend"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot force-pushed the renovate/lxml-5.x branch 2 times, most recently from 120e3ad to bdc328f Compare December 6, 2025 18:51
@renovate renovate Bot force-pushed the renovate/lxml-5.x branch 5 times, most recently from 42e586d to 0a769b9 Compare December 18, 2025 13:24
@renovate renovate Bot force-pushed the renovate/lxml-5.x branch 5 times, most recently from 182e613 to d6fd400 Compare December 27, 2025 10:34
@renovate renovate Bot force-pushed the renovate/lxml-5.x branch 4 times, most recently from c55c447 to 8d633c6 Compare January 3, 2026 14:32
@renovate renovate Bot force-pushed the renovate/lxml-5.x branch 3 times, most recently from daff86d to 29b4a19 Compare January 14, 2026 16:19
@renovate renovate Bot force-pushed the renovate/lxml-5.x branch 6 times, most recently from 40ce12d to 7001dd0 Compare January 18, 2026 10:51
@renovate renovate Bot force-pushed the renovate/lxml-5.x branch 4 times, most recently from 96b499f to bcc870e Compare January 30, 2026 03:26
@renovate renovate Bot closed this Mar 4, 2026
@renovate renovate Bot changed the title chore(deps): update dependency lxml to <=5.4.0 - autoclosed chore(deps): update dependency lxml to <=5.4.0 Mar 7, 2026
@renovate renovate Bot reopened this Mar 7, 2026
@renovate renovate Bot force-pushed the renovate/lxml-5.x branch 7 times, most recently from 4d74718 to c239e86 Compare March 11, 2026 20:08
@renovate renovate Bot changed the title chore(deps): update dependency lxml to <=5.4.0 chore(deps): update dependency lxml to <=5.4.0 - autoclosed Mar 18, 2026
@renovate renovate Bot closed this Mar 18, 2026
@renovate renovate Bot changed the title chore(deps): update dependency lxml to <=5.4.0 - autoclosed chore(deps): update dependency lxml to <=5.4.0 Mar 21, 2026
@renovate renovate Bot reopened this Mar 21, 2026
@renovate renovate Bot force-pushed the renovate/lxml-5.x branch 5 times, most recently from d7a3453 to 060890b Compare March 27, 2026 21:13
@renovate renovate Bot force-pushed the renovate/lxml-5.x branch 6 times, most recently from 0c5e437 to 5286d3e Compare April 2, 2026 21:03
@renovate renovate Bot changed the title chore(deps): update dependency lxml to <=5.4.0 chore(deps): update dependency lxml to <=5.4.0 - autoclosed Apr 6, 2026
@renovate renovate Bot closed this Apr 6, 2026
@renovate renovate Bot changed the title chore(deps): update dependency lxml to <=5.4.0 - autoclosed chore(deps): update dependency lxml to <=5.4.0 Apr 11, 2026
@renovate renovate Bot reopened this Apr 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants