Skip to content

build(deps): bump the python-deps group with 4 updates - #1346

Merged
gab-arrobo merged 1 commit into
mainfrom
dependabot/pip/python-deps-8370aa267f
Oct 9, 2026
Merged

gab-arrobo merged 1 commit into
mainfrom
dependabot/pip/python-deps-8370aa267f

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor

Bumps the python-deps group with 4 updates: markupsafe, scapy, fonttools and getmac.

Updates markupsafe from 3.0.3 to 3.0.4

Release notes

Sourced from markupsafe's releases.

3.0.4

This is the MarkupSafe 3.0.4 fix release, which fixes bugs but does not otherwise change behavior and should not result in breaking changes compared to the latest feature release.

PyPI: https://pypi.org/project/MarkupSafe/3.0.4/ Changes: https://markupsafe.palletsprojects.com/page/changes/#version-3-0-4 Milestone: https://github.com/pallets/markupsafe/milestone/17?closed=1

  • Build Python 3.15, armv7l, ppc64le, Android, and iOS wheels.
  • Improve performance of striptags. #521
Changelog

Sourced from markupsafe's changelog.

Version 3.0.4

Released 2026-10-02

  • Build Python 3.15, armv7l, ppc64le, Android, and iOS wheels.
  • Improve performance of striptags. :issue:521
Commits

Updates scapy from 2.7.0 to 2.8.0

Release notes

Sourced from scapy's releases.

v2.8.0

Hi everyone. This release is a bit different, as it is heavily focused on security fixes as we are clearing our backlog of AI-Assisted reports. We have also clarified the guidelines around AI, contributions and security reports. To contributors, feel free to reach out if you haven't heard back from us in a whilte !

Deprecation notice

  • This major version will be the last to support Python 3.7 and 3.8. While this was initially planned for 2.7.0, support was extended because of how used those versions still were. They have been EoL for more than 2 years, and we highly encourage remaining users to upgrade.

A note about contributing guidelines

We have clarified our CONTRIBUTING and SECURITY guidelines. This notably includes some new guidance related to the use of AI, and some instructions regarding the submission of security issues. We encourage contributors to take a moment to read the updated versions.

Security

Scapy has taken part in OpenAI + Trail of Bits collab's initiative called "Patch the Planet". As part of this initiative, we have received a free security coverage of our code overseen by KernelClint (Trail of Bits) and multiple OpenAI agents. This has led to the discovery of around 130+ bugs, among which were 54 issues that could be considered related to security, with various degrees of severity. You can find a partial list on https://github.com/secdev/scapy/security/advisories and here but please bear in mind that some reports have been written entirely by AI.

After analysis, we have marked 5 vulnerabilities with a "High" level of impact, which justify an immediate upgrade to 2.8.0, or backporting if packaged by downstream repositories:

The other issues have been triaged as "Moderate" or "Low" and don't justify immediate action from users or downstream package maintainers (those include crashes, issues in various protocol implementations, automatons and answering machines, mis-implementations of protocols like our TLS stack, etc. but nothing that leads to a potential compromission of the host machine).

We would like to thank again OpenAI and Trail of Bits (and in particular @​KernelClint) for this opportunity and the time spent on this project.

Changelog

  • Windows protocols:
    • Kerberos: IAKERB support, WinSSP, KDC pinning, S4U+FAST fix, NTLM MIC server-side check
    • SMB: various SMB2 fixes, new smbclient() features
    • DCE/RPC: fragmentation fixes, proper client auth denial, context commit fixes
    • NTLM/SPNEGO/WinSSP: late fallback mechanism, encryption support, doc fixes
    • [new] registry abstraction layer for [MS-RRP] RPC
    • [MS-NRTP] fix
  • Automotive related changes:
    • Added SAE J1939 support
    • Added standalone UDS/KWP/OBD/GMLAN packets
    • Improved CAN/ISO-TP soft-socket robustness
    • Added configurable busy-response retries in automotive scanners
  • Work has begun to clean up the remaining compatibility code that allowed the transition from Python 2.
  • Minor security fixes (the full list is available in the Security tab):
    • RADIUS: verify Message-Authenticator
    • fwdmachine: verify upstream TLS certs, correct TLS server context
    • tls/sslv2: stricter security handling
    • Several fuzzing-found crash fixes (HSRP, Bluetooth, Kerberos)
    • Bound/robustness fixes across pcap, pcapng, ISOTP, TCP reassembly, BGP, IPv6, HTTP, DNS, LDAP, modbus parsing
  • Bluetooth:
    • Many new vendor-specific command modules (Realtek, Barrot, Intel, Espressif, CSR, Zephyr)
    • Fixed link-layer byte order, normalized field naming

... (truncated)

Commits
  • e2e35c0 util: Handle corrupted gzip streams in pcap/pcapng readers (#5215)
  • 9ef9871 libpcap: fix timeval on multiple platforms leading to a crash (#5209)
  • ac0ab2e tls: ML-DSA certificates, x509 cleanup, add server certificate verification (...
  • 580c62e libpcap: pass positive BIOCIMMEDIATE to ioctl (#5213)
  • b0a6933 tests: Restore test for GHSA-c547 (#5212)
  • b9c6129 arch: minor cleanups to winpcapy and libpcap (#5211)
  • 90623e7 Revert "inet6: fix IndexError when dissecting IPv6 with truncated nh=43 paylo...
  • 7daa15d Improve performance of packet dissection and build (#5085)
  • 59f9a0e inet6: fix IndexError when dissecting IPv6 with truncated nh=43 payload (#5207)
  • 23b8047 Update CONTRIBUTING.md with AI documentation policy
  • Additional commits viewable in compare view

Updates fonttools from 4.66.0 to 4.66.1

Release notes

Sourced from fonttools's releases.

4.66.1

  • [designspaceLib] When splitting a DesignSpace v5 document with makeNames=True (as varLib.build_many does), family and style names set explicitly on an instance now take precedence over the ones computed from the STAT labels, in all languages, and a PostScript name is no longer made up from the labels for an instance that has its own style name (#3131, #4206, #4208).
  • [cmap] Decompiling a format 4 subtable whose idRangeOffset points outside glyphIndexArray now raises TTLibError. A negative index used to silently map the code point to the wrong glyph, and one past the end raised a bare AssertionError (#4209).
  • [cmap] Fix compiling a format 2 subtable when the lowest glyph ID in a lead-byte row is 32768 or higher, which failed with struct.error (#4210).
Changelog

Sourced from fonttools's changelog.

4.66.1 (released 2026-09-29)

  • [designspaceLib] When splitting a DesignSpace v5 document with makeNames=True (as varLib.build_many does), family and style names set explicitly on an instance now take precedence over the ones computed from the STAT labels, in all languages, and a PostScript name is no longer made up from the labels for an instance that has its own style name (#3131, #4206, #4208).
  • [cmap] Decompiling a format 4 subtable whose idRangeOffset points outside glyphIndexArray now raises TTLibError. A negative index used to silently map the code point to the wrong glyph, and one past the end raised a bare AssertionError (#4209).
  • [cmap] Fix compiling a format 2 subtable when the lowest glyph ID in a lead-byte row is 32768 or higher, which failed with struct.error (#4210).
Commits
  • 9e95795 Release 4.66.1
  • 8fc91fb Update NEWS.rst [skip ci]
  • 82dc507 Merge pull request #4209 from insaf021/cmap4-idrangeoffset-bounds
  • a83553e trim comments
  • 85049d3 Merge pull request #4208 from fonttools/fix-split-stat-names-override
  • 1ad111d Merge pull request #4210 from youdie006/cmap-format2-high-gids
  • c9e9d68 [cmap] fix format 2 compile for glyph IDs above 32767
  • 85625c5 raise TTLibError for out-of-range glyphIndexArray offset in cmap format 4
  • 879173e [designspaceLib] Let explicit instance names win over STAT labels when splitting
  • 718b61b Bump version: 4.66.0 → 4.66.1.dev0
  • See full diff in compare view

Updates getmac from 0.9.5 to 0.9.6

Release notes

Sourced from getmac's releases.

0.9.6

Changed

  • Made library py.typed

Thanks @​chemelli74 for the contribution!

Changelog

Sourced from getmac's changelog.

0.9.6 (10/03/2026)

Changed

  • Made library py.typed
Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the python-deps group with 4 updates: [markupsafe](https://github.com/pallets/markupsafe), [scapy](https://github.com/secdev/scapy), [fonttools](https://github.com/fonttools/fonttools) and [getmac](https://github.com/GhostofGoes/getmac).


Updates `markupsafe` from 3.0.3 to 3.0.4
- [Release notes](https://github.com/pallets/markupsafe/releases)
- [Changelog](https://github.com/pallets/markupsafe/blob/main/CHANGES.rst)
- [Commits](pallets/markupsafe@3.0.3...3.0.4)

Updates `scapy` from 2.7.0 to 2.8.0
- [Release notes](https://github.com/secdev/scapy/releases)
- [Commits](secdev/scapy@v2.7.0...v2.8.0)

Updates `fonttools` from 4.66.0 to 4.66.1
- [Release notes](https://github.com/fonttools/fonttools/releases)
- [Changelog](https://github.com/fonttools/fonttools/blob/main/NEWS.rst)
- [Commits](fonttools/fonttools@4.66.0...4.66.1)

Updates `getmac` from 0.9.5 to 0.9.6
- [Release notes](https://github.com/GhostofGoes/getmac/releases)
- [Changelog](https://github.com/GhostofGoes/getmac/blob/main/CHANGELOG.md)
- [Commits](GhostofGoes/getmac@0.9.5...0.9.6)

---
updated-dependencies:
- dependency-name: markupsafe
  dependency-version: 3.0.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-deps
- dependency-name: scapy
  dependency-version: 2.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-deps
- dependency-name: fonttools
  dependency-version: 4.66.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-deps
- dependency-name: getmac
  dependency-version: 0.9.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Oct 9, 2026
@dependabot
dependabot Bot requested a review from a team October 9, 2026 04:05
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Oct 9, 2026
@gab-arrobo
gab-arrobo merged commit 0a55d79 into main Oct 9, 2026
19 checks passed
@gab-arrobo
gab-arrobo deleted the dependabot/pip/python-deps-8370aa267f branch October 9, 2026 06:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant