Files
langchain/libs/text-splitters/extended_testing_deps.txt
dependabot[bot] dec42f6bea chore(deps): update lxml requirement from <7.0,>=6.1.2 to >=6.1.3,<7.0 in /libs/text-splitters (#40569)
Updates the requirements on [lxml](https://github.com/lxml/lxml) to
permit the latest version.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/lxml/lxml/blob/master/CHANGES.txt">lxml's
changelog</a>.</em></p>
<blockquote>
<h1>6.1.3 (2026-09-02)</h1>
<h2>Bugs fixed</h2>
<ul>
<li>LP#2165901: External parameter entity parsing was allowed by default
(with <code>resolve_entities=&quot;internal&quot;</code>).
Issue found by Tomer Fichman.</li>
</ul>
<h1>6.1.2 (2026-08-18)</h1>
<ul>
<li>
<p>GH#526: Some build files were missing in the sdist.
Patch by Nicola Soranzo.</p>
</li>
<li>
<p>Some minor corrections for error handling cases.</p>
</li>
</ul>
<h2>Other changes</h2>
<ul>
<li>Built with Cython 3.2.9.</li>
</ul>
<h1>6.1.1 (2026-05-18)</h1>
<h2>Bugs fixed</h2>
<ul>
<li>
<p>The known link attributes in <code>lxml.html.defs.link_attrs</code>
were missing <code>xlink:href</code>,
which can be used for URL bypass attacks in embedded SVG/MathML/etc.
content.
<a
href="https://github.com/fedora-python/lxml_html_clean/security/advisories/GHSA-4jhm-jv67-739f">https://github.com/fedora-python/lxml_html_clean/security/advisories/GHSA-4jhm-jv67-739f</a></p>
</li>
<li>
<p>The Linux wheels use a patched libxslt 1.1.43, fixing CVE-2025-7424
and CVE-2025-11731.</p>
</li>
<li>
<p>The Windows wheels use libxslt 1.1.45, fixing CVE-2025-7424 and
CVE-2025-11731.</p>
</li>
</ul>
<h1>6.1.0 (2026-04-17)</h1>
<p>This release fixes a possible external entity injection (XXE)
vulnerability in
<code>iterparse()</code> and the <code>ETCompatXMLParser</code>.</p>
<h2>Features added</h2>
<ul>
<li>GH#486: The HTML ARIA accessibility attributes were added to the set
of safe attributes</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/lxml/lxml/commit/3c1a4c7f2d5a3c19efe01adfd3c33ac3c8fe52c1"><code>3c1a4c7</code></a>
Prepare release of 6.1.3.</li>
<li><a
href="https://github.com/lxml/lxml/commit/c1191fc55b8d574544203d07e7a02ba3378ced8d"><code>c1191fc</code></a>
Update changelog.</li>
<li><a
href="https://github.com/lxml/lxml/commit/03ec3123b9683e7f02ce659f34322667683d3eef"><code>03ec312</code></a>
Disable parameter entity parsing when internal-only entity parsing is
requested.</li>
<li><a
href="https://github.com/lxml/lxml/commit/11d03e922e0a7845131df3ab2fb5e894c0ced0ab"><code>11d03e9</code></a>
Build: Prevent duplicate Py3.8 wheel builds.</li>
<li><a
href="https://github.com/lxml/lxml/commit/9efc586ed3555be22548a3188f7f435826834961"><code>9efc586</code></a>
Build: Exclude musllinux-ARM from Py3.8 wheel building to prevent slow
emulat...</li>
<li><a
href="https://github.com/lxml/lxml/commit/9716fb1e1a80db4ba5e36bf99947dfccd8730471"><code>9716fb1</code></a>
Build: Include older PyPy versions.</li>
<li><a
href="https://github.com/lxml/lxml/commit/0f3327d3c8fc1ba01c90a866770ad8c4889e537f"><code>0f3327d</code></a>
Build: Exclude Win-Aarch64 from wheel build.</li>
<li><a
href="https://github.com/lxml/lxml/commit/6967c960976541979570099de9866af398fb292f"><code>6967c96</code></a>
Build: Make all built wheels downloadable even if they don't pass the
release...</li>
<li><a
href="https://github.com/lxml/lxml/commit/061218d210747a1181dea76fb6b6d0eebe946b2d"><code>061218d</code></a>
Build: Exclude Py3.15 i686 wheels from validation (because they are
intention...</li>
<li><a
href="https://github.com/lxml/lxml/commit/ce9fe0dd26bd5b64fe03b6bcdf68a997ee5a2596"><code>ce9fe0d</code></a>
Build: Fix Py3.8 windows build.</li>
<li>See full diff in <a
href="https://github.com/lxml/lxml/compare/lxml-6.1.2...lxml-6.1.3">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-17 14:10:10 -07:00

3 lines
43 B
Plaintext

lxml>=6.1.3,<7.0
beautifulsoup4>=4.12.3,<5