chore(deps): update dependency charset-normalizer to v3.5.1 - #261
Conversation
There was a problem hiding this comment.
LGTM — routine dependency bump.
Extended reasoning...
Overview
This PR only touches two autogenerated lock files (requirements.txt, requirements-dev.txt), bumping the transitive dependency charset-normalizer from 3.4.9 to 3.5.0 (used via requests). No application source code is changed.
Security risks
None identified. The changelog for 3.5.0 lists bug fixes (empty payload crash, BOM/SIG detection, iso2022 misdetection) and an internal build-engine swap (mypyc to Cython) with no API changes affecting pyUSPTO's usage of requests.
Level of scrutiny
Minimal scrutiny is appropriate: this is a Renovate-generated, mechanical lock file update to a transitive dependency with no direct API usage in this codebase.
Other factors
No outstanding review comments in the PR timeline, and this is the first review pass. The change is self-contained and low risk.
2dc5e00 to
799667c
Compare
There was a problem hiding this comment.
LGTM — routine transitive dependency bump (charset-normalizer 3.4.9 → 3.5.1) via Renovate.
Extended reasoning...
Overview
This PR only touches requirements.txt and requirements-dev.txt, bumping the pinned version of charset-normalizer (a transitive dependency of requests) from 3.4.9 to 3.5.1. No application code, configuration, or CI files are changed.
Security risks
None identified. charset-normalizer is a well-known, widely-used encoding-detection library. The changelog for 3.5.0/3.5.1 lists only bug fixes (multi-byte/BOM detection edge cases), a build-system change (mypyc → Cython), and a raised setuptools upper bound — nothing security-relevant, and no new capabilities or API surface are introduced.
Level of scrutiny
Minimal scrutiny is appropriate here. This is a mechanical, autogenerated pip-compile lockfile update for a transitive dependency, not a direct dependency of the project's own logic. The diff is a two-line version bump duplicated across both requirement files, consistent with the existing pip-compile format.
Other factors
No prior review activity on this PR. The bug hunting system found no issues, and there's nothing in the changelog suggesting a breaking change to encoding detection behavior that would affect pyUSPTO's use of requests.
This PR contains the following updates:
==3.4.9→==3.5.1Release Notes
jawah/charset_normalizer (charset-normalizer)
v3.5.1Compare Source
Changed
Fixed
Only impacted large content input >1M bytes.
v3.5.0Compare Source
Added
Fixed
Changed
pure Python fallback. The previous engine (mypyc) started to hit rough limit around
the optimization of our noise/coherence detector while Cython allows us to
steer the engine toward the right generated optimized sources.
This change SHOULD not impact bundler (e.g. Pyinstaller) as the module are
immediately discoverable (i.e. not hidden import like mypyc did).
Moreover, a long wished distribution is the abi3 wheels, this will allow us
to no longer rush each year when a new Python interpreter is released.
We still distribute the interpreter specific wheels for faster performance.
Misc
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.