Skip to content

chore(deps): update dependency charset-normalizer to v3.5.1 - #261

Merged
dpieski merged 1 commit into
mainfrom
renovate/charset-normalizer-3.x
Aug 21, 2026
Merged

dpieski merged 1 commit into
mainfrom
renovate/charset-normalizer-3.x

Conversation

@renovate

@renovate renovate Bot commented Aug 12, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
charset-normalizer (changelog) ==3.4.9 → ==3.5.1 age adoption passing confidence

Release Notes

jawah/charset_normalizer (charset-normalizer)

v3.5.1

Compare Source

Changed
  • Raised upper bound of setuptools to v84 (#​794)
  • Cache performance access optimization for our CharInfo struct (prebuilt only).
Fixed
  • No longer decoding large content when the noise detector output give a high entropy.
    Only impacted large content input >1M bytes.

v3.5.0

Compare Source

Added
  • Explicit support for Python 3.15
Fixed
  • Comparing a CharsetMatch to a non-alias encoding strings (#​773)
  • Return 0.0 CharsetMatch.multi_byte_usage for empty payloads instead of crashing (#​774)
  • A file with both a charset declaration and BOM/SIG did not verify first the BOM/SIG charset.
  • iso2022* cases misdetected due to a flaw in our multibyte chunking logic.
Changed
  • Replaced the optional mypyc build with Cython extensions while retaining the
    pure Python fallback. The previous engine (mypyc) started to hit rough limit around
    the optimization of our noise/coherence detector while Cython allows us to
    steer the engine toward the right generated optimized sources.
    This change SHOULD not impact bundler (e.g. Pyinstaller) as the module are
    immediately discoverable (i.e. not hidden import like mypyc did).
    Moreover, a long wished distribution is the abi3 wheels, this will allow us
    to no longer rush each year when a new Python interpreter is released.
    We still distribute the interpreter specific wheels for faster performance.
  • Applied micro-optimization on several utils.
  • CharsetMatches no longer sort on each match insertion.
Misc
  • Removed an old performance optimization attempt in apy.py (success_fast_tracked+payload_result_cache).

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — routine dependency bump.

Extended reasoning...

Overview

This PR only touches two autogenerated lock files (requirements.txt, requirements-dev.txt), bumping the transitive dependency charset-normalizer from 3.4.9 to 3.5.0 (used via requests). No application source code is changed.

Security risks

None identified. The changelog for 3.5.0 lists bug fixes (empty payload crash, BOM/SIG detection, iso2022 misdetection) and an internal build-engine swap (mypyc to Cython) with no API changes affecting pyUSPTO's usage of requests.

Level of scrutiny

Minimal scrutiny is appropriate: this is a Renovate-generated, mechanical lock file update to a transitive dependency with no direct API usage in this codebase.

Other factors

No outstanding review comments in the PR timeline, and this is the first review pass. The change is self-contained and low risk.

@renovate renovate Bot changed the title chore(deps): update dependency charset-normalizer to v3.5.0 chore(deps): update dependency charset-normalizer to v3.5.1 Aug 15, 2026
@renovate
renovate Bot force-pushed the renovate/charset-normalizer-3.x branch from 2dc5e00 to 799667c Compare August 15, 2026 09:02

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — routine transitive dependency bump (charset-normalizer 3.4.9 → 3.5.1) via Renovate.

Extended reasoning...

Overview

This PR only touches requirements.txt and requirements-dev.txt, bumping the pinned version of charset-normalizer (a transitive dependency of requests) from 3.4.9 to 3.5.1. No application code, configuration, or CI files are changed.

Security risks

None identified. charset-normalizer is a well-known, widely-used encoding-detection library. The changelog for 3.5.0/3.5.1 lists only bug fixes (multi-byte/BOM detection edge cases), a build-system change (mypyc → Cython), and a raised setuptools upper bound — nothing security-relevant, and no new capabilities or API surface are introduced.

Level of scrutiny

Minimal scrutiny is appropriate here. This is a mechanical, autogenerated pip-compile lockfile update for a transitive dependency, not a direct dependency of the project's own logic. The diff is a two-line version bump duplicated across both requirement files, consistent with the existing pip-compile format.

Other factors

No prior review activity on this PR. The bug hunting system found no issues, and there's nothing in the changelog suggesting a breaking change to encoding detection behavior that would affect pyUSPTO's use of requests.

@dpieski
dpieski merged commit 6170e2b into main Aug 21, 2026
11 checks passed
@renovate
renovate Bot deleted the renovate/charset-normalizer-3.x branch August 21, 2026 18:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant