Skip to content

Update patch-updates#199

Merged
renovate[bot] merged 1 commit intomainfrom
renovate/patch-updates
Feb 15, 2026
Merged

Update patch-updates#199
renovate[bot] merged 1 commit intomainfrom
renovate/patch-updates

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Feb 15, 2026

This PR contains the following updates:

Package Change Age Confidence
@changesets/read (source) 0.6.20.6.6 age confidence
@types/node (source) 20.19.1920.19.33 age confidence
imageio ==2.37.0==2.37.2 age confidence
joblib ==1.5.0==1.5.3 age confidence
matplotlib ==3.10.3==3.10.8 age confidence
nltk (source) ==3.9.1==3.9.2 age confidence
npm-check-updates 17.1.1417.1.18 age confidence
orjson (changelog) ==3.11.5==3.11.7 age confidence
pnpm (source) 9.15.59.15.9 age confidence
pnpm (source) 9.15.59.15.9 age confidence
requests (source, changelog) ==2.32.4==2.32.5 age confidence
spacy (source, changelog) ==3.8.2==3.8.11 age confidence
tornado (source) ==6.5.1==6.5.4 age confidence
xlrd ==2.0.1==2.0.2 age confidence

Release Notes

changesets/changesets (@​changesets/read)

v0.6.6

Compare Source

v0.6.5

Compare Source

Patch Changes

v0.6.4

Compare Source

Patch Changes

v0.6.3

Compare Source

Patch Changes
imageio/imageio (imageio)

v2.37.2

Compare Source

Bug
  • Gracefully handle reading of invalid EXIF orientation in Pillow plugin
    (#​1159,
    8b9d78d)

  • Prevent OverflowError for FPS in pyav plugin
    (#​1121,
    e03963c)

Maint
joblib/joblib (joblib)

v1.5.3

Compare Source

  • The Memory object won't overwrite an already existing .gitignore file in its
    cache directory anymore.
    #​1742

  • Harden the safety checks in eval_expr(pre_dispatch) to prevent excessive
    memory allocation and potential crashes by limiting the allowed length of the
    expression and the maximum numeric value of sub-expressions and not
    evaluating expressions with non-numeric literals.
    #​1744

  • Vendor cloudpickle 3.1.2 to fix a pickling problem with interactively
    defined abstract base classes and type annotations in Python 3.14+.

v1.5.2

Compare Source

  • Vendor loky3.5.6 fixing the resource tracker for python 3.13.7+
    #​1740

Memory:


- Ensure that temporary files managed by the ``Memory`` object do not collide
  when using the same cache directory when the cache directory is accessed
  concurrently from different nodes on a cluster with a shared filesystem.
  https://github.com/joblib/joblib/pull/1656

v1.5.1

Compare Source

  • Fix backend hints causing errors when no multiprocessing is present
    #​1721

  • Vendor loky3.5.5 fixing the resource_tracker clean up with earlier Python
    versions. #​1724

matplotlib/matplotlib (matplotlib)

v3.10.8: REL: v3.10.8

Compare Source

This is a bugfix release in the 3.10.x series.

The primary highlights of this release are:

  • Properly allow freethreaded mode in the MacOS backend
  • Better error handling for MacOS backend

v3.10.7: REL: v3.10.7

Compare Source

This is the latest bugfix release in the 3.10.x series.

The most important update in this release is that the minimum version
of pyparsing has been updated to version 3.0.

v3.10.6: REL: v3.10.6

Compare Source

This is a bugfix release in the 3.10.x series.

Highlights from this release include:

- Fix regression of hi-dpi support for Qt
- Fix race condition in TexManager.make_dvi & make_png
- Various documentation and other bugfixes

v3.10.5: REL: v3.10.5

Compare Source

This is the fourth bugfix release of the 3.10.x series.

Included in this release is distributed wheels for Python 3.14 (including freethreaded) and Windows ARM.

There are also several smaller bugfixes.

nltk/nltk (nltk)

v3.9.2

Compare Source

raineorshine/npm-check-updates (npm-check-updates)

v17.1.18

Compare Source

Breaking

The only breaking change in v18 is with the -g/--global flag.

npm-check-updates -g will now auto-detect your package manager based on the execution path. Previously, it defaulted to npm.

  • yarn dlx ncu -g --packageManager yarnyarn dlx ncu -g
  • pnpm dlx ncu --global --packageManager pnpmpnpm dlx ncu -g
  • bunx ncu -g--packageManager pnpmbunx ncu -g

If for some reason you were running ncu -g with an alternative package manager and relying on it checking the global npm packages, you will need to now explicitly specify npm:

  • ncu -gncu -g--packageManager npm

Thanks to @​LuisFerLCC for the improvement (#​1514).

raineorshine/npm-check-updates@v17.1.18...v18.0.0

v17.1.17

Compare Source

v17.1.16

Compare Source

v17.1.15

Compare Source

ijl/orjson (orjson)

v3.11.7

Compare Source

Changed
  • Use a faster library to serialize float. Users with byte-exact regression
    tests should note positive exponents are now written using a +, e.g.,
    1.2e+30 instead of 1.2e30. Both formats are spec-compliant.
  • ABI compatibility with CPython 3.15 alpha 5 free-threading.

v3.11.6

Compare Source

Changed
  • orjson now includes code licensed under the Mozilla Public License 2.0 (MPL-2.0).
  • Drop support for Python 3.9.
  • ABI compatibility with CPython 3.15 alpha 5.
  • Build now depends on Rust 1.89 or later instead of 1.85.
Fixed
  • Fix sporadic crash serializing deeply nested list of dict.
pnpm/pnpm (pnpm)

v9.15.9: pnpm 9.15.9

Compare Source

Patch Changes

  • Fix running pnpm CLI from pnpm CLI on Windows when the CLI is bundled to an executable #​8971.

Platinum Sponsors

Bit Bit Syntax

Gold Sponsors

Discord u|screen
JetBrains Nx
CodeRabbit Route4Me
Workleap Stackblitz

v9.15.8: pnpm 9.15.8

Compare Source

Patch Changes

  • pnpm self-update should always update the version in the packageManager field of package.json.
  • The pnpm CLI process should not stay hanging, when --silent reporting is used.
  • When --loglevel is set to error, don't show installation summary, execution time, and big tarball download progress.
  • Don't show info output when --loglevel=error is used.

Platinum Sponsors

Bit Bit Syntax

Gold Sponsors

Discord u|screen
JetBrains Nx
CodeRabbit Route4Me
Workleap Stackblitz

v9.15.7: pnpm 9.15.7

Compare Source

Patch Changes

  • pnpm self-update should not leave a directory with a broken pnpm installation if the installation fails.
  • Allow scope registry CLI option without --config. prefix such as --@​scope:registry=https://scope.example.com/npm #​9089.
  • pnpm self-update should not read the pnpm settings from the package.json file in the current working directory.
  • pnpm update -i should list only packages that have newer versions #​9206.
  • Fix a bug causing entries in the catalogs section of the pnpm-lock.yaml file to be removed when dedupe-peer-dependents=false on a filtered install. #​9112

Platinum Sponsors

Bit Bit Syntax

Gold Sponsors

Discord u|screen
JetBrains Nx
CodeRabbit Route4Me
Workleap Stackblitz

v9.15.6: pnpm 9.15.6

Compare Source

Patch Changes

  • Fix instruction for updating pnpm with corepack #​9101.
  • Print pnpm's version after the execution time at the end of the console output.
  • The pnpm version specified by packageManager cannot start with v.
  • Fix a bug causing catalog snapshots to be removed from the pnpm-lock.yaml file when using --fix-lockfile and --filter. #​8639
  • Fix a bug causing catalog protocol dependencies to not re-resolve on a filtered install #​8638.
psf/requests (requests)

v2.32.5

Compare Source

Bugfixes

  • The SSLContext caching feature originally introduced in 2.32.0 has created
    a new class of issues in Requests that have had negative impact across a number
    of use cases. The Requests team has decided to revert this feature as long term
    maintenance of it is proving to be unsustainable in its current iteration.

Deprecations

  • Added support for Python 3.14.
  • Dropped support for Python 3.8 following its end of support.
explosion/spaCy (spacy)

v3.8.11

Compare Source

v3.8.10

Compare Source

v3.8.9

Compare Source

v3.8.8

Compare Source

v3.8.7

Compare Source

v3.8.6

Compare Source

v3.8.5

Compare Source

v3.8.4

Compare Source

v3.8.3

Compare Source

tornadoweb/tornado (tornado)

v6.5.4

Compare Source

v6.5.3

Compare Source

v6.5.2

Compare Source


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot enabled auto-merge (squash) February 15, 2026 15:53
@renovate renovate bot force-pushed the renovate/patch-updates branch from f8feb6c to 9540ac6 Compare February 15, 2026 16:01
@renovate renovate bot force-pushed the renovate/patch-updates branch from 9540ac6 to 379da04 Compare February 15, 2026 16:01
@renovate renovate bot merged commit d5cedf8 into main Feb 15, 2026
12 of 13 checks passed
@renovate renovate bot deleted the renovate/patch-updates branch February 15, 2026 16:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

Comments