-
fix(deps): Bump fonttools to address cve (#4125)
发布于
2025-12-10 17:11:53 +00:00 Note
Constrain fonttools to >=4.60.2 (CVE-2025-66034), bump extras to
4.61.0, switch setup_ingest to ubuntu-latest-m, and release 0.18.22.- Dependencies:
- Constrain
fonttools>=4.60.2inrequirements/deps/constraints.txt
to address CVE-2025-66034. - Bump
fonttoolsto4.61.0inrequirements/extra-*.txt; refresh
files via uv and align constraint references. - CI:
- Update
setup_ingestjob in.github/workflows/ci.ymlto run on
ubuntu-latest-m. - Release:
- Bump version to
0.18.22and updateCHANGELOG.md.
- Bump version to
Written by Cursor
Bugbot for commit
6ec072e0f48249f0b07d7ca12e35a09dcc78c04f. This will update automatically
on new commits. Configure
here.下载附件