Commit dc6d84e
authored
chore(deps): update dependency black to v26 [security] (#29)
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [black](https://redirect.github.com/psf/black)
([changelog](https://redirect.github.com/psf/black/blob/main/CHANGES.md))
| `24.8.0` → `26.3.1` |

|

|
### GitHub Vulnerability Alerts
####
[CVE-2026-32274](https://redirect.github.com/psf/black/security/advisories/GHSA-3936-cmfr-pm3m)
### Impact
Black writes a cache file, the name of which is computed from various
formatting options. The value of the `--python-cell-magics` option was
placed in the filename without sanitization, which allowed an attacker
who controls the value of this argument to write cache files to
arbitrary file system locations.
### Patches
Fixed in Black 26.3.1.
### Workarounds
Do not allow untrusted user input into the value of the
`--python-cell-magics` option.
---
### Release Notes
<details>
<summary>psf/black (black)</summary>
###
[`v26.3.1`](https://redirect.github.com/psf/black/blob/HEAD/CHANGES.md#2631)
[Compare
Source](https://redirect.github.com/psf/black/compare/26.3.0...26.3.1)
##### Stable style
- Prevent Jupyter notebook magic masking collisions from corrupting
cells by using
exact-length placeholders for short magics and aborting if a placeholder
can no longer
be unmasked safely
([#​5038](https://redirect.github.com/psf/black/issues/5038))
##### Configuration
- Always hash cache filename components derived from
`--python-cell-magics` so custom
magic names cannot affect cache paths
([#​5038](https://redirect.github.com/psf/black/issues/5038))
##### *Blackd*
- Disable browser-originated requests by default, add configurable
origin allowlisting
and request body limits, and bound executor submissions to improve
backpressure
([#​5039](https://redirect.github.com/psf/black/issues/5039))
###
[`v26.3.0`](https://redirect.github.com/psf/black/blob/HEAD/CHANGES.md#2630)
[Compare
Source](https://redirect.github.com/psf/black/compare/26.1.0...26.3.0)
##### Stable style
- Don't double-decode input, causing non-UTF-8 files to be corrupted
([#​4964](https://redirect.github.com/psf/black/issues/4964))
- Fix crash on standalone comment in lambda default arguments
([#​4993](https://redirect.github.com/psf/black/issues/4993))
- Preserve parentheses when `# type: ignore` comments would be merged
with other
comments on the same line, preventing AST equivalence failures
([#​4888](https://redirect.github.com/psf/black/issues/4888))
##### Preview style
- Fix bug where `if` guards in `case` blocks were incorrectly split when
the pattern had
a trailing comma
([#​4884](https://redirect.github.com/psf/black/issues/4884))
- Fix `string_processing` crashing on unassigned long string literals
with trailing
commas (one-item tuples)
([#​4929](https://redirect.github.com/psf/black/issues/4929))
- Simplify implementation of the power operator "hugging" logic
([#​4918](https://redirect.github.com/psf/black/issues/4918))
##### Packaging
- Fix shutdown errors in PyInstaller builds on macOS by disabling
multiprocessing in
frozen environments
([#​4930](https://redirect.github.com/psf/black/issues/4930))
##### Performance
- Introduce winloop for windows as an alternative to uvloop
([#​4996](https://redirect.github.com/psf/black/issues/4996))
- Remove deprecated function `uvloop.install()` in favor of
`uvloop.new_event_loop()`
([#​4996](https://redirect.github.com/psf/black/issues/4996))
- Rename `maybe_install_uvloop` function to `maybe_use_uvloop` to
simplify loop
installation and creation of either a uvloop/winloop evenloop or default
eventloop
([#​4996](https://redirect.github.com/psf/black/issues/4996))
##### Output
- Emit a clear warning when the target Python version is newer than the
running Python
version, since AST safety checks cannot parse newer syntax. Also replace
the
misleading "INTERNAL ERROR" message with an actionable error explaining
the version
mismatch
([#​4983](https://redirect.github.com/psf/black/issues/4983))
##### *Blackd*
- Introduce winloop to be used when windows in use which enables blackd
to run faster on
windows when winloop is installed.
([#​4996](https://redirect.github.com/psf/black/issues/4996))
##### Integrations
- Remove unused gallery script
([#​5030](https://redirect.github.com/psf/black/issues/5030))
- Harden parsing of `black` requirements in the GitHub Action when
`use_pyproject` is
enabled so that only version specifiers are accepted and direct
references such as
`black @​ https://...` are rejected. Users should upgrade to the
latest version of the
action as soon as possible. This update is received automatically when
using
`psf/black@stable`, and is independent of the version of Black installed
by the
action.
([#​5031](https://redirect.github.com/psf/black/issues/5031))
##### Documentation
- Expand preview style documentation with detailed examples for
`wrap_comprehension_in`,
`simplify_power_operator_hugging`, and `wrap_long_dict_values_in_parens`
features
([#​4987](https://redirect.github.com/psf/black/issues/4987))
- Add detailed documentation for formatting Jupyter Notebooks
([#​5009](https://redirect.github.com/psf/black/issues/5009))
###
[`v26.1.0`](https://redirect.github.com/psf/black/blob/HEAD/CHANGES.md#2610)
[Compare
Source](https://redirect.github.com/psf/black/compare/25.12.0...26.1.0)
##### Highlights
Introduces the 2026 stable style
([#​4892](https://redirect.github.com/psf/black/issues/4892)),
stabilizing the following changes:
- `always_one_newline_after_import`: Always force one blank line after
import
statements, except when the line after the import is a comment or an
import statement
([#​4489](https://redirect.github.com/psf/black/issues/4489))
- `fix_fmt_skip_in_one_liners`: Fix `# fmt: skip` behavior on one-liner
declarations,
such as `def foo(): return "mock" # fmt: skip`, where previously the
declaration would
have been incorrectly collapsed
([#​4800](https://redirect.github.com/psf/black/issues/4800))
- `fix_module_docstring_detection`: Fix module docstrings being treated
as normal
strings if preceded by comments
([#​4764](https://redirect.github.com/psf/black/issues/4764))
- `fix_type_expansion_split`: Fix type expansions split in generic
functions
([#​4777](https://redirect.github.com/psf/black/issues/4777))
- `multiline_string_handling`: Make expressions involving multiline
strings more compact
([#​1879](https://redirect.github.com/psf/black/issues/1879))
- `normalize_cr_newlines`: Add `\r` style newlines to the potential
newlines to
normalize file newlines both from and to
([#​4710](https://redirect.github.com/psf/black/issues/4710))
- `remove_parens_around_except_types`: Remove parentheses around
multiple exception
types in `except` and `except*` without `as`
([#​4720](https://redirect.github.com/psf/black/issues/4720))
- `remove_parens_from_assignment_lhs`: Remove unnecessary parentheses
from the left-hand
side of assignments while preserving magic trailing commas and
intentional multiline
formatting
([#​4865](https://redirect.github.com/psf/black/issues/4865))
- `standardize_type_comments`: Format type comments which have zero or
more spaces
between `#` and `type:` or between `type:` and value to `# type:
(value)`
([#​4645](https://redirect.github.com/psf/black/issues/4645))
The following change was not in any previous stable release:
- Regenerated the `_width_table.py` and added tests for the Khmer
language
([#​4253](https://redirect.github.com/psf/black/issues/4253))
This release alo bumps `pathspec` to v1 and fixes inconsistencies with
Git's
`.gitignore` logic
([#​4958](https://redirect.github.com/psf/black/issues/4958)).
Now, files will be ignored if a pattern matches them, even
if the parent directory is directly unignored. For example, Black would
previously
format `exclude/not_this/foo.py` with this `.gitignore`:
```
exclude/
!exclude/not_this/
```
Now, `exclude/not_this/foo.py` will remain ignored. To ensure
`exclude/not_this/` and
all of it's children are included in formatting (and in Git), use this
`.gitignore`:
```
*/exclude/*
!*/exclude/not_this/
```
This new behavior matches Git. The leading `*/` are only necessary if
you wish to ignore
matching subdirectories (like the previous behavior did), and not just
matching root
directories.
##### Output
- Explicitly shutdown the multiprocessing manager when run in diff mode
too ([#​4952](https://redirect.github.com/psf/black/issues/4952))
##### Integrations
- Upgraded PyPI upload workflow to use Trusted Publishing
([#​4611](https://redirect.github.com/psf/black/issues/4611))
###
[`v25.12.0`](https://redirect.github.com/psf/black/blob/HEAD/CHANGES.md#25120)
[Compare
Source](https://redirect.github.com/psf/black/compare/25.11.0...25.12.0)
##### Highlights
- Black no longer supports running with Python 3.9
([#​4842](https://redirect.github.com/psf/black/issues/4842))
##### Stable style
- Fix bug where comments preceding `# fmt: off`/`# fmt: on` blocks were
incorrectly
removed, particularly affecting Jupytext's `# %% [markdown]` comments
([#​4845](https://redirect.github.com/psf/black/issues/4845))
- Fix crash when multiple `# fmt: skip` comments are used in a
multi-part if-clause, on
string literals, or on dictionary entries with long lines
([#​4872](https://redirect.github.com/psf/black/issues/4872))
- Fix possible crash when `fmt: ` directives aren't on the top level
([#​4856](https://redirect.github.com/psf/black/issues/4856))
##### Preview style
- Fix `fmt: skip` skipping the line after instead of the line it's on
([#​4855](https://redirect.github.com/psf/black/issues/4855))
- Remove unnecessary parentheses from the left-hand side of assignments
while preserving
magic trailing commas and intentional multiline formatting
([#​4865](https://redirect.github.com/psf/black/issues/4865))
- Fix `fix_fmt_skip_in_one_liners` crashing on `with` statements
([#​4853](https://redirect.github.com/psf/black/issues/4853))
- Fix `fix_fmt_skip_in_one_liners` crashing on annotated parameters
([#​4854](https://redirect.github.com/psf/black/issues/4854))
- Fix new lines being added after imports with `# fmt: skip` on them
([#​4894](https://redirect.github.com/psf/black/issues/4894))
##### Packaging
- Releases now include arm64 Windows binaries and wheels
([#​4814](https://redirect.github.com/psf/black/issues/4814))
##### Integrations
- Add `output-file` input to GitHub Action `psf/black` to write
formatter output to a
file for artifact capture and log cleanliness
([#​4824](https://redirect.github.com/psf/black/issues/4824))
###
[`v25.11.0`](https://redirect.github.com/psf/black/blob/HEAD/CHANGES.md#25110)
[Compare
Source](https://redirect.github.com/psf/black/compare/25.9.0...25.11.0)
##### Highlights
- Enable base 3.14 support
([#​4804](https://redirect.github.com/psf/black/issues/4804))
- Add support for the new Python 3.14 t-string syntax introduced by PEP
750 ([#​4805](https://redirect.github.com/psf/black/issues/4805))
##### Stable style
- Fix bug where comments between `# fmt: off` and `# fmt: on` were
reformatted
([#​4811](https://redirect.github.com/psf/black/issues/4811))
- Comments containing fmt directives now preserve their exact formatting
instead of
being normalized
([#​4811](https://redirect.github.com/psf/black/issues/4811))
##### Preview style
- Move `multiline_string_handling` from `--unstable` to `--preview`
([#​4760](https://redirect.github.com/psf/black/issues/4760))
- Fix bug where module docstrings would be treated as normal strings if
preceded by
comments
([#​4764](https://redirect.github.com/psf/black/issues/4764))
- Fix bug where python 3.12 generics syntax split line happens weirdly
([#​4777](https://redirect.github.com/psf/black/issues/4777))
- Standardize type comments to form `# type: <value>`
([#​4645](https://redirect.github.com/psf/black/issues/4645))
- Fix `fix_fmt_skip_in_one_liners` preview feature to respect `# fmt:
skip` for compound
statements with semicolon-separated bodies
([#​4800](https://redirect.github.com/psf/black/issues/4800))
##### Configuration
- Add `no_cache` option to control caching behavior.
([#​4803](https://redirect.github.com/psf/black/issues/4803))
##### Packaging
- Releases now include arm64 Linux binaries
([#​4773](https://redirect.github.com/psf/black/issues/4773))
##### Output
- Write unchanged content to stdout when excluding formatting from stdin
using pipes
([#​4610](https://redirect.github.com/psf/black/issues/4610))
##### *Blackd*
- Implemented BlackDClient. This simple python client allows to easily
send formatting
requests to blackd
([#​4774](https://redirect.github.com/psf/black/issues/4774))
##### Integrations
- Enable 3.14 base CI
([#​4804](https://redirect.github.com/psf/black/issues/4804))
- Enhance GitHub Action `psf/black` to support the `required-version`
major-version-only
"stability" format when using pyproject.toml
([#​4770](https://redirect.github.com/psf/black/issues/4770))
- Improve error message for vim plugin users. It now handles
independently vim version
- Vim: Warn on unsupported Vim and Python versions independently
([#​4772](https://redirect.github.com/psf/black/issues/4772))
- Vim: Print the import paths when importing black fails
([#​4675](https://redirect.github.com/psf/black/issues/4675))
- Vim: Fix handling of virtualenvs that have a different Python version
([#​4675](https://redirect.github.com/psf/black/issues/4675))
###
[`v25.9.0`](https://redirect.github.com/psf/black/blob/HEAD/CHANGES.md#2590)
[Compare
Source](https://redirect.github.com/psf/black/compare/25.1.0...25.9.0)
##### Highlights
- Remove support for pre-python 3.7 `await/async` as soft
keywords/variable names
([#​4676](https://redirect.github.com/psf/black/issues/4676))
##### Stable style
- Fix crash while formatting a long `del` statement containing tuples
([#​4628](https://redirect.github.com/psf/black/issues/4628))
- Fix crash while formatting expressions using the walrus operator in
complex `with`
statements
([#​4630](https://redirect.github.com/psf/black/issues/4630))
- Handle `# fmt: skip` followed by a comment at the end of file
([#​4635](https://redirect.github.com/psf/black/issues/4635))
- Fix crash when a tuple appears in the `as` clause of a `with`
statement
([#​4634](https://redirect.github.com/psf/black/issues/4634))
- Fix crash when tuple is used as a context manager inside a `with`
statement
([#​4646](https://redirect.github.com/psf/black/issues/4646))
- Fix crash when formatting a `\` followed by a `\r` followed by a
comment
([#​4663](https://redirect.github.com/psf/black/issues/4663))
- Fix crash on a `\\r\n`
([#​4673](https://redirect.github.com/psf/black/issues/4673))
- Fix crash on `await ...` (where `...` is a literal `Ellipsis`)
([#​4676](https://redirect.github.com/psf/black/issues/4676))
- Fix crash on parenthesized expression inside a type parameter bound
([#​4684](https://redirect.github.com/psf/black/issues/4684))
- Fix crash when using line ranges excluding indented single line
decorated items
([#​4670](https://redirect.github.com/psf/black/issues/4670))
##### Preview style
- Fix a bug where one-liner functions/conditionals marked with `# fmt:
skip` would still
be formatted
([#​4552](https://redirect.github.com/psf/black/issues/4552))
- Improve `multiline_string_handling` with ternaries and dictionaries
([#​4657](https://redirect.github.com/psf/black/issues/4657))
- Fix a bug where `string_processing` would not split f-strings directly
after
expressions
([#​4680](https://redirect.github.com/psf/black/issues/4680))
- Wrap the `in` clause of comprehensions across lines if necessary
([#​4699](https://redirect.github.com/psf/black/issues/4699))
- Remove parentheses around multiple exception types in `except` and
`except*` without
`as`.
([#​4720](https://redirect.github.com/psf/black/issues/4720))
- Add `\r` style newlines to the potential newlines to normalize file
newlines both from
and to
([#​4710](https://redirect.github.com/psf/black/issues/4710))
##### Parser
- Rewrite tokenizer to improve performance and compliance
([#​4536](https://redirect.github.com/psf/black/issues/4536))
- Fix bug where certain unusual expressions (e.g., lambdas) were not
accepted in type
parameter bounds and defaults.
([#​4602](https://redirect.github.com/psf/black/issues/4602))
##### Performance
- Avoid using an extra process when running with only one worker
([#​4734](https://redirect.github.com/psf/black/issues/4734))
##### Integrations
- Fix the version check in the vim file to reject Python 3.8
([#​4567](https://redirect.github.com/psf/black/issues/4567))
- Enhance GitHub Action `psf/black` to read Black version from an
additional section in
pyproject.toml: `[project.dependency-groups]`
([#​4606](https://redirect.github.com/psf/black/issues/4606))
- Build gallery docker image with python3-slim and reduce image size
([#​4686](https://redirect.github.com/psf/black/issues/4686))
##### Documentation
- Add FAQ entry for windows emoji not displaying
([#​4714](https://redirect.github.com/psf/black/issues/4714))
###
[`v25.1.0`](https://redirect.github.com/psf/black/blob/HEAD/CHANGES.md#2510)
[Compare
Source](https://redirect.github.com/psf/black/compare/24.10.0...25.1.0)
##### Highlights
This release introduces the new 2025 stable style
([#​4558](https://redirect.github.com/psf/black/issues/4558)),
stabilizing the following
changes:
- Normalize casing of Unicode escape characters in strings to lowercase
([#​2916](https://redirect.github.com/psf/black/issues/2916))
- Fix inconsistencies in whether certain strings are detected as
docstrings
([#​4095](https://redirect.github.com/psf/black/issues/4095))
- Consistently add trailing commas to typed function parameters
([#​4164](https://redirect.github.com/psf/black/issues/4164))
- Remove redundant parentheses in if guards for case blocks
([#​4214](https://redirect.github.com/psf/black/issues/4214))
- Add parentheses to if clauses in case blocks when the line is too long
([#​4269](https://redirect.github.com/psf/black/issues/4269))
- Whitespace before `# fmt: skip` comments is no longer normalized
([#​4146](https://redirect.github.com/psf/black/issues/4146))
- Fix line length computation for certain expressions that involve the
power operator
([#​4154](https://redirect.github.com/psf/black/issues/4154))
- Check if there is a newline before the terminating quotes of a
docstring
([#​4185](https://redirect.github.com/psf/black/issues/4185))
- Fix type annotation spacing between `*` and more complex type variable
tuple
([#​4440](https://redirect.github.com/psf/black/issues/4440))
The following changes were not in any previous release:
- Remove parentheses around sole list items
([#​4312](https://redirect.github.com/psf/black/issues/4312))
- Generic function definitions are now formatted more elegantly:
parameters are split
over multiple lines first instead of type parameter definitions
([#​4553](https://redirect.github.com/psf/black/issues/4553))
##### Stable style
- Fix formatting cells in IPython notebooks with magic methods and
starting or trailing
empty lines
([#​4484](https://redirect.github.com/psf/black/issues/4484))
- Fix crash when formatting `with` statements containing tuple
generators/unpacking
([#​4538](https://redirect.github.com/psf/black/issues/4538))
##### Preview style
- Fix/remove string merging changing f-string quotes on f-strings with
internal quotes
([#​4498](https://redirect.github.com/psf/black/issues/4498))
- Collapse multiple empty lines after an import into one
([#​4489](https://redirect.github.com/psf/black/issues/4489))
- Prevent `string_processing` and `wrap_long_dict_values_in_parens` from
removing
parentheses around long dictionary values
([#​4377](https://redirect.github.com/psf/black/issues/4377))
- Move `wrap_long_dict_values_in_parens` from the unstable to preview
style
([#​4561](https://redirect.github.com/psf/black/issues/4561))
##### Packaging
- Store license identifier inside the `License-Expression` metadata
field, see
[PEP 639](https://peps.python.org/pep-0639/).
([#​4479](https://redirect.github.com/psf/black/issues/4479))
##### Performance
- Speed up the `is_fstring_start` function in Black's tokenizer
([#​4541](https://redirect.github.com/psf/black/issues/4541))
##### Integrations
- If using stdin with `--stdin-filename` set to a force excluded path,
stdin won't be
formatted.
([#​4539](https://redirect.github.com/psf/black/issues/4539))
###
[`v24.10.0`](https://redirect.github.com/psf/black/blob/HEAD/CHANGES.md#24100)
[Compare
Source](https://redirect.github.com/psf/black/compare/24.8.0...24.10.0)
##### Highlights
- Black is now officially tested with Python 3.13 and provides Python
3.13
mypyc-compiled wheels.
([#​4436](https://redirect.github.com/psf/black/issues/4436))
([#​4449](https://redirect.github.com/psf/black/issues/4449))
- Black will issue an error when used with Python 3.12.5, due to an
upstream memory
safety issue in Python 3.12.5 that can cause Black's AST safety checks
to fail. Please
use Python 3.12.6 or Python 3.12.4 instead.
([#​4447](https://redirect.github.com/psf/black/issues/4447))
- Black no longer supports running with Python 3.8
([#​4452](https://redirect.github.com/psf/black/issues/4452))
##### Stable style
- Fix crashes involving comments in parenthesised return types or `X |
Y` style unions.
([#​4453](https://redirect.github.com/psf/black/issues/4453))
- Fix skipping Jupyter cells with unknown `%%` magic
([#​4462](https://redirect.github.com/psf/black/issues/4462))
##### Preview style
- Fix type annotation spacing between \* and more complex type variable
tuple (i.e. `def
fn(*args: *tuple[*Ts, T]) -> None: pass`)
([#​4440](https://redirect.github.com/psf/black/issues/4440))
##### Caching
- Fix bug where the cache was shared between runs with and without
`--unstable`
([#​4466](https://redirect.github.com/psf/black/issues/4466))
##### Packaging
- Upgrade version of mypyc used to 1.12 beta
([#​4450](https://redirect.github.com/psf/black/issues/4450))
([#​4449](https://redirect.github.com/psf/black/issues/4449))
- `blackd` now requires a newer version of aiohttp.
([#​4451](https://redirect.github.com/psf/black/issues/4451))
##### Output
- Added Python target version information on parse error
([#​4378](https://redirect.github.com/psf/black/issues/4378))
- Add information about Black version to internal error messages
([#​4457](https://redirect.github.com/psf/black/issues/4457))
</details>
---
### Configuration
📅 **Schedule**: Branch creation - "" (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/NiklasRosenstein/python-github-bot-api).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My42Ni40IiwidXBkYXRlZEluVmVyIjoiNDMuNjYuNCIsInRhcmdldEJyYW5jaCI6ImRldmVsb3AiLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19-->
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>1 parent 7fd1fc3 commit dc6d84e
1 file changed
Lines changed: 72 additions & 19 deletions
0 commit comments