Skip to content

security check: fontTools 4.54.1->4.60.2#35219

Merged
zitsen merged 1 commit intomainfrom
fix/TD-6713663608-MAIN-B
Apr 23, 2026
Merged

security check: fontTools 4.54.1->4.60.2#35219
zitsen merged 1 commit intomainfrom
fix/TD-6713663608-MAIN-B

Conversation

@DuanKuanJun
Copy link
Copy Markdown
Contributor

Description

Issue(s)

  • Close/close/Fix/fix/Resolve/resolve: Issue Link

Checklist

Please check the items in the checklist if applicable.

  • Is the user manual updated?
  • Are the test cases passed and automated?
  • Is there no significant decrease in test coverage?

Copilot AI review requested due to automatic review settings April 23, 2026 08:17
@DuanKuanJun DuanKuanJun requested review from a team, guanshengliang and zitsen as code owners April 23, 2026 08:17
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the pinned fonttools dependency to address security scanning findings, and refreshes the Python lockfile used under test/ accordingly.

Changes:

  • Bump fonttools in tools/tdgpt/requirements.txt from 4.54.1 to 4.60.2.
  • Update test/uv.lock to newer fonttools resolutions (now including marker-specific versions).

Reviewed changes

Copilot reviewed 1 out of 2 changed files in this pull request and generated 1 comment.

File Description
tools/tdgpt/requirements.txt Updates the pinned fonttools version for the tdgpt tool environment.
test/uv.lock Refreshes resolved fonttools versions and dependency metadata in the test lockfile.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread tools/tdgpt/requirements.txt
Copy link
Copy Markdown
Contributor

@gemini-code-assist gemini-code-assist Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the fonttools dependency across the project. In test/uv.lock, the package is updated to version 4.60.2 for Python environments older than 3.10 and version 4.62.1 for Python 3.10 and above. A version inconsistency was identified in tools/tdgpt/requirements.txt, where fonttools was updated to 4.60.2; it is recommended to update this to 4.62.1 to maintain consistency with the lockfile's resolution for modern Python environments.

Comment thread tools/tdgpt/requirements.txt
@zitsen zitsen merged commit 6e152b2 into main Apr 23, 2026
18 of 21 checks passed
@zitsen zitsen deleted the fix/TD-6713663608-MAIN-B branch April 23, 2026 08:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants