Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: pydata/pydata-sphinx-theme
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: v0.21.0
Choose a base ref
...
head repository: pydata/pydata-sphinx-theme
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: v0.22.0
Choose a head ref
  • 18 commits
  • 34 files changed
  • 9 contributors

Commits on Aug 27, 2026

  1. Back to dev

    Yann-P committed Aug 27, 2026
    Configuration menu
    Copy the full SHA
    46ac937 View commit details
    Browse the repository at this point in the history

Commits on Aug 31, 2026

  1. Bump astral-sh/setup-uv from 10.0.0 to 10.0.1 (#2478)

    Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from
    10.0.0 to 10.0.1.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/astral-sh/setup-uv/releases">astral-sh/setup-uv's
    releases</a>.</em></p>
    <blockquote>
    <h2>v10.0.1 🌈 Tolerate transient manifest timeouts</h2>
    <h2>Changes</h2>
    <p>Thank you <a
    href="https://github.com/arguile"><code>@​arguile</code></a>- for making
    this action more resilient.</p>
    <h2>🐛 Bug fixes</h2>
    <ul>
    <li>Tolerate transient manifest timeouts <a
    href="https://github.com/arguile"><code>@​arguile</code></a>- (<a
    href="https://redirect.github.com/astral-sh/setup-uv/issues/1016">#1016</a>)</li>
    </ul>
    <h2>🧰 Maintenance</h2>
    <ul>
    <li>chore: update known checksums for 0.12.4 @<a
    href="https://github.com/apps/github-actions">github-actions[bot]</a>
    (<a
    href="https://redirect.github.com/astral-sh/setup-uv/issues/1017">#1017</a>)</li>
    </ul>
    <h2>📚 Documentation</h2>
    <ul>
    <li>docs: update version references to v10.0.0 @<a
    href="https://github.com/apps/github-actions">github-actions[bot]</a>
    (<a
    href="https://redirect.github.com/astral-sh/setup-uv/issues/1014">#1014</a>)</li>
    </ul>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/astral-sh/setup-uv/commit/20cfd1bf945f4377ade1205e4dbc17946fc9a30d"><code>20cfd1b</code></a>
    chore: update known checksums for 0.12.4 (<a
    href="https://redirect.github.com/astral-sh/setup-uv/issues/1017">#1017</a>)</li>
    <li><a
    href="https://github.com/astral-sh/setup-uv/commit/d73a0cab66a532d7afa440d9df4a67ea9fe65a30"><code>d73a0ca</code></a>
    Tolerate transient manifest timeouts (<a
    href="https://redirect.github.com/astral-sh/setup-uv/issues/1016">#1016</a>)</li>
    <li><a
    href="https://github.com/astral-sh/setup-uv/commit/ae3b92d1bdb308a10adfe7b8f408e5cc8c30f3f6"><code>ae3b92d</code></a>
    docs: update version references to v10.0.0 (<a
    href="https://redirect.github.com/astral-sh/setup-uv/issues/1014">#1014</a>)</li>
    <li>See full diff in <a
    href="https://github.com/astral-sh/setup-uv/compare/ae62891fec2bb8e7d6c99fc78c9fec3a63790f8d...20cfd1bf945f4377ade1205e4dbc17946fc9a30d">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=astral-sh/setup-uv&package-manager=github_actions&previous-version=10.0.0&new-version=10.0.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Aug 31, 2026
    Configuration menu
    Copy the full SHA
    1ba2644 View commit details
    Browse the repository at this point in the history

Commits on Sep 2, 2026

  1. Bump postcss-selector-parser (#2479)

    Bumps and
    [postcss-selector-parser](https://github.com/postcss/postcss-selector-parser).
    These dependencies needed to be updated together.
    Updates `postcss-selector-parser` from 6.0.16 to 6.1.4
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/postcss/postcss-selector-parser/releases">postcss-selector-parser's
    releases</a>.</em></p>
    <blockquote>
    <h2>6.1.4</h2>
    <ul>
    <li>fix: tolerate non-node children when serializing selectors</li>
    </ul>
    <h2>6.1.3</h2>
    <ul>
    <li>Fix <a
    href="https://github.com/advisories/GHSA-w9m9-85wc-3x92">CVE-2026-9358</a>
    (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 via backport of (<a
    href="https://redirect.github.com/postcss/postcss-selector-parser/pull/316">#316</a>
    by <a href="https://github.com/MoOx"><code>@​MoOx</code></a>)</li>
    </ul>
    <h2>v6.1.2</h2>
    <h1>6.1.2</h1>
    <ul>
    <li>Fixed: erroneous trailing combinators in pseudos</li>
    </ul>
    <h2>v6.1.1</h2>
    <h1>6.1.1</h1>
    <ul>
    <li>Fixed: improve typings of constructor helpers (<a
    href="https://redirect.github.com/postcss/postcss-selector-parser/issues/292">#292</a>)</li>
    </ul>
    <h2>v6.1.0</h2>
    <h1>6.1.0</h1>
    <ul>
    <li>Feature: add <code>sourceIndex</code> to <code>Selector</code> nodes
    (<a
    href="https://redirect.github.com/postcss/postcss-selector-parser/issues/290">#290</a>)</li>
    </ul>
    </blockquote>
    </details>
    <details>
    <summary>Changelog</summary>
    <p><em>Sourced from <a
    href="https://github.com/postcss/postcss-selector-parser/blob/main/CHANGELOG.md">postcss-selector-parser's
    changelog</a>.</em></p>
    <blockquote>
    <h1>Changelog of <code>postcss-selector-parser</code></h1>
    <h2>7.1.5 - 2026-08-07</h2>
    <ul>
    <li>fix: don't treat a non-prefix token before <code>|</code> as a
    namespace (<a
    href="https://redirect.github.com/postcss/postcss-selector-parser/pull/324">#324</a>
    by <a
    href="https://github.com/spokodev"><code>@​spokodev</code></a>)</li>
    <li>fix: preserve whitespace before a <code>*</code> namespace in
    attribute selectors (<a
    href="https://redirect.github.com/postcss/postcss-selector-parser/pull/325">#325</a>
    by <a
    href="https://github.com/spokodev"><code>@​spokodev</code></a>)</li>
    <li>fix: TypeError on unclosed <code>[</code>, <code>(</code> and
    trailing <code>|</code> (<a
    href="https://redirect.github.com/postcss/postcss-selector-parser/pull/330">#330</a>
    by <a
    href="https://github.com/theRizwan"><code>@​theRizwan</code></a>)</li>
    </ul>
    <h2>7.1.4 - 2026-06-11</h2>
    <ul>
    <li>fix: tolerate non-node children when serializing selectors</li>
    </ul>
    <h2>7.1.3 - 2026-06-11</h2>
    <ul>
    <li>Improve fix CVE-2026-9358 (NVD) /
    SNYK-JS-POSTCSSSELECTORPARSER-16873882 (clone/walk)</li>
    </ul>
    <h2>7.1.2 - 2026-06-09</h2>
    <ul>
    <li>Fix <a
    href="https://github.com/advisories/GHSA-w9m9-85wc-3x92">CVE-2026-9358</a>
    (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 (<a
    href="https://redirect.github.com/postcss/postcss-selector-parser/pull/316">#316</a>
    by <a href="https://github.com/MoOx"><code>@​MoOx</code></a>)</li>
    </ul>
    <h2>7.1.1</h2>
    <ul>
    <li>perf: replace startsWith with strict equality (<a
    href="https://redirect.github.com/postcss/postcss-selector-parser/issues/308">#308</a>)</li>
    <li>fix(types): add walkUniversal declaration (<a
    href="https://redirect.github.com/postcss/postcss-selector-parser/issues/311">#311</a>)</li>
    </ul>
    <h2>7.1.0</h2>
    <ul>
    <li>feat: insert(Before|After) support multiple new node</li>
    </ul>
    <h2>7.0.0</h2>
    <ul>
    <li>Feat: make insertions during iteration safe (major)</li>
    </ul>
    <h2>6.1.2</h2>
    <ul>
    <li>Fixed: erroneous trailing combinators in pseudos</li>
    </ul>
    <h2>6.1.1</h2>
    <ul>
    <li>Fixed: improve typings of constructor helpers (<a
    href="https://redirect.github.com/postcss/postcss-selector-parser/issues/292">#292</a>)</li>
    </ul>
    <h2>6.1.0</h2>
    <ul>
    <li>Feature: add <code>sourceIndex</code> to <code>Selector</code> nodes
    (<a
    href="https://redirect.github.com/postcss/postcss-selector-parser/issues/290">#290</a>)</li>
    </ul>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/postcss/postcss-selector-parser/commit/4a7e4e3685db8ab8e52e51ecdbe8162a8568f70c"><code>4a7e4e3</code></a>
    7.1.4</li>
    <li><a
    href="https://github.com/postcss/postcss-selector-parser/commit/e2021c523d5ef1bf27836aef3bd724a28ba7894f"><code>e2021c5</code></a>
    fix: tolerate non-node children when serializing selectors</li>
    <li><a
    href="https://github.com/postcss/postcss-selector-parser/commit/7893b741fa87d0401e39c3a7f00d89cf7408ad32"><code>7893b74</code></a>
    7.1.3</li>
    <li><a
    href="https://github.com/postcss/postcss-selector-parser/commit/5bc698cef66f8abd12610dc623e5d67cbc0f869d"><code>5bc698c</code></a>
    Improve fix CVE-2026-9358 (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882
    (clo...</li>
    <li><a
    href="https://github.com/postcss/postcss-selector-parser/commit/db3232710d7270b34e50b4ffae493ac19204f570"><code>db32327</code></a>
    run oxfmt</li>
    <li><a
    href="https://github.com/postcss/postcss-selector-parser/commit/16e2581b40894504cf2b979fc0ebf7d0b2f39366"><code>16e2581</code></a>
    simplify deps (<a
    href="https://redirect.github.com/postcss/postcss-selector-parser/issues/319">#319</a>)</li>
    <li><a
    href="https://github.com/postcss/postcss-selector-parser/commit/b185e2057871669f9c571ad82e4350799e0a2329"><code>b185e20</code></a>
    Add description in package.json + full repo url</li>
    <li><a
    href="https://github.com/postcss/postcss-selector-parser/commit/de415f19aac008f0e731590222f3a963193be05c"><code>de415f1</code></a>
    Add Tidelift security notice</li>
    <li><a
    href="https://github.com/postcss/postcss-selector-parser/commit/c4f2c8c04a8107e4e401f257ef00592b59633774"><code>c4f2c8c</code></a>
    CI: make Node 14 test job lockfile-v3 compatible (<a
    href="https://redirect.github.com/postcss/postcss-selector-parser/issues/318">#318</a>)</li>
    <li><a
    href="https://github.com/postcss/postcss-selector-parser/commit/4e93663bfe861f9fc3173db603c8fadb70f8090a"><code>4e93663</code></a>
    Fix test run on node &lt; 20</li>
    <li>Additional commits viewable in <a
    href="https://github.com/postcss/postcss-selector-parser/compare/v6.0.16...6.1.4">compare
    view</a></li>
    </ul>
    </details>
    <details>
    <summary>Maintainer changes</summary>
    <p>This version was pushed to npm by <a
    href="https://www.npmjs.com/~moox">moox</a>, a new releaser for
    postcss-selector-parser since your current version.</p>
    </details>
    <br />
    
    Updates `postcss-selector-parser` from 7.1.1 to 7.1.5
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/postcss/postcss-selector-parser/releases">postcss-selector-parser's
    releases</a>.</em></p>
    <blockquote>
    <h2>6.1.4</h2>
    <ul>
    <li>fix: tolerate non-node children when serializing selectors</li>
    </ul>
    <h2>6.1.3</h2>
    <ul>
    <li>Fix <a
    href="https://github.com/advisories/GHSA-w9m9-85wc-3x92">CVE-2026-9358</a>
    (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 via backport of (<a
    href="https://redirect.github.com/postcss/postcss-selector-parser/pull/316">#316</a>
    by <a href="https://github.com/MoOx"><code>@​MoOx</code></a>)</li>
    </ul>
    <h2>v6.1.2</h2>
    <h1>6.1.2</h1>
    <ul>
    <li>Fixed: erroneous trailing combinators in pseudos</li>
    </ul>
    <h2>v6.1.1</h2>
    <h1>6.1.1</h1>
    <ul>
    <li>Fixed: improve typings of constructor helpers (<a
    href="https://redirect.github.com/postcss/postcss-selector-parser/issues/292">#292</a>)</li>
    </ul>
    <h2>v6.1.0</h2>
    <h1>6.1.0</h1>
    <ul>
    <li>Feature: add <code>sourceIndex</code> to <code>Selector</code> nodes
    (<a
    href="https://redirect.github.com/postcss/postcss-selector-parser/issues/290">#290</a>)</li>
    </ul>
    </blockquote>
    </details>
    <details>
    <summary>Changelog</summary>
    <p><em>Sourced from <a
    href="https://github.com/postcss/postcss-selector-parser/blob/main/CHANGELOG.md">postcss-selector-parser's
    changelog</a>.</em></p>
    <blockquote>
    <h1>Changelog of <code>postcss-selector-parser</code></h1>
    <h2>7.1.5 - 2026-08-07</h2>
    <ul>
    <li>fix: don't treat a non-prefix token before <code>|</code> as a
    namespace (<a
    href="https://redirect.github.com/postcss/postcss-selector-parser/pull/324">#324</a>
    by <a
    href="https://github.com/spokodev"><code>@​spokodev</code></a>)</li>
    <li>fix: preserve whitespace before a <code>*</code> namespace in
    attribute selectors (<a
    href="https://redirect.github.com/postcss/postcss-selector-parser/pull/325">#325</a>
    by <a
    href="https://github.com/spokodev"><code>@​spokodev</code></a>)</li>
    <li>fix: TypeError on unclosed <code>[</code>, <code>(</code> and
    trailing <code>|</code> (<a
    href="https://redirect.github.com/postcss/postcss-selector-parser/pull/330">#330</a>
    by <a
    href="https://github.com/theRizwan"><code>@​theRizwan</code></a>)</li>
    </ul>
    <h2>7.1.4 - 2026-06-11</h2>
    <ul>
    <li>fix: tolerate non-node children when serializing selectors</li>
    </ul>
    <h2>7.1.3 - 2026-06-11</h2>
    <ul>
    <li>Improve fix CVE-2026-9358 (NVD) /
    SNYK-JS-POSTCSSSELECTORPARSER-16873882 (clone/walk)</li>
    </ul>
    <h2>7.1.2 - 2026-06-09</h2>
    <ul>
    <li>Fix <a
    href="https://github.com/advisories/GHSA-w9m9-85wc-3x92">CVE-2026-9358</a>
    (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 (<a
    href="https://redirect.github.com/postcss/postcss-selector-parser/pull/316">#316</a>
    by <a href="https://github.com/MoOx"><code>@​MoOx</code></a>)</li>
    </ul>
    <h2>7.1.1</h2>
    <ul>
    <li>perf: replace startsWith with strict equality (<a
    href="https://redirect.github.com/postcss/postcss-selector-parser/issues/308">#308</a>)</li>
    <li>fix(types): add walkUniversal declaration (<a
    href="https://redirect.github.com/postcss/postcss-selector-parser/issues/311">#311</a>)</li>
    </ul>
    <h2>7.1.0</h2>
    <ul>
    <li>feat: insert(Before|After) support multiple new node</li>
    </ul>
    <h2>7.0.0</h2>
    <ul>
    <li>Feat: make insertions during iteration safe (major)</li>
    </ul>
    <h2>6.1.2</h2>
    <ul>
    <li>Fixed: erroneous trailing combinators in pseudos</li>
    </ul>
    <h2>6.1.1</h2>
    <ul>
    <li>Fixed: improve typings of constructor helpers (<a
    href="https://redirect.github.com/postcss/postcss-selector-parser/issues/292">#292</a>)</li>
    </ul>
    <h2>6.1.0</h2>
    <ul>
    <li>Feature: add <code>sourceIndex</code> to <code>Selector</code> nodes
    (<a
    href="https://redirect.github.com/postcss/postcss-selector-parser/issues/290">#290</a>)</li>
    </ul>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/postcss/postcss-selector-parser/commit/4a7e4e3685db8ab8e52e51ecdbe8162a8568f70c"><code>4a7e4e3</code></a>
    7.1.4</li>
    <li><a
    href="https://github.com/postcss/postcss-selector-parser/commit/e2021c523d5ef1bf27836aef3bd724a28ba7894f"><code>e2021c5</code></a>
    fix: tolerate non-node children when serializing selectors</li>
    <li><a
    href="https://github.com/postcss/postcss-selector-parser/commit/7893b741fa87d0401e39c3a7f00d89cf7408ad32"><code>7893b74</code></a>
    7.1.3</li>
    <li><a
    href="https://github.com/postcss/postcss-selector-parser/commit/5bc698cef66f8abd12610dc623e5d67cbc0f869d"><code>5bc698c</code></a>
    Improve fix CVE-2026-9358 (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882
    (clo...</li>
    <li><a
    href="https://github.com/postcss/postcss-selector-parser/commit/db3232710d7270b34e50b4ffae493ac19204f570"><code>db32327</code></a>
    run oxfmt</li>
    <li><a
    href="https://github.com/postcss/postcss-selector-parser/commit/16e2581b40894504cf2b979fc0ebf7d0b2f39366"><code>16e2581</code></a>
    simplify deps (<a
    href="https://redirect.github.com/postcss/postcss-selector-parser/issues/319">#319</a>)</li>
    <li><a
    href="https://github.com/postcss/postcss-selector-parser/commit/b185e2057871669f9c571ad82e4350799e0a2329"><code>b185e20</code></a>
    Add description in package.json + full repo url</li>
    <li><a
    href="https://github.com/postcss/postcss-selector-parser/commit/de415f19aac008f0e731590222f3a963193be05c"><code>de415f1</code></a>
    Add Tidelift security notice</li>
    <li><a
    href="https://github.com/postcss/postcss-selector-parser/commit/c4f2c8c04a8107e4e401f257ef00592b59633774"><code>c4f2c8c</code></a>
    CI: make Node 14 test job lockfile-v3 compatible (<a
    href="https://redirect.github.com/postcss/postcss-selector-parser/issues/318">#318</a>)</li>
    <li><a
    href="https://github.com/postcss/postcss-selector-parser/commit/4e93663bfe861f9fc3173db603c8fadb70f8090a"><code>4e93663</code></a>
    Fix test run on node &lt; 20</li>
    <li>Additional commits viewable in <a
    href="https://github.com/postcss/postcss-selector-parser/compare/v6.0.16...6.1.4">compare
    view</a></li>
    </ul>
    </details>
    <details>
    <summary>Maintainer changes</summary>
    <p>This version was pushed to npm by <a
    href="https://www.npmjs.com/~moox">moox</a>, a new releaser for
    postcss-selector-parser since your current version.</p>
    </details>
    <br />
    
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the
    [Security Alerts
    page](https://github.com/pydata/pydata-sphinx-theme/network/alerts).
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Sep 2, 2026
    Configuration menu
    Copy the full SHA
    a9100da View commit details
    Browse the repository at this point in the history
  2. Bump browserslist from 4.28.1 to 4.28.8 (#2480)

    Bumps [browserslist](https://github.com/browserslist/browserslist) from
    4.28.1 to 4.28.8.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/browserslist/browserslist/releases">browserslist's
    releases</a>.</em></p>
    <blockquote>
    <h2>4.28.8</h2>
    <ul>
    <li>Fixed <code>including kaios</code> in baseline queries (by <a
    href="https://github.com/Jaybhade"><code>@​Jaybhade</code></a>).</li>
    </ul>
    <h2>4.28.7</h2>
    <ul>
    <li>Improved parsing performance.</li>
    <li>Fixed unbounded memory growth (by <a
    href="https://github.com/alanturing881"><code>@​alanturing881</code></a>).</li>
    <li>Fixed prototype write issue (by <a
    href="https://github.com/alanturing881"><code>@​alanturing881</code></a>).</li>
    </ul>
    <h2>4.28.6</h2>
    <ul>
    <li>Fixed Electron version queries (by <a
    href="https://github.com/spokodev"><code>@​spokodev</code></a>).</li>
    </ul>
    <h2>4.28.5</h2>
    <ul>
    <li>Fixed <code>&gt;</code> and <code>&gt;=</code> queries (by <a
    href="https://github.com/spokodev"><code>@​spokodev</code></a>).</li>
    </ul>
    <h2>4.28.4</h2>
    <ul>
    <li>Fixed <code>SyntaxError</code> regression of 4.28.3.</li>
    </ul>
    <h2>4.28.3</h2>
    <ul>
    <li>Fixed baseline query case-insensitivity (by <a
    href="https://github.com/swwind"><code>@​swwind</code></a>).</li>
    </ul>
    <h2>4.28.2</h2>
    <ul>
    <li>Fix prototype pollution (by <a
    href="https://github.com/chluo1997"><code>@​chluo1997</code></a>).</li>
    </ul>
    </blockquote>
    </details>
    <details>
    <summary>Changelog</summary>
    <p><em>Sourced from <a
    href="https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md">browserslist's
    changelog</a>.</em></p>
    <blockquote>
    <h2>4.28.8</h2>
    <ul>
    <li>Fixed <code>including kaios</code> in baseline queries (by <a
    href="https://github.com/Jaybhade"><code>@​Jaybhade</code></a>).</li>
    </ul>
    <h2>4.28.7</h2>
    <ul>
    <li>Improved parsing performance.</li>
    <li>Fixed unbounded memory growth (by <a
    href="https://github.com/alanturing881"><code>@​alanturing881</code></a>).</li>
    <li>Fixed prototype write issue (by <a
    href="https://github.com/alanturing881"><code>@​alanturing881</code></a>).</li>
    </ul>
    <h2>4.28.6</h2>
    <ul>
    <li>Fixed Electron version queries (by <a
    href="https://github.com/spokodev"><code>@​spokodev</code></a>).</li>
    </ul>
    <h2>4.28.5</h2>
    <ul>
    <li>Fixed <code>&gt;</code> and <code>&gt;=</code> queries (by <a
    href="https://github.com/spokodev"><code>@​spokodev</code></a>).</li>
    </ul>
    <h2>4.28.4</h2>
    <ul>
    <li>Fixed <code>SyntaxError</code> regression of 4.28.3.</li>
    </ul>
    <h2>4.28.3</h2>
    <ul>
    <li>Fixed baseline query case-insensitivity (by <a
    href="https://github.com/swwind"><code>@​swwind</code></a>).</li>
    </ul>
    <h2>4.28.2</h2>
    <ul>
    <li>Fix prototype pollution (by <a
    href="https://github.com/chluo1997"><code>@​chluo1997</code></a>).</li>
    </ul>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/browserslist/browserslist/commit/f2f2e6cfb01bb4942941d328737546f4e2ae41ad"><code>f2f2e6c</code></a>
    Release 4.28.8 version</li>
    <li><a
    href="https://github.com/browserslist/browserslist/commit/d0787c88fa29ba895fea51cfe921232c7b5d1377"><code>d0787c8</code></a>
    Update dependencies</li>
    <li><a
    href="https://github.com/browserslist/browserslist/commit/fcf8fa9857b30ccdf801a548f5d09d3c4ff0d43f"><code>fcf8fa9</code></a>
    Merge pull request <a
    href="https://redirect.github.com/browserslist/browserslist/issues/939">#939</a>
    from Jaybhade/fix/baseline-kaios-without-downstream</li>
    <li><a
    href="https://github.com/browserslist/browserslist/commit/57ecd64454e9252afdd6a7e76926e13dda48a38c"><code>57ecd64</code></a>
    fix: support &quot;including kaios&quot; without downstream</li>
    <li><a
    href="https://github.com/browserslist/browserslist/commit/093a0f67bb0becda55235d767b134df3197c54a1"><code>093a0f6</code></a>
    Update EM banner</li>
    <li><a
    href="https://github.com/browserslist/browserslist/commit/b637868045806d2fba4c24eb0060e4cc8b1db276"><code>b637868</code></a>
    Release 4.28.7 version</li>
    <li><a
    href="https://github.com/browserslist/browserslist/commit/313f4659b9f985ade89d1d6a54a860371c41cc46"><code>313f465</code></a>
    Update dependencies</li>
    <li><a
    href="https://github.com/browserslist/browserslist/commit/c935c5a206f8b13db8846818bc03643e147dcbdf"><code>c935c5a</code></a>
    Fix regexp performance</li>
    <li><a
    href="https://github.com/browserslist/browserslist/commit/d7e9e653cb53399065943f59f0b3063987b0a008"><code>d7e9e65</code></a>
    Rewrite structure parsing to make it always fast</li>
    <li><a
    href="https://github.com/browserslist/browserslist/commit/ec4a55efd76bdfa506ec7ce4fea1691559e9ca8f"><code>ec4a55e</code></a>
    Fix import order</li>
    <li>Additional commits viewable in <a
    href="https://github.com/browserslist/browserslist/compare/4.28.1...4.28.8">compare
    view</a></li>
    </ul>
    </details>
    <details>
    <summary>Maintainer changes</summary>
    <p>This version was pushed to npm by <a
    href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new
    releaser for browserslist since your current version.</p>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=browserslist&package-manager=npm_and_yarn&previous-version=4.28.1&new-version=4.28.8)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the
    [Security Alerts
    page](https://github.com/pydata/pydata-sphinx-theme/network/alerts).
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Sep 2, 2026
    Configuration menu
    Copy the full SHA
    8a24f5d View commit details
    Browse the repository at this point in the history

Commits on Sep 3, 2026

  1. fix a console error when pstAnnouncementUrl is undefined (#2481)

    Thanks for maintaining this!
    
    This fixes a console issue when banner data is not available.
    bollwyvl authored Sep 3, 2026
    Configuration menu
    Copy the full SHA
    f84f9b1 View commit details
    Browse the repository at this point in the history

Commits on Sep 4, 2026

  1. Bump hynek/build-and-inspect-python-package from 2.18.0 to 3.0.1 (#2461)

    Bumps
    [hynek/build-and-inspect-python-package](https://github.com/hynek/build-and-inspect-python-package)
    from 2.18.0 to 3.0.1.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/hynek/build-and-inspect-python-package/releases">hynek/build-and-inspect-python-package's
    releases</a>.</em></p>
    <blockquote>
    <h2>v3.0.1</h2>
    <h3>Fixed</h3>
    <ul>
    <li>To avoid <em>uv</em> configuration interference with the project
    that is being built, the installation of our own tools is now ran in a
    different directory. Additionally, <code>UV_EXCLUDE_NEWER</code> is
    unset. <a
    href="https://redirect.github.com/hynek/build-and-inspect-python-package/pull/240">#240</a></li>
    </ul>
    <h2>v3.0.0</h2>
    <h3>Security</h3>
    <ul>
    <li>Given the increase and supply-chain attacks and advancements in
    tooling (for example, <a
    href="https://github.com/suzuki-shunsuke/pinact"><em>pinact</em></a> or
    GitHub's Dependabot), this action will stop force-tagging minor and
    micro releases. This means, there will be no <code>@V3</code> or
    <code>@v3.0</code> tag that gets updated and force-pushed with each
    update. Always tag with the full version and commit hash; use <a
    href="https://zizmor.sh">Zizmor</a> to secure your actions if you
    can.</li>
    </ul>
    <h3>Changed</h3>
    <ul>
    <li>Only updates of actions and build dependencies, notably including
    Twine 7 that adds support for packaging metadata 2.5 and <a
    href="https://peps.python.org/pep-0794/">PEP 794 – Import Name
    Metadata</a>.</li>
    </ul>
    </blockquote>
    </details>
    <details>
    <summary>Changelog</summary>
    <p><em>Sourced from <a
    href="https://github.com/hynek/build-and-inspect-python-package/blob/main/CHANGELOG.md">hynek/build-and-inspect-python-package's
    changelog</a>.</em></p>
    <blockquote>
    <h1>Changelog</h1>
    <p>All notable changes to this project will be documented in this
    file.</p>
    <p>The format is based on <a
    href="https://keepachangelog.com/en/1.0.0/">Keep a Changelog</a>, and
    this project adheres to <a
    href="https://semver.org/spec/v2.0.0.html">Semantic Versioning</a>.</p>
    <!-- raw HTML omitted -->
    <h2><a
    href="https://github.com/hynek/build-and-inspect-python-package/compare/v3.0.1...HEAD">Unreleased</a></h2>
    <h2><a
    href="https://github.com/hynek/build-and-inspect-python-package/compare/v3.0.0...v3.0.1">3.0.1</a>
    - 2026-07-30</h2>
    <h3>Fixed</h3>
    <ul>
    <li>To avoid <em>uv</em> configuration interference with the project
    that is being built, the installation of our own tools is now ran in a
    different directory.
    Additionally, <code>UV_EXCLUDE_NEWER</code> is unset.
    <a
    href="https://redirect.github.com/hynek/build-and-inspect-python-package/pull/240">#240</a></li>
    </ul>
    <h2><a
    href="https://github.com/hynek/build-and-inspect-python-package/compare/v2.18.0...v3.0.0">3.0.0</a>
    - 2026-07-30</h2>
    <h3>Security</h3>
    <ul>
    <li>Given the increase and supply-chain attacks and advancements in
    tooling (for example, <a
    href="https://github.com/suzuki-shunsuke/pinact"><em>pinact</em></a> or
    GitHub's Dependabot), this action will stop force-tagging minor and
    micro releases.
    This means, there will be no <code>@V3</code> or <code>@v3.0</code> tag
    that gets updated and force-pushed with each update.
    Always tag with the full version and commit hash; use <a
    href="https://zizmor.sh">Zizmor</a> to secure your actions if you
    can.</li>
    </ul>
    <h3>Changed</h3>
    <ul>
    <li>Only updates of actions and build dependencies, notably including
    Twine 7 that adds support for packaging metadata 2.5 and <a
    href="https://peps.python.org/pep-0794/">PEP 794 – Import Name
    Metadata</a>.</li>
    </ul>
    <h2><a
    href="https://github.com/hynek/build-and-inspect-python-package/compare/v2.17.0...v2.18.0">2.18.0</a>
    - 2026-05-11</h2>
    <h3>Added</h3>
    <ul>
    <li>New input: <code>skip-sdist</code> to skip building the source
    distribution.
    <a
    href="https://redirect.github.com/hynek/build-and-inspect-python-package/issues/228">#228</a></li>
    </ul>
    <h2><a
    href="https://github.com/hynek/build-and-inspect-python-package/compare/v2.16.0...v2.17.0">2.17.0</a>
    - 2026-03-27</h2>
    <h3>Fixed</h3>
    <ul>
    <li>The action now passes Zizmor in pedantic mode.
    <a
    href="https://redirect.github.com/hynek/build-and-inspect-python-package/issues/212">#212</a></li>
    </ul>
    <!-- raw HTML omitted -->
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/hynek/build-and-inspect-python-package/commit/2abe76da66d0a6a4a227101f9348ee855797cfa5"><code>2abe76d</code></a>
    v3.0.1</li>
    <li><a
    href="https://github.com/hynek/build-and-inspect-python-package/commit/24fa8387643ae438edaa8a8180b5971505940986"><code>24fa838</code></a>
    Switch to /tmp/baipp when syncing our tools (<a
    href="https://redirect.github.com/hynek/build-and-inspect-python-package/issues/240">#240</a>)</li>
    <li><a
    href="https://github.com/hynek/build-and-inspect-python-package/commit/c6bb487909b3140d953646377c9320f01b56da31"><code>c6bb487</code></a>
    Start next cycle</li>
    <li><a
    href="https://github.com/hynek/build-and-inspect-python-package/commit/12fab959b87bed57ce97554949bdd5db1207e442"><code>12fab95</code></a>
    v3.0.0</li>
    <li><a
    href="https://github.com/hynek/build-and-inspect-python-package/commit/c1f438b421b28a1cc4362bcd01105527b8cc56a7"><code>c1f438b</code></a>
    Announce changes to versioning</li>
    <li><a
    href="https://github.com/hynek/build-and-inspect-python-package/commit/444be5d3ea585ffacdcf653b917f8cfdf2cb38bd"><code>444be5d</code></a>
    Add changelog</li>
    <li><a
    href="https://github.com/hynek/build-and-inspect-python-package/commit/86390fb93bacde17c922e92819b4658877860f2b"><code>86390fb</code></a>
    update actions (<a
    href="https://redirect.github.com/hynek/build-and-inspect-python-package/issues/238">#238</a>)</li>
    <li><a
    href="https://github.com/hynek/build-and-inspect-python-package/commit/b21444cb833a3407130073207f6c692ef711646c"><code>b21444c</code></a>
    Bump Python dependencies (<a
    href="https://redirect.github.com/hynek/build-and-inspect-python-package/issues/237">#237</a>)</li>
    <li><a
    href="https://github.com/hynek/build-and-inspect-python-package/commit/fdf34a910b6a2985b8bbe0e4ec3d389f7832ef74"><code>fdf34a9</code></a>
    update actions</li>
    <li><a
    href="https://github.com/hynek/build-and-inspect-python-package/commit/60bf0a2f6cd85431ac9b57101e497425671665ba"><code>60bf0a2</code></a>
    docs: calm down section casing</li>
    <li>Additional commits viewable in <a
    href="https://github.com/hynek/build-and-inspect-python-package/compare/d44ca7d91762de7a7d5436ddae667c6da6d1c3df...2abe76da66d0a6a4a227101f9348ee855797cfa5">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=hynek/build-and-inspect-python-package&package-manager=github_actions&previous-version=2.18.0&new-version=3.0.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: Yann Pellegrini <3519082+Yann-P@users.noreply.github.com>
    dependabot[bot] and Yann-P authored Sep 4, 2026
    Configuration menu
    Copy the full SHA
    9e7ca85 View commit details
    Browse the repository at this point in the history

Commits on Sep 10, 2026

  1. Bump svgo from 4.0.2 to 4.1.0 (#2485)

    Bumps [svgo](https://github.com/svg/svgo) from 4.0.2 to 4.1.0.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/svg/svgo/releases">svgo's
    releases</a>.</em></p>
    <blockquote>
    <h2>v4.1.0</h2>
    <p>This minor release upgrades the SAX parser and introduces stricter
    XML validation. It also includes important security hardening for
    <code>removeScripts</code>, dependency updates, and improvements to the
    test and regression infrastructure.</p>
    <h3>Support SVGO</h3>
    <p>If SVGO is valuable to you or your organization, please consider <a
    href="https://opencollective.com/svgo">supporting the project on
    OpenCollective</a>. Your sponsorship helps fund ongoing maintenance and
    security work.</p>
    <h3>Stricter XML validation</h3>
    <p>SVGO now uses <a
    href="https://www.npmjs.com/package/sax"><code>sax</code> 1.6.1</a>,
    upgraded from 1.5.0 (<a
    href="https://redirect.github.com/svg/svgo/pull/2257">#2257</a>).</p>
    <p>The new parser version validates numeric character references against
    the ranges permitted by XML. Invalid references are now rejected in both
    text and attributes, including:</p>
    <ul>
    <li>disallowed control characters such as
    <code>&amp;[#1](https://github.com/svg/svgo/issues/1);</code>,
    <code>&amp;#xB;</code>, and <code>&amp;#x1F;</code>;</li>
    <li>UTF-16 surrogate code points such as <code>&amp;#xD800;</code>;</li>
    <li>invalid XML code points such as <code>&amp;#xFFFF;</code>.</li>
    </ul>
    <p>Valid boundary values—including <code>U+0020</code>,
    <code>U+D7FF</code>, <code>U+E000</code>, <code>U+FFFD</code>, and
    characters through <code>U+10FFFF</code>—remain supported.</p>
    <p>Parser failures are consistently exposed as
    <code>SvgoParserError</code> errors with an <code>Invalid character
    entity</code> reason.</p>
    <p>This is an intentional behavior change: malformed SVGs that were
    previously accepted may now produce a parser error, while valid XML
    documents are unaffected.</p>
    <h3>Security</h3>
    <p>The <a
    href="https://svgo.dev/docs/plugins/removeScripts/"><code>removeScripts</code></a>
    plugin has been hardened against several script-execution bypasses:</p>
    <ul>
    <li>Filters executable <code>data:</code> URLs containing HTML, XHTML,
    or SVG documents while preserving inert data such as PNG images, and
    filters legacy <code>vbscript:</code> URLs (<a
    href="https://redirect.github.com/svg/svgo/pull/2263">#2263</a>).</li>
    <li>Sanitizes content inside SVG <code>&lt;foreignObject&gt;</code>
    elements by removing HTML event-handler attributes, <code>srcdoc</code>,
    and executable URLs from <code>action</code>, <code>data</code>,
    <code>formaction</code>, <code>href</code>, and <code>src</code>, while
    preserving non-executable HTML and visual content (<a
    href="https://redirect.github.com/svg/svgo/pull/2264">#2264</a>).</li>
    <li>Recognizes namespace-prefixed SVG <code>&lt;a&gt;</code> elements
    and removes ASCII tabs and newlines before checking URL schemes,
    preventing values such as
    <code>java&amp;[#9](https://github.com/svg/svgo/issues/9);script:</code>
    from bypassing detection while preserving elements in unrelated custom
    namespaces (<a
    href="https://redirect.github.com/svg/svgo/pull/2268">#2268</a>).</li>
    </ul>
    <p>These changes address:</p>
    <ul>
    <li><a
    href="https://github.com/svg/svgo/security/advisories/GHSA-4vpr-x523-8j87">GHSA-4vpr-x523-8j87</a></li>
    <li><a
    href="https://github.com/svg/svgo/security/advisories/GHSA-w27v-7q3p-w38r">GHSA-w27v-7q3p-w38r</a></li>
    </ul>
    <h3>Dependencies</h3>
    <ul>
    <li>Upgraded <code>css-select</code> to v6 and <code>css-what</code> to
    v7, and updated SVGO's custom selector adapter for
    <code>css-select</code> v6 (<a
    href="https://redirect.github.com/svg/svgo/pull/2244">#2244</a>).</li>
    </ul>
    <h3>Project maintenance</h3>
    <p><a href="https://github.com/TrySound"><code>@​TrySound</code></a> is
    back as an active SVGO maintainer.</p>
    <p>Many thanks to <a
    href="https://github.com/KTibow"><code>@​KTibow</code></a>, <a
    href="https://github.com/SethFalco"><code>@​SethFalco</code></a>, and <a
    href="https://github.com/XhmikosR"><code>@​XhmikosR</code></a> for
    maintaining and improving SVGO over the past several years.</p>
    <p><strong>Full Changelog:</strong> <a
    href="https://github.com/svg/svgo/compare/v4.0.2...v4.1.0">https://github.com/svg/svgo/compare/v4.0.2...v4.1.0</a></p>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/svg/svgo/commit/5765cbe4e0a930dca648c6b81d335b1522cd7375"><code>5765cbe</code></a>
    chore: prepare v4.1.0 release (<a
    href="https://redirect.github.com/svg/svgo/issues/2275">#2275</a>)</li>
    <li><a
    href="https://github.com/svg/svgo/commit/3db3ef33e409a0bc0fdaf255e46c908b00e93bc2"><code>3db3ef3</code></a>
    fix(removeScripts): handle anchor URL bypasses (<a
    href="https://redirect.github.com/svg/svgo/issues/2268">#2268</a>)</li>
    <li><a
    href="https://github.com/svg/svgo/commit/4e9b9aed2a4607cf28025871151421d5bfe86484"><code>4e9b9ae</code></a>
    chore: cache regression screenshots (<a
    href="https://redirect.github.com/svg/svgo/issues/2267">#2267</a>)</li>
    <li><a
    href="https://github.com/svg/svgo/commit/d55270ce17b99ebfe16e4fad028bd162187205a1"><code>d55270c</code></a>
    chore(regression): migrate comparison workers to Tinypool (<a
    href="https://redirect.github.com/svg/svgo/issues/2266">#2266</a>)</li>
    <li><a
    href="https://github.com/svg/svgo/commit/fd51e474a300417d9361d9302d596b1763146327"><code>fd51e47</code></a>
    fix(removeScripts): sanitize foreignObject content (<a
    href="https://redirect.github.com/svg/svgo/issues/2264">#2264</a>)</li>
    <li><a
    href="https://github.com/svg/svgo/commit/dcaf957c6eb34832844de11ef2792e3e0e8db5dd"><code>dcaf957</code></a>
    chore: optimize fixtures in a bounded worker pool (<a
    href="https://redirect.github.com/svg/svgo/issues/2265">#2265</a>)</li>
    <li><a
    href="https://github.com/svg/svgo/commit/a3542937d9c85debab04b1ff75207768caf8a058"><code>a354293</code></a>
    fix(removeScripts): filter executable data URLs (<a
    href="https://redirect.github.com/svg/svgo/issues/2263">#2263</a>)</li>
    <li><a
    href="https://github.com/svg/svgo/commit/4e0d2ac5e7abd5f12d650d3e4b4d2500d4944cc5"><code>4e0d2ac</code></a>
    ci(typecheck): return typechecking on CI</li>
    <li><a
    href="https://github.com/svg/svgo/commit/0b97fedd00a3001f1da616f61578c2c12e6cde1f"><code>0b97fed</code></a>
    test(typescript): drop tsd for vitest type testing API</li>
    <li><a
    href="https://github.com/svg/svgo/commit/f6e8ae1afb012c2b47675622728d76b9bfd734f5"><code>f6e8ae1</code></a>
    chore(pnpm): drop package.json#pnpm.onlyBuiltDependencies</li>
    <li>Additional commits viewable in <a
    href="https://github.com/svg/svgo/compare/v4.0.2...v4.1.0">compare
    view</a></li>
    </ul>
    </details>
    <details>
    <summary>Maintainer changes</summary>
    <p>This version was pushed to npm by <a
    href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new
    releaser for svgo since your current version.</p>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=svgo&package-manager=npm_and_yarn&previous-version=4.0.2&new-version=4.1.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the
    [Security Alerts
    page](https://github.com/pydata/pydata-sphinx-theme/network/alerts).
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Sep 10, 2026
    Configuration menu
    Copy the full SHA
    b2ffa22 View commit details
    Browse the repository at this point in the history
  2. Add a configuration option for which templates to skip empty checks (#���

    …2477)
    
    Thanks to new the
    [sphinx-benchmark](https://github.com/Schefflera-Arboricola/sphinx-benchmark/)
    tool, I looked at how long it was taking to build sunpy's documentation
    with our sunpy-sphinx-theme child theme of pydata-sphinx-theme.
    
    
    This is the relevant bit of the profile before I changed anything:
    
    ```
    Build time:  317.0214979859993
    ========================================================================================================================================================
    html-page-context  —  208.281944s own time (65.70% of build)  |  701 emissions  |  depth 0
    ========================================================================================================================================================
      Handler                                           Kind                Ext/Module                                   Calls       Total(s)        Avg(ms)
    --------------------------------------------------------------------------------------------------------------------------------------------------------
      update_and_remove_templates                       theme               pydata_sphinx_theme                            701     206.208510        294.163
      set_secondary_sidebar_items                       theme               pydata_sphinx_theme                            701       1.519667          2.168
    [...]
    ```
    
    I looked into this and found it was because of the template render check
    for empty templates:
    
    
    https://github.com/pydata/pydata-sphinx-theme/blob/46ac937b31ac7b54b9c4b83932dd246245395329/src/pydata_sphinx_theme/utils.py#L151-L153
    
    I was confused by this till I looked into it more, it's because the main
    left side bar is different in sunpy-sphinx-theme and has a different
    name, so was being rendered twice for each page. In pydata-sphinx-theme
    itself the main nav is skipped from this check. This PR adds a config
    option which lets me configure the sunpy-sphinx-theme to skip the empty
    check on the main nav
    (sunpy/sunpy-sphinx-theme#332).
    
    This leads to a much happier profile, and a much faster build:
    
    ```
    Build time:  190.35233786200115
    ========================================================================================================================================================
    html-page-context  —  1.670405s own time (0.88% of build)  |  701 emissions  |  depth 0
    ========================================================================================================================================================
      Handler                                           Kind                Ext/Module                                   Calls       Total(s)        Avg(ms)
    --------------------------------------------------------------------------------------------------------------------------------------------------------
      set_secondary_sidebar_items                       theme               pydata_sphinx_theme                            701       0.646747          0.923
      update_and_remove_templates                       theme               pydata_sphinx_theme                            701       0.533664          0.761
    ```
    
    ~I had some trouble figuring out exactly the right path through the
    config system, I'm not sure how best to unit test it either.~
    Cadair authored Sep 10, 2026
    Configuration menu
    Copy the full SHA
    9dea08f View commit details
    Browse the repository at this point in the history
  3. Mark the current page with aria-current in both navs (#2471)

    Closes #1886.
    
    Both navs already know which page you are on, and both say so only with
    a `current` CSS class. That is invisible to assistive technology, so a
    screen reader user gets no "you are here" in either navigation. The
    breadcrumb has used `aria-current="page"` for a while; this gives the
    sidebar and header nav the same treatment.
    
    ## Scope, and the half I have left open
    
    `current` does two jobs. It highlights the whole section you are inside,
    which is right for a visual highlight, and it marks the page you are on.
    Only the second is what `aria-current="page"` means, so the attribute
    goes only on the page actually being viewed.
    
    For the header nav that matches what @drammock asked for on the issue: a
    top-level entry is marked when you are on that page, and not when you
    are merely somewhere beneath it.
    
    | Page | breadcrumb | sidebar | header nav |
    |---|---|---|---|
    | `user_guide/ablog.html`, inside a section | yes | yes | no |
    | `user_guide/index.html`, the section's own page | yes | yes | yes |
    
    **@gabalafou's other question is deliberately still open.** You asked
    how best to convey the thing the underline and the notch convey
    visually, that the reader is somewhere inside this section. I do not
    think `aria-current="page"` is that answer, and I did not want to
    quietly decide it inside a bug fix.
    
    The candidate worth discussing is `aria-current="location"`, which is a
    valid token and is described as the current location within a context
    rather than the current page. If you like it, it is a small follow-up on
    top of this, and `is_current` already carries exactly the state it
    needs. Happy to write it either way, but it is your call to make rather
    than mine.
    
    ## The cached sidebar needed the same handling
    
    This was the interesting part. `_move_current_markers` reuses a sibling
    page's rendered sidebar and relocates the `current` markers onto this
    page's entry, so `aria-current` has to move with them. A cached sidebar
    that kept the attribute would announce **the wrong page** as the current
    one, which is worse than marking nothing at all.
    
    `test_sidebar_toctree_cache` catches this precisely, since it asserts a
    cached sidebar is byte-identical to a freshly built one. It failed until
    the attribute moved too, which is a good test.
    
    ## Verification
    
    - `tox -e py312-tests-no-cov`, **116 passed**
    - `tox -e a11y-tests-chromium`, **34 passed, 2 xfailed**
    - `tox -e docs-dev`, and I read the rendered HTML rather than trusting
    the source: on a nested page `aria-current="page"` appears twice,
    breadcrumb and sidebar, and on a section landing page three times, with
    the header nav included
    - `ruff check` and `ruff format` clean
    
    Three regression fixtures pick up the new attribute, and the diff in
    each is one line. The added test states the intent directly rather than
    leaning on those snapshots, and it fails without the change with `assert
    0 == 1` on "exactly one sidebar entry may be the current page".
    
    One note on the environment, in case it helps anyone else: `tox -e
    docs-dev` exits 1 on a missing graphviz `dot` binary **after** writing
    complete HTML, so that exit code is not a failed build.
    opensource-joe authored Sep 10, 2026
    Configuration menu
    Copy the full SHA
    5f3493b View commit details
    Browse the repository at this point in the history
  4. Bump js-yaml from 4.3.1 to 4.3.2 (#2486)

    Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.3.1 to 4.3.2.
    <details>
    <summary>Changelog</summary>
    <p><em>Sourced from <a
    href="https://github.com/nodeca/js-yaml/blob/4.3.2/CHANGELOG.md">js-yaml's
    changelog</a>.</em></p>
    <blockquote>
    <h2>4.3.2 - 2026-08-26</h2>
    <h3>Changed</h3>
    <ul>
    <li>[backport] Hard-limit merge sequence size to 100.</li>
    </ul>
    <h3>Security</h3>
    <ul>
    <li>[backport] Count empty mappings in merge sequences toward
    <code>maxTotalMergeKeys</code>
    to limit CPU usage, <a
    href="https://redirect.github.com/nodeca/js-yaml/issues/797">#797</a>.</li>
    </ul>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/nodeca/js-yaml/commit/79ca68d90f333fbe6d9e42827527e62636200191"><code>79ca68d</code></a>
    4.3.2 released</li>
    <li><a
    href="https://github.com/nodeca/js-yaml/commit/d90b6612a5a84385bdcb556c44578eac76dc0f6b"><code>d90b661</code></a>
    Backport merge limits from v5.4.1</li>
    <li>See full diff in <a
    href="https://github.com/nodeca/js-yaml/compare/4.3.1...4.3.2">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=js-yaml&package-manager=npm_and_yarn&previous-version=4.3.1&new-version=4.3.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the
    [Security Alerts
    page](https://github.com/pydata/pydata-sphinx-theme/network/alerts).
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Sep 10, 2026
    Configuration menu
    Copy the full SHA
    aa9517b View commit details
    Browse the repository at this point in the history
  5. Fix primary sidebar collapse glitches on resize and expand (#2482)

    Two fixes to the left/primary sidebar's "Collapse Sidebar" button, split
    out of #2474, in order to simplify review.
    
    Each clip shows `main` on the left and this branch on the right.
    Developed with AI tooling (Claude, Opus 5/Fable 5.1). I take
    responsibility for the changes and will stay around to followup with
    fixes if there is trouble.
    
    ## Resizing the window no longer animates the layout
    
    
    https://github.com/user-attachments/assets/c8068bbd-d548-4272-a30e-1aecbf3c182f
    
    What to look at: the moment the window widens. On the left (`main`) the
    sidebar comes in too wide and the article is squeezed into a narrow
    column for a moment before both settle. On the right (this PR) the
    layout settles at once.
    
    <details>
    <summary>Why it happens and how it is fixed</summary>
    
    The collapse button animates the sidebar by transitioning `width`, but
    that declaration is not scoped to a viewport width, so it also animates
    the width change the breakpoint itself causes. For 400ms after widening
    the window past 960px the article is a quarter of its width and the page
    nearly twice as tall as it settles at, and the text moves under the
    reader.
    
    The collapse button now animates a custom property instead of `width`,
    so a resize changes nothing that is animated. The property is
    `--pst-sidebar-primary-width`, registered with `@property` so it can be
    transitioned. The collapse animation itself is unchanged. A sidebar that
    was collapsed before the resize keeps its collapsed width on both sides
    of the breakpoint, so that case does not animate either (it never did on
    `main`, and the test keeps it that way).
    
    Browser support: `@property` has been in Chrome since 85 (2020), Safari
    since 16.4 (2023) and Firefox since 128 (2024). In an older browser the
    sidebar still lays out correctly; only the collapse button's width
    animation is lost, the sidebar just changes width at once.
    
    </details>
    
    ## Expanding the sidebar fades its content back in
    
    
    https://github.com/user-attachments/assets/0ed0d32b-1bb6-4602-b144-74c084719396
    
    What to look at: the second press, when the sidebar expands again. On
    the left the navigation and the "Collapse Sidebar" label pop in at once
    while the sidebar is still widening. On the right they fade in as the
    sidebar widens.
    
    <details>
    <summary>Why it happens and how it is fixed</summary>
    
    The sidebar's content fades out when it collapses but snaps back when it
    expands. The delay for the expanding case is written as the string
    `"0s"`, which Sass emits quoted and the browser discards as an invalid
    transition declaration, so the content is shown at once instead of
    fading in.
    
    </details>
    
    ## Tests
    
    `test_sidebar_width_not_animated_across_breakpoint`: widening past the
    breakpoint must leave no transition running on the sidebar and must not
    change its width afterwards. It runs twice, with the sidebar expanded
    and collapsed. The expanded run fails on `main` and passes here; the
    collapsed run passes on both and guards the new custom property.
    Measured on Chromium only.
    
    ## How this was tested
    
    Default theme configuration. Nothing here depends on a theme option: the
    collapse button is part of the primary sidebar the theme ships by
    default (`html_sidebars` not overridden), and the width bug also
    reproduces on the theme's own docs at
    pydata-sphinx-theme.readthedocs.io.
    
    The clips come from a small Sphinx site made for this: a nested toctree
    so the sidebar has entries, one page with thirty sections, otherwise
    default options. The same site is built once with `main` and once with
    this branch and the two are recorded side by side in Chromium through
    Playwright, at 1400x900 with the window narrowed to 700px for the
    resize.
    
    The Playwright test uses the `sidebars` test site already in the repo
    (`tests/sites/sidebars`), whose only configuration is turning the
    primary sidebar off on one page.
    consideRatio authored Sep 10, 2026
    Configuration menu
    Copy the full SHA
    6344b44 View commit details
    Browse the repository at this point in the history
  6. Bump 0.21.0 -> 0.22.0rc0

    Yann-P committed Sep 10, 2026
    Configuration menu
    Copy the full SHA
    dbbd279 View commit details
    Browse the repository at this point in the history

Commits on Sep 16, 2026

  1. Upgrade and fix precommit issues (#2487)

    Supersedes #2462
    Yann-P authored Sep 16, 2026
    Configuration menu
    Copy the full SHA
    f243d8e View commit details
    Browse the repository at this point in the history

Commits on Sep 17, 2026

  1. Remove flaky animation test

    Introduced by #2482
    
    Since it is a test for an animation, I do not believe it is worth the
    trouble
    Yann-P committed Sep 17, 2026
    Configuration menu
    Copy the full SHA
    902af21 View commit details
    Browse the repository at this point in the history

Commits on Sep 18, 2026

  1. Fix behavior on X.Y stable for X.Y.Z releases (#2497)

    Make a `version_match=1.13` work for release `1.13.2`. In `main`, the
    banner compares the release string against the preferred entry's
    version, so a patch release of the stable minor shows "unstable
    development version" unless the JSON version (and hence `version_match`)
    is rewritten and everything rebuilt for every point release. This has
    been a stumbling block for multiple projects, namely #1552, #1629,
    #1908, and now MNE-Python:
    
    <img width="1126" height="715" alt="Screenshot 2026-09-16 at 09 49 06"
    src="https://github.com/user-attachments/assets/fe3aa34a-e175-492b-b67d-c7b55c57e07c"
    />
    
    (We didn't hit this bug until now because we had our own version-warning
    script -- which PST's `showVersionWarningBanner` was originally adapted
    from I think -- that [I removed
    recently](mne-tools/mne-python#14158) in favor
    of the theme's banner; that script decided stable vs not from the URL
    path, i.e. the same identity version_match carries here.)
    
    The fix checks `version_match` against the preferred entry before
    falling back to the release-string comparison, so existing setups are
    unaffected. The only case in the added test that fails on main is the
    1.13.2 / 1.13 row, so other behaviors should hopefully be safely
    preserved. This is the release vs version fragility described in #1629.
    With `version_match` checked first, the banner and the switcher agree on
    what the current version is. But that issue cites other issues like doc
    clarity so no `Closes` on it I think.
    
    It would be great to get this fix into 0.22 if possible!
    
    Changes drafted with Claude Fable 5.1 but reviewed / understood by me
    (even though my JS skills are limited!).
    larsoner authored Sep 18, 2026
    Configuration menu
    Copy the full SHA
    d2b1e71 View commit details
    Browse the repository at this point in the history

Commits on Sep 22, 2026

  1. Replace the unmaintained Graphviz setup action (#2495)

    Fixes #2493
    
    ## Summary
    
    - replace `ts-graphviz/setup-graphviz@v2` with the package manager
    already available on each hosted runner
    - keep Homebrew on the macOS runner image snapshot instead of updating
    into a potentially inconsistent formula/bottle state
    - verify that `dot` is available after every requested Graphviz
    installation
    
    This keeps the existing `graphviz` input and its callers unchanged while
    removing the deprecated Node-based action dependency. It also preserves
    the no-update behavior used to avoid the macOS failure in #2490.
    
    ## Validation
    
    - `pre-commit` trailing-whitespace and end-of-file hooks
    - `actionlint .github/workflows/*.yml` (completed with the repository’s
    existing shellcheck diagnostics)
    - parsed the composite action as YAML
    - `HOMEBREW_NO_AUTO_UPDATE=1 brew install --dry-run graphviz` on macOS
    
    The repository’s docs and accessibility matrices exercise the
    installation on Linux, macOS, and Windows.
    
    ---------
    
    Co-authored-by: Yann Pellegrini <mail@yann-p.fr>
    Junaid-PK and Yann-P authored Sep 22, 2026
    Configuration menu
    Copy the full SHA
    4696cdc View commit details
    Browse the repository at this point in the history
  2. Bump scientific-python/upload-nightly-action from 0.6.4 to 0.6.5 (#2488)

    Bumps
    [scientific-python/upload-nightly-action](https://github.com/scientific-python/upload-nightly-action)
    from 0.6.4 to 0.6.5.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/scientific-python/upload-nightly-action/releases">scientific-python/upload-nightly-action's
    releases</a>.</em></p>
    <blockquote>
    <h2>0.6.5</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>Add details about the consequences of not regularly uploading wheels
    by <a href="https://github.com/betatim"><code>@​betatim</code></a> in <a
    href="https://redirect.github.com/scientific-python/upload-nightly-action/pull/173">scientific-python/upload-nightly-action#173</a></li>
    <li>Add issue-opener when wheels are almost dead by <a
    href="https://github.com/larsoner"><code>@​larsoner</code></a> in <a
    href="https://redirect.github.com/scientific-python/upload-nightly-action/pull/175">scientific-python/upload-nightly-action#175</a></li>
    <li>MNT: Update to pixi lock spec v7 and project version v0.6.5 by <a
    href="https://github.com/matthewfeickert"><code>@​matthewfeickert</code></a>
    in <a
    href="https://redirect.github.com/scientific-python/upload-nightly-action/pull/183">scientific-python/upload-nightly-action#183</a></li>
    </ul>
    <h2>New Contributors</h2>
    <ul>
    <li><a href="https://github.com/larsoner"><code>@​larsoner</code></a>
    made their first contribution in <a
    href="https://redirect.github.com/scientific-python/upload-nightly-action/pull/175">scientific-python/upload-nightly-action#175</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/scientific-python/upload-nightly-action/compare/0.6.4...0.6.5">https://github.com/scientific-python/upload-nightly-action/compare/0.6.4...0.6.5</a></p>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/scientific-python/upload-nightly-action/commit/16fa02eacee1655195143de09f03676e60ef2bf5"><code>16fa02e</code></a>
    MNT: Update to pixi lock spec v7 and project version v0.6.5 (<a
    href="https://redirect.github.com/scientific-python/upload-nightly-action/issues/183">#183</a>)</li>
    <li><a
    href="https://github.com/scientific-python/upload-nightly-action/commit/fd44fdec3c85b792b5857cda6fbab11b7a40e68e"><code>fd44fde</code></a>
    chore: Move requirements file under tools/ (<a
    href="https://redirect.github.com/scientific-python/upload-nightly-action/issues/182">#182</a>)</li>
    <li><a
    href="https://github.com/scientific-python/upload-nightly-action/commit/1dbb7f3d0a14e96add4c98b8eb4404673397f828"><code>1dbb7f3</code></a>
    Build(deps): Bump pygithub from 2.9.1 to 2.10.0 in the python group (<a
    href="https://redirect.github.com/scientific-python/upload-nightly-action/issues/180">#180</a>)</li>
    <li><a
    href="https://github.com/scientific-python/upload-nightly-action/commit/2ca17bdd99443b3331cd4bf71240377b56decc97"><code>2ca17bd</code></a>
    Build(deps): Bump prefix-dev/setup-pixi in the actions group (<a
    href="https://redirect.github.com/scientific-python/upload-nightly-action/issues/179">#179</a>)</li>
    <li><a
    href="https://github.com/scientific-python/upload-nightly-action/commit/1a97ddfaddedd815698cafe2c0c3463fd43f9095"><code>1a97ddf</code></a>
    Build(deps): Bump the actions group with 3 updates (<a
    href="https://redirect.github.com/scientific-python/upload-nightly-action/issues/177">#177</a>)</li>
    <li><a
    href="https://github.com/scientific-python/upload-nightly-action/commit/c88d30e2c2fc9bfeb991ce88d07ed259ffbe6772"><code>c88d30e</code></a>
    Add issue-opener when wheels are almost dead (<a
    href="https://redirect.github.com/scientific-python/upload-nightly-action/issues/175">#175</a>)</li>
    <li><a
    href="https://github.com/scientific-python/upload-nightly-action/commit/d7703012cf92b5a200b5a197117df8a5518b24a4"><code>d770301</code></a>
    Build(deps): Bump the actions group with 4 updates (<a
    href="https://redirect.github.com/scientific-python/upload-nightly-action/issues/174">#174</a>)</li>
    <li><a
    href="https://github.com/scientific-python/upload-nightly-action/commit/33e7342b1dd8f27cffee961a531c3d9ce2d34a79"><code>33e7342</code></a>
    Add details about the consequences of not regularly uploading wheels (<a
    href="https://redirect.github.com/scientific-python/upload-nightly-action/issues/173">#173</a>)</li>
    <li><a
    href="https://github.com/scientific-python/upload-nightly-action/commit/64f2a4593de027a1cec3f361b13f97033192f0c8"><code>64f2a45</code></a>
    Build(deps): Bump the actions group with 3 updates (<a
    href="https://redirect.github.com/scientific-python/upload-nightly-action/issues/170">#170</a>)</li>
    <li><a
    href="https://github.com/scientific-python/upload-nightly-action/commit/9aaae99e2011eef05e293ad9ce15a521694fe9a9"><code>9aaae99</code></a>
    Build(deps): Bump the actions group with 4 updates (<a
    href="https://redirect.github.com/scientific-python/upload-nightly-action/issues/168">#168</a>)</li>
    <li>Additional commits viewable in <a
    href="https://github.com/scientific-python/upload-nightly-action/compare/e76cfec8a4611fd02808a801b0ff5a7d7c1b2d99...16fa02eacee1655195143de09f03676e60ef2bf5">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=scientific-python/upload-nightly-action&package-manager=github_actions&previous-version=0.6.4&new-version=0.6.5)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: Yann Pellegrini <3519082+Yann-P@users.noreply.github.com>
    dependabot[bot] and Yann-P authored Sep 22, 2026
    Configuration menu
    Copy the full SHA
    369659d View commit details
    Browse the repository at this point in the history

Commits on Sep 25, 2026

  1. Bump 0.22.0rc0 -> 0.22.0

    Yann-P committed Sep 25, 2026
    Configuration menu
    Copy the full SHA
    eeb5304 View commit details
    Browse the repository at this point in the history
Loading