-
Notifications
You must be signed in to change notification settings - Fork 391
Comparing changes
Open a pull request
base repository: pydata/pydata-sphinx-theme
base: v0.21.0
head repository: pydata/pydata-sphinx-theme
compare: v0.22.0
- 18 commits
- 34 files changed
- 9 contributors
Commits on Aug 27, 2026
-
Configuration menu - View commit details
-
Copy full SHA for 46ac937 - Browse repository at this point
Copy the full SHA 46ac937View commit details
Commits on Aug 31, 2026
-
Bump astral-sh/setup-uv from 10.0.0 to 10.0.1 (#2478)
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 10.0.0 to 10.0.1. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/setup-uv/releases">astral-sh/setup-uv's releases</a>.</em></p> <blockquote> <h2>v10.0.1 🌈 Tolerate transient manifest timeouts</h2> <h2>Changes</h2> <p>Thank you <a href="https://github.com/arguile"><code>@arguile</code></a>- for making this action more resilient.</p> <h2>🐛 Bug fixes</h2> <ul> <li>Tolerate transient manifest timeouts <a href="https://github.com/arguile"><code>@arguile</code></a>- (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/1016">#1016</a>)</li> </ul> <h2>🧰 Maintenance</h2> <ul> <li>chore: update known checksums for 0.12.4 @<a href="https://github.com/apps/github-actions">github-actions[bot]</a> (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/1017">#1017</a>)</li> </ul> <h2>📚 Documentation</h2> <ul> <li>docs: update version references to v10.0.0 @<a href="https://github.com/apps/github-actions">github-actions[bot]</a> (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/1014">#1014</a>)</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/astral-sh/setup-uv/commit/20cfd1bf945f4377ade1205e4dbc17946fc9a30d"><code>20cfd1b</code></a> chore: update known checksums for 0.12.4 (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/1017">#1017</a>)</li> <li><a href="https://github.com/astral-sh/setup-uv/commit/d73a0cab66a532d7afa440d9df4a67ea9fe65a30"><code>d73a0ca</code></a> Tolerate transient manifest timeouts (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/1016">#1016</a>)</li> <li><a href="https://github.com/astral-sh/setup-uv/commit/ae3b92d1bdb308a10adfe7b8f408e5cc8c30f3f6"><code>ae3b92d</code></a> docs: update version references to v10.0.0 (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/1014">#1014</a>)</li> <li>See full diff in <a href="https://github.com/astral-sh/setup-uv/compare/ae62891fec2bb8e7d6c99fc78c9fec3a63790f8d...20cfd1bf945f4377ade1205e4dbc17946fc9a30d">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 1ba2644 - Browse repository at this point
Copy the full SHA 1ba2644View commit details
Commits on Sep 2, 2026
-
Bump postcss-selector-parser (#2479)
Bumps and [postcss-selector-parser](https://github.com/postcss/postcss-selector-parser). These dependencies needed to be updated together. Updates `postcss-selector-parser` from 6.0.16 to 6.1.4 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/postcss/postcss-selector-parser/releases">postcss-selector-parser's releases</a>.</em></p> <blockquote> <h2>6.1.4</h2> <ul> <li>fix: tolerate non-node children when serializing selectors</li> </ul> <h2>6.1.3</h2> <ul> <li>Fix <a href="https://github.com/advisories/GHSA-w9m9-85wc-3x92">CVE-2026-9358</a> (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 via backport of (<a href="https://redirect.github.com/postcss/postcss-selector-parser/pull/316">#316</a> by <a href="https://github.com/MoOx"><code>@MoOx</code></a>)</li> </ul> <h2>v6.1.2</h2> <h1>6.1.2</h1> <ul> <li>Fixed: erroneous trailing combinators in pseudos</li> </ul> <h2>v6.1.1</h2> <h1>6.1.1</h1> <ul> <li>Fixed: improve typings of constructor helpers (<a href="https://redirect.github.com/postcss/postcss-selector-parser/issues/292">#292</a>)</li> </ul> <h2>v6.1.0</h2> <h1>6.1.0</h1> <ul> <li>Feature: add <code>sourceIndex</code> to <code>Selector</code> nodes (<a href="https://redirect.github.com/postcss/postcss-selector-parser/issues/290">#290</a>)</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/postcss/postcss-selector-parser/blob/main/CHANGELOG.md">postcss-selector-parser's changelog</a>.</em></p> <blockquote> <h1>Changelog of <code>postcss-selector-parser</code></h1> <h2>7.1.5 - 2026-08-07</h2> <ul> <li>fix: don't treat a non-prefix token before <code>|</code> as a namespace (<a href="https://redirect.github.com/postcss/postcss-selector-parser/pull/324">#324</a> by <a href="https://github.com/spokodev"><code>@spokodev</code></a>)</li> <li>fix: preserve whitespace before a <code>*</code> namespace in attribute selectors (<a href="https://redirect.github.com/postcss/postcss-selector-parser/pull/325">#325</a> by <a href="https://github.com/spokodev"><code>@spokodev</code></a>)</li> <li>fix: TypeError on unclosed <code>[</code>, <code>(</code> and trailing <code>|</code> (<a href="https://redirect.github.com/postcss/postcss-selector-parser/pull/330">#330</a> by <a href="https://github.com/theRizwan"><code>@theRizwan</code></a>)</li> </ul> <h2>7.1.4 - 2026-06-11</h2> <ul> <li>fix: tolerate non-node children when serializing selectors</li> </ul> <h2>7.1.3 - 2026-06-11</h2> <ul> <li>Improve fix CVE-2026-9358 (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 (clone/walk)</li> </ul> <h2>7.1.2 - 2026-06-09</h2> <ul> <li>Fix <a href="https://github.com/advisories/GHSA-w9m9-85wc-3x92">CVE-2026-9358</a> (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 (<a href="https://redirect.github.com/postcss/postcss-selector-parser/pull/316">#316</a> by <a href="https://github.com/MoOx"><code>@MoOx</code></a>)</li> </ul> <h2>7.1.1</h2> <ul> <li>perf: replace startsWith with strict equality (<a href="https://redirect.github.com/postcss/postcss-selector-parser/issues/308">#308</a>)</li> <li>fix(types): add walkUniversal declaration (<a href="https://redirect.github.com/postcss/postcss-selector-parser/issues/311">#311</a>)</li> </ul> <h2>7.1.0</h2> <ul> <li>feat: insert(Before|After) support multiple new node</li> </ul> <h2>7.0.0</h2> <ul> <li>Feat: make insertions during iteration safe (major)</li> </ul> <h2>6.1.2</h2> <ul> <li>Fixed: erroneous trailing combinators in pseudos</li> </ul> <h2>6.1.1</h2> <ul> <li>Fixed: improve typings of constructor helpers (<a href="https://redirect.github.com/postcss/postcss-selector-parser/issues/292">#292</a>)</li> </ul> <h2>6.1.0</h2> <ul> <li>Feature: add <code>sourceIndex</code> to <code>Selector</code> nodes (<a href="https://redirect.github.com/postcss/postcss-selector-parser/issues/290">#290</a>)</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/postcss/postcss-selector-parser/commit/4a7e4e3685db8ab8e52e51ecdbe8162a8568f70c"><code>4a7e4e3</code></a> 7.1.4</li> <li><a href="https://github.com/postcss/postcss-selector-parser/commit/e2021c523d5ef1bf27836aef3bd724a28ba7894f"><code>e2021c5</code></a> fix: tolerate non-node children when serializing selectors</li> <li><a href="https://github.com/postcss/postcss-selector-parser/commit/7893b741fa87d0401e39c3a7f00d89cf7408ad32"><code>7893b74</code></a> 7.1.3</li> <li><a href="https://github.com/postcss/postcss-selector-parser/commit/5bc698cef66f8abd12610dc623e5d67cbc0f869d"><code>5bc698c</code></a> Improve fix CVE-2026-9358 (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 (clo...</li> <li><a href="https://github.com/postcss/postcss-selector-parser/commit/db3232710d7270b34e50b4ffae493ac19204f570"><code>db32327</code></a> run oxfmt</li> <li><a href="https://github.com/postcss/postcss-selector-parser/commit/16e2581b40894504cf2b979fc0ebf7d0b2f39366"><code>16e2581</code></a> simplify deps (<a href="https://redirect.github.com/postcss/postcss-selector-parser/issues/319">#319</a>)</li> <li><a href="https://github.com/postcss/postcss-selector-parser/commit/b185e2057871669f9c571ad82e4350799e0a2329"><code>b185e20</code></a> Add description in package.json + full repo url</li> <li><a href="https://github.com/postcss/postcss-selector-parser/commit/de415f19aac008f0e731590222f3a963193be05c"><code>de415f1</code></a> Add Tidelift security notice</li> <li><a href="https://github.com/postcss/postcss-selector-parser/commit/c4f2c8c04a8107e4e401f257ef00592b59633774"><code>c4f2c8c</code></a> CI: make Node 14 test job lockfile-v3 compatible (<a href="https://redirect.github.com/postcss/postcss-selector-parser/issues/318">#318</a>)</li> <li><a href="https://github.com/postcss/postcss-selector-parser/commit/4e93663bfe861f9fc3173db603c8fadb70f8090a"><code>4e93663</code></a> Fix test run on node < 20</li> <li>Additional commits viewable in <a href="https://github.com/postcss/postcss-selector-parser/compare/v6.0.16...6.1.4">compare view</a></li> </ul> </details> <details> <summary>Maintainer changes</summary> <p>This version was pushed to npm by <a href="https://www.npmjs.com/~moox">moox</a>, a new releaser for postcss-selector-parser since your current version.</p> </details> <br /> Updates `postcss-selector-parser` from 7.1.1 to 7.1.5 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/postcss/postcss-selector-parser/releases">postcss-selector-parser's releases</a>.</em></p> <blockquote> <h2>6.1.4</h2> <ul> <li>fix: tolerate non-node children when serializing selectors</li> </ul> <h2>6.1.3</h2> <ul> <li>Fix <a href="https://github.com/advisories/GHSA-w9m9-85wc-3x92">CVE-2026-9358</a> (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 via backport of (<a href="https://redirect.github.com/postcss/postcss-selector-parser/pull/316">#316</a> by <a href="https://github.com/MoOx"><code>@MoOx</code></a>)</li> </ul> <h2>v6.1.2</h2> <h1>6.1.2</h1> <ul> <li>Fixed: erroneous trailing combinators in pseudos</li> </ul> <h2>v6.1.1</h2> <h1>6.1.1</h1> <ul> <li>Fixed: improve typings of constructor helpers (<a href="https://redirect.github.com/postcss/postcss-selector-parser/issues/292">#292</a>)</li> </ul> <h2>v6.1.0</h2> <h1>6.1.0</h1> <ul> <li>Feature: add <code>sourceIndex</code> to <code>Selector</code> nodes (<a href="https://redirect.github.com/postcss/postcss-selector-parser/issues/290">#290</a>)</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/postcss/postcss-selector-parser/blob/main/CHANGELOG.md">postcss-selector-parser's changelog</a>.</em></p> <blockquote> <h1>Changelog of <code>postcss-selector-parser</code></h1> <h2>7.1.5 - 2026-08-07</h2> <ul> <li>fix: don't treat a non-prefix token before <code>|</code> as a namespace (<a href="https://redirect.github.com/postcss/postcss-selector-parser/pull/324">#324</a> by <a href="https://github.com/spokodev"><code>@spokodev</code></a>)</li> <li>fix: preserve whitespace before a <code>*</code> namespace in attribute selectors (<a href="https://redirect.github.com/postcss/postcss-selector-parser/pull/325">#325</a> by <a href="https://github.com/spokodev"><code>@spokodev</code></a>)</li> <li>fix: TypeError on unclosed <code>[</code>, <code>(</code> and trailing <code>|</code> (<a href="https://redirect.github.com/postcss/postcss-selector-parser/pull/330">#330</a> by <a href="https://github.com/theRizwan"><code>@theRizwan</code></a>)</li> </ul> <h2>7.1.4 - 2026-06-11</h2> <ul> <li>fix: tolerate non-node children when serializing selectors</li> </ul> <h2>7.1.3 - 2026-06-11</h2> <ul> <li>Improve fix CVE-2026-9358 (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 (clone/walk)</li> </ul> <h2>7.1.2 - 2026-06-09</h2> <ul> <li>Fix <a href="https://github.com/advisories/GHSA-w9m9-85wc-3x92">CVE-2026-9358</a> (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 (<a href="https://redirect.github.com/postcss/postcss-selector-parser/pull/316">#316</a> by <a href="https://github.com/MoOx"><code>@MoOx</code></a>)</li> </ul> <h2>7.1.1</h2> <ul> <li>perf: replace startsWith with strict equality (<a href="https://redirect.github.com/postcss/postcss-selector-parser/issues/308">#308</a>)</li> <li>fix(types): add walkUniversal declaration (<a href="https://redirect.github.com/postcss/postcss-selector-parser/issues/311">#311</a>)</li> </ul> <h2>7.1.0</h2> <ul> <li>feat: insert(Before|After) support multiple new node</li> </ul> <h2>7.0.0</h2> <ul> <li>Feat: make insertions during iteration safe (major)</li> </ul> <h2>6.1.2</h2> <ul> <li>Fixed: erroneous trailing combinators in pseudos</li> </ul> <h2>6.1.1</h2> <ul> <li>Fixed: improve typings of constructor helpers (<a href="https://redirect.github.com/postcss/postcss-selector-parser/issues/292">#292</a>)</li> </ul> <h2>6.1.0</h2> <ul> <li>Feature: add <code>sourceIndex</code> to <code>Selector</code> nodes (<a href="https://redirect.github.com/postcss/postcss-selector-parser/issues/290">#290</a>)</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/postcss/postcss-selector-parser/commit/4a7e4e3685db8ab8e52e51ecdbe8162a8568f70c"><code>4a7e4e3</code></a> 7.1.4</li> <li><a href="https://github.com/postcss/postcss-selector-parser/commit/e2021c523d5ef1bf27836aef3bd724a28ba7894f"><code>e2021c5</code></a> fix: tolerate non-node children when serializing selectors</li> <li><a href="https://github.com/postcss/postcss-selector-parser/commit/7893b741fa87d0401e39c3a7f00d89cf7408ad32"><code>7893b74</code></a> 7.1.3</li> <li><a href="https://github.com/postcss/postcss-selector-parser/commit/5bc698cef66f8abd12610dc623e5d67cbc0f869d"><code>5bc698c</code></a> Improve fix CVE-2026-9358 (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 (clo...</li> <li><a href="https://github.com/postcss/postcss-selector-parser/commit/db3232710d7270b34e50b4ffae493ac19204f570"><code>db32327</code></a> run oxfmt</li> <li><a href="https://github.com/postcss/postcss-selector-parser/commit/16e2581b40894504cf2b979fc0ebf7d0b2f39366"><code>16e2581</code></a> simplify deps (<a href="https://redirect.github.com/postcss/postcss-selector-parser/issues/319">#319</a>)</li> <li><a href="https://github.com/postcss/postcss-selector-parser/commit/b185e2057871669f9c571ad82e4350799e0a2329"><code>b185e20</code></a> Add description in package.json + full repo url</li> <li><a href="https://github.com/postcss/postcss-selector-parser/commit/de415f19aac008f0e731590222f3a963193be05c"><code>de415f1</code></a> Add Tidelift security notice</li> <li><a href="https://github.com/postcss/postcss-selector-parser/commit/c4f2c8c04a8107e4e401f257ef00592b59633774"><code>c4f2c8c</code></a> CI: make Node 14 test job lockfile-v3 compatible (<a href="https://redirect.github.com/postcss/postcss-selector-parser/issues/318">#318</a>)</li> <li><a href="https://github.com/postcss/postcss-selector-parser/commit/4e93663bfe861f9fc3173db603c8fadb70f8090a"><code>4e93663</code></a> Fix test run on node < 20</li> <li>Additional commits viewable in <a href="https://github.com/postcss/postcss-selector-parser/compare/v6.0.16...6.1.4">compare view</a></li> </ul> </details> <details> <summary>Maintainer changes</summary> <p>This version was pushed to npm by <a href="https://www.npmjs.com/~moox">moox</a>, a new releaser for postcss-selector-parser since your current version.</p> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/pydata/pydata-sphinx-theme/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for a9100da - Browse repository at this point
Copy the full SHA a9100daView commit details -
Bump browserslist from 4.28.1 to 4.28.8 (#2480)
Bumps [browserslist](https://github.com/browserslist/browserslist) from 4.28.1 to 4.28.8. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/browserslist/browserslist/releases">browserslist's releases</a>.</em></p> <blockquote> <h2>4.28.8</h2> <ul> <li>Fixed <code>including kaios</code> in baseline queries (by <a href="https://github.com/Jaybhade"><code>@Jaybhade</code></a>).</li> </ul> <h2>4.28.7</h2> <ul> <li>Improved parsing performance.</li> <li>Fixed unbounded memory growth (by <a href="https://github.com/alanturing881"><code>@alanturing881</code></a>).</li> <li>Fixed prototype write issue (by <a href="https://github.com/alanturing881"><code>@alanturing881</code></a>).</li> </ul> <h2>4.28.6</h2> <ul> <li>Fixed Electron version queries (by <a href="https://github.com/spokodev"><code>@spokodev</code></a>).</li> </ul> <h2>4.28.5</h2> <ul> <li>Fixed <code>></code> and <code>>=</code> queries (by <a href="https://github.com/spokodev"><code>@spokodev</code></a>).</li> </ul> <h2>4.28.4</h2> <ul> <li>Fixed <code>SyntaxError</code> regression of 4.28.3.</li> </ul> <h2>4.28.3</h2> <ul> <li>Fixed baseline query case-insensitivity (by <a href="https://github.com/swwind"><code>@swwind</code></a>).</li> </ul> <h2>4.28.2</h2> <ul> <li>Fix prototype pollution (by <a href="https://github.com/chluo1997"><code>@chluo1997</code></a>).</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md">browserslist's changelog</a>.</em></p> <blockquote> <h2>4.28.8</h2> <ul> <li>Fixed <code>including kaios</code> in baseline queries (by <a href="https://github.com/Jaybhade"><code>@Jaybhade</code></a>).</li> </ul> <h2>4.28.7</h2> <ul> <li>Improved parsing performance.</li> <li>Fixed unbounded memory growth (by <a href="https://github.com/alanturing881"><code>@alanturing881</code></a>).</li> <li>Fixed prototype write issue (by <a href="https://github.com/alanturing881"><code>@alanturing881</code></a>).</li> </ul> <h2>4.28.6</h2> <ul> <li>Fixed Electron version queries (by <a href="https://github.com/spokodev"><code>@spokodev</code></a>).</li> </ul> <h2>4.28.5</h2> <ul> <li>Fixed <code>></code> and <code>>=</code> queries (by <a href="https://github.com/spokodev"><code>@spokodev</code></a>).</li> </ul> <h2>4.28.4</h2> <ul> <li>Fixed <code>SyntaxError</code> regression of 4.28.3.</li> </ul> <h2>4.28.3</h2> <ul> <li>Fixed baseline query case-insensitivity (by <a href="https://github.com/swwind"><code>@swwind</code></a>).</li> </ul> <h2>4.28.2</h2> <ul> <li>Fix prototype pollution (by <a href="https://github.com/chluo1997"><code>@chluo1997</code></a>).</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/browserslist/browserslist/commit/f2f2e6cfb01bb4942941d328737546f4e2ae41ad"><code>f2f2e6c</code></a> Release 4.28.8 version</li> <li><a href="https://github.com/browserslist/browserslist/commit/d0787c88fa29ba895fea51cfe921232c7b5d1377"><code>d0787c8</code></a> Update dependencies</li> <li><a href="https://github.com/browserslist/browserslist/commit/fcf8fa9857b30ccdf801a548f5d09d3c4ff0d43f"><code>fcf8fa9</code></a> Merge pull request <a href="https://redirect.github.com/browserslist/browserslist/issues/939">#939</a> from Jaybhade/fix/baseline-kaios-without-downstream</li> <li><a href="https://github.com/browserslist/browserslist/commit/57ecd64454e9252afdd6a7e76926e13dda48a38c"><code>57ecd64</code></a> fix: support "including kaios" without downstream</li> <li><a href="https://github.com/browserslist/browserslist/commit/093a0f67bb0becda55235d767b134df3197c54a1"><code>093a0f6</code></a> Update EM banner</li> <li><a href="https://github.com/browserslist/browserslist/commit/b637868045806d2fba4c24eb0060e4cc8b1db276"><code>b637868</code></a> Release 4.28.7 version</li> <li><a href="https://github.com/browserslist/browserslist/commit/313f4659b9f985ade89d1d6a54a860371c41cc46"><code>313f465</code></a> Update dependencies</li> <li><a href="https://github.com/browserslist/browserslist/commit/c935c5a206f8b13db8846818bc03643e147dcbdf"><code>c935c5a</code></a> Fix regexp performance</li> <li><a href="https://github.com/browserslist/browserslist/commit/d7e9e653cb53399065943f59f0b3063987b0a008"><code>d7e9e65</code></a> Rewrite structure parsing to make it always fast</li> <li><a href="https://github.com/browserslist/browserslist/commit/ec4a55efd76bdfa506ec7ce4fea1691559e9ca8f"><code>ec4a55e</code></a> Fix import order</li> <li>Additional commits viewable in <a href="https://github.com/browserslist/browserslist/compare/4.28.1...4.28.8">compare view</a></li> </ul> </details> <details> <summary>Maintainer changes</summary> <p>This version was pushed to npm by <a href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new releaser for browserslist since your current version.</p> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/pydata/pydata-sphinx-theme/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 8a24f5d - Browse repository at this point
Copy the full SHA 8a24f5dView commit details
Commits on Sep 3, 2026
-
fix a console error when pstAnnouncementUrl is undefined (#2481)
Thanks for maintaining this! This fixes a console issue when banner data is not available.
Configuration menu - View commit details
-
Copy full SHA for f84f9b1 - Browse repository at this point
Copy the full SHA f84f9b1View commit details
Commits on Sep 4, 2026
-
Bump hynek/build-and-inspect-python-package from 2.18.0 to 3.0.1 (#2461)
Bumps [hynek/build-and-inspect-python-package](https://github.com/hynek/build-and-inspect-python-package) from 2.18.0 to 3.0.1. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/hynek/build-and-inspect-python-package/releases">hynek/build-and-inspect-python-package's releases</a>.</em></p> <blockquote> <h2>v3.0.1</h2> <h3>Fixed</h3> <ul> <li>To avoid <em>uv</em> configuration interference with the project that is being built, the installation of our own tools is now ran in a different directory. Additionally, <code>UV_EXCLUDE_NEWER</code> is unset. <a href="https://redirect.github.com/hynek/build-and-inspect-python-package/pull/240">#240</a></li> </ul> <h2>v3.0.0</h2> <h3>Security</h3> <ul> <li>Given the increase and supply-chain attacks and advancements in tooling (for example, <a href="https://github.com/suzuki-shunsuke/pinact"><em>pinact</em></a> or GitHub's Dependabot), this action will stop force-tagging minor and micro releases. This means, there will be no <code>@V3</code> or <code>@v3.0</code> tag that gets updated and force-pushed with each update. Always tag with the full version and commit hash; use <a href="https://zizmor.sh">Zizmor</a> to secure your actions if you can.</li> </ul> <h3>Changed</h3> <ul> <li>Only updates of actions and build dependencies, notably including Twine 7 that adds support for packaging metadata 2.5 and <a href="https://peps.python.org/pep-0794/">PEP 794 – Import Name Metadata</a>.</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/hynek/build-and-inspect-python-package/blob/main/CHANGELOG.md">hynek/build-and-inspect-python-package's changelog</a>.</em></p> <blockquote> <h1>Changelog</h1> <p>All notable changes to this project will be documented in this file.</p> <p>The format is based on <a href="https://keepachangelog.com/en/1.0.0/">Keep a Changelog</a>, and this project adheres to <a href="https://semver.org/spec/v2.0.0.html">Semantic Versioning</a>.</p> <!-- raw HTML omitted --> <h2><a href="https://github.com/hynek/build-and-inspect-python-package/compare/v3.0.1...HEAD">Unreleased</a></h2> <h2><a href="https://github.com/hynek/build-and-inspect-python-package/compare/v3.0.0...v3.0.1">3.0.1</a> - 2026-07-30</h2> <h3>Fixed</h3> <ul> <li>To avoid <em>uv</em> configuration interference with the project that is being built, the installation of our own tools is now ran in a different directory. Additionally, <code>UV_EXCLUDE_NEWER</code> is unset. <a href="https://redirect.github.com/hynek/build-and-inspect-python-package/pull/240">#240</a></li> </ul> <h2><a href="https://github.com/hynek/build-and-inspect-python-package/compare/v2.18.0...v3.0.0">3.0.0</a> - 2026-07-30</h2> <h3>Security</h3> <ul> <li>Given the increase and supply-chain attacks and advancements in tooling (for example, <a href="https://github.com/suzuki-shunsuke/pinact"><em>pinact</em></a> or GitHub's Dependabot), this action will stop force-tagging minor and micro releases. This means, there will be no <code>@V3</code> or <code>@v3.0</code> tag that gets updated and force-pushed with each update. Always tag with the full version and commit hash; use <a href="https://zizmor.sh">Zizmor</a> to secure your actions if you can.</li> </ul> <h3>Changed</h3> <ul> <li>Only updates of actions and build dependencies, notably including Twine 7 that adds support for packaging metadata 2.5 and <a href="https://peps.python.org/pep-0794/">PEP 794 – Import Name Metadata</a>.</li> </ul> <h2><a href="https://github.com/hynek/build-and-inspect-python-package/compare/v2.17.0...v2.18.0">2.18.0</a> - 2026-05-11</h2> <h3>Added</h3> <ul> <li>New input: <code>skip-sdist</code> to skip building the source distribution. <a href="https://redirect.github.com/hynek/build-and-inspect-python-package/issues/228">#228</a></li> </ul> <h2><a href="https://github.com/hynek/build-and-inspect-python-package/compare/v2.16.0...v2.17.0">2.17.0</a> - 2026-03-27</h2> <h3>Fixed</h3> <ul> <li>The action now passes Zizmor in pedantic mode. <a href="https://redirect.github.com/hynek/build-and-inspect-python-package/issues/212">#212</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/hynek/build-and-inspect-python-package/commit/2abe76da66d0a6a4a227101f9348ee855797cfa5"><code>2abe76d</code></a> v3.0.1</li> <li><a href="https://github.com/hynek/build-and-inspect-python-package/commit/24fa8387643ae438edaa8a8180b5971505940986"><code>24fa838</code></a> Switch to /tmp/baipp when syncing our tools (<a href="https://redirect.github.com/hynek/build-and-inspect-python-package/issues/240">#240</a>)</li> <li><a href="https://github.com/hynek/build-and-inspect-python-package/commit/c6bb487909b3140d953646377c9320f01b56da31"><code>c6bb487</code></a> Start next cycle</li> <li><a href="https://github.com/hynek/build-and-inspect-python-package/commit/12fab959b87bed57ce97554949bdd5db1207e442"><code>12fab95</code></a> v3.0.0</li> <li><a href="https://github.com/hynek/build-and-inspect-python-package/commit/c1f438b421b28a1cc4362bcd01105527b8cc56a7"><code>c1f438b</code></a> Announce changes to versioning</li> <li><a href="https://github.com/hynek/build-and-inspect-python-package/commit/444be5d3ea585ffacdcf653b917f8cfdf2cb38bd"><code>444be5d</code></a> Add changelog</li> <li><a href="https://github.com/hynek/build-and-inspect-python-package/commit/86390fb93bacde17c922e92819b4658877860f2b"><code>86390fb</code></a> update actions (<a href="https://redirect.github.com/hynek/build-and-inspect-python-package/issues/238">#238</a>)</li> <li><a href="https://github.com/hynek/build-and-inspect-python-package/commit/b21444cb833a3407130073207f6c692ef711646c"><code>b21444c</code></a> Bump Python dependencies (<a href="https://redirect.github.com/hynek/build-and-inspect-python-package/issues/237">#237</a>)</li> <li><a href="https://github.com/hynek/build-and-inspect-python-package/commit/fdf34a910b6a2985b8bbe0e4ec3d389f7832ef74"><code>fdf34a9</code></a> update actions</li> <li><a href="https://github.com/hynek/build-and-inspect-python-package/commit/60bf0a2f6cd85431ac9b57101e497425671665ba"><code>60bf0a2</code></a> docs: calm down section casing</li> <li>Additional commits viewable in <a href="https://github.com/hynek/build-and-inspect-python-package/compare/d44ca7d91762de7a7d5436ddae667c6da6d1c3df...2abe76da66d0a6a4a227101f9348ee855797cfa5">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Yann Pellegrini <3519082+Yann-P@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 9e7ca85 - Browse repository at this point
Copy the full SHA 9e7ca85View commit details
Commits on Sep 10, 2026
-
Bump svgo from 4.0.2 to 4.1.0 (#2485)
Bumps [svgo](https://github.com/svg/svgo) from 4.0.2 to 4.1.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/svg/svgo/releases">svgo's releases</a>.</em></p> <blockquote> <h2>v4.1.0</h2> <p>This minor release upgrades the SAX parser and introduces stricter XML validation. It also includes important security hardening for <code>removeScripts</code>, dependency updates, and improvements to the test and regression infrastructure.</p> <h3>Support SVGO</h3> <p>If SVGO is valuable to you or your organization, please consider <a href="https://opencollective.com/svgo">supporting the project on OpenCollective</a>. Your sponsorship helps fund ongoing maintenance and security work.</p> <h3>Stricter XML validation</h3> <p>SVGO now uses <a href="https://www.npmjs.com/package/sax"><code>sax</code> 1.6.1</a>, upgraded from 1.5.0 (<a href="https://redirect.github.com/svg/svgo/pull/2257">#2257</a>).</p> <p>The new parser version validates numeric character references against the ranges permitted by XML. Invalid references are now rejected in both text and attributes, including:</p> <ul> <li>disallowed control characters such as <code>&[#1](https://github.com/svg/svgo/issues/1);</code>, <code>&#xB;</code>, and <code>&#x1F;</code>;</li> <li>UTF-16 surrogate code points such as <code>&#xD800;</code>;</li> <li>invalid XML code points such as <code>&#xFFFF;</code>.</li> </ul> <p>Valid boundary values—including <code>U+0020</code>, <code>U+D7FF</code>, <code>U+E000</code>, <code>U+FFFD</code>, and characters through <code>U+10FFFF</code>—remain supported.</p> <p>Parser failures are consistently exposed as <code>SvgoParserError</code> errors with an <code>Invalid character entity</code> reason.</p> <p>This is an intentional behavior change: malformed SVGs that were previously accepted may now produce a parser error, while valid XML documents are unaffected.</p> <h3>Security</h3> <p>The <a href="https://svgo.dev/docs/plugins/removeScripts/"><code>removeScripts</code></a> plugin has been hardened against several script-execution bypasses:</p> <ul> <li>Filters executable <code>data:</code> URLs containing HTML, XHTML, or SVG documents while preserving inert data such as PNG images, and filters legacy <code>vbscript:</code> URLs (<a href="https://redirect.github.com/svg/svgo/pull/2263">#2263</a>).</li> <li>Sanitizes content inside SVG <code><foreignObject></code> elements by removing HTML event-handler attributes, <code>srcdoc</code>, and executable URLs from <code>action</code>, <code>data</code>, <code>formaction</code>, <code>href</code>, and <code>src</code>, while preserving non-executable HTML and visual content (<a href="https://redirect.github.com/svg/svgo/pull/2264">#2264</a>).</li> <li>Recognizes namespace-prefixed SVG <code><a></code> elements and removes ASCII tabs and newlines before checking URL schemes, preventing values such as <code>java&[#9](https://github.com/svg/svgo/issues/9);script:</code> from bypassing detection while preserving elements in unrelated custom namespaces (<a href="https://redirect.github.com/svg/svgo/pull/2268">#2268</a>).</li> </ul> <p>These changes address:</p> <ul> <li><a href="https://github.com/svg/svgo/security/advisories/GHSA-4vpr-x523-8j87">GHSA-4vpr-x523-8j87</a></li> <li><a href="https://github.com/svg/svgo/security/advisories/GHSA-w27v-7q3p-w38r">GHSA-w27v-7q3p-w38r</a></li> </ul> <h3>Dependencies</h3> <ul> <li>Upgraded <code>css-select</code> to v6 and <code>css-what</code> to v7, and updated SVGO's custom selector adapter for <code>css-select</code> v6 (<a href="https://redirect.github.com/svg/svgo/pull/2244">#2244</a>).</li> </ul> <h3>Project maintenance</h3> <p><a href="https://github.com/TrySound"><code>@TrySound</code></a> is back as an active SVGO maintainer.</p> <p>Many thanks to <a href="https://github.com/KTibow"><code>@KTibow</code></a>, <a href="https://github.com/SethFalco"><code>@SethFalco</code></a>, and <a href="https://github.com/XhmikosR"><code>@XhmikosR</code></a> for maintaining and improving SVGO over the past several years.</p> <p><strong>Full Changelog:</strong> <a href="https://github.com/svg/svgo/compare/v4.0.2...v4.1.0">https://github.com/svg/svgo/compare/v4.0.2...v4.1.0</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/svg/svgo/commit/5765cbe4e0a930dca648c6b81d335b1522cd7375"><code>5765cbe</code></a> chore: prepare v4.1.0 release (<a href="https://redirect.github.com/svg/svgo/issues/2275">#2275</a>)</li> <li><a href="https://github.com/svg/svgo/commit/3db3ef33e409a0bc0fdaf255e46c908b00e93bc2"><code>3db3ef3</code></a> fix(removeScripts): handle anchor URL bypasses (<a href="https://redirect.github.com/svg/svgo/issues/2268">#2268</a>)</li> <li><a href="https://github.com/svg/svgo/commit/4e9b9aed2a4607cf28025871151421d5bfe86484"><code>4e9b9ae</code></a> chore: cache regression screenshots (<a href="https://redirect.github.com/svg/svgo/issues/2267">#2267</a>)</li> <li><a href="https://github.com/svg/svgo/commit/d55270ce17b99ebfe16e4fad028bd162187205a1"><code>d55270c</code></a> chore(regression): migrate comparison workers to Tinypool (<a href="https://redirect.github.com/svg/svgo/issues/2266">#2266</a>)</li> <li><a href="https://github.com/svg/svgo/commit/fd51e474a300417d9361d9302d596b1763146327"><code>fd51e47</code></a> fix(removeScripts): sanitize foreignObject content (<a href="https://redirect.github.com/svg/svgo/issues/2264">#2264</a>)</li> <li><a href="https://github.com/svg/svgo/commit/dcaf957c6eb34832844de11ef2792e3e0e8db5dd"><code>dcaf957</code></a> chore: optimize fixtures in a bounded worker pool (<a href="https://redirect.github.com/svg/svgo/issues/2265">#2265</a>)</li> <li><a href="https://github.com/svg/svgo/commit/a3542937d9c85debab04b1ff75207768caf8a058"><code>a354293</code></a> fix(removeScripts): filter executable data URLs (<a href="https://redirect.github.com/svg/svgo/issues/2263">#2263</a>)</li> <li><a href="https://github.com/svg/svgo/commit/4e0d2ac5e7abd5f12d650d3e4b4d2500d4944cc5"><code>4e0d2ac</code></a> ci(typecheck): return typechecking on CI</li> <li><a href="https://github.com/svg/svgo/commit/0b97fedd00a3001f1da616f61578c2c12e6cde1f"><code>0b97fed</code></a> test(typescript): drop tsd for vitest type testing API</li> <li><a href="https://github.com/svg/svgo/commit/f6e8ae1afb012c2b47675622728d76b9bfd734f5"><code>f6e8ae1</code></a> chore(pnpm): drop package.json#pnpm.onlyBuiltDependencies</li> <li>Additional commits viewable in <a href="https://github.com/svg/svgo/compare/v4.0.2...v4.1.0">compare view</a></li> </ul> </details> <details> <summary>Maintainer changes</summary> <p>This version was pushed to npm by <a href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new releaser for svgo since your current version.</p> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/pydata/pydata-sphinx-theme/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for b2ffa22 - Browse repository at this point
Copy the full SHA b2ffa22View commit details -
Add a configuration option for which templates to skip empty checks (#���
…2477) Thanks to new the [sphinx-benchmark](https://github.com/Schefflera-Arboricola/sphinx-benchmark/) tool, I looked at how long it was taking to build sunpy's documentation with our sunpy-sphinx-theme child theme of pydata-sphinx-theme. This is the relevant bit of the profile before I changed anything: ``` Build time: 317.0214979859993 ======================================================================================================================================================== html-page-context — 208.281944s own time (65.70% of build) | 701 emissions | depth 0 ======================================================================================================================================================== Handler Kind Ext/Module Calls Total(s) Avg(ms) -------------------------------------------------------------------------------------------------------------------------------------------------------- update_and_remove_templates theme pydata_sphinx_theme 701 206.208510 294.163 set_secondary_sidebar_items theme pydata_sphinx_theme 701 1.519667 2.168 [...] ``` I looked into this and found it was because of the template render check for empty templates: https://github.com/pydata/pydata-sphinx-theme/blob/46ac937b31ac7b54b9c4b83932dd246245395329/src/pydata_sphinx_theme/utils.py#L151-L153 I was confused by this till I looked into it more, it's because the main left side bar is different in sunpy-sphinx-theme and has a different name, so was being rendered twice for each page. In pydata-sphinx-theme itself the main nav is skipped from this check. This PR adds a config option which lets me configure the sunpy-sphinx-theme to skip the empty check on the main nav (sunpy/sunpy-sphinx-theme#332). This leads to a much happier profile, and a much faster build: ``` Build time: 190.35233786200115 ======================================================================================================================================================== html-page-context — 1.670405s own time (0.88% of build) | 701 emissions | depth 0 ======================================================================================================================================================== Handler Kind Ext/Module Calls Total(s) Avg(ms) -------------------------------------------------------------------------------------------------------------------------------------------------------- set_secondary_sidebar_items theme pydata_sphinx_theme 701 0.646747 0.923 update_and_remove_templates theme pydata_sphinx_theme 701 0.533664 0.761 ``` ~I had some trouble figuring out exactly the right path through the config system, I'm not sure how best to unit test it either.~
Configuration menu - View commit details
-
Copy full SHA for 9dea08f - Browse repository at this point
Copy the full SHA 9dea08fView commit details -
Mark the current page with aria-current in both navs (#2471)
Closes #1886. Both navs already know which page you are on, and both say so only with a `current` CSS class. That is invisible to assistive technology, so a screen reader user gets no "you are here" in either navigation. The breadcrumb has used `aria-current="page"` for a while; this gives the sidebar and header nav the same treatment. ## Scope, and the half I have left open `current` does two jobs. It highlights the whole section you are inside, which is right for a visual highlight, and it marks the page you are on. Only the second is what `aria-current="page"` means, so the attribute goes only on the page actually being viewed. For the header nav that matches what @drammock asked for on the issue: a top-level entry is marked when you are on that page, and not when you are merely somewhere beneath it. | Page | breadcrumb | sidebar | header nav | |---|---|---|---| | `user_guide/ablog.html`, inside a section | yes | yes | no | | `user_guide/index.html`, the section's own page | yes | yes | yes | **@gabalafou's other question is deliberately still open.** You asked how best to convey the thing the underline and the notch convey visually, that the reader is somewhere inside this section. I do not think `aria-current="page"` is that answer, and I did not want to quietly decide it inside a bug fix. The candidate worth discussing is `aria-current="location"`, which is a valid token and is described as the current location within a context rather than the current page. If you like it, it is a small follow-up on top of this, and `is_current` already carries exactly the state it needs. Happy to write it either way, but it is your call to make rather than mine. ## The cached sidebar needed the same handling This was the interesting part. `_move_current_markers` reuses a sibling page's rendered sidebar and relocates the `current` markers onto this page's entry, so `aria-current` has to move with them. A cached sidebar that kept the attribute would announce **the wrong page** as the current one, which is worse than marking nothing at all. `test_sidebar_toctree_cache` catches this precisely, since it asserts a cached sidebar is byte-identical to a freshly built one. It failed until the attribute moved too, which is a good test. ## Verification - `tox -e py312-tests-no-cov`, **116 passed** - `tox -e a11y-tests-chromium`, **34 passed, 2 xfailed** - `tox -e docs-dev`, and I read the rendered HTML rather than trusting the source: on a nested page `aria-current="page"` appears twice, breadcrumb and sidebar, and on a section landing page three times, with the header nav included - `ruff check` and `ruff format` clean Three regression fixtures pick up the new attribute, and the diff in each is one line. The added test states the intent directly rather than leaning on those snapshots, and it fails without the change with `assert 0 == 1` on "exactly one sidebar entry may be the current page". One note on the environment, in case it helps anyone else: `tox -e docs-dev` exits 1 on a missing graphviz `dot` binary **after** writing complete HTML, so that exit code is not a failed build.
Configuration menu - View commit details
-
Copy full SHA for 5f3493b - Browse repository at this point
Copy the full SHA 5f3493bView commit details -
Bump js-yaml from 4.3.1 to 4.3.2 (#2486)
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.3.1 to 4.3.2. <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/nodeca/js-yaml/blob/4.3.2/CHANGELOG.md">js-yaml's changelog</a>.</em></p> <blockquote> <h2>4.3.2 - 2026-08-26</h2> <h3>Changed</h3> <ul> <li>[backport] Hard-limit merge sequence size to 100.</li> </ul> <h3>Security</h3> <ul> <li>[backport] Count empty mappings in merge sequences toward <code>maxTotalMergeKeys</code> to limit CPU usage, <a href="https://redirect.github.com/nodeca/js-yaml/issues/797">#797</a>.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/nodeca/js-yaml/commit/79ca68d90f333fbe6d9e42827527e62636200191"><code>79ca68d</code></a> 4.3.2 released</li> <li><a href="https://github.com/nodeca/js-yaml/commit/d90b6612a5a84385bdcb556c44578eac76dc0f6b"><code>d90b661</code></a> Backport merge limits from v5.4.1</li> <li>See full diff in <a href="https://github.com/nodeca/js-yaml/compare/4.3.1...4.3.2">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/pydata/pydata-sphinx-theme/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for aa9517b - Browse repository at this point
Copy the full SHA aa9517bView commit details -
Fix primary sidebar collapse glitches on resize and expand (#2482)
Two fixes to the left/primary sidebar's "Collapse Sidebar" button, split out of #2474, in order to simplify review. Each clip shows `main` on the left and this branch on the right. Developed with AI tooling (Claude, Opus 5/Fable 5.1). I take responsibility for the changes and will stay around to followup with fixes if there is trouble. ## Resizing the window no longer animates the layout https://github.com/user-attachments/assets/c8068bbd-d548-4272-a30e-1aecbf3c182f What to look at: the moment the window widens. On the left (`main`) the sidebar comes in too wide and the article is squeezed into a narrow column for a moment before both settle. On the right (this PR) the layout settles at once. <details> <summary>Why it happens and how it is fixed</summary> The collapse button animates the sidebar by transitioning `width`, but that declaration is not scoped to a viewport width, so it also animates the width change the breakpoint itself causes. For 400ms after widening the window past 960px the article is a quarter of its width and the page nearly twice as tall as it settles at, and the text moves under the reader. The collapse button now animates a custom property instead of `width`, so a resize changes nothing that is animated. The property is `--pst-sidebar-primary-width`, registered with `@property` so it can be transitioned. The collapse animation itself is unchanged. A sidebar that was collapsed before the resize keeps its collapsed width on both sides of the breakpoint, so that case does not animate either (it never did on `main`, and the test keeps it that way). Browser support: `@property` has been in Chrome since 85 (2020), Safari since 16.4 (2023) and Firefox since 128 (2024). In an older browser the sidebar still lays out correctly; only the collapse button's width animation is lost, the sidebar just changes width at once. </details> ## Expanding the sidebar fades its content back in https://github.com/user-attachments/assets/0ed0d32b-1bb6-4602-b144-74c084719396 What to look at: the second press, when the sidebar expands again. On the left the navigation and the "Collapse Sidebar" label pop in at once while the sidebar is still widening. On the right they fade in as the sidebar widens. <details> <summary>Why it happens and how it is fixed</summary> The sidebar's content fades out when it collapses but snaps back when it expands. The delay for the expanding case is written as the string `"0s"`, which Sass emits quoted and the browser discards as an invalid transition declaration, so the content is shown at once instead of fading in. </details> ## Tests `test_sidebar_width_not_animated_across_breakpoint`: widening past the breakpoint must leave no transition running on the sidebar and must not change its width afterwards. It runs twice, with the sidebar expanded and collapsed. The expanded run fails on `main` and passes here; the collapsed run passes on both and guards the new custom property. Measured on Chromium only. ## How this was tested Default theme configuration. Nothing here depends on a theme option: the collapse button is part of the primary sidebar the theme ships by default (`html_sidebars` not overridden), and the width bug also reproduces on the theme's own docs at pydata-sphinx-theme.readthedocs.io. The clips come from a small Sphinx site made for this: a nested toctree so the sidebar has entries, one page with thirty sections, otherwise default options. The same site is built once with `main` and once with this branch and the two are recorded side by side in Chromium through Playwright, at 1400x900 with the window narrowed to 700px for the resize. The Playwright test uses the `sidebars` test site already in the repo (`tests/sites/sidebars`), whose only configuration is turning the primary sidebar off on one page.
Configuration menu - View commit details
-
Copy full SHA for 6344b44 - Browse repository at this point
Copy the full SHA 6344b44View commit details -
Configuration menu - View commit details
-
Copy full SHA for dbbd279 - Browse repository at this point
Copy the full SHA dbbd279View commit details
Commits on Sep 16, 2026
-
Configuration menu - View commit details
-
Copy full SHA for f243d8e - Browse repository at this point
Copy the full SHA f243d8eView commit details
Commits on Sep 17, 2026
-
Introduced by #2482 Since it is a test for an animation, I do not believe it is worth the trouble
Configuration menu - View commit details
-
Copy full SHA for 902af21 - Browse repository at this point
Copy the full SHA 902af21View commit details
Commits on Sep 18, 2026
-
Fix behavior on X.Y stable for X.Y.Z releases (#2497)
Make a `version_match=1.13` work for release `1.13.2`. In `main`, the banner compares the release string against the preferred entry's version, so a patch release of the stable minor shows "unstable development version" unless the JSON version (and hence `version_match`) is rewritten and everything rebuilt for every point release. This has been a stumbling block for multiple projects, namely #1552, #1629, #1908, and now MNE-Python: <img width="1126" height="715" alt="Screenshot 2026-09-16 at 09 49 06" src="https://github.com/user-attachments/assets/fe3aa34a-e175-492b-b67d-c7b55c57e07c" /> (We didn't hit this bug until now because we had our own version-warning script -- which PST's `showVersionWarningBanner` was originally adapted from I think -- that [I removed recently](mne-tools/mne-python#14158) in favor of the theme's banner; that script decided stable vs not from the URL path, i.e. the same identity version_match carries here.) The fix checks `version_match` against the preferred entry before falling back to the release-string comparison, so existing setups are unaffected. The only case in the added test that fails on main is the 1.13.2 / 1.13 row, so other behaviors should hopefully be safely preserved. This is the release vs version fragility described in #1629. With `version_match` checked first, the banner and the switcher agree on what the current version is. But that issue cites other issues like doc clarity so no `Closes` on it I think. It would be great to get this fix into 0.22 if possible! Changes drafted with Claude Fable 5.1 but reviewed / understood by me (even though my JS skills are limited!).
Configuration menu - View commit details
-
Copy full SHA for d2b1e71 - Browse repository at this point
Copy the full SHA d2b1e71View commit details
Commits on Sep 22, 2026
-
Replace the unmaintained Graphviz setup action (#2495)
Fixes #2493 ## Summary - replace `ts-graphviz/setup-graphviz@v2` with the package manager already available on each hosted runner - keep Homebrew on the macOS runner image snapshot instead of updating into a potentially inconsistent formula/bottle state - verify that `dot` is available after every requested Graphviz installation This keeps the existing `graphviz` input and its callers unchanged while removing the deprecated Node-based action dependency. It also preserves the no-update behavior used to avoid the macOS failure in #2490. ## Validation - `pre-commit` trailing-whitespace and end-of-file hooks - `actionlint .github/workflows/*.yml` (completed with the repository’s existing shellcheck diagnostics) - parsed the composite action as YAML - `HOMEBREW_NO_AUTO_UPDATE=1 brew install --dry-run graphviz` on macOS The repository’s docs and accessibility matrices exercise the installation on Linux, macOS, and Windows. --------- Co-authored-by: Yann Pellegrini <mail@yann-p.fr>
Configuration menu - View commit details
-
Copy full SHA for 4696cdc - Browse repository at this point
Copy the full SHA 4696cdcView commit details -
Bump scientific-python/upload-nightly-action from 0.6.4 to 0.6.5 (#2488)
Bumps [scientific-python/upload-nightly-action](https://github.com/scientific-python/upload-nightly-action) from 0.6.4 to 0.6.5. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/scientific-python/upload-nightly-action/releases">scientific-python/upload-nightly-action's releases</a>.</em></p> <blockquote> <h2>0.6.5</h2> <h2>What's Changed</h2> <ul> <li>Add details about the consequences of not regularly uploading wheels by <a href="https://github.com/betatim"><code>@betatim</code></a> in <a href="https://redirect.github.com/scientific-python/upload-nightly-action/pull/173">scientific-python/upload-nightly-action#173</a></li> <li>Add issue-opener when wheels are almost dead by <a href="https://github.com/larsoner"><code>@larsoner</code></a> in <a href="https://redirect.github.com/scientific-python/upload-nightly-action/pull/175">scientific-python/upload-nightly-action#175</a></li> <li>MNT: Update to pixi lock spec v7 and project version v0.6.5 by <a href="https://github.com/matthewfeickert"><code>@matthewfeickert</code></a> in <a href="https://redirect.github.com/scientific-python/upload-nightly-action/pull/183">scientific-python/upload-nightly-action#183</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/larsoner"><code>@larsoner</code></a> made their first contribution in <a href="https://redirect.github.com/scientific-python/upload-nightly-action/pull/175">scientific-python/upload-nightly-action#175</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/scientific-python/upload-nightly-action/compare/0.6.4...0.6.5">https://github.com/scientific-python/upload-nightly-action/compare/0.6.4...0.6.5</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/scientific-python/upload-nightly-action/commit/16fa02eacee1655195143de09f03676e60ef2bf5"><code>16fa02e</code></a> MNT: Update to pixi lock spec v7 and project version v0.6.5 (<a href="https://redirect.github.com/scientific-python/upload-nightly-action/issues/183">#183</a>)</li> <li><a href="https://github.com/scientific-python/upload-nightly-action/commit/fd44fdec3c85b792b5857cda6fbab11b7a40e68e"><code>fd44fde</code></a> chore: Move requirements file under tools/ (<a href="https://redirect.github.com/scientific-python/upload-nightly-action/issues/182">#182</a>)</li> <li><a href="https://github.com/scientific-python/upload-nightly-action/commit/1dbb7f3d0a14e96add4c98b8eb4404673397f828"><code>1dbb7f3</code></a> Build(deps): Bump pygithub from 2.9.1 to 2.10.0 in the python group (<a href="https://redirect.github.com/scientific-python/upload-nightly-action/issues/180">#180</a>)</li> <li><a href="https://github.com/scientific-python/upload-nightly-action/commit/2ca17bdd99443b3331cd4bf71240377b56decc97"><code>2ca17bd</code></a> Build(deps): Bump prefix-dev/setup-pixi in the actions group (<a href="https://redirect.github.com/scientific-python/upload-nightly-action/issues/179">#179</a>)</li> <li><a href="https://github.com/scientific-python/upload-nightly-action/commit/1a97ddfaddedd815698cafe2c0c3463fd43f9095"><code>1a97ddf</code></a> Build(deps): Bump the actions group with 3 updates (<a href="https://redirect.github.com/scientific-python/upload-nightly-action/issues/177">#177</a>)</li> <li><a href="https://github.com/scientific-python/upload-nightly-action/commit/c88d30e2c2fc9bfeb991ce88d07ed259ffbe6772"><code>c88d30e</code></a> Add issue-opener when wheels are almost dead (<a href="https://redirect.github.com/scientific-python/upload-nightly-action/issues/175">#175</a>)</li> <li><a href="https://github.com/scientific-python/upload-nightly-action/commit/d7703012cf92b5a200b5a197117df8a5518b24a4"><code>d770301</code></a> Build(deps): Bump the actions group with 4 updates (<a href="https://redirect.github.com/scientific-python/upload-nightly-action/issues/174">#174</a>)</li> <li><a href="https://github.com/scientific-python/upload-nightly-action/commit/33e7342b1dd8f27cffee961a531c3d9ce2d34a79"><code>33e7342</code></a> Add details about the consequences of not regularly uploading wheels (<a href="https://redirect.github.com/scientific-python/upload-nightly-action/issues/173">#173</a>)</li> <li><a href="https://github.com/scientific-python/upload-nightly-action/commit/64f2a4593de027a1cec3f361b13f97033192f0c8"><code>64f2a45</code></a> Build(deps): Bump the actions group with 3 updates (<a href="https://redirect.github.com/scientific-python/upload-nightly-action/issues/170">#170</a>)</li> <li><a href="https://github.com/scientific-python/upload-nightly-action/commit/9aaae99e2011eef05e293ad9ce15a521694fe9a9"><code>9aaae99</code></a> Build(deps): Bump the actions group with 4 updates (<a href="https://redirect.github.com/scientific-python/upload-nightly-action/issues/168">#168</a>)</li> <li>Additional commits viewable in <a href="https://github.com/scientific-python/upload-nightly-action/compare/e76cfec8a4611fd02808a801b0ff5a7d7c1b2d99...16fa02eacee1655195143de09f03676e60ef2bf5">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Yann Pellegrini <3519082+Yann-P@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 369659d - Browse repository at this point
Copy the full SHA 369659dView commit details
Commits on Sep 25, 2026
-
Configuration menu - View commit details
-
Copy full SHA for eeb5304 - Browse repository at this point
Copy the full SHA eeb5304View commit details
This comparison is taking too long to generate.
Unfortunately it looks like we can’t render this comparison for you right now. It might be too big, or there might be something weird with your repository.
You can try running this command locally to see the comparison on your machine:
git diff v0.21.0...v0.22.0