Skip to content

Bump fonttools from 4.65.0 to 4.66.0 - #5494

Merged
github-actions[bot] merged 1 commit into
mainfrom
dependabot/pip/fonttools-4.66.0
Sep 28, 2026
Merged

github-actions[bot] merged 1 commit into
mainfrom
dependabot/pip/fonttools-4.66.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps fonttools from 4.65.0 to 4.66.0.

Release notes

Sourced from fonttools's releases.

4.66.0

  • Drop support for EOL Python 3.10; fontTools now requires Python 3.11 or later. fontTools.misc.enumTools now only re-exports enum.StrEnum and is deprecated. Explicitly test and declare support for Python 3.15 (#4183, #4196).
  • [unicodedata] Update the bundled script, script extension, block and bidi-mirroring tables to Unicode 18.0.0, and require unicodedata2 18.0.0 when it is used (#4192, #4197).
  • [feaLib] Support language statements listing multiple language tags, e.g. language AZE CRT;adobe-type-tools/feature_file_workshops#8dflt cannot be combined with other tags. LanguageStatement.language is still the first tag; all of them are in the new languages attribute (#4201, #4202).
  • [feaLib] Fix lookups being dropped when a script/language pair is repeated within a feature block: the repeated statement replaced the language system's lookups with a fresh copy of the default ones (#4189).
  • [feaLib] Raise FeatureLibError instead of UnboundLocalError when a STAT table block lacks ElidedFallbackName or ElidedFallbackNameID (#3834, #4179).
  • [cffLib] Always recompile the CFF2 VarStore when saving. Previously the bytes compiled by an earlier save were reused, so a CFF2 variable font that was saved and then modified in place, e.g. by the instancer, was written with a stale VarStore next to its updated charstrings (#4199).
  • [ttLib] Support static VARC fonts that omit fvar while retaining gvar or CFF2 variation data for component-internal axes: hidden axes are addressed by index and gvar can compile, decompile and round-trip through TTX without fvar, reading the axis count from a new axisCount element (#4187, #4188).
  • [ttLib] Fix drawing VARC components whose condition is negated (format 5), which raised AttributeError (#4191).
  • [instancer] Fix VARC axis references left stale when removing an unrelated axis, reject pinning or restricting axes referenced by VARC components, and stop culling avar2 ranges for component-internal variations, which can reach outside the font-level ranges (#4190, #4193).
  • [bezierTools] Preserve exact endpoints in splitQuadraticAtT and splitCubicAtTC as well, like splitCubicAtT since 4.55.4 (#3742, #4194).
  • [bezierTools] Fix ZeroDivisionError in lineLineIntersections for collinear vertical lines; they are now treated as parallel like horizontal ones (#3515, #4181).
  • [subset] pyftsubset now preserves the input font's flavor (WOFF, WOFF2) when --flavor is omitted, instead of writing uncompressed sfnt data under the same extension; pass --flavor=none to force uncompressed output (#3630, #4182).
  • [merge] Report incompatible unitsPerEm values by name, with the input values, instead of a bare assertion (#2844, #4184).
  • [designspaceLib] Fix the type annotation and documentation of DesignSpaceDocument.default, which holds a SourceDescriptor, not a source name (#2994, #4186).
  • [ttLib.sfnt] Raise TTLibError instead of AssertionError for inconsistent WOFF table, metadata and private-data lengths, so the checks also hold under python -O (#4178).
  • [misc.etree] Disable entity resolution altogether on lxml >= 5.0 as well: lxml's resolve_entities="internal" still fetched external parameter entities before lxml 6.1.3, so a crafted DTD could read local files into parsed XML content (#4195).
  • [cmap] Bound the expansion of format 4 segments and format 12/13 groups when decompiling, like HarfBuzz does: groups are clamped to U+10FFFF, inverted or overlapping groups are skipped with a warning, and groups mapped to the missing glyph are not expanded. A crafted font could previously exhaust memory with a single group ending at 0xFFFFFFFF (#4204).
  • [varLib.avar] Escape axis names and tags when varLib.avar.unbuild emits its designspace snippet, so a crafted font cannot inject markup (#4203).
Changelog

Sourced from fonttools's changelog.

4.66.0 (released 2026-09-23)

  • Drop support for EOL Python 3.10; fontTools now requires Python 3.11 or later. fontTools.misc.enumTools now only re-exports enum.StrEnum and is deprecated. Explicitly test and declare support for Python 3.15 (#4183, #4196).
  • [unicodedata] Update the bundled script, script extension, block and bidi-mirroring tables to Unicode 18.0.0, and require unicodedata2 18.0.0 when it is used (#4192, #4197).
  • [feaLib] Support language statements listing multiple language tags, e.g. language AZE CRT;, as Glyphs does and as proposed for the spec adobe-type-tools/feature_file_workshops#8 references are registered under every listed language. dflt cannot be combined with other tags. LanguageStatement.language is still the first tag; all of them are in the new languages attribute (#4201, #4202).
  • [feaLib] Fix lookups being dropped when a script/language pair is repeated within a feature block: the repeated statement replaced the language system's lookups with a fresh copy of the default ones (#4189).
  • [feaLib] Raise FeatureLibError instead of UnboundLocalError when a STAT table block lacks ElidedFallbackName or ElidedFallbackNameID (#3834, #4179).
  • [cffLib] Always recompile the CFF2 VarStore when saving. Previously the bytes compiled by an earlier save were reused, so a CFF2 variable font that was saved and then modified in place, e.g. by the instancer, was written with a stale VarStore next to its updated charstrings (#4199).
  • [ttLib] Support static VARC fonts that omit fvar while retaining gvar or CFF2 variation data for component-internal axes: hidden axes are addressed by index and gvar can compile, decompile and round-trip through TTX without fvar, reading the axis count from a new axisCount element (#4187, #4188).
  • [ttLib] Fix drawing VARC components whose condition is negated (format 5), which raised AttributeError (#4191).
  • [instancer] Fix VARC axis references left stale when removing an unrelated axis, reject pinning or restricting axes referenced by VARC components, and stop culling avar2 ranges for component-internal variations, which can reach outside the font-level ranges (#4190, #4193).
  • [bezierTools] Preserve exact endpoints in splitQuadraticAtT and splitCubicAtTC as well, like splitCubicAtT since 4.55.4 (#3742, #4194).
  • [bezierTools] Fix ZeroDivisionError in lineLineIntersections for collinear vertical lines; they are now treated as parallel like horizontal ones (#3515, #4181).
  • [subset] pyftsubset now preserves the input font's flavor (WOFF, WOFF2) when --flavor is omitted, instead of writing uncompressed sfnt data under the same extension; pass --flavor=none to force uncompressed output (#3630, #4182).
  • [merge] Report incompatible unitsPerEm values by name, with the input values, instead of a bare assertion (#2844, #4184).
  • [designspaceLib] Fix the type annotation and documentation of DesignSpaceDocument.default, which holds a SourceDescriptor, not a

... (truncated)

Commits
  • f54ab64 Release 4.66.0
  • 18dd898 Update NEWS.rst [skip ci]
  • 116a3f0 Merge pull request #4204 from fonttools/cmap12-bound-group-ranges
  • 083571a [cmap] Bound format 4 and 12/13 range expansion like HarfBuzz
  • 236a218 Merge pull request #4199 from tomekthewo/cff2-stale-varstore-cache
  • 0fccde3 Merge pull request #4203 from insaf021/avar-unbuild-escape-axis-names
  • fe7aa95 escape name-table axis names in varLib.avar.unbuild output
  • 460d36e Merge pull request #4202 from fonttools/feaLib-multi-language-fixups
  • a402e4e [feaLib] Test that statement_keywords covers parse_block
  • 9939b30 [feaLib] Reject dflt combined with other language tags
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [fonttools](https://github.com/fonttools/fonttools) from 4.65.0 to 4.66.0.
- [Release notes](https://github.com/fonttools/fonttools/releases)
- [Changelog](https://github.com/fonttools/fonttools/blob/main/NEWS.rst)
- [Commits](fonttools/fonttools@4.65.0...4.66.0)

---
updated-dependencies:
- dependency-name: fonttools
  dependency-version: 4.66.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 28, 2026
@github-actions
github-actions Bot enabled auto-merge (squash) September 28, 2026 02:44
@github-actions

Copy link
Copy Markdown
Contributor

✅MegaLinter analysis: Success

Descriptor Linter Files Fixed Errors Max errors Warnings Elapsed time
✅ COPYPASTE jscpd yes no no 6.35s
✅ JSON prettier 7 0 0 0 0.58s
✅ JSON v8r 7 0 0 2.91s
✅ MARKDOWN markdownlint 68 0 0 0 1.77s
✅ MARKDOWN markdown-table-formatter 68 0 0 0 0.31s
✅ PYTHON black 2040 0 0 0 37.82s
✅ PYTHON isort 2040 0 0 0 2.18s
✅ REPOSITORY betterleaks yes no no 1.28s
✅ REPOSITORY checkov yes no no 25.96s
✅ REPOSITORY git_diff yes no no 0.18s
✅ REPOSITORY secretlint yes no no 4.71s
✅ REPOSITORY syft yes no no 2.49s
✅ REPOSITORY trivy-sbom yes no no 2.3s
✅ YAML prettier 11 0 0 0 0.79s
✅ YAML v8r 11 0 0 8.66s
✅ YAML yamllint 11 0 0 0.41s

Notices

⚠️ Your configuration references items that have been removed from MegaLinter and are ignored: MAKEFILE_CHECKMAKE. See Removed linters to find their replacements.

See detailed reports in MegaLinter artifacts

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@10.1.0 --custom-flavor-setup --custom-flavor-linters PYTHON_BLACK,PYTHON_ISORT,COPYPASTE_JSCPD,JSON_V8R,JSON_PRETTIER,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_CHECKOV,REPOSITORY_GIT_DIFF,REPOSITORY_BETTERLEAKS,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY_SBOM,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

MegaLinter is provided by OX Security
Show us your support by starring ⭐ the repository

@github-actions
github-actions Bot merged commit a38158e into main Sep 28, 2026
25 checks passed
@dependabot
dependabot Bot deleted the dependabot/pip/fonttools-4.66.0 branch September 28, 2026 03:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants