Skip to content

Bump tornado from 6.5.7 to 6.5.8 - #464

Merged
aaronspring merged 1 commit into
mainfrom
dependabot/uv/tornado-6.5.8
Sep 21, 2026
Merged

aaronspring merged 1 commit into
mainfrom
dependabot/uv/tornado-6.5.8

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 1, 2026

Copy link
Copy Markdown
Contributor

Bumps tornado from 6.5.7 to 6.5.8.

Changelog

Sourced from tornado's changelog.

Release notes

.. toctree:: :maxdepth: 2

releases/v6.5.8 releases/v6.5.7 releases/v6.5.6 releases/v6.5.5 releases/v6.5.4 releases/v6.5.3 releases/v6.5.2 releases/v6.5.1 releases/v6.5.0 releases/v6.4.2 releases/v6.4.1 releases/v6.4.0 releases/v6.3.3 releases/v6.3.2 releases/v6.3.1 releases/v6.3.0 releases/v6.2.0 releases/v6.1.0 releases/v6.0.4 releases/v6.0.3 releases/v6.0.2 releases/v6.0.1 releases/v6.0.0 releases/v5.1.1 releases/v5.1.0 releases/v5.0.2 releases/v5.0.1 releases/v5.0.0 releases/v4.5.3 releases/v4.5.2 releases/v4.5.1 releases/v4.5.0 releases/v4.4.3 releases/v4.4.2 releases/v4.4.1 releases/v4.4.0 releases/v4.3.0 releases/v4.2.1 releases/v4.2.0 releases/v4.1.0 releases/v4.0.2 releases/v4.0.1 releases/v4.0.0 releases/v3.2.2

... (truncated)

Commits
  • a55abe3 Merge pull request #3704 from bdarnell/security-6.5.8
  • fc79488 docs: add additional credit to release notes
  • 7b01763 Fix test_strip_headers_on_redirect's URL-embedded-credentials cases
  • d72fff8 release notes and version bump for 6.5.8
  • b168818 auth: Formally deprecated OpenIDMixin
  • da28476 web: Also check for semicolons in deprecated mixed-case cookie args
  • 8d6363e httputil: Enforce a new limit on the number of arguments in a request
  • de85b3f httputil: Apply multipart max_parts limit earlier
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [tornado](https://github.com/tornadoweb/tornado) from 6.5.7 to 6.5.8.
- [Changelog](https://github.com/tornadoweb/tornado/blob/master/docs/releases.rst)
- [Commits](tornadoweb/tornado@v6.5.7...v6.5.8)

---
updated-dependencies:
- dependency-name: tornado
  dependency-version: 6.5.8
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Sep 1, 2026
@aaronspring

Copy link
Copy Markdown
Collaborator

Why is tornado in this repo at all?

It comes in exclusively through the Jupyter stack of the docs/notebook extra, on two paths:

xskillscore[complete] → ipykernel → tornado
xskillscore[complete] → nbsphinx → nbconvert → nbclient → jupyter-client → tornado

tornado provides the IOLoop and the ZMQ transport that an IPython kernel runs on, so it is needed to execute docs/source/*.ipynb during the docs build — not by any xskillscore code path.

It is not a runtime dependency. pip install xskillscore installs only dask[array], numpy, properscoring, scipy, statsmodels, xarray, xhistogram. (Note that plain dask[array] does not pull tornado either — that would be distributed, which we don't require.)

On the severity: 6.5.8 is a security release, but the fixes (multipart/argument-count limits in httputil, cookie-arg handling in web, redirect header stripping) apply to code serving untrusted HTTP with Tornado. Here Tornado only carries kernel traffic on localhost during a docs build, so the practical exposure is nil. No reason not to take the bump, just no urgency.

Same caveat as #465: uv.lock isn't consumed by any workflow — CI installs via the conda env files in ci/ plus pip install --no-deps -e . — so this bump doesn't change any environment CI or users actually get. If you want these PRs to mean something, add a uv sync --locked job; otherwise a .github/dependabot.yml grouping dev/docs transitives would cut the noise.


Generated by Claude Code

@aaronspring
aaronspring merged commit f3cd917 into main Sep 21, 2026
16 checks passed
@aaronspring
aaronspring deleted the dependabot/uv/tornado-6.5.8 branch September 21, 2026 16:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant