Skip to content

build(deps): bump python-slugify from 8.0.4 to 9.1.1 - #14664

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/pip/python-slugify-9.1.1
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/pip/python-slugify-9.1.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps python-slugify from 8.0.4 to 9.1.1.

Release notes

Sourced from python-slugify's releases.

9.1.1

Bug fix in the modern algorithm. Legacy output is unchanged and remains the permanent default.

  • Modern mode only: avoid emitting a trailing separator when a hard cut truncates through repeated post-replacement delimiters, keeping the delimiter run with the next word that fits. Legacy output and public smart_truncate are unchanged (曾楚笑, #200).

Full Changelog: un33k/python-slugify@v9.1.0...v9.1.1

🚀 Generated with Dojo ⛩️

9.1.0

Modern-algorithm improvements and fixes. Legacy output is unchanged and remains the permanent default.

  • Modern mode only: decode uppercase &#X..; hexadecimal references as HTML allows, in addition to lowercase &#x..; (Rupayon Haldar, #195).
  • Modern mode only: preserve post-replacement output when the whole slug already fits max_length, so intentional repeated/trailing delimiters are not collapsed at the length limit. Public smart_truncate is unchanged (emme1t, #193).
  • Fix add_uppercase_char to apply insertions atomically, leaving the input list unchanged if iteration fails. Built-in transliteration tables are unaffected (Cristian Ramirez, #194).
  • Modern mode only: validate argument types up front, raising TypeError for a bool/non-int max_length or a non-str separator. Legacy behavior is unchanged (Jon Bailey, #196).

Internal: the legacy pipeline is now frozen in slugify/_legacy.py with the public slugify() dispatching by algorithm; tests reorganized under tests/.

Full Changelog: un33k/python-slugify@v9.0.0...v9.1.0

🚀 Generated with Dojo ⛩️

9.0.0

Highlights

  • Preserve legacy slug output by default while adding explicit algorithm="modern" opt-in behavior.
  • Add explicit transliteration backend and replacement-stage controls, with matching CLI options.
  • Add opt-in AnyASCII support while preserving existing dependency and backend-selection behavior.
  • Fix CLI regex-pattern forwarding and modern-mode handling for entities, iterables, separators, and delimiters.
  • Add Python 3.14 support, packaging modernization, expanded compatibility checks, and migration guidance.

See the changelog and migration guide for details.

PyPI: https://pypi.org/project/python-slugify/9.0.0/

🚀 Created with Dojo ⛩️

Changelog

Sourced from python-slugify's changelog.

9.1.1

  • Modern mode only: avoid emitting a trailing separator when a hard cut truncates through repeated post-replacement delimiters, keeping the delimiter run with the next word that fits. Legacy output and public smart_truncate are unchanged (曾楚笑, #200).

9.1.0

  • Modern mode only: decode uppercase &#X..; hexadecimal references as HTML allows, in addition to lowercase &#x..;. Legacy output is unchanged (Rupayon Haldar, #195).
  • Modern mode only: preserve post-replacement output when the whole slug already fits max_length, so intentional repeated/trailing delimiters are not collapsed at the length limit. Public smart_truncate is unchanged (emme1t, #193).
  • Fix add_uppercase_char to apply insertions atomically, leaving the input list unchanged if iteration fails. Built-in transliteration tables are unaffected (Cristian Ramirez, #194).
  • Modern mode only: validate argument types up front, raising TypeError for a bool/non-int max_length (bool is an int subclass) or a non-str separator. Legacy behavior is unchanged and still treats max_length=True as its historical single-character truncation (Jon Bailey, #196).

9.0.0 — unreleased

  • Add keyword-only algorithm='legacy' (permanent default) and explicit algorithm='modern' opt-in, plus CLI --algorithm. Preserve historical default entity ordering, numeric handling, iterator consumption, separator truncation, and public smart_truncate behavior.

  • Preserve legacy auto backend selection and two-pass replacement defaults; add explicit backend and replacement_stage keyword-only options and matching CLI flags.

  • Add opt-in AnyASCII extra without removing or changing the base text-unidecode dependency.

  • Forward CLI --regex-pattern (Jacobo de Vera, #176; report by @​peter-bloomfield, #175).

  • Modern mode only: decode entities before transliteration; handle invalid numeric references per match, including surrogate references (#178, #181, #187).

  • Modern mode only: materialize replacement rules and stopword iterables consistently; preserve bytes/bytearray UTF-8 input with clear rejection of unsupported types (#183, #190).

  • Modern mode only: budget internal tokens using emitted separator widths, support empty separators, and preserve literal word characters that match delimiters. Public smart_truncate remains unchanged (#47, #185, #186).

  • Add regression coverage for whitespace, ordinals, backend-specific output, replacement stages, CLI execution, and installed artifacts.

  • Move package metadata to pyproject.toml, retain the typed marker and source tests, and remove the unsafe publish/upload/tag shortcut.

  • Document output changes, backend license distinctions, compatibility limits, and migration precautions in docs/release-9/migration.md.

  • Support Python 3.14.

  • Drop support for Python 3.9 and lower.

  • Use tox for local test runs and in CI.

  • Test the project against both unidecode and text_unidecode.

  • Fix type annotation issues identified by mypy.

  • Run CI against pull requests.

  • Fix package build warnings.

Commits
  • 6aa0b0f Release 9.1.1: fix modern hard-cut trailing delimiter
  • 8f9a550 Avoid trailing post-replacement delimiters in modern hard cuts (#200)
  • c442cd4 Lead Quickstart examples with algorithm='modern'
  • 6e6fc4b Reframe README intro around 9+ modern algorithm, drop PyPI prose
  • b9171f7 Use version-agnostic 9.x wording in README
  • e9f287d Fix CI and DEV workflows to use the current test directory (#199)
  • 54c356b Finalize 9.1.0 changelog for release
  • 3f9e9b7 Freeze legacy into _legacy.py, reorganize tests, ship 9.1.0 (#198)
  • 2f23599 Fix add_uppercase_char to leave input unchanged on error (#194)
  • 548b14f Preserve fitting post-replacement output during modern truncation (#193)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [python-slugify](https://github.com/un33k/python-slugify) from 8.0.4 to 9.1.1.
- [Release notes](https://github.com/un33k/python-slugify/releases)
- [Changelog](https://github.com/un33k/python-slugify/blob/master/CHANGELOG.md)
- [Commits](un33k/python-slugify@v8.0.4...v9.1.1)

---
updated-dependencies:
- dependency-name: python-slugify
  dependency-version: 9.1.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file major A high priority issue which might affect a lot of people or large parts of the codebase labels Sep 28, 2026
@cla-bot cla-bot Bot added the cla-signed CLA Bot: community license agreement signed label Sep 28, 2026
@mattiagiupponi

Copy link
Copy Markdown
Contributor

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

cla-signed CLA Bot: community license agreement signed dependencies Pull requests that update a dependency file major A high priority issue which might affect a lot of people or large parts of the codebase

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant