Skip to content

Bump fonttools from 4.63.0 to 4.66.1 - #5527

Merged
github-actions[bot] merged 1 commit into
mainfrom
dependabot/pip/fonttools-4.66.1
Oct 7, 2026
Merged

github-actions[bot] merged 1 commit into
mainfrom
dependabot/pip/fonttools-4.66.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Bumps fonttools from 4.63.0 to 4.66.1.

Release notes

Sourced from fonttools's releases.

4.66.1

  • [designspaceLib] When splitting a DesignSpace v5 document with makeNames=True (as varLib.build_many does), family and style names set explicitly on an instance now take precedence over the ones computed from the STAT labels, in all languages, and a PostScript name is no longer made up from the labels for an instance that has its own style name (#3131, #4206, #4208).
  • [cmap] Decompiling a format 4 subtable whose idRangeOffset points outside glyphIndexArray now raises TTLibError. A negative index used to silently map the code point to the wrong glyph, and one past the end raised a bare AssertionError (#4209).
  • [cmap] Fix compiling a format 2 subtable when the lowest glyph ID in a lead-byte row is 32768 or higher, which failed with struct.error (#4210).

4.66.0

  • Drop support for EOL Python 3.10; fontTools now requires Python 3.11 or later. fontTools.misc.enumTools now only re-exports enum.StrEnum and is deprecated. Explicitly test and declare support for Python 3.15 (#4183, #4196).
  • [unicodedata] Update the bundled script, script extension, block and bidi-mirroring tables to Unicode 18.0.0, and require unicodedata2 18.0.0 when it is used (#4192, #4197).
  • [feaLib] Support language statements listing multiple language tags, e.g. language AZE CRT;adobe-type-tools/feature_file_workshops#8dflt cannot be combined with other tags. LanguageStatement.language is still the first tag; all of them are in the new languages attribute (#4201, #4202).
  • [feaLib] Fix lookups being dropped when a script/language pair is repeated within a feature block: the repeated statement replaced the language system's lookups with a fresh copy of the default ones (#4189).
  • [feaLib] Raise FeatureLibError instead of UnboundLocalError when a STAT table block lacks ElidedFallbackName or ElidedFallbackNameID (#3834, #4179).
  • [cffLib] Always recompile the CFF2 VarStore when saving. Previously the bytes compiled by an earlier save were reused, so a CFF2 variable font that was saved and then modified in place, e.g. by the instancer, was written with a stale VarStore next to its updated charstrings (#4199).
  • [ttLib] Support static VARC fonts that omit fvar while retaining gvar or CFF2 variation data for component-internal axes: hidden axes are addressed by index and gvar can compile, decompile and round-trip through TTX without fvar, reading the axis count from a new axisCount element (#4187, #4188).
  • [ttLib] Fix drawing VARC components whose condition is negated (format 5), which raised AttributeError (#4191).
  • [instancer] Fix VARC axis references left stale when removing an unrelated axis, reject pinning or restricting axes referenced by VARC components, and stop culling avar2 ranges for component-internal variations, which can reach outside the font-level ranges (#4190, #4193).
  • [bezierTools] Preserve exact endpoints in splitQuadraticAtT and splitCubicAtTC as well, like splitCubicAtT since 4.55.4 (#3742, #4194).
  • [bezierTools] Fix ZeroDivisionError in lineLineIntersections for collinear vertical lines; they are now treated as parallel like horizontal ones (#3515, #4181).
  • [subset] pyftsubset now preserves the input font's flavor (WOFF, WOFF2) when --flavor is omitted, instead of writing uncompressed sfnt data under the same extension; pass --flavor=none to force uncompressed output (#3630, #4182).
  • [merge] Report incompatible unitsPerEm values by name, with the input values, instead of a bare assertion (#2844, #4184).
  • [designspaceLib] Fix the type annotation and documentation of DesignSpaceDocument.default, which holds a SourceDescriptor, not a source name (#2994, #4186).
  • [ttLib.sfnt] Raise TTLibError instead of AssertionError for inconsistent WOFF table, metadata and private-data lengths, so the checks also hold under python -O (#4178).
  • [misc.etree] Disable entity resolution altogether on lxml >= 5.0 as well: lxml's resolve_entities="internal" still fetched external parameter entities before lxml 6.1.3, so a crafted DTD could read local files into parsed XML content (#4195).
  • [cmap] Bound the expansion of format 4 segments and format 12/13 groups when decompiling, like HarfBuzz does: groups are clamped to U+10FFFF, inverted or overlapping groups are skipped with a warning, and groups mapped to the missing glyph are not expanded. A crafted font could previously exhaust memory with a single group ending at 0xFFFFFFFF (#4204).
  • [varLib.avar] Escape axis names and tags when varLib.avar.unbuild emits its designspace snippet, so a crafted font cannot inject markup (#4203).

4.65.0

  • [glyf] Add __iter__, items and values methods to the glyf table to make it more dict-like (#4156).
  • [feaLib] Escape the anonymous block tag when scanning for its terminator, so tags containing regex metacharacters are matched literally (#4167).
  • [varLib] Strip directory components from <variable-font name="..."/> when deriving the output filename in the varLib command line, so a designspace cannot write outside the output directory (#4168).
  • [feaLib] Fix tracking of the current script and language across redundant script statements. Rules following a script statement that names the first declared language system no longer end up under the DFLT script, and a script statement naming the already-current script still narrows the language systems and terminates the current lookup while leaving the lookupflag alone, matching makeotf (#1824, #2522, #4169).
  • [varLib.interpolatable] Escape glyph names in the HTML report (#4172).
  • [otlLib] Fix overflow handling when building contextual lookups: offset overflows now raise OTLOffsetOverflowError instead of AttributeError so another contextual format can be tried (regression from #3439). When all formats overflow, split the ruleset in halves until it fits (#4171).

4.64.0

  • [feaLib] Fix name-table parsing for multibyte Mac encodings (#1196, #4092).
  • [ttProgram] Also indent TrueType assembly following IDEF[ ], like function definitions (#4093).
  • [subset] Keep East Asian spacing palt by default (#4094).
  • [subset] Bug fix for MATH table in which constructions for glyphs that are only added during MATH closure were kept (#4096).
  • [ufoLib] Make glyph-to-group construction accessible outside of lookup function (#4102).
  • [glyf] Use reverse glyph map for O(1) __setitem__ membership (#4103).
  • [ttLib] Fix fixLookupOverFlows() reporting success when it had not promoted any lookup to Extension, masking unresolvable overflows.
  • [ttLib] Add support for TrueType Collection version 2 (#4100).
  • [ttLib] Pin a single head.modified timestamp across TTCollection.save (#4111).
  • [ttLib] Give an actionable error when LookupList overflow is unrecoverable (#4109).
  • [ttLib] Add support for the AAT bitmap tables bhed, bdat, bloc, variants of head, EBDT, EBLC used in legacy Apple bitmap-only fonts (#4115).
  • [ttLib] Check OS/2 fsSelection/macStyle consistency against bhed as well as head (#4118, #4119).
  • [misc.roundTools] Add types and documentation (#4123).
  • [varLib.instancer] Instance the BASE table (#4137).
  • [varLib.instancer] Fix Private-dict vsindex handling in instantiateCFF2 (#4129, #4132).
  • [varLib.instancer] Fix crash instancing CFF2 fonts without a VariationStore (#4130, #4131).

... (truncated)

Changelog

Sourced from fonttools's changelog.

4.66.1 (released 2026-09-29)

  • [designspaceLib] When splitting a DesignSpace v5 document with makeNames=True (as varLib.build_many does), family and style names set explicitly on an instance now take precedence over the ones computed from the STAT labels, in all languages, and a PostScript name is no longer made up from the labels for an instance that has its own style name (#3131, #4206, #4208).
  • [cmap] Decompiling a format 4 subtable whose idRangeOffset points outside glyphIndexArray now raises TTLibError. A negative index used to silently map the code point to the wrong glyph, and one past the end raised a bare AssertionError (#4209).
  • [cmap] Fix compiling a format 2 subtable when the lowest glyph ID in a lead-byte row is 32768 or higher, which failed with struct.error (#4210).

4.66.0 (released 2026-09-23)

  • Drop support for EOL Python 3.10; fontTools now requires Python 3.11 or later. fontTools.misc.enumTools now only re-exports enum.StrEnum and is deprecated. Explicitly test and declare support for Python 3.15 (#4183, #4196).
  • [unicodedata] Update the bundled script, script extension, block and bidi-mirroring tables to Unicode 18.0.0, and require unicodedata2 18.0.0 when it is used (#4192, #4197).
  • [feaLib] Support language statements listing multiple language tags, e.g. language AZE CRT;, as Glyphs does and as proposed for the spec adobe-type-tools/feature_file_workshops#8 references are registered under every listed language. dflt cannot be combined with other tags. LanguageStatement.language is still the first tag; all of them are in the new languages attribute (#4201, #4202).
  • [feaLib] Fix lookups being dropped when a script/language pair is repeated within a feature block: the repeated statement replaced the language system's lookups with a fresh copy of the default ones (#4189).
  • [feaLib] Raise FeatureLibError instead of UnboundLocalError when a STAT table block lacks ElidedFallbackName or ElidedFallbackNameID (#3834, #4179).
  • [cffLib] Always recompile the CFF2 VarStore when saving. Previously the bytes compiled by an earlier save were reused, so a CFF2 variable font that was saved and then modified in place, e.g. by the instancer, was written with a stale VarStore next to its updated charstrings (#4199).
  • [ttLib] Support static VARC fonts that omit fvar while retaining gvar or CFF2 variation data for component-internal axes: hidden axes are addressed by index and gvar can compile, decompile and round-trip through TTX without fvar, reading the axis count from a new axisCount element (#4187, #4188).
  • [ttLib] Fix drawing VARC components whose condition is negated (format 5), which raised AttributeError (#4191).
  • [instancer] Fix VARC axis references left stale when removing an unrelated axis, reject pinning or restricting axes referenced by VARC components, and stop culling avar2 ranges for component-internal variations,

... (truncated)

Commits
  • 9e95795 Release 4.66.1
  • 8fc91fb Update NEWS.rst [skip ci]
  • 82dc507 Merge pull request #4209 from insaf021/cmap4-idrangeoffset-bounds
  • a83553e trim comments
  • 85049d3 Merge pull request #4208 from fonttools/fix-split-stat-names-override
  • 1ad111d Merge pull request #4210 from youdie006/cmap-format2-high-gids
  • c9e9d68 [cmap] fix format 2 compile for glyph IDs above 32767
  • 85625c5 raise TTLibError for out-of-range glyphIndexArray offset in cmap format 4
  • 879173e [designspaceLib] Let explicit instance names win over STAT labels when splitting
  • 718b61b Bump version: 4.66.0 → 4.66.1.dev0
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Oct 7, 2026
@github-actions
github-actions Bot enabled auto-merge (squash) October 7, 2026 02:44
@github-actions

github-actions Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

✅MegaLinter analysis: Success

Descriptor Linter Files Fixed Errors Max errors Warnings Elapsed time
✅ COPYPASTE jscpd yes no no 8.24s
✅ JSON prettier 7 0 0 0 1.24s
✅ JSON v8r 7 0 0 4.24s
✅ MARKDOWN markdownlint 69 0 0 0 2.01s
✅ MARKDOWN markdown-table-formatter 69 0 0 0 0.49s
✅ PYTHON black 2041 0 0 0 55.54s
✅ PYTHON isort 2041 2 0 0 2.89s
✅ REPOSITORY betterleaks yes no no 1.33s
✅ REPOSITORY checkov yes no no 33.25s
✅ REPOSITORY git_diff yes no no 0.12s
✅ REPOSITORY secretlint yes no no 5.99s
✅ REPOSITORY syft yes no no 3.05s
✅ REPOSITORY trivy-sbom yes no no 3.01s
✅ YAML prettier 11 0 0 0 0.65s
✅ YAML v8r 11 0 0 12.55s
✅ YAML yamllint 11 0 0 0.5s

Notices

⚠️ Your configuration references items that have been removed from MegaLinter and are ignored: MAKEFILE_CHECKMAKE. See Removed linters to find their replacements.

See detailed reports in MegaLinter artifacts

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@10.1.0 --custom-flavor-setup --custom-flavor-linters PYTHON_BLACK,PYTHON_ISORT,COPYPASTE_JSCPD,JSON_V8R,JSON_PRETTIER,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_CHECKOV,REPOSITORY_GIT_DIFF,REPOSITORY_BETTERLEAKS,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY_SBOM,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

MegaLinter is provided by OX Security
Show us your support by starring ⭐ the repository

Bumps [fonttools](https://github.com/fonttools/fonttools) from 4.63.0 to 4.66.1.
- [Release notes](https://github.com/fonttools/fonttools/releases)
- [Changelog](https://github.com/fonttools/fonttools/blob/main/NEWS.rst)
- [Commits](fonttools/fonttools@4.63.0...4.66.1)

---
updated-dependencies:
- dependency-name: fonttools
  dependency-version: 4.66.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/pip/fonttools-4.66.1 branch from b20dd31 to 4d36637 Compare October 7, 2026 03:27
@github-actions
github-actions Bot merged commit c94946e into main Oct 7, 2026
26 checks passed
@dependabot
dependabot Bot deleted the dependabot/pip/fonttools-4.66.1 branch October 7, 2026 04:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants