Skip to content

Backport PR #31282 on branch v3.10.x (SEC: Block shell escapes in latex and ps commands)#31542

Closed
ksunden wants to merge 30 commits intomatplotlib:mainfrom
ksunden:backport-of-pr-31282-on-v3.10.x
Closed

Backport PR #31282 on branch v3.10.x (SEC: Block shell escapes in latex and ps commands)#31542
ksunden wants to merge 30 commits intomatplotlib:mainfrom
ksunden:backport-of-pr-31282-on-v3.10.x

Conversation

@ksunden
Copy link
Copy Markdown
Member

@ksunden ksunden commented Apr 21, 2026

PR summary

PR checklist

steveberardi and others added 30 commits January 14, 2026 17:29
…t-of-pr-30960-on-v3.10.x

Backport PR matplotlib#30960 on branch v3.10.x (SVG backend - handle font weight as integer)
…t-of-pr-30952-on-v3.10.x

Backport PR matplotlib#30952 on branch v3.10.x (DOC: Tutorial on API shortcuts)
…t-of-pr-30969-on-v3.10.x

Backport PR matplotlib#30969 on branch v3.10.x (DOC: Simplify barh() example)
…t-of-pr-30985-on-v3.10.x

Backport PR matplotlib#30985 on branch v3.10.x (MNT: do not assign a numpy array shape)
…t-of-pr-31035-on-v3.10.x

Backport PR matplotlib#31035 on branch v3.10.x (DOCS: Fix typo in time array step size comment)
…t-of-pr-31153-on-v3.10.x

Backport PR matplotlib#31153 on branch v3.10.x (TST: Use correct method of clearing mock objects)
BLD: Temporarily pin setuptools-scm<10
(cherry picked from commit 443c728)
…ckport

Backport PR matplotlib#31401: BLD: Temporarily pin setuptools-scm<10
…t-of-pr-31420-on-v3.10.x

Backport PR matplotlib#31420 on branch v3.10.x (Fix outdated Savannah URL for freetype download)
…t-of-pr-31323-on-v3.10.x

Backport PR matplotlib#31323 on branch v3.10.x (FIX: Prevent crash when removing a subfigure containing subplots)
…ontmaps

mathtext: Fix type inconsistency with fontmaps
(cherry picked from commit fc6aa04)
…31437-on-v3.10.x

Backport PR matplotlib#31437: mathtext: Fix type inconsistency with fontmaps
…t-of-pr-31504-on-v3.10.x

Backport PR matplotlib#31504 on branch v3.10.x (Re-order variants to prioritize narrower types)
…t-of-pr-31020-on-v3.10.x

Backport PR matplotlib#31020 on branch v3.10.x (DOC: Fix doc builds with Sphinx 9)
…t-of-pr-31278-on-v3.10.x

Backport PR matplotlib#31278 on branch v3.10.x (Fix `clabel` manual argument not accepting unit-typed coordinates)
…t-of-pr-31075-on-v3.10.x

Backport PR matplotlib#31075 on branch v3.10.x (Fix remove method for figure title and xy-labels)
SEC: Block shell escapes in latex and ps commands
(cherry picked from commit 8ff895d)

The test that was edited had significant updates on main, so the old
test was kept on backport and no similar call exists in the old test.
@ksunden
Copy link
Copy Markdown
Member Author

ksunden commented Apr 21, 2026

I am confused as to why the cherry pick pulled in all of this... please hold

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

10 participants