Skip to content

feat(deps): support chardet v7 - #1110

Merged
jkowalleck merged 2 commits into
CycloneDX:mainfrom
tamird:tamird/chardet-compat
Sep 29, 2026
Merged

jkowalleck merged 2 commits into
CycloneDX:mainfrom
tamird:tamird/chardet-compat

Conversation

@tamird

@tamird tamird commented Sep 28, 2026

Copy link
Copy Markdown

Description

Installing cyclonedx-bom alongside a Chardet 7 requirement currently fails dependency resolution because this project caps Chardet below 6. Allow Chardet 7 while retaining Chardet 5, and exclude Chardet 6: 6.0.0.post1 returns no encoding for the existing CP1252 requirements fixture, so requirements - falls back to UTF-8 and fails.

On Python 3.12, the existing tests for requirements on stdin passed with Chardet 7.0.0 and 7.6.0, including the CP1252 fixture. The final native Poetry lock continues to choose Chardet 5.2.0 for the project's full Python 3.9+ range; the 7.x behavior was qualified separately with the same configured test command.

Tox's isolated wheel setup stopped before tests because poetry-core 2.5.0 emitted an invalid requirement from the unchanged cyclonedx-python-lib union. The results above came from running Tox's configured unittest command directly in the Poetry project environment. That environment's Requests 2.32.5 also emitted RequestsDependencyWarning when Chardet 7 was selected.

Resolves or fixes issue: #1109

AI Tool Disclosure

  • My contribution does not include any AI-generated content
  • My contribution includes AI-generated content, as disclosed below:
    • AI Tools: OpenAI Codex
    • LLMs and versions: The model version was not exposed to this session.
    • Prompts: Assess whether cyclonedx-bom can admit Chardet 7 while preserving requirements read from stdin, including non-UTF8 input; prepare a minimal dependency update, use the existing tests, and report validation limits.

Affirmation

Codex for Tamir.

The Chardet <6 constraint cannot resolve with a requirement for
Chardet 7. Allow Chardet 7 while retaining Chardet 5 support.

Exclude Chardet 6: 6.0.0.post1 returns no encoding for the existing
CP1252 requirements fixture, so stdin decoding falls back to UTF-8
and fails. The existing tests for requirements on stdin pass with
Chardet 7.0.0 and 7.6.0 on Python 3.12, including that fixture.

The native Poetry lock continues to resolve Chardet 5.2.0 for the
project's Python 3.9+ range.

Codex for Tamir.

Signed-off-by: Tamir Duberstein <tamird@gmail.com>
@tamird
tamird requested a review from a team as a code owner September 28, 2026 17:53
@codacy-production

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@read-the-docs-community

read-the-docs-community Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Documentation build overview

📚 CycloneDX Python SBOM Tool | 🛠️ Build #34831325 | 📁 Comparing c6229c7 against latest (f6f4941)

  🔍 Preview build  

1 file changed
± changelog.html

@jkowalleck jkowalleck changed the title fix: Allow Chardet 7 chore(deps): Allow Chardet 7 Sep 29, 2026
Comment thread pyproject.toml Outdated
@jkowalleck jkowalleck changed the title chore(deps): Allow Chardet 7 chore(deps): support chardet v7 Sep 29, 2026
@jkowalleck jkowalleck added the dependencies topic: modify/update a dependency label Sep 29, 2026
@jkowalleck jkowalleck linked an issue Sep 29, 2026 that may be closed by this pull request
1 task done
@tamird
tamird requested a review from jkowalleck September 29, 2026 14:05
@jkowalleck

Copy link
Copy Markdown
Member

the version of poetry we use to build the package seams to be bugged regarding version constriants here.
need to investigate, properly will revert f3dede1

@tamird

tamird commented Sep 29, 2026

Copy link
Copy Markdown
Author

I can prepare a migration to uv, if you like?

@jkowalleck
jkowalleck force-pushed the tamird/chardet-compat branch 2 times, most recently from f3dede1 to c6229c7 Compare September 29, 2026 15:03
@jkowalleck jkowalleck changed the title chore(deps): support chardet v7 feat(deps): support chardet v7 Sep 29, 2026
@jkowalleck

Copy link
Copy Markdown
Member

I can prepare a migration to uv, if you like?

thanks. not needed at the moment.
will stick with poetry for a while, as long as it does the job okay.

@jkowalleck
jkowalleck merged commit e1e1040 into CycloneDX:main Sep 29, 2026
35 of 66 checks passed
@tamird
tamird deleted the tamird/chardet-compat branch September 29, 2026 15:26
@jkowalleck

Copy link
Copy Markdown
Member

released per https://github.com/CycloneDX/cyclonedx-python/releases/tag/v7.5.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies topic: modify/update a dependency

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Allow Chardet 7

2 participants