There is a security vulnerability in the future package that does not seem likely to be resolved. Can xhtml2pdf be released to not require this package? CVE: https://github.com/advisories/GHSA-v3c5-jqr6-7qm8 Discussions: https://github.com/PythonCharmers/python-future/issues/612 https://github.com/PythonCharmers/python-future/pull/610