Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump pip from 19.3.1 to 21.2.2 in /python/helpers #238

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

dependabot-preview[bot]
Copy link

Bumps pip from 19.3.1 to 21.2.2.

Changelog

Sourced from pip's changelog.

21.2.2 (2021-07-31)

Bug Fixes

  • New resolver: When a package is specified with extras in constraints, and with extras in non-constraint requirements, the resolver now correctly identifies the constraint's existence and avoids backtracking. (#10233)

21.2.1 (2021-07-25)

Process

  • The source distribution re-installation feature removal has been delayed to 21.3.

21.2 (2021-07-24)

Process

  • pip freeze, pip list, and pip show no longer normalize underscore (_) in distribution names to dash (-). This is a side effect of the migration to importlib.metadata, since the underscore-dash normalization behavior is non-standard and specific to setuptools. This should not affect other parts of pip (for example, when feeding the pip freeze result back into pip install) since pip internally performs standard PEP 503 normalization independently to setuptools.

Deprecations and Removals

  • Git version parsing is now done with regular expression to prepare for the pending upstream removal of non-PEP-440 version parsing logic. (#10117)
  • Re-enable the "Value for ... does not match" location warnings to field a new round of feedback for the distutils-sysconfig transition. (#10151)
  • Remove deprecated --find-links option in pip freeze (#9069)

Features

  • New resolver: Loosen URL comparison logic when checking for direct URL reference equivalency. The logic includes the following notable characteristics:

    • The authentication part of the URL is explicitly ignored.
    • Most of the fragment part, including egg=, is explicitly ignored. Only subdirectory= and hash values (e.g. sha256=) are kept.

    * The query part of the URL is parsed to allow ordering differences. (#10002)

  • Support TOML v1.0.0 syntax in pyproject.toml. (#10034)

  • Added a warning message for errors caused due to Long Paths being disabled on Windows. (#10045)

  • Change the encoding of log file from default text encoding to UTF-8. (#10071)

  • Log the resolved commit SHA when installing a package from a Git repository. (#10149)

  • Add a warning when passing an invalid requirement to pip uninstall. (#4958)

  • Add new subcommand pip index used to interact with indexes, and implement pip index version to list available versions of a package. (#7975)

  • When pip is asked to uninstall a project without the dist-info/RECORD file it will no longer traceback with FileNotFoundError, but it will provide a better error message instead, such as:

    ERROR: Cannot uninstall foobar 0.1, RECORD file not found. You might be able to recover from this via: 'pip install --force-reinstall --no-deps foobar==0.1'.
    

... (truncated)

Commits
  • f7d912a Bump for release
  • c7f3f19 Update AUTHORS.txt
  • 08eee0b Correctly normalize relative paths for 'pip show'
  • aaba499 Post a deprecation warning for distutils configs
  • a2cbacf Respect the base's constraint for extra-ed package
  • 3d7b9c5 Correctly ignore osx_framework_user mismatches
  • 5fc6d16 Suppress location warning on abiflag differences
  • cc5563e Kill location warning on Deb and RH system Python
  • ec41e0c Patch tenacity to quote typing.NoReturn
  • 8a38cc6 Fix broken link in README.rst
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in the .dependabot/config.yml file in this repo:

  • Update frequency
  • Automerge options (never/patch/minor, and dev/runtime dependencies)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

Bumps [pip](https://github.com/pypa/pip) from 19.3.1 to 21.2.2.
- [Release notes](https://github.com/pypa/pip/releases)
- [Changelog](https://github.com/pypa/pip/blob/main/NEWS.rst)
- [Commits](pypa/pip@19.3.1...21.2.2)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
@dependabot-preview dependabot-preview bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Jul 31, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file python Pull requests that update Python code
Projects
None yet
0 participants