build(deps): bump the pip group across 1 directory with 14 updates#179
build(deps): bump the pip group across 1 directory with 14 updates#179dependabot[bot] wants to merge 1 commit intomasterfrom
Conversation
Bumps the pip group with 14 updates in the / directory: | Package | From | To | | --- | --- | --- | | [cryptography](https://github.com/pyca/cryptography) | `3.4.7` | `44.0.1` | | [future](https://github.com/PythonCharmers/python-future) | `0.18.2` | `1.0.0` | | [idna](https://github.com/kjd/idna) | `2.10` | `3.7` | | [twisted](https://github.com/twisted/twisted) | `22.4.0` | `24.7.0rc1` | | [certifi](https://github.com/certifi/python-certifi) | `2021.10.8` | `2024.7.4` | | [jinja2](https://github.com/pallets/jinja) | `3.1.2` | `3.1.6` | | [mako](https://github.com/sqlalchemy/mako) | `1.2.0` | `1.2.2` | | [pillow](https://github.com/python-pillow/Pillow) | `9.1.1` | `10.3.0` | | [requests](https://github.com/psf/requests) | `2.27.1` | `2.32.4` | | [sqlparse](https://github.com/andialbrecht/sqlparse) | `0.4.2` | `0.5.0` | | [urllib3](https://github.com/urllib3/urllib3) | `1.26.9` | `2.5.0` | | [werkzeug](https://github.com/pallets/werkzeug) | `2.1.2` | `3.0.6` | | [zipp](https://github.com/jaraco/zipp) | `3.8.1` | `3.19.1` | | [pg8000](https://github.com/tlocke/pg8000) | `1.26.1` | `1.31.5` | Updates `cryptography` from 3.4.7 to 44.0.1 - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@3.4.7...44.0.1) Updates `future` from 0.18.2 to 1.0.0 - [Release notes](https://github.com/PythonCharmers/python-future/releases) - [Changelog](https://github.com/PythonCharmers/python-future/blob/master/docs/changelog.rst) - [Commits](PythonCharmers/python-future@v0.18.2...v1.0.0) Updates `idna` from 2.10 to 3.7 - [Release notes](https://github.com/kjd/idna/releases) - [Changelog](https://github.com/kjd/idna/blob/master/HISTORY.rst) - [Commits](kjd/idna@v2.10...v3.7) Updates `twisted` from 22.4.0 to 24.7.0rc1 - [Release notes](https://github.com/twisted/twisted/releases) - [Changelog](https://github.com/twisted/twisted/blob/twisted-24.7.0rc1/NEWS.rst) - [Commits](twisted/twisted@twisted-22.4.0...twisted-24.7.0rc1) Updates `certifi` from 2021.10.8 to 2024.7.4 - [Commits](certifi/python-certifi@2021.10.08...2024.07.04) Updates `jinja2` from 3.1.2 to 3.1.6 - [Release notes](https://github.com/pallets/jinja/releases) - [Changelog](https://github.com/pallets/jinja/blob/main/CHANGES.rst) - [Commits](pallets/jinja@3.1.2...3.1.6) Updates `mako` from 1.2.0 to 1.2.2 - [Release notes](https://github.com/sqlalchemy/mako/releases) - [Changelog](https://github.com/sqlalchemy/mako/blob/main/CHANGES) - [Commits](https://github.com/sqlalchemy/mako/commits) Updates `pillow` from 9.1.1 to 10.3.0 - [Release notes](https://github.com/python-pillow/Pillow/releases) - [Changelog](https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst) - [Commits](python-pillow/Pillow@9.1.1...10.3.0) Updates `requests` from 2.27.1 to 2.32.4 - [Release notes](https://github.com/psf/requests/releases) - [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md) - [Commits](psf/requests@v2.27.1...v2.32.4) Updates `sqlparse` from 0.4.2 to 0.5.0 - [Changelog](https://github.com/andialbrecht/sqlparse/blob/master/CHANGELOG) - [Commits](andialbrecht/sqlparse@0.4.2...0.5.0) Updates `urllib3` from 1.26.9 to 2.5.0 - [Release notes](https://github.com/urllib3/urllib3/releases) - [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst) - [Commits](urllib3/urllib3@1.26.9...2.5.0) Updates `werkzeug` from 2.1.2 to 3.0.6 - [Release notes](https://github.com/pallets/werkzeug/releases) - [Changelog](https://github.com/pallets/werkzeug/blob/main/CHANGES.rst) - [Commits](pallets/werkzeug@2.1.2...3.0.6) Updates `zipp` from 3.8.1 to 3.19.1 - [Release notes](https://github.com/jaraco/zipp/releases) - [Changelog](https://github.com/jaraco/zipp/blob/main/NEWS.rst) - [Commits](jaraco/zipp@v3.8.1...v3.19.1) Updates `pg8000` from 1.26.1 to 1.31.5 - [Commits](https://github.com/tlocke/pg8000/commits) --- updated-dependencies: - dependency-name: cryptography dependency-version: 44.0.1 dependency-type: direct:production dependency-group: pip - dependency-name: future dependency-version: 1.0.0 dependency-type: direct:production dependency-group: pip - dependency-name: idna dependency-version: '3.7' dependency-type: direct:production dependency-group: pip - dependency-name: twisted dependency-version: 24.7.0rc1 dependency-type: direct:production dependency-group: pip - dependency-name: certifi dependency-version: 2024.7.4 dependency-type: direct:production dependency-group: pip - dependency-name: jinja2 dependency-version: 3.1.6 dependency-type: direct:production dependency-group: pip - dependency-name: mako dependency-version: 1.2.2 dependency-type: direct:production dependency-group: pip - dependency-name: pillow dependency-version: 10.3.0 dependency-type: direct:production dependency-group: pip - dependency-name: requests dependency-version: 2.32.4 dependency-type: direct:production dependency-group: pip - dependency-name: sqlparse dependency-version: 0.5.0 dependency-type: direct:production dependency-group: pip - dependency-name: urllib3 dependency-version: 2.5.0 dependency-type: direct:production dependency-group: pip - dependency-name: werkzeug dependency-version: 3.0.6 dependency-type: direct:production dependency-group: pip - dependency-name: zipp dependency-version: 3.19.1 dependency-type: direct:production dependency-group: pip - dependency-name: pg8000 dependency-version: 1.31.5 dependency-type: direct:production dependency-group: pip ... Signed-off-by: dependabot[bot] <support@github.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
|
Review or Edit in CodeSandboxOpen the branch in Web Editor • VS Code • Insiders |
|
There was a problem hiding this comment.
Important
Looks good to me! 👍
Reviewed everything up to 2b63db2 in 2 minutes and 30 seconds. Click for details.
- Reviewed
206lines of code in5files - Skipped
0files when reviewing. - Skipped posting
5draft comments. View those below. - Modify your settings and rules to customize what types of comments Ellipsis leaves. And don't forget to react with 👍 or 👎 to teach Ellipsis.
1. requirements-ci.txt:103
- Draft comment:
Consider using a stable Twisted version rather than the release candidate '24.7.0rc1' unless you require its latest features. This might improve overall stability. - Reason this comment was not posted:
Decided after close inspection that this draft comment was likely wrong and/or not actionable: usefulness confidence = 10% vs. threshold = 50% According to the rules, we should NOT comment on dependency changes or library versions. The PR author likely has a specific reason for choosing this version, and we don't have enough context to know if a stable version would work. This falls under the category of dependency-related comments that we should avoid. Maybe using a release candidate in CI requirements could lead to unstable tests? The suggestion seems well-intentioned for stability. While stability is important, the rules explicitly state not to comment on dependency versions we don't recognize. The author may need this RC version for testing or compatibility reasons. This comment should be deleted as it violates the rule about not commenting on dependency changes and library versions.
2. requirements-cidb.txt:3
- Draft comment:
pg8000 updated to 1.31.5 appears correct. - Reason this comment was not posted:
Confidence changes required:0%<= threshold50%None
3. requirements-ciworker.txt:15
- Draft comment:
The worker requirements pin 'mock' at 3.0.5, which differs from the main CI version (4.0.3). Ensure this discrepancy is intentional for compatibility with older Python versions. - Reason this comment was not posted:
Confidence changes required:33%<= threshold50%None
4. requirements-master-docker-extras.txt:1
- Draft comment:
Dependencies in this file (e.g. requests==2.32.4) appear updated and consistent. - Reason this comment was not posted:
Confidence changes required:0%<= threshold50%None
5. requirements-minimal.txt:12
- Draft comment:
There are several inconsistencies between this minimal dependency file and the main CI requirements. For example, 'astroid' is pinned at 1.4.9 here (line 14) versus 2.11.4 elsewhere, 'attrs' at 22.1.0 (line 15) versus 21.4.0, and 'moto' is 4.0.1 here versus 2.1.0 in CI. Similar discrepancies exist for pylint and pyOpenSSL. Consider regenerating or synchronizing the minimal file to ensure consistency. - Reason this comment was not posted:
Comment was not on a location in the diff, so it can't be submitted as a review comment.
Workflow ID: wflow_fR2qfZm6oQKFBucN
You can customize by changing your verbosity settings, reacting with 👍 or 👎, replying to comments, or adding code review rules.
Bumps the pip group with 14 updates in the / directory:
3.4.744.0.10.18.21.0.02.103.722.4.024.7.0rc12021.10.82024.7.43.1.23.1.61.2.01.2.29.1.110.3.02.27.12.32.40.4.20.5.01.26.92.5.02.1.23.0.63.8.13.19.11.26.11.31.5Updates
cryptographyfrom 3.4.7 to 44.0.1Changelog
Sourced from cryptography's changelog.
... (truncated)
Commits
adaaaedBump for 44.0.1 release (#12441)ccc61da[backport] test and build on armv7l (#12420) (#12431)f299a48remove deprecated call (#12052)439eb05Bump version for 44.0.0 (#12051)2c5ad4dchore(deps): bump maturin from 1.7.4 to 1.7.5 in /.github/requirements (#12050)d23968achore(deps): bump libc from 0.2.165 to 0.2.166 (#12049)133c0e0Bump x509-limbo and/or wycheproof in CI (#12047)f2259d7Bump BoringSSL and/or OpenSSL in CI (#12046)e201c87fixed metadata in changelog (#12044)c6104ccProhibit Python 3.9.0, 3.9.1 -- they have a bug that causes errors (#12045)Updates
futurefrom 0.18.2 to 1.0.0Release notes
Sourced from future's releases.
... (truncated)
Changelog
Sourced from future's changelog.
... (truncated)
Commits
2bdbfa5Tidy up READMEa7097f8Update docse32250eUpdate docs pointing to changelogdde60adMove old "What's New" entries to the change logb2ea420Remove hacky logo from docsa10a78bUpdate "What's New"9f87630Update the FAQ entries on compatibility and contributingf4a1f04Docs: replace http links with https30c525eMerge branch 'master' of https://github.com/PythonCharmers/python-future70b36a8Disable Python 2.6 CI tests for nowUpdates
idnafrom 2.10 to 3.7Release notes
Sourced from idna's releases.
Changelog
Sourced from idna's changelog.
... (truncated)
Commits
1d365e1Release v3.7c1b3154Merge pull request #172 from kjd/optimize-contextj0394ec7Merge branch 'master' into optimize-contextjcd58a23Merge pull request #152 from elliotwutingfeng/dev5beb28bMore efficient resolution of joiner contexts1b12148Update ossf/scorecard-action to v2.3.1d516b87Update Github actions/checkout to v4c095c75Merge branch 'master' into dev60a0a4cFix typo in GitHub Actions workflow key5918a0eMerge branch 'master' into devUpdates
twistedfrom 22.4.0 to 24.7.0rc1Release notes
Sourced from twisted's releases.
... (truncated)
Changelog
Sourced from twisted's changelog.
... (truncated)
Commits
6d157catox -e towncrier046a164Merge commit from fork4a930deMerge commit from fork83bfa2aMerge branch 'trunk' into advisory-fix-1bbb59e6- bugfix news fragment addedbf29cc5#12257 More HTTP server benchmarks (#12258)c678ea7Align the Tox configb53f137Fix the bugs612b154Show uncovered linesbf5fc20Don't rename so Codspeed is happyUpdates
certififrom 2021.10.8 to 2024.7.4Commits
bd815382024.07.04 (#295)06a2cbfBump peter-evans/create-pull-request from 6.0.5 to 6.1.0 (#294)13bba02Bump actions/checkout from 4.1.6 to 4.1.7 (#293)e8abcd0Bump pypa/gh-action-pypi-publish from 1.8.14 to 1.9.0 (#292)124f4ad2024.06.02 (#291)c2196ce--- (#290)fefdeecBump actions/checkout from 4.1.4 to 4.1.5 (#289)3c5fb15Bump actions/download-artifact from 4.1.6 to 4.1.7 (#286)4a9569aBump actions/checkout from 4.1.2 to 4.1.4 (#287)1fc8086Bump peter-evans/create-pull-request from 6.0.4 to 6.0.5 (#288)Updates
jinja2from 3.1.2 to 3.1.6Release notes
Sourced from jinja2's releases.
... (truncated)
Changelog
Sourced from jinja2's changelog.
... (truncated)
Commits
1520688release version 3.1.690457bbMerge commit from fork065334dattr filter uses env.getattr033c200start version 3.1.6bc68d4euse global contributing guide (#2070)247de5euse global contributing guideab8218cuse project advisory link instead of globalb4ffc8frelease version 3.1.5 (#2066)877f6e5release version 3.1.58d58859remove test pypiUpdates
makofrom 1.2.0 to 1.2.2Release notes
Sourced from mako's releases.
Commits
Updates
pillowfrom 9.1.1 to 10.3.0Release notes
Sourced from pillow's releases.
... (truncated)
Changelog
Sourced from pillow's changelog.
... (truncated)
Commits
5c89d8810.3.0 version bump63cbfcfUpdate CHANGES.rst [ci skip]2776126Merge pull request #7928 from python-pillow/lcmsaeb51cbMerge branch 'main' into lcms5beb0b6Update CHANGES.rst [ci skip]cac6ffaMerge pull request #7927 from python-pillow/imagemathf5eeeacName as 'options' in lambda_eval and unsafe_eval, but '_dict' in deprecated evalfacf3afAdded release notes2a93abaUse strncpy to avoid buffer overflowa670597Update CHANGES.rst [ci skip]Updates
requestsfrom 2.27.1 to 2.32.4Release notes
Sourced from requests's releases.
... (truncated)
Changelog
Sourced from requests's changelog.