From 5126b35da51ddaaf73b6c98a51c3c6905695dbb6 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 6 May 2024 13:42:33 -0600 Subject: [PATCH] Bump the pip group across 1 directory with 6 updates (#3239) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Bumps the pip group with 6 updates in the /python/tests directory: | Package | From | To | | --- | --- | --- | | [certifi](https://github.com/certifi/python-certifi) | `2020.12.5` | `2023.7.22` | | [grpcio](https://github.com/grpc/grpc) | `1.34.0` | `1.53.2` | | [idna](https://github.com/kjd/idna) | `2.10` | `3.7` | | [protobuf](https://github.com/protocolbuffers/protobuf) | `3.14.0` | `3.18.3` | | [rsa](https://github.com/sybrenstuvel/python-rsa) | `4.6` | `4.7` | | [urllib3](https://github.com/urllib3/urllib3) | `1.26.2` | `1.26.18` | Updates `certifi` from 2020.12.5 to 2023.7.22
Commits

Updates `grpcio` from 1.34.0 to 1.53.2
Release notes

Sourced from grpcio's releases.

Release v1.53.2

This is release gRPC Core 1.53.2 (glockenspiel).

For gRPC documentation, see grpc.io. For previous releases, see Releases.

This release contains refinements, improvements, and bug fixes.

Core

Release v1.53.1

This is release gRPC Core 1.53.1 (glockenspiel).

For gRPC documentation, see grpc.io. For previous releases, see Releases.

This release contains refinements, improvements, and bug fixes.

Release v1.53.0

This is release 1.53.0 (glockenspiel) of gRPC Core.

For gRPC documentation, see grpc.io. For previous releases, see Releases.

This release contains refinements, improvements, and bug fixes, with highlights listed below.

Core

C++

... (truncated)

Changelog

Sourced from grpcio's changelog.

gRPC Release Schedule

Below is the release schedule for gRPC Java, Go and Core and its dependent languages C++, C#, Objective-C, PHP, Python and Ruby.

Releases are scheduled every six weeks on Tuesdays on a best effort basis. In some unavoidable situations a release may be delayed or released early or a language may skip a release altogether and do the next release to catch up with other languages. See the past releases in the links above. A six-week cycle gives us a good balance between delivering new features/fixes quickly and keeping the release overhead low.

The gRPC release support policy can be found here.

Releases are cut from release branches. For Core and Java repos, the release branch is cut two weeks before the scheduled release date. For Go, the branch is cut just before the release. An RC (release candidate) is published for Core and its dependent languages just after the branch cut. This RC is later promoted to release version if no further changes are made to the release branch. We do our best to keep head of master branch stable at all times regardless of release schedule. Daily build packages from master branch for C#, PHP, Python, Ruby and Protoc plugins are published on packages.grpc.io. If you depend on gRPC in production we recommend to set up your CI system to test the RCs and, if possible, the daily builds.

Names of gRPC releases are here.

Release Scheduled Branch Cut Scheduled Release Date
v1.17.0 Nov 19, 2018 Dec 4, 2018
v1.18.0 Jan 2, 2019 Jan 15, 2019
v1.19.0 Feb 12, 2019 Feb 26, 2019
v1.20.0 Mar 26, 2019 Apr 9, 2019
v1.21.0 May 7, 2019 May 21, 2019
v1.22.0 Jun 18, 2019 Jul 2, 2019
v1.23.0 Jul 30, 2019 Aug 13, 2019
v1.24.0 Sept 10, 2019 Sept 24, 2019
v1.25.0 Oct 22, 2019 Nov 5, 2019
v1.26.0 Dec 3, 2019 Dec 17, 2019
v1.27.0 Jan 14, 2020 Jan 28, 2020
v1.28.0 Feb 25, 2020 Mar 10, 2020
v1.29.0 Apr 7, 2020 Apr 21, 2020
v1.30.0 May 19, 2020 Jun 2, 2020
v1.31.0 Jul 14, 2020 Jul 28, 2020
v1.32.0 Aug 25, 2020 Sep 8, 2020
v1.33.0 Oct 6, 2020 Oct 20, 2020
Commits

Updates `idna` from 2.10 to 3.7
Release notes

Sourced from idna's releases.

v3.7

What's Changed

Thanks to Guido Vranken for reporting the issue.

Full Changelog: https://github.com/kjd/idna/compare/v3.6...v3.7

Changelog

Sourced from idna's changelog.

3.7 (2024-04-11) ++++++++++++++++

Thanks to Guido Vranken for reporting the issue.

3.6 (2023-11-25) ++++++++++++++++

3.5 (2023-11-24) ++++++++++++++++

Thanks Jon Ribbens, Diogo Teles Sant'Anna, Wu Tingfeng for contributions to this release.

3.4 (2022-09-14) ++++++++++++++++

Thanks to Seth Michael Larson for contributions to this release.

3.3 (2021-10-13) ++++++++++++++++

... (truncated)

Commits

Updates `protobuf` from 3.14.0 to 3.18.3
Release notes

Sourced from protobuf's releases.

Protocol Buffers v3.18.3

C++

Protocol Buffers v3.18.2

Java

Protocol Buffers v3.18.1

Python

Ruby

Protocol Buffers v3.18.0

C++

... (truncated)

Commits

Updates `rsa` from 4.6 to 4.7
Changelog

Sourced from rsa's changelog.

Version 4.7 - released 2021-01-10

Commits

Updates `urllib3` from 1.26.2 to 1.26.18
Release notes

Sourced from urllib3's releases.

1.26.18

1.26.17

1.26.16

1.26.15

1.26.14

1.26.13

1.26.12

1.26.11

If you or your organization rely on urllib3 consider supporting us via GitHub Sponsors.

:warning: urllib3 v2.0 will drop support for Python 2: Read more in the v2.0 Roadmap

1.26.10

If you or your organization rely on urllib3 consider supporting us via GitHub Sponsors.

:warning: urllib3 v2.0 will drop support for Python 2: Read more in the v2.0 Roadmap

:closed_lock_with_key: This is the first release to be signed with Sigstore! You can verify the distributables using the .sig and .crt files included on this release.

1.26.9

If you or your organization rely on urllib3 consider supporting us via GitHub Sponsors.

... (truncated)

Changelog

Sourced from urllib3's changelog.

1.26.18 (2023-10-17)

1.26.17 (2023-10-02)

1.26.16 (2023-05-23)

1.26.15 (2023-03-10)

1.26.14 (2023-01-11)

1.26.13 (2022-11-23)

1.26.12 (2022-08-22)

1.26.11 (2022-07-25)

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) ---
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore ` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore ` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore ` will remove the ignore condition of the specified dependency and ignore conditions You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/SatcherInstitute/health-equity-tracker/network/alerts).
Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Ben Hammond --- python/tests/requirements.txt | 48 ++++++++++++++++++++++------------- 1 file changed, 30 insertions(+), 18 deletions(-) diff --git a/python/tests/requirements.txt b/python/tests/requirements.txt index 3f93e0e07c..2e4d013bbf 100644 --- a/python/tests/requirements.txt +++ b/python/tests/requirements.txt @@ -4,16 +4,20 @@ # # pip-compile --output-file=python/tests/requirements.txt python/tests/requirements.in # +astroid==3.1.0 + # via pylint cachetools==4.2.4 # via google-auth -certifi==2020.12.5 +certifi==2023.7.22 # via requests cffi==1.14.4 # via google-crc32c charset-normalizer==3.3.2 # via requests +dill==0.3.8 + # via pylint freezegun==1.4.0 - # via -r tests/requirements.in + # via -r requirements.in google-api-core[grpc]==1.24.1 # via # google-cloud-bigquery @@ -25,18 +29,18 @@ google-auth==1.24.0 # google-cloud-core # google-cloud-storage google-cloud==0.34.0 - # via -r tests/../ingestion/requirements.in + # via -r ../ingestion/requirements.in google-cloud-bigquery==2.6.1 - # via -r tests/../ingestion/requirements.in + # via -r ../ingestion/requirements.in google-cloud-core==1.7.3 # via - # -r tests/../ingestion/requirements.in + # -r ../ingestion/requirements.in # google-cloud-bigquery # google-cloud-storage google-cloud-pubsub==2.6.0 - # via -r tests/../ingestion/requirements.in + # via -r ../ingestion/requirements.in google-cloud-storage==1.38.0 - # via -r tests/../ingestion/requirements.in + # via -r ../ingestion/requirements.in google-crc32c==1.1.0 # via google-resumable-media google-resumable-media==1.2.0 @@ -49,28 +53,34 @@ googleapis-common-protos[grpc]==1.52.0 # grpc-google-iam-v1 grpc-google-iam-v1==0.12.3 # via google-cloud-pubsub -grpcio==1.34.0 +grpcio==1.53.2 # via # google-api-core # googleapis-common-protos # grpc-google-iam-v1 -idna==2.10 +idna==3.7 # via requests +isort==5.13.2 + # via pylint libcst==0.3.16 # via google-cloud-pubsub +mccabe==0.7.0 + # via pylint mypy-extensions==0.4.3 # via typing-inspect numpy==1.26.4 # via pandas pandas==2.2.2 # via - # -r tests/../ingestion/requirements.in - # -r tests/requirements.in + # -r ../ingestion/requirements.in + # -r requirements.in +platformdirs==4.2.1 + # via pylint proto-plus==1.13.0 # via # google-cloud-bigquery # google-cloud-pubsub -protobuf==3.14.0 +protobuf==3.18.3 # via # google-api-core # google-cloud-bigquery @@ -84,6 +94,8 @@ pyasn1-modules==0.2.8 # via google-auth pycparser==2.20 # via cffi +pylint==3.1.0 + # via -r ../ingestion/requirements.in python-dateutil==2.9.0.post0 # via # freezegun @@ -96,10 +108,10 @@ pyyaml==5.3.1 # via libcst requests==2.31.0 # via - # -r tests/../ingestion/requirements.in + # -r ../ingestion/requirements.in # google-api-core # google-cloud-storage -rsa==4.6 +rsa==4.7 # via google-auth six==1.15.0 # via @@ -108,9 +120,9 @@ six==1.15.0 # google-cloud-bigquery # google-cloud-core # google-resumable-media - # grpcio - # protobuf # python-dateutil +tomlkit==0.12.4 + # via pylint typing-extensions==3.7.4.3 # via # libcst @@ -119,10 +131,10 @@ typing-inspect==0.6.0 # via libcst tzdata==2024.1 # via pandas -urllib3==1.26.2 +urllib3==1.26.18 # via requests xlrd==2.0.1 - # via -r tests/../ingestion/requirements.in + # via -r ../ingestion/requirements.in # The following packages are considered to be unsafe in a requirements file: # setuptools