Skip to content

Update pip requirement from <19.3,>=9 to >=9,<19.4#1273

Merged
stealthycoin merged 3 commits intomasterfrom
dependabot/pip/pip-gte-9-and-lt-19.4
Oct 15, 2019
Merged

Update pip requirement from <19.3,>=9 to >=9,<19.4#1273
stealthycoin merged 3 commits intomasterfrom
dependabot/pip/pip-gte-9-and-lt-19.4

Conversation

@dependabot-preview
Copy link
Contributor

@dependabot-preview dependabot-preview bot commented Oct 15, 2019

Updates the requirements on pip to permit the latest version.

Changelog

Sourced from pip's changelog.

19.3 (2019-10-14)

Deprecations and Removals

  • Remove undocumented support for un-prefixed URL requirements pointing to SVN repositories. Users relying on this can get the original behavior by prefixing their URL with svn+ (which is backwards-compatible). (#7037)
  • Remove the deprecated --venv option from pip config. (#7163)

Features

  • Print a better error message when --no-binary or --only-binary is given an argument starting with -. (#3191)
  • Make pip show warn about packages not found. (#6858)
  • Support including a port number in --trusted-host for both HTTP and HTTPS. (#6886)
  • Redact single-part login credentials from URLs in log messages. (#6891)
  • Implement manylinux2014 platform tag support. manylinux2014 is the successor to manylinux2010. It allows carefully compiled binary wheels to be installed on compatible Linux platforms. The manylinux2014 platform tag definition can be found in PEP599. (#7102)

Bug Fixes

  • Abort installation if any archive contains a file which would be placed outside the extraction location. (#3907)
  • pip's CLI completion code no longer prints a Traceback if it is interrupted. (#3942)
  • Correct inconsistency related to the hg+file scheme. (#4358)
  • Fix rmtree_errorhandler to skip non-existing directories. (#4910)
  • Ignore errors copying socket files for local source installs (in Python 3). (#5306)
  • Fix requirement line parser to correctly handle PEP 440 requirements with a URL pointing to an archive file. (#6202)
  • The pip-wheel-metadata directory does not need to persist between invocations of pip, use a temporary directory instead of the current setup.py directory. (#6213)
  • Fix --trusted-host processing under HTTPS to trust any port number used with the host. (#6705)
  • Switch to new distlib wheel script template. This should be functionally equivalent for end users. (#6763)
  • Skip copying .tox and .nox directories to temporary build directories (#6770)
  • Fix handling of tokens (single part credentials) in URLs. (#6795)
  • Fix a regression that caused ~ expansion not to occur in --find-links paths. (#6804)
  • Fix bypassed pip upgrade warning on Windows. (#6841)
  • Fix 'm' flag erroneously being appended to ABI tag in Python 3.8 on platforms that do not provide SOABI (#6885)
  • Hide security-sensitive strings like passwords in log messages related to version control system (aka VCS) command invocations. (#6890)
  • Correctly uninstall symlinks that were installed in a virtualenv, by tools such as flit install --symlink. (#6892)
  • Don't fail installation using pip.exe on Windows when pip wouldn't be upgraded. (#6924)
  • Use canonical distribution names when computing Required-By in pip show. (#6947)
  • Don't use hardlinks for locking selfcheck state file. (#6954)
  • Ignore "require_virtualenv" in pip config (#6991)
  • Fix pip freeze not showing correct entry for mercurial packages that use subdirectories. (#7071)
  • Fix a crash when sys.stdin is set to None, such as on AWS Lambda. (#7118, #7119)

Vendored Libraries

  • Upgrade certifi to 2019.9.11
  • Add contextlib2 0.6.0 as a vendored dependency.
  • Remove Lockfile as a vendored dependency.
... (truncated)
Commits
  • afcb3e7 Release 19.3
  • 707fe21 Updating AUTHORS.txt
  • 8df9329 Add release target
  • a0b75cc Remove intermediate pip-wheel-metadata dir
  • 1c3f31c Merge pull request #7072 from TonyBeswick/master
  • 8c66447 Use python-version instead of deprecated version
  • 7e11e25 Update AUTHORS.txt
  • 7ebc541 Fixed missing return statement in Mercurial.controls_location(), it
  • 24a2be8 Reverting VersionControl.controls_location() to pre PR state. Its an optim...
  • f197479 Fixed LF getting converted to CRLF in last commit.
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

Dependabot will merge this PR once CI passes on it, as requested by @jamesls.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in the .dependabot/config.yml file in this repo:

  • Update frequency
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

@codecov-io
Copy link

codecov-io commented Oct 15, 2019

Codecov Report

Merging #1273 into master will decrease coverage by 0.03%.
The diff coverage is 40%.

Impacted file tree graph

@@            Coverage Diff             @@
##           master    #1273      +/-   ##
==========================================
- Coverage   96.22%   96.19%   -0.04%     
==========================================
  Files          28       28              
  Lines        5275     5278       +3     
  Branches      672      673       +1     
==========================================
+ Hits         5076     5077       +1     
- Misses        129      130       +1     
- Partials       70       71       +1
Impacted Files Coverage Δ
chalice/compat.py 39.47% <40%> (-0.53%) ⬇️

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update d2ebbd3...3f8f76e. Read the comment docs.

@stealthycoin stealthycoin force-pushed the dependabot/pip/pip-gte-9-and-lt-19.4 branch from 8ce938c to 11d7b1b Compare October 15, 2019 19:29
Updates the requirements on [pip](https://github.com/pypa/pip) to permit the latest version.
- [Release notes](https://github.com/pypa/pip/releases)
- [Changelog](https://github.com/pypa/pip/blob/master/NEWS.rst)
- [Commits](pypa/pip@9.0.0...19.3)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
@stealthycoin stealthycoin force-pushed the dependabot/pip/pip-gte-9-and-lt-19.4 branch from 11d7b1b to b67104c Compare October 15, 2019 19:57
return 'from pip import main'
# Pip changed their import structure again in 19.3
# https://github.com/pypa/pip/commit/09fd200
elif pip_major_version == '19' and int(pip_minor_version) >= 3:
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We can simplify this a bit and just say (pip_major_version, pip_minor_version) >= (19, 3) to account for future versions. You also want to make sure these are ints.

@stealthycoin stealthycoin force-pushed the dependabot/pip/pip-gte-9-and-lt-19.4 branch from b67104c to 93c7be0 Compare October 15, 2019 20:01
Copy link
Member

@jamesls jamesls left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you link the chalice package issue as well? Otherwise looks good.

@stealthycoin stealthycoin force-pushed the dependabot/pip/pip-gte-9-and-lt-19.4 branch from 93c7be0 to 3f8f76e Compare October 15, 2019 20:11
@dependabot-preview
Copy link
Contributor Author

One of your CI runs failed on this pull request, so Dependabot won't merge it.

Dependabot will still automatically merge this pull request if you amend it and your tests pass.

@dependabot-preview
Copy link
Contributor Author

One of your CI runs failed on this pull request, so Dependabot won't merge it.

Dependabot will still automatically merge this pull request if you amend it and your tests pass.

@stealthycoin stealthycoin merged commit 5a93952 into master Oct 15, 2019
@stealthycoin stealthycoin deleted the dependabot/pip/pip-gte-9-and-lt-19.4 branch October 15, 2019 20:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants