Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump pip from 19.2.3 to 19.3 #5229

Merged
merged 1 commit into from Oct 15, 2019
Merged

Conversation

dependabot-preview[bot]
Copy link
Contributor

Bumps pip from 19.2.3 to 19.3.

Changelog

Sourced from pip's changelog.

19.3 (2019-10-14)

Deprecations and Removals

  • Remove undocumented support for un-prefixed URL requirements pointing to SVN repositories. Users relying on this can get the original behavior by prefixing their URL with svn+ (which is backwards-compatible). (#7037)
  • Remove the deprecated --venv option from pip config. (#7163)

Features

  • Print a better error message when --no-binary or --only-binary is given an argument starting with -. (#3191)
  • Make pip show warn about packages not found. (#6858)
  • Support including a port number in --trusted-host for both HTTP and HTTPS. (#6886)
  • Redact single-part login credentials from URLs in log messages. (#6891)
  • Implement manylinux2014 platform tag support. manylinux2014 is the successor to manylinux2010. It allows carefully compiled binary wheels to be installed on compatible Linux platforms. The manylinux2014 platform tag definition can be found in PEP599. (#7102)

Bug Fixes

  • Abort installation if any archive contains a file which would be placed outside the extraction location. (#3907)
  • pip's CLI completion code no longer prints a Traceback if it is interrupted. (#3942)
  • Correct inconsistency related to the hg+file scheme. (#4358)
  • Fix rmtree_errorhandler to skip non-existing directories. (#4910)
  • Ignore errors copying socket files for local source installs (in Python 3). (#5306)
  • Fix requirement line parser to correctly handle PEP 440 requirements with a URL pointing to an archive file. (#6202)
  • The pip-wheel-metadata directory does not need to persist between invocations of pip, use a temporary directory instead of the current setup.py directory. (#6213)
  • Fix --trusted-host processing under HTTPS to trust any port number used with the host. (#6705)
  • Switch to new distlib wheel script template. This should be functionally equivalent for end users. (#6763)
  • Skip copying .tox and .nox directories to temporary build directories (#6770)
  • Fix handling of tokens (single part credentials) in URLs. (#6795)
  • Fix a regression that caused ~ expansion not to occur in --find-links paths. (#6804)
  • Fix bypassed pip upgrade warning on Windows. (#6841)
  • Fix 'm' flag erroneously being appended to ABI tag in Python 3.8 on platforms that do not provide SOABI (#6885)
  • Hide security-sensitive strings like passwords in log messages related to version control system (aka VCS) command invocations. (#6890)
  • Correctly uninstall symlinks that were installed in a virtualenv, by tools such as flit install --symlink. (#6892)
  • Don't fail installation using pip.exe on Windows when pip wouldn't be upgraded. (#6924)
  • Use canonical distribution names when computing Required-By in pip show. (#6947)
  • Don't use hardlinks for locking selfcheck state file. (#6954)
  • Ignore "require_virtualenv" in pip config (#6991)
  • Fix pip freeze not showing correct entry for mercurial packages that use subdirectories. (#7071)
  • Fix a crash when sys.stdin is set to None, such as on AWS Lambda. (#7118, #7119)

Vendored Libraries

  • Upgrade certifi to 2019.9.11
  • Add contextlib2 0.6.0 as a vendored dependency.
  • Remove Lockfile as a vendored dependency.
... (truncated)
Commits
  • afcb3e7 Release 19.3
  • 707fe21 Updating AUTHORS.txt
  • 8df9329 Add release target
  • a0b75cc Remove intermediate pip-wheel-metadata dir
  • 1c3f31c Merge pull request #7072 from TonyBeswick/master
  • 8c66447 Use python-version instead of deprecated version
  • 7e11e25 Update AUTHORS.txt
  • 7ebc541 Fixed missing return statement in Mercurial.controls_location(), it
  • 24a2be8 Reverting VersionControl.controls_location() to pre PR state. Its an optim...
  • f197479 Fixed LF getting converted to CRLF in last commit.
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in your Dependabot dashboard:

  • Update frequency (including time of day and day of week)
  • Pull request limits (per update run and/or open at any time)
  • Automerge options (never/patch/minor, and dev/runtime dependencies)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

Bumps [pip](https://github.com/pypa/pip) from 19.2.3 to 19.3.
- [Release notes](https://github.com/pypa/pip/releases)
- [Changelog](https://github.com/pypa/pip/blob/master/NEWS.rst)
- [Commits](pypa/pip@19.2.3...19.3)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
@dependabot-preview dependabot-preview bot added dependencies Update the dependencies python labels Oct 15, 2019
Copy link

@github-actions github-actions bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@dependabot-preview dependabot-preview bot merged commit 8a30de9 into master Oct 15, 2019
@dependabot-preview dependabot-preview bot deleted the dependabot/pip/pip-19.3 branch October 15, 2019 09:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Update the dependencies
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant