Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

⬆️ Bump pip from 19.1.1 to 19.3.1 #12

Merged
merged 1 commit into from
Oct 21, 2019
Merged

Conversation

dependabot-preview[bot]
Copy link
Contributor

@dependabot-preview dependabot-preview bot commented Oct 21, 2019

Bumps pip from 19.1.1 to 19.3.1.

Changelog

Sourced from pip's changelog.

19.3.1 (2019-10-17)

Features

  • Document Python 3.8 support. (#7219)

Bug Fixes

  • Fix bug that prevented installation of PEP 517 packages without setup.py. (#6606)

19.3 (2019-10-14)

Deprecations and Removals

  • Remove undocumented support for un-prefixed URL requirements pointing to SVN repositories. Users relying on this can get the original behavior by prefixing their URL with svn+ (which is backwards-compatible). (#7037)
  • Remove the deprecated --venv option from pip config. (#7163)

Features

  • Print a better error message when --no-binary or --only-binary is given an argument starting with -. (#3191)
  • Make pip show warn about packages not found. (#6858)
  • Support including a port number in --trusted-host for both HTTP and HTTPS. (#6886)
  • Redact single-part login credentials from URLs in log messages. (#6891)
  • Implement manylinux2014 platform tag support. manylinux2014 is the successor to manylinux2010. It allows carefully compiled binary wheels to be installed on compatible Linux platforms. The manylinux2014 platform tag definition can be found in PEP599. (#7102)

Bug Fixes

  • Abort installation if any archive contains a file which would be placed outside the extraction location. (#3907)
  • pip's CLI completion code no longer prints a Traceback if it is interrupted. (#3942)
  • Correct inconsistency related to the hg+file scheme. (#4358)
  • Fix rmtree_errorhandler to skip non-existing directories. (#4910)
  • Ignore errors copying socket files for local source installs (in Python 3). (#5306)
  • Fix requirement line parser to correctly handle PEP 440 requirements with a URL pointing to an archive file. (#6202)
  • The pip-wheel-metadata directory does not need to persist between invocations of pip, use a temporary directory instead of the current setup.py directory. (#6213)
  • Fix --trusted-host processing under HTTPS to trust any port number used with the host. (#6705)
  • Switch to new distlib wheel script template. This should be functionally equivalent for end users. (#6763)
  • Skip copying .tox and .nox directories to temporary build directories (#6770)
  • Fix handling of tokens (single part credentials) in URLs. (#6795)
  • Fix a regression that caused ~ expansion not to occur in --find-links paths. (#6804)
  • Fix bypassed pip upgrade warning on Windows. (#6841)
  • Fix 'm' flag erroneously being appended to ABI tag in Python 3.8 on platforms that do not provide SOABI (#6885)
  • Hide security-sensitive strings like passwords in log messages related to version control system (aka VCS) command invocations. (#6890)
  • Correctly uninstall symlinks that were installed in a virtualenv, by tools such as flit install --symlink. (#6892)
... (truncated)
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Note: This repo was added to Dependabot recently, so you'll receive a maximum of 5 PRs for your first few update runs. Once an update run creates fewer than 5 PRs we'll remove that limit.

You can always request more updates by clicking Bump now in your Dependabot dashboard.

Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in your Dependabot dashboard:

  • Update frequency (including time of day and day of week)
  • Pull request limits (per update run and/or open at any time)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

Bumps [pip](https://github.com/pypa/pip) from 19.1.1 to 19.3.1.
- [Release notes](https://github.com/pypa/pip/releases)
- [Changelog](https://github.com/pypa/pip/blob/master/NEWS.rst)
- [Commits](pypa/pip@19.1.1...19.3.1)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
@dependabot-preview dependabot-preview bot added the dependencies Upgrade or downgrade of project dependencies. label Oct 21, 2019
@codecov-io
Copy link

codecov-io commented Oct 21, 2019

Codecov Report

Merging #12 into master will not change coverage.
The diff coverage is n/a.

Impacted file tree graph

@@           Coverage Diff           @@
##           master      #12   +/-   ##
=======================================
  Coverage   99.17%   99.17%           
=======================================
  Files           8        8           
  Lines         241      241           
=======================================
  Hits          239      239           
  Misses          2        2
Flag Coverage Δ
#unittests 99.17% <ø> (ø) ⬆️

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update c4579c1...ada6b03. Read the comment docs.

@frenck frenck merged commit 526c43d into master Oct 21, 2019
@frenck frenck deleted the dependabot/pip/pip-19.3.1 branch October 21, 2019 06:46
@github-actions github-actions bot locked and limited conversation to collaborators Mar 15, 2021
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
dependencies Upgrade or downgrade of project dependencies.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants