Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump gunicorn from 19.6.0 to 20.0.4 in /config/web #24

Merged
merged 1 commit into from
Apr 15, 2020

Conversation

dependabot-preview[bot]
Copy link
Contributor

@dependabot-preview dependabot-preview bot commented Apr 15, 2020

Bumps gunicorn from 19.6.0 to 20.0.4.

Release notes

Sourced from gunicorn's releases.

20.0.4

  • fix binding a socket using the file descriptor
  • remove support for the bdist_rpm build

20.0.3

  • fixed load of a config file without a Python extension
  • fixed socketfromfd.fromfd when defaults are not set

note: we now warn when we load a config file without Python Extension

20.0.2

  • fix changelog

20.0.1

  • fixed the way the config module is loaded. __file__ is now available
  • fixed wsgi.input_terminated. It is always true.
  • use the highest protocol version of openssl by default
  • only support Python >= 3.5
  • added __repr__ method to Config instance
  • fixed support of AIX platform and musl libc in socketfromfd.fromfd function
  • fixed support of applications loaded from a factory function
  • fixed chunked encoding support to prevent any request smuggling <https://portswigger.net/research/http-desync-attacks-request-smuggling-reborn>_
  • Capture os.sendfile before patching in gevent and eventlet workers. fix RecursionError.
  • removed locking in reloader when adding new files
  • load the WSGI application before the loader to pick up all files

note this release add official support for applications loaded from a factory function as documented in Flask and other places.

20.0

  • Fixed fdopen RuntimeWarning in Python 3.8
  • Added check and exception for str type on value in Response process_headers method.
  • Ensure WSGI header value is string before conducting regex search on it.
  • Added pypy3 to list of tested environments
  • Grouped StopIteration and KeyboardInterrupt exceptions with same body together in Arbiter.run()
  • Added setproctitle module to extras_require in setup.py
  • Avoid unnecessary chown of temporary files
  • Logging: Handle auth type case insensitively
  • Removed util.import_module
  • Removed fallback for types.SimpleNamespace in tests utils
  • Use SourceFileLoader instead instead of execfile_
  • Use importlib instead of __import__ and eval`
  • Fixed eventlet patching
  • Added optional datadog <https://www.datadoghq.com>_ tags for statsd metrics
  • Header values now are encoded using latin-1, not ascii.
  • Rewritten parse_address util added test
  • Removed redundant super() arguments
... (truncated)
Commits
  • 5d0c778 bump to 20.0.4
  • 67cb620 remove socketfromfd module
  • c583377 Revert "socketfromfd: remove python 2 compatibility"
  • ab25bae Revert "socketfromfd: fix cross platform usage"
  • 8c759dd Revert "fix linting on python 3.8"
  • d530e67 Revert "refactor module"
  • 5bae77c Merge branch '20.x'
  • d95ed44 point website to last version
  • 0c3af6e Merge branch 'master' into 20.x
  • f646bde fix bad cherry-picking
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Note: This repo was added to Dependabot recently, so you'll receive a maximum of 5 PRs for your first few update runs. Once an update run creates fewer than 5 PRs we'll remove that limit.

You can always request more updates by clicking Bump now in your Dependabot dashboard.

Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in your Dependabot dashboard:

  • Update frequency (including time of day and day of week)
  • Pull request limits (per update run and/or open at any time)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

@dependabot-preview dependabot-preview bot added the dependencies Pull requests that update a dependency file label Apr 15, 2020
@codecov
Copy link

codecov bot commented Apr 15, 2020

Codecov Report

Merging #24 into master will not change coverage.
The diff coverage is n/a.

Impacted file tree graph

@@           Coverage Diff           @@
##           master      #24   +/-   ##
=======================================
  Coverage   53.21%   53.21%           
=======================================
  Files          52       52           
  Lines         389      389           
=======================================
  Hits          207      207           
  Misses        182      182           

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update ea206ea...5947138. Read the comment docs.

@dependabot-preview dependabot-preview bot force-pushed the dependabot/pip/config/web/gunicorn-20.0.4 branch from 24c22c2 to 8f75580 Compare April 15, 2020 19:51
Bumps [gunicorn](https://github.com/benoitc/gunicorn) from 19.6.0 to 20.0.4.
- [Release notes](https://github.com/benoitc/gunicorn/releases)
- [Commits](benoitc/gunicorn@19.6.0...20.0.4)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
@dependabot-preview dependabot-preview bot force-pushed the dependabot/pip/config/web/gunicorn-20.0.4 branch from 8f75580 to 5947138 Compare April 15, 2020 20:15
@garciparedes garciparedes merged commit 50370a8 into master Apr 15, 2020
@dependabot-preview dependabot-preview bot deleted the dependabot/pip/config/web/gunicorn-20.0.4 branch April 15, 2020 21:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant