Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump pip from 20.0.2 to 20.3.2 #518

Closed
wants to merge 1 commit into from

Conversation

dependabot-preview[bot]
Copy link

Bumps pip from 20.0.2 to 20.3.2.

Changelog

Sourced from pip's changelog.

20.3.2 (2020-12-15)

Features

  • New resolver: Resolve direct and pinned (== or ===) requirements first to improve resolver performance. (#9185)
  • Add a mechanism to delay resolving certain packages, and use it for setuptools. (#9249)

Bug Fixes

  • New resolver: The "Requirement already satisfied" log is not printed only once for each package during resolution. (#9117)
  • Fix crash when logic for redacting authentication information from URLs in --help is given a list of strings, instead of a single string. (#9191)
  • New resolver: Correctly implement PEP 592. Do not return yanked versions from an index, unless the version range can only be satisfied by yanked candidates. (#9203)
  • New resolver: Make constraints also apply to package variants with extras, so the resolver correctly avoids backtracking on them. (#9232)
  • New resolver: Discard a candidate if it fails to provide metadata from source, or if the provided metadata is inconsistent, instead of quitting outright. (#9246)

Vendored Libraries

  • Update vendoring to 20.8

Improved Documentation

  • Update documentation to reflect that pip still uses legacy resolver by default in Python 2 environments. (#9269)

20.3.1 (2020-12-03)

Deprecations and Removals

  • The --build-dir option has been restored as a no-op, to soften the transition for tools that still used it. (#9193)

20.3 (2020-11-30)

Deprecations and Removals

  • Remove --unstable-feature flag as it has been deprecated. (#9133)

Features

  • Add support for 600: Future 'manylinux' Platform Tags for Portable Linux Built Distributions. (#9077)
  • The new resolver now resolves packages in a deterministic order. (#9100)
  • Add support for MacOS Big Sur compatibility tags. (#9138)
Commits
  • e1fded5 Bump for release
  • 08816b3 Update AUTHORS.txt
  • cfa013b Merge pull request #9278 from gpiks/update_vendoring_packages
  • 6b2ccdd Update packaging to version 20.8
  • 94b89c9 Merge pull request #9269 from brainwane/docs-update-python-2-pip-20-3
  • acc0cc9 docs: Fix typo
  • 8acf6d4 docs: Fix README for PyPI rendering
  • df7a97f docs: Fix small style issues.
  • c7591bf docs: Clarify that old resolver is default with Python 2
  • 0f8f3d7 Merge pull request #9264 from uranusjr/new-resolver-dont-abort-on-inconsisten...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in your Dependabot dashboard:

  • Update frequency (including time of day and day of week)
  • Pull request limits (per update run and/or open at any time)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

Bumps [pip](https://github.com/pypa/pip) from 20.0.2 to 20.3.2.
- [Release notes](https://github.com/pypa/pip/releases)
- [Changelog](https://github.com/pypa/pip/blob/master/NEWS.rst)
- [Commits](pypa/pip@20.0.2...20.3.2)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
@dependabot-preview dependabot-preview bot added the dependencies Pull requests that update a dependency file label Dec 15, 2020
@coveralls
Copy link

Coverage Status

Coverage remained the same at 42.065% when pulling 29267b9 on dependabot/pip/pip-20.3.2 into 10a4d82 on master.

@dependabot-preview
Copy link
Author

Superseded by #522.

@dependabot-preview dependabot-preview bot deleted the dependabot/pip/pip-20.3.2 branch December 16, 2020 06:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant