Skip to content
This repository has been archived by the owner on Aug 19, 2022. It is now read-only.

Bump pip from 20.3.1 to 20.3.2 in /.github/workflows #233

Merged

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Dec 15, 2020

Bumps pip from 20.3.1 to 20.3.2.

Changelog

Sourced from pip's changelog.

20.3.2 (2020-12-15)

Features

  • New resolver: Resolve direct and pinned (== or ===) requirements first to improve resolver performance. ([#9185](https://github.com/pypa/pip/issues/9185) <https://github.com/pypa/pip/issues/9185>_)
  • Add a mechanism to delay resolving certain packages, and use it for setuptools. ([#9249](https://github.com/pypa/pip/issues/9249) <https://github.com/pypa/pip/issues/9249>_)

Bug Fixes

  • New resolver: The "Requirement already satisfied" log is not printed only once for each package during resolution. ([#9117](https://github.com/pypa/pip/issues/9117) <https://github.com/pypa/pip/issues/9117>_)
  • Fix crash when logic for redacting authentication information from URLs in --help is given a list of strings, instead of a single string. ([#9191](https://github.com/pypa/pip/issues/9191) <https://github.com/pypa/pip/issues/9191>_)
  • New resolver: Correctly implement PEP 592. Do not return yanked versions from an index, unless the version range can only be satisfied by yanked candidates. ([#9203](https://github.com/pypa/pip/issues/9203) <https://github.com/pypa/pip/issues/9203>_)
  • New resolver: Make constraints also apply to package variants with extras, so the resolver correctly avoids backtracking on them. ([#9232](https://github.com/pypa/pip/issues/9232) <https://github.com/pypa/pip/issues/9232>_)
  • New resolver: Discard a candidate if it fails to provide metadata from source, or if the provided metadata is inconsistent, instead of quitting outright. ([#9246](https://github.com/pypa/pip/issues/9246) <https://github.com/pypa/pip/issues/9246>_)

Vendored Libraries

  • Update vendoring to 20.8

Improved Documentation

  • Update documentation to reflect that pip still uses legacy resolver by default in Python 2 environments. ([#9269](https://github.com/pypa/pip/issues/9269) <https://github.com/pypa/pip/issues/9269>_)
Commits
  • e1fded5 Bump for release
  • 08816b3 Update AUTHORS.txt
  • cfa013b Merge pull request #9278 from gpiks/update_vendoring_packages
  • 6b2ccdd Update packaging to version 20.8
  • 94b89c9 Merge pull request #9269 from brainwane/docs-update-python-2-pip-20-3
  • acc0cc9 docs: Fix typo
  • 8acf6d4 docs: Fix README for PyPI rendering
  • df7a97f docs: Fix small style issues.
  • c7591bf docs: Clarify that old resolver is default with Python 2
  • 0f8f3d7 Merge pull request #9264 from uranusjr/new-resolver-dont-abort-on-inconsisten...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [pip](https://github.com/pypa/pip) from 20.3.1 to 20.3.2.
- [Release notes](https://github.com/pypa/pip/releases)
- [Changelog](https://github.com/pypa/pip/blob/master/NEWS.rst)
- [Commits](pypa/pip@20.3.1...20.3.2)

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Dec 15, 2020
@github-actions github-actions bot merged commit 2cc8f3b into master Dec 15, 2020
@dependabot dependabot bot deleted the dependabot/pip/dot-github/workflows/pip-20.3.2 branch December 15, 2020 05:23
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
dependencies Pull requests that update a dependency file python Pull requests that update Python code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

0 participants