Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump pip from 20.3.1 to 20.3.2 in /.github/workflows #42

Merged

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Dec 15, 2020

Bumps pip from 20.3.1 to 20.3.2.

Changelog

Sourced from pip's changelog.

20.3.2 (2020-12-15)

Features

  • New resolver: Resolve direct and pinned (== or ===) requirements first to improve resolver performance. ([#9185](https://github.com/pypa/pip/issues/9185) <https://github.com/pypa/pip/issues/9185>_)
  • Add a mechanism to delay resolving certain packages, and use it for setuptools. ([#9249](https://github.com/pypa/pip/issues/9249) <https://github.com/pypa/pip/issues/9249>_)

Bug Fixes

  • New resolver: The "Requirement already satisfied" log is not printed only once for each package during resolution. ([#9117](https://github.com/pypa/pip/issues/9117) <https://github.com/pypa/pip/issues/9117>_)
  • Fix crash when logic for redacting authentication information from URLs in --help is given a list of strings, instead of a single string. ([#9191](https://github.com/pypa/pip/issues/9191) <https://github.com/pypa/pip/issues/9191>_)
  • New resolver: Correctly implement PEP 592. Do not return yanked versions from an index, unless the version range can only be satisfied by yanked candidates. ([#9203](https://github.com/pypa/pip/issues/9203) <https://github.com/pypa/pip/issues/9203>_)
  • New resolver: Make constraints also apply to package variants with extras, so the resolver correctly avoids backtracking on them. ([#9232](https://github.com/pypa/pip/issues/9232) <https://github.com/pypa/pip/issues/9232>_)
  • New resolver: Discard a candidate if it fails to provide metadata from source, or if the provided metadata is inconsistent, instead of quitting outright. ([#9246](https://github.com/pypa/pip/issues/9246) <https://github.com/pypa/pip/issues/9246>_)

Vendored Libraries

  • Update vendoring to 20.8

Improved Documentation

  • Update documentation to reflect that pip still uses legacy resolver by default in Python 2 environments. ([#9269](https://github.com/pypa/pip/issues/9269) <https://github.com/pypa/pip/issues/9269>_)
Commits
  • e1fded5 Bump for release
  • 08816b3 Update AUTHORS.txt
  • cfa013b Merge pull request #9278 from gpiks/update_vendoring_packages
  • 6b2ccdd Update packaging to version 20.8
  • 94b89c9 Merge pull request #9269 from brainwane/docs-update-python-2-pip-20-3
  • acc0cc9 docs: Fix typo
  • 8acf6d4 docs: Fix README for PyPI rendering
  • df7a97f docs: Fix small style issues.
  • c7591bf docs: Clarify that old resolver is default with Python 2
  • 0f8f3d7 Merge pull request #9264 from uranusjr/new-resolver-dont-abort-on-inconsisten...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [pip](https://github.com/pypa/pip) from 20.3.1 to 20.3.2.
- [Release notes](https://github.com/pypa/pip/releases)
- [Changelog](https://github.com/pypa/pip/blob/master/NEWS.rst)
- [Commits](pypa/pip@20.3.1...20.3.2)

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Dec 15, 2020
@thalesbertaglia thalesbertaglia merged commit 805b852 into master Dec 15, 2020
@dependabot dependabot bot deleted the dependabot/pip/dot-github/workflows/pip-20.3.2 branch December 15, 2020 10:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file python Pull requests that update Python code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant