Skip to content
This repository has been archived by the owner on Feb 17, 2021. It is now read-only.

Bump pip from 20.2.4 to 20.3.3 in /.github/workflows #260

Merged
merged 1 commit into from
Jan 18, 2021

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jan 14, 2021

Bumps pip from 20.2.4 to 20.3.3.

Changelog

Sourced from pip's changelog.

20.3.3 (2020-12-15)

Bug Fixes

  • Revert "Skip candidate not providing valid metadata", as that caused pip to be overeager about downloading from the package index. ([#9264](https://github.com/pypa/pip/issues/9264) <https://github.com/pypa/pip/issues/9264>_)

20.3.2 (2020-12-15)

Features

  • New resolver: Resolve direct and pinned (== or ===) requirements first to improve resolver performance. ([#9185](https://github.com/pypa/pip/issues/9185) <https://github.com/pypa/pip/issues/9185>_)
  • Add a mechanism to delay resolving certain packages, and use it for setuptools. ([#9249](https://github.com/pypa/pip/issues/9249) <https://github.com/pypa/pip/issues/9249>_)

Bug Fixes

  • New resolver: The "Requirement already satisfied" log is not printed only once for each package during resolution. ([#9117](https://github.com/pypa/pip/issues/9117) <https://github.com/pypa/pip/issues/9117>_)
  • Fix crash when logic for redacting authentication information from URLs in --help is given a list of strings, instead of a single string. ([#9191](https://github.com/pypa/pip/issues/9191) <https://github.com/pypa/pip/issues/9191>_)
  • New resolver: Correctly implement PEP 592. Do not return yanked versions from an index, unless the version range can only be satisfied by yanked candidates. ([#9203](https://github.com/pypa/pip/issues/9203) <https://github.com/pypa/pip/issues/9203>_)
  • New resolver: Make constraints also apply to package variants with extras, so the resolver correctly avoids backtracking on them. ([#9232](https://github.com/pypa/pip/issues/9232) <https://github.com/pypa/pip/issues/9232>_)
  • New resolver: Discard a candidate if it fails to provide metadata from source, or if the provided metadata is inconsistent, instead of quitting outright. ([#9246](https://github.com/pypa/pip/issues/9246) <https://github.com/pypa/pip/issues/9246>_)

Vendored Libraries

  • Update vendoring to 20.8

Improved Documentation

  • Update documentation to reflect that pip still uses legacy resolver by default in Python 2 environments. ([#9269](https://github.com/pypa/pip/issues/9269) <https://github.com/pypa/pip/issues/9269>_)

20.3.1 (2020-12-03)

Deprecations and Removals

... (truncated)

Commits
  • a387de1 Bump for release
  • b4fb710 Merge pull request #9293 from pypa/revert-9264-new-resolver-dont-abort-on-inc...
  • 95c3ae3 📰
  • 7165ab8 Revert "Skip candidate not providing valid metadata"
  • 03d5f56 Merge pull request #9291 from uranusjr/skip-search-tests
  • 145be2e Skip pip search tests unless explicitly requested
  • 2b0b426 Merge pull request #9281 from pradyunsg/release/20.3.2
  • e647c61 Bump for development
  • e1fded5 Bump for release
  • 08816b3 Update AUTHORS.txt
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Jan 14, 2021
@dependabot dependabot bot force-pushed the dependabot/pip/dot-github/workflows/pip-20.3.3 branch from bcf8501 to 36865eb Compare January 17, 2021 18:40
@staticdev staticdev merged commit e1aff24 into master Jan 18, 2021
@dependabot dependabot bot deleted the dependabot/pip/dot-github/workflows/pip-20.3.3 branch January 18, 2021 07:36
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
dependencies Pull requests that update a dependency file python Pull requests that update Python code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant