Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump pip from 20.3.1 to 20.3.3 #6739

Merged
merged 1 commit into from
Dec 22, 2020
Merged

Bump pip from 20.3.1 to 20.3.3 #6739

merged 1 commit into from
Dec 22, 2020

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Dec 21, 2020

Bumps pip from 20.3.1 to 20.3.3.

Changelog

Sourced from pip's changelog.

20.3.3 (2020-12-15)

Bug Fixes

  • Revert "Skip candidate not providing valid metadata", as that caused pip to be overeager about downloading from the package index. ([#9264](https://github.com/pypa/pip/issues/9264) <https://github.com/pypa/pip/issues/9264>_)

20.3.2 (2020-12-15)

Features

  • New resolver: Resolve direct and pinned (== or ===) requirements first to improve resolver performance. ([#9185](https://github.com/pypa/pip/issues/9185) <https://github.com/pypa/pip/issues/9185>_)
  • Add a mechanism to delay resolving certain packages, and use it for setuptools. ([#9249](https://github.com/pypa/pip/issues/9249) <https://github.com/pypa/pip/issues/9249>_)

Bug Fixes

  • New resolver: The "Requirement already satisfied" log is not printed only once for each package during resolution. ([#9117](https://github.com/pypa/pip/issues/9117) <https://github.com/pypa/pip/issues/9117>_)
  • Fix crash when logic for redacting authentication information from URLs in --help is given a list of strings, instead of a single string. ([#9191](https://github.com/pypa/pip/issues/9191) <https://github.com/pypa/pip/issues/9191>_)
  • New resolver: Correctly implement PEP 592. Do not return yanked versions from an index, unless the version range can only be satisfied by yanked candidates. ([#9203](https://github.com/pypa/pip/issues/9203) <https://github.com/pypa/pip/issues/9203>_)
  • New resolver: Make constraints also apply to package variants with extras, so the resolver correctly avoids backtracking on them. ([#9232](https://github.com/pypa/pip/issues/9232) <https://github.com/pypa/pip/issues/9232>_)
  • New resolver: Discard a candidate if it fails to provide metadata from source, or if the provided metadata is inconsistent, instead of quitting outright. ([#9246](https://github.com/pypa/pip/issues/9246) <https://github.com/pypa/pip/issues/9246>_)

Vendored Libraries

  • Update vendoring to 20.8

Improved Documentation

  • Update documentation to reflect that pip still uses legacy resolver by default in Python 2 environments. ([#9269](https://github.com/pypa/pip/issues/9269) <https://github.com/pypa/pip/issues/9269>_)
Commits
  • a387de1 Bump for release
  • b4fb710 Merge pull request #9293 from pypa/revert-9264-new-resolver-dont-abort-on-inc...
  • 95c3ae3 📰
  • 7165ab8 Revert "Skip candidate not providing valid metadata"
  • 03d5f56 Merge pull request #9291 from uranusjr/skip-search-tests
  • 145be2e Skip pip search tests unless explicitly requested
  • 2b0b426 Merge pull request #9281 from pradyunsg/release/20.3.2
  • e647c61 Bump for development
  • e1fded5 Bump for release
  • 08816b3 Update AUTHORS.txt
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually

Bumps [pip](https://github.com/pypa/pip) from 20.3.1 to 20.3.3.
- [Release notes](https://github.com/pypa/pip/releases)
- [Changelog](https://github.com/pypa/pip/blob/master/NEWS.rst)
- [Commits](pypa/pip@20.3.1...20.3.3)

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Dec 21, 2020
@cla-bot cla-bot bot added the cla-signed CLA Bot: community license agreement signed label Dec 21, 2020
@codecov
Copy link

codecov bot commented Dec 21, 2020

Codecov Report

Merging #6739 (764cef5) into master (7ad1eaa) will not change coverage.
The diff coverage is n/a.

@@           Coverage Diff           @@
##           master    #6739   +/-   ##
=======================================
  Coverage   35.40%   35.40%           
=======================================
  Files         216      216           
  Lines       23022    23022           
  Branches     3791     3791           
=======================================
  Hits         8150     8150           
  Misses      14398    14398           
  Partials      474      474           

@afabiani afabiani added this to the 3.2 milestone Dec 22, 2020
@afabiani afabiani merged commit 893bfb1 into master Dec 22, 2020
@dependabot dependabot bot deleted the dependabot/pip/pip-20.3.3 branch December 22, 2020 09:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
cla-signed CLA Bot: community license agreement signed dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant