Skip to content
This repository has been archived by the owner on Aug 19, 2022. It is now read-only.

Bump pip from 21.3 to 21.3.1 in /.github/workflows #389

Merged
merged 1 commit into from
Oct 25, 2021

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Oct 25, 2021

Bumps pip from 21.3 to 21.3.1.

Changelog

Sourced from pip's changelog.

21.3.1 (2021-10-22)

Bug Fixes

  • Always refuse installing or building projects that have no pyproject.toml nor setup.py. ([#10531](https://github.com/pypa/pip/issues/10531) <https://github.com/pypa/pip/issues/10531>_)
  • Tweak running-as-root detection, to check os.getuid if it exists, on Unix-y and non-Linux/non-MacOS machines. ([#10565](https://github.com/pypa/pip/issues/10565) <https://github.com/pypa/pip/issues/10565>_)
  • When installing projects with a pyproject.toml in editable mode, and the build backend does not support :pep:660, prepare metadata using prepare_metadata_for_build_wheel instead of setup.py egg_info. Also, refuse installing projects that only have a setup.cfg and no setup.py nor pyproject.toml. These restore the pre-21.3 behaviour. ([#10573](https://github.com/pypa/pip/issues/10573) <https://github.com/pypa/pip/issues/10573>_)
  • Restore compatibility of where configuration files are loaded from on MacOS (back to Library/Application Support/pip, instead of Preferences/pip). ([#10585](https://github.com/pypa/pip/issues/10585) <https://github.com/pypa/pip/issues/10585>_)

Vendored Libraries

  • Upgrade pep517 to 0.12.0
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [pip](https://github.com/pypa/pip) from 21.3 to 21.3.1.
- [Release notes](https://github.com/pypa/pip/releases)
- [Changelog](https://github.com/pypa/pip/blob/main/NEWS.rst)
- [Commits](pypa/pip@21.3...21.3.1)

---
updated-dependencies:
- dependency-name: pip
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Oct 25, 2021
@staticdev staticdev merged commit db13315 into main Oct 25, 2021
@dependabot dependabot bot deleted the dependabot/pip/dot-github/workflows/pip-21.3.1 branch October 25, 2021 16:29
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
dependencies Pull requests that update a dependency file python Pull requests that update Python code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant