Skip to content

chore(deps): bump the dependencies group with 11 updates#494

Merged
TrueBrain merged 1 commit intomainfrom
dependabot/pip/dependencies-b192afb258
Jul 27, 2023
Merged

chore(deps): bump the dependencies group with 11 updates#494
TrueBrain merged 1 commit intomainfrom
dependabot/pip/dependencies-b192afb258

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Jul 27, 2023

Bumps the dependencies group with 11 updates:

Package Update
aiohttp 3.8.4 to 3.8.5
certifi 2023.5.7 to 2023.7.22
charset-normalizer 3.1.0 to 3.2.0
click 8.1.3 to 8.1.6
frozenlist 1.3.3 to 1.4.0
gitpython 3.1.31 to 3.1.32
pyjwt 2.7.0 to 2.8.0
pyyaml 6.0 to 6.0.1
sentry-sdk 1.27.0 to 1.28.1
urllib3 2.0.3 to 2.0.4
wikitextparser 0.52.1 to 0.53.0

Updates aiohttp from 3.8.4 to 3.8.5

Release notes

Sourced from aiohttp's releases.

3.8.5

Security bugfixes

  • Upgraded the vendored copy of llhttp_ to v8.1.1 -- by :user:webknjaz and :user:Dreamsorcerer.

    Thanks to :user:sethmlarson for reporting this and providing us with comprehensive reproducer, workarounds and fixing details! For more information, see GHSA-45c4-8wx5-qw6w.

    .. _llhttp: https://llhttp.org

    (#7346)

Features

  • Added information to C parser exceptions to show which character caused the error. -- by :user:Dreamsorcerer

    (#7366)

Bugfixes

  • Fixed a transport is :data:None error -- by :user:Dreamsorcerer.

    (#3355)


Changelog

Sourced from aiohttp's changelog.

3.8.5 (2023-07-19)

Security bugfixes

  • Upgraded the vendored copy of llhttp_ to v8.1.1 -- by :user:webknjaz and :user:Dreamsorcerer.

    Thanks to :user:sethmlarson for reporting this and providing us with comprehensive reproducer, workarounds and fixing details! For more information, see GHSA-45c4-8wx5-qw6w.

    .. _llhttp: https://llhttp.org

    [#7346](https://github.com/aio-libs/aiohttp/issues/7346) <https://github.com/aio-libs/aiohttp/issues/7346>_

Features

  • Added information to C parser exceptions to show which character caused the error. -- by :user:Dreamsorcerer

    [#7366](https://github.com/aio-libs/aiohttp/issues/7366) <https://github.com/aio-libs/aiohttp/issues/7366>_

Bugfixes

  • Fixed a transport is :data:None error -- by :user:Dreamsorcerer.

    [#3355](https://github.com/aio-libs/aiohttp/issues/3355) <https://github.com/aio-libs/aiohttp/issues/3355>_


Commits

Updates certifi from 2023.5.7 to 2023.7.22

Commits

Updates charset-normalizer from 3.1.0 to 3.2.0

Release notes

Sourced from charset-normalizer's releases.

Version 3.2.0

3.2.0 (2023-06-07)

Changed

  • Typehint for function from_path no longer enforce PathLike as its first argument
  • Minor improvement over the global detection reliability

Added

  • Introduce function is_binary that relies on main capabilities, and is optimized to detect binaries
  • Propagate enable_fallback argument throughout from_bytes, from_path, and from_fp that allow a deeper control over the detection (default True)
  • Explicit support for Python 3.12

Fixed

  • Edge case detection failure where a file would contain 'very-long' camel-cased word (Issue #289)
Changelog

Sourced from charset-normalizer's changelog.

3.2.0 (2023-06-07)

Changed

  • Typehint for function from_path no longer enforce PathLike as its first argument
  • Minor improvement over the global detection reliability

Added

  • Introduce function is_binary that relies on main capabilities, and optimized to detect binaries
  • Propagate enable_fallback argument throughout from_bytes, from_path, and from_fp that allow a deeper control over the detection (default True)
  • Explicit support for Python 3.12

Fixed

  • Edge case detection failure where a file would contain 'very-long' camel cased word (Issue #289)
Commits
  • 0424c80 Add workflow_call for ci.yml workflow (reusable) (#307)
  • 782885e Fix issue 289, add function is_binary, add explicit support py 3.12 (#306)
  • 1b0fb5c ⬆️ Bump pytest from 7.3.2 to 7.4.0 (#304)
  • 3acf08e ⬆️ Bump mypy from 1.3.0 to 1.4.1 (#305)
  • 5c030b5 Replace emoji shortcodes with UTF-8 emoji (#303)
  • f9f686b ⬆️ Bump pypa/cibuildwheel from 2.13.0 to 2.13.1 (#302)
  • d42cdaf ⬆️ Bump slsa-framework/slsa-github-generator from 1.6.0 to 1.7.0 (#301)
  • f8e7db1 ⬆️ Bump pytest from 7.3.1 to 7.3.2 (#300)
  • 6f02962 ⬆️ Bump pytest-cov from 4.0.0 to 4.1.0 (#298)
  • 8028c56 ⬆️ Bump pypa/cibuildwheel from 2.12.3 to 2.13.0 (#299)
  • Additional commits viewable in compare view

Updates click from 8.1.3 to 8.1.6

Release notes

Sourced from click's releases.

8.1.6

This is a fix release for the 8.1.x feature branch. If you were having issues with type checking tools like pyright or mypy not accepting uses of Click's decorators, this should fix that.

8.1.5

This is a fix release for the 8.1.x feature branch. This fixes an issue with decorator type annotations that caused type checkers to fail for valid code. There are no runtime behavior changes.

8.1.4

This is a fix release for the 8.1.x feature branch.

Changelog

Sourced from click's changelog.

Version 8.1.6

Released 2023-07-18

  • Fix an issue with type hints for @click.group(). :issue:2558

Version 8.1.5

Released 2023-07-13

  • Fix an issue with type hints for @click.command(), @click.option(), and other decorators. Introduce typing tests. :issue:2558

Version 8.1.4

Released 2023-07-06

  • Replace all typing.Dict occurrences to typing.MutableMapping for parameter hints. :issue:2255
  • Improve type hinting for decorators and give all generic types parameters. :issue:2398
  • Fix return value and type signature of shell_completion.add_completion_class function. :pr:2421
  • Bash version detection doesn't fail on Windows. :issue:2461
  • Completion works if there is a dot (.) in the program name. :issue:2166
  • Improve type annotations for pyright type checker. :issue:2268
  • Improve responsiveness of click.clear(). :issue:2284
  • Improve command name detection when using Shiv or PEX. :issue:2332
  • Avoid showing empty lines if command help text is empty. :issue:2368
  • ZSH completion script works when loaded from fpath. :issue:2344.
  • EOFError and KeyboardInterrupt tracebacks are not suppressed when standalone_mode is disabled. :issue:2380
  • @group.command does not fail if the group was created with a custom command_class. :issue:2416
  • multiple=True is allowed for flag options again and does not require setting default=(). :issue:2246, 2292, 2295
  • Make the decorators returned by @argument() and @option() reusable when the cls parameter is used. :issue:2294
  • Don't fail when writing filenames to streams with strict errors. Replace invalid bytes with the replacement character (). :issue:2395
  • Remove unnecessary attempt to detect MSYS2 environment. :issue:2355
  • Remove outdated and unnecessary detection of App Engine environment. :pr:2554
  • echo() does not fail when no streams are attached, such as with pythonw on Windows. :issue:2415
  • Argument with expose_value=False do not cause completion to fail. :issue:2336
Commits

Updates frozenlist from 1.3.3 to 1.4.0

Release notes

Sourced from frozenlist's releases.

1.4.0

The published source distribution package became buildable under Python 3.12.


Bugfixes

  • Removed an unused :py:data:typing.Tuple import (#411)_

Deprecations and Removals

  • Dropped Python 3.7 support. (#413)_

Misc


Changelog

Sourced from frozenlist's changelog.

1.4.0 (2023-07-12)

The published source distribution package became buildable under Python 3.12.


Bugfixes

  • Removed an unused :py:data:typing.Tuple import [#411](https://github.com/aio-libs/frozenlist/issues/411) <https://github.com/aio-libs/frozenlist/issues/411>_

Deprecations and Removals

  • Dropped Python 3.7 support. [#413](https://github.com/aio-libs/frozenlist/issues/413) <https://github.com/aio-libs/frozenlist/issues/413>_

Misc

  • [#410](https://github.com/aio-libs/frozenlist/issues/410) <https://github.com/aio-libs/frozenlist/issues/410>, [#433](https://github.com/aio-libs/frozenlist/issues/433) <https://github.com/aio-libs/frozenlist/issues/433>

Commits
  • 9d96e08 🐛 Add "Gitter" to the spelling allowlist
  • 7b65e79 📦 Bump frozenlist to v1.4.0
  • b3a6bd7 🧪 Check dist meta in strict mode
  • 116c164 📝🔥 Remove references to Discourse
  • ad22ce8 📝 Replace Gitter mentions with Matrix
  • f119a80 📦📝 Link CoC from the PyPI page sidebar
  • adcdfce 🎨📝 Replace PyPI badge w/ shields.io in README
  • fc7747e 📝📦 Link the changelog from PyPI
  • 16e5426 📝 Update docs links with new FQDN
  • 2a284f3 🧪 Report coverage for the tests
  • Additional commits viewable in compare view

Updates gitpython from 3.1.31 to 3.1.32

Release notes

Sourced from gitpython's releases.

v3.1.32 - with another security update

What's Changed

New Contributors

Full Changelog: gitpython-developers/GitPython@3.1.31...3.1.32

Commits
  • 5d45ce2 prepare 3.1.32 release
  • ca965ec Merge pull request #1609 from Beuc/block-insecure-options-clone-non-multi
  • 5c59e0d Block insecure non-multi options in clone/clone_from
  • c09a71e Merge pull request #1606 from r-darwish/no-del
  • a3859ee fixes
  • 8186159 Don't rely on del
  • 741edb5 Merge pull request #1603 from eUgEntOptIc44/eugenoptic44-fix-pypi-long-descri...
  • 0c543cd Improve readability of README.md
  • 9cd7ddb Improve the 'long_description' displayed on pypi
  • 6fc11e6 update README to reflect the status quo on git command usage
  • Additional commits viewable in compare view

Updates pyjwt from 2.7.0 to 2.8.0

Release notes

Sourced from pyjwt's releases.

2.8.0

What's Changed

New Contributors

Full Changelog: jpadilla/pyjwt@2.7.0...2.8.0

Changelog

Sourced from pyjwt's changelog.

v2.8.0 <https://github.com/jpadilla/pyjwt/compare/2.7.0...2.8.0>__

Changed


- Update python version test matrix by @auvipy in `[#895](https://github.com/jpadilla/pyjwt/issues/895) <https://github.com/jpadilla/pyjwt/pull/895>`__

Fixed


Added
  • Add strict_aud as an option to jwt.decode by @​woodruffw in [#902](https://github.com/jpadilla/pyjwt/issues/902) &lt;https://github.com/jpadilla/pyjwt/pull/902&gt;__
  • Export PyJWKClientConnectionError class by @​daviddavis in [#887](https://github.com/jpadilla/pyjwt/issues/887) &lt;https://github.com/jpadilla/pyjwt/pull/887&gt;__
  • Allows passing of ssl.SSLContext to PyJWKClient by @​juur in [#891](https://github.com/jpadilla/pyjwt/issues/891) &lt;https://github.com/jpadilla/pyjwt/pull/891&gt;__
Commits

Updates pyyaml from 6.0 to 6.0.1

Changelog

Sourced from pyyaml's changelog.

6.0.1 (2023-07-18)

Commits

Updates sentry-sdk from 1.27.0 to 1.28.1

Release notes

Sourced from sentry-sdk's releases.

1.28.1

Various fixes & improvements

1.28.0

Various fixes & improvements

Changelog

Sourced from sentry-sdk's changelog.

1.28.1

Various fixes & improvements

1.28.0

Various fixes & improvements

1.27.1

Various fixes & improvements

  • Add Starlette/FastAPI template tag for adding Sentry tracing information (#2225) by @​antonpirker
    • By adding {{ sentry_trace_meta }} to your Starlette/FastAPI Jinja2 templates we will include Sentry trace information as a meta tag in the rendered HTML to allow your frontend to pick up and continue the trace started in the backend.
  • Fixed generation of baggage when a DSC is already in propagation context (#2232) by @​antonpirker
  • Handle explicitly passing None for trace_configs in aiohttp (#2230) by @​Harmon758
  • Support newest Starlette versions (#2227) by @​antonpirker
Commits
  • e1c77cc Updated changelog
  • 78b5113 release: 1.28.1
  • d586149 Make sure each task that is started by Celery Beat has its own trace. (#2249)
  • 093003f remove stale.yml (#2245)
  • d874091 Add Sampling Decision to Trace Envelope Header (#2239)
  • 5704f12 Skip distributions with incomplete metadata (#2231)
  • 7a9b1b7 Do not add trace headers (sentry-trace and baggage) to HTTP requests to S...
  • 994a45b Redis: Add support for redis.asyncio (#1933)
  • b89fa8d Prevent adding sentry-trace header multiple times (#2235)
  • 684c43f Django: Fix 404 Handler handler being labeled as "generic ASGI request" (#1277)
  • Additional commits viewable in compare view

Updates urllib3 from 2.0.3 to 2.0.4

Release notes

Sourced from urllib3's releases.

2.0.4

  • Added support for union operators to HTTPHeaderDict (#2254)
  • Added BaseHTTPResponse to urllib3.__all__ (#3078)
  • Fixed urllib3.connection.HTTPConnection to raise the http.client.connect audit event to have the same behavior as the standard library HTTP client (#2757)
  • Relied on the standard library for checking hostnames in supported PyPy releases (#3087)
Changelog

Sourced from urllib3's changelog.

2.0.4 (2023-07-19)

  • Added support for union operators to HTTPHeaderDict ([#2254](https://github.com/urllib3/urllib3/issues/2254) <https://github.com/urllib3/urllib3/issues/2254>__)
  • Added BaseHTTPResponse to urllib3.__all__ ([#3078](https://github.com/urllib3/urllib3/issues/3078) <https://github.com/urllib3/urllib3/issues/3078>__)
  • Fixed urllib3.connection.HTTPConnection to raise the http.client.connect audit event to have the same behavior as the standard library HTTP client ([#2757](https://github.com/urllib3/urllib3/issues/2757) <https://github.com/urllib3/urllib3/issues/2757>__)
  • Relied on the standard library for checking hostnames in supported PyPy releases ([#3087](https://github.com/urllib3/urllib3/issues/3087) <https://github.com/urllib3/urllib3/issues/3087>__)
Commits
  • c9fa144 Release version 2.0.4 (#3084)
  • d40d146 Add Illia to CODEOWNERS
  • 0a375d1 Raise http.client.connect audit events in HTTPConnection (#2859)
  • c056eb3 Bump actions/setup-python from 4.6.0 to 4.7.0
  • a1c184b Remove warnings filters fixed in pytest 7.4.0 (#3086)
  • 609c546 Add support for union operators to HTTPHeaderDict (#2943)
  • 05b21ca Bump cryptography from 41.0.0 to 41.0.2
  • 9aa0d4f Bump cryptography from 39.0.1 to 41.0.0 (#3057)
  • 326c423 Rely on the standard library for checking hostnames in supported PyPy releases
  • d0ac08d Bump gh-action-pypi-publish to v1.8.8
  • Additional commits viewable in compare view

Updates wikitextparser from 0.52.1 to 0.53.0

Changelog

Sourced from wikitextparser's changelog.

v0.53.0

  • Fixed a bug in plain_text()/remove_markup, not being able to handle table with row/colspan. (#116)
  • plain_text() will now include table captions.
Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually

Bumps the dependencies group with 11 updates:

| Package | Update |
| --- | --- |
| [aiohttp](https://github.com/aio-libs/aiohttp) | 3.8.4 to 3.8.5 |
| [certifi](https://github.com/certifi/python-certifi) | 2023.5.7 to 2023.7.22 |
| [charset-normalizer](https://github.com/Ousret/charset_normalizer) | 3.1.0 to 3.2.0 |
| [click](https://github.com/pallets/click) | 8.1.3 to 8.1.6 |
| [frozenlist](https://github.com/aio-libs/frozenlist) | 1.3.3 to 1.4.0 |
| [gitpython](https://github.com/gitpython-developers/GitPython) | 3.1.31 to 3.1.32 |
| [pyjwt](https://github.com/jpadilla/pyjwt) | 2.7.0 to 2.8.0 |
| [pyyaml](https://github.com/yaml/pyyaml) | 6.0 to 6.0.1 |
| [sentry-sdk](https://github.com/getsentry/sentry-python) | 1.27.0 to 1.28.1 |
| [urllib3](https://github.com/urllib3/urllib3) | 2.0.3 to 2.0.4 |
| [wikitextparser](https://github.com/5j9/wikitextparser) | 0.52.1 to 0.53.0 |


Updates `aiohttp` from 3.8.4 to 3.8.5
- [Release notes](https://github.com/aio-libs/aiohttp/releases)
- [Changelog](https://github.com/aio-libs/aiohttp/blob/v3.8.5/CHANGES.rst)
- [Commits](aio-libs/aiohttp@v3.8.4...v3.8.5)

Updates `certifi` from 2023.5.7 to 2023.7.22
- [Commits](certifi/python-certifi@2023.05.07...2023.07.22)

Updates `charset-normalizer` from 3.1.0 to 3.2.0
- [Release notes](https://github.com/Ousret/charset_normalizer/releases)
- [Changelog](https://github.com/Ousret/charset_normalizer/blob/master/CHANGELOG.md)
- [Commits](jawah/charset_normalizer@3.1.0...3.2.0)

Updates `click` from 8.1.3 to 8.1.6
- [Release notes](https://github.com/pallets/click/releases)
- [Changelog](https://github.com/pallets/click/blob/8.1.6/CHANGES.rst)
- [Commits](pallets/click@8.1.3...8.1.6)

Updates `frozenlist` from 1.3.3 to 1.4.0
- [Release notes](https://github.com/aio-libs/frozenlist/releases)
- [Changelog](https://github.com/aio-libs/frozenlist/blob/master/CHANGES.rst)
- [Commits](aio-libs/frozenlist@v1.3.3...v1.4.0)

Updates `gitpython` from 3.1.31 to 3.1.32
- [Release notes](https://github.com/gitpython-developers/GitPython/releases)
- [Changelog](https://github.com/gitpython-developers/GitPython/blob/main/CHANGES)
- [Commits](gitpython-developers/GitPython@3.1.31...3.1.32)

Updates `pyjwt` from 2.7.0 to 2.8.0
- [Release notes](https://github.com/jpadilla/pyjwt/releases)
- [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst)
- [Commits](jpadilla/pyjwt@2.7.0...2.8.0)

Updates `pyyaml` from 6.0 to 6.0.1
- [Changelog](https://github.com/yaml/pyyaml/blob/6.0.1/CHANGES)
- [Commits](yaml/pyyaml@6.0...6.0.1)

Updates `sentry-sdk` from 1.27.0 to 1.28.1
- [Release notes](https://github.com/getsentry/sentry-python/releases)
- [Changelog](https://github.com/getsentry/sentry-python/blob/master/CHANGELOG.md)
- [Commits](getsentry/sentry-python@1.27.0...1.28.1)

Updates `urllib3` from 2.0.3 to 2.0.4
- [Release notes](https://github.com/urllib3/urllib3/releases)
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst)
- [Commits](urllib3/urllib3@2.0.3...2.0.4)

Updates `wikitextparser` from 0.52.1 to 0.53.0
- [Changelog](https://github.com/5j9/wikitextparser/blob/master/CHANGELOG.rst)
- [Commits](5j9/wikitextparser@v0.52.1...v0.53.0)

---
updated-dependencies:
- dependency-name: aiohttp
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: certifi
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: charset-normalizer
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: click
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: frozenlist
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: gitpython
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: pyjwt
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: pyyaml
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: sentry-sdk
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: urllib3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: wikitextparser
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Jul 27, 2023
@TrueBrain TrueBrain merged commit 1b26d0e into main Jul 27, 2023
@TrueBrain TrueBrain deleted the dependabot/pip/dependencies-b192afb258 branch July 27, 2023 14:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant