Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update yarl requirement from <1.15.3,>=1.8 to >=1.8,<1.15.5 #5916

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Oct 16, 2024

Updates the requirements on yarl to permit the latest version.

Release notes

Sourced from yarl's releases.

1.15.4

Miscellaneous internal changes

  • Improved performance of the quoter when all characters are safe -- by :user:bdraco.

    Related issues and pull requests on GitHub: #1288.

  • Improved performance of unquoting strings -- by :user:bdraco.

    Related issues and pull requests on GitHub: #1292, #1293.

  • Improved performance of calling :py:meth:~yarl.URL.build -- by :user:bdraco.

    Related issues and pull requests on GitHub: #1297.


Changelog

Sourced from yarl's changelog.

1.15.4

(2024-10-16)

Miscellaneous internal changes

  • Improved performance of the quoter when all characters are safe -- by :user:bdraco.

    Related issues and pull requests on GitHub: :issue:1288.

  • Improved performance of unquoting strings -- by :user:bdraco.

    Related issues and pull requests on GitHub: :issue:1292, :issue:1293.

  • Improved performance of calling :py:meth:~yarl.URL.build -- by :user:bdraco.

    Related issues and pull requests on GitHub: :issue:1297.


1.15.3

(2024-10-15)

Bug fixes

  • Fixed :py:meth:~yarl.URL.build failing to validate paths must start with a / when passing authority -- by :user:bdraco.

    The validation only worked correctly when passing host.

    Related issues and pull requests on GitHub: :issue:1265.

Removals and backward incompatible breaking changes

  • Removed support for Python 3.8 as it has reached end of life -- by :user:bdraco.

... (truncated)

Commits
  • f75a81d Release 1.15.4 (#1301)
  • d40efff Improve performance of URL.build by avoiding operations (#1297)
  • 6e574b6 Fix query benchmarks to avoid testing property cache hits (#1300)
  • cd1d352 Add benchmark for building a URL with query (#1299)
  • 10ce80a Remove redundant hypothesis pytest mark (#1298)
  • 760c627 Add query string benchmarks (#1295)
  • 976f540 Fix path quoting benchmarks to use the same quoting config as production (#1294)
  • 2395cb8 Avoid creating a new unquoted string if nothing changes (#1293)
  • 4533b3c Use faster Python unicode API for unquoter (#1292)
  • e776a70 Improve quoter performance when all characters are safe (#1288)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Updates the requirements on [yarl](https://github.com/aio-libs/yarl) to permit the latest version.
- [Release notes](https://github.com/aio-libs/yarl/releases)
- [Changelog](https://github.com/aio-libs/yarl/blob/master/CHANGES.rst)
- [Commits](aio-libs/yarl@v1.8.0...v1.15.4)

---
updated-dependencies:
- dependency-name: yarl
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added the Dependencies Pull requests that update a dependency file label Oct 16, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Dependencies Pull requests that update a dependency file no-changelog no-issue
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants