Skip to content

Bump flit-core from 3.8.0 to 3.9.0 - #7912

Closed
dependabot[bot] wants to merge 1 commit into
v2from
dependabot/pip/v2/flit-core-3.9.0
Closed

dependabot[bot] wants to merge 1 commit into
v2from
dependabot/pip/v2/flit-core-3.9.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 24, 2023

Copy link
Copy Markdown
Contributor

Bumps flit-core from 3.8.0 to 3.9.0.

Changelog

Sourced from flit-core's changelog.

Release history

Version 3.9

  • New options :option:flit build --use-vcs and :option:flit build --no-use-vcs to enable & disable including all committed files in the sdist. For now --use-vcs is the default, but this is likely to change in a future version, to bring flit build in line with standard build frontends like python -m build (:ghpull:625).
  • Sdist file names, and the name of the top-level folder in an sdist, are now normalised, in accordance with :pep:625 (:ghpull:628).
  • A statically defined version number can now be parsed from files called version.py, _version.py or __version__.py inside a packge, as well as from __init__.py, so executing code is required in fewer cases (:ghpull:630).
  • Fix setting the flag for regular files in zip metadata (:ghpull:639).
  • The timestamp embedded in the gzip wrapper for sdists now defaults to a fixed date, so building an sdist twice on the same machine should produce identical results, even without any special steps (:ghpull:635). Setting :envvar:SOURCE_DATE_EPOCH is still recommended for properly :doc:reproducible builds <reproducible>.

Version 3.8

  • A project name containing hyphens is now automatically translated to use underscores for the import name (:ghpull:566).
  • New option :option:flit install --only-deps to install the dependencies of the package, but not the package itself.
  • Add support for recursive globbing (**) in sdist includes and excludes (:ghpull:550).
  • Python's bytecode cache files (__pycache__ folders and .pyc files) are now always excluded from sdists (:ghpull:581).
  • Use tomllib in Python 3.11, rather than tomli (:ghpull:573, :ghpull:604).
  • Fix crash when unable to get a password from keyring (:ghpull:567).
  • Fix including modified files in sdist when using Mercurial (:ghpull:541).
  • Fix for some cases of determining whether a package supports Python 2 or not (:ghpull:593).
  • Fix parsing version number from code using multiple assignments (:ghpull:474).
  • Document how to use a PyPI token with :envvar:FLIT_PASSWORD (:ghpull:602).
  • Fix link to information about environment variables for pip (:ghpull:576).
  • Link to the docs for the latest stable version in package metadata (:ghpull:589).
  • Remove a mention of the toml package, which is no longer needed, from the :doc:development page (:ghpull:601).
  • The :doc:bootstrap <bootstrap> install script for flit_core accepts a new --install-root option.
  • Ensure the license file is included in packages on PyPI (:ghpull:603).

... (truncated)

Commits
  • c8ae08d Bump version: 3.8.0 → 3.9.0
  • 1043d79 Merge pull request #642 from pypa/relnotes-3.9
  • 73a0b1b Try adding RTD config file
  • a19b966 Add release notes for 3.9
  • d7c8cc0 Merge pull request #628 from mgorny/normalize-sdist
  • 070be04 Merge pull request #635 from pypa/sdist-timestamp-2016
  • 43604be Merge pull request #639 from henryiii/henryiii/fix/zipinfo
  • 9fc3ba0 fix: regular file flag was not set
  • 0c6608f Merge pull request #630 from amyreese/version-file
  • 9be0c3e Fix indentation
  • Additional commits viewable in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
> **Note** > Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [flit-core](https://github.com/pypa/flit) from 3.8.0 to 3.9.0.
- [Changelog](https://github.com/pypa/flit/blob/main/doc/history.rst)
- [Commits](pypa/flit@3.8.0...3.9.0)

---
updated-dependencies:
- dependency-name: flit-core
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies This issue is a problem in a dependency. label May 24, 2023
@codecov-commenter

codecov-commenter commented May 24, 2023

Copy link
Copy Markdown

Codecov Report

Merging #7912 (83412a4) into v2 (522036b) will decrease coverage by 0.02%.
The diff coverage is n/a.

@@            Coverage Diff             @@
##               v2    #7912      +/-   ##
==========================================
- Coverage   93.08%   93.07%   -0.02%     
==========================================
  Files         355      355              
  Lines       37656    37656              
  Branches     6029     6029              
==========================================
- Hits        35052    35047       -5     
- Misses       1948     1953       +5     
  Partials      656      656              

see 2 files with indirect coverage changes

@tjni tjni mentioned this pull request Aug 5, 2023
2 tasks
@nateprewitt nateprewitt added the v2 label Aug 22, 2023
@kyleknap

kyleknap commented Feb 5, 2024

Copy link
Copy Markdown
Contributor

@dependabot rebase

@dependabot @github

dependabot Bot commented on behalf of github Feb 5, 2024

Copy link
Copy Markdown
Contributor Author

The dependabot.yml entry that created this PR has been deleted so this PR can't be rebased. Please close the PR so Dependabot can create a new one with the current dependabot.yml.

@kyleknap

kyleknap commented Feb 5, 2024

Copy link
Copy Markdown
Contributor

@dependabot recreate

@dependabot @github

dependabot Bot commented on behalf of github Feb 5, 2024

Copy link
Copy Markdown
Contributor Author

The dependabot.yml entry that created this PR has been deleted so this PR can't be recreated. Please close the PR so Dependabot can create a new one with the current dependabot.yml.

@kyleknap

kyleknap commented Feb 5, 2024

Copy link
Copy Markdown
Contributor

Closing per dependabot comment to get this recreated: #7912 (comment)

@kyleknap kyleknap closed this Feb 5, 2024
@dependabot @github

dependabot Bot commented on behalf of github Feb 5, 2024

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/pip/v2/flit-core-3.9.0 branch February 5, 2024 22:20
@kyleknap

kyleknap commented Feb 5, 2024

Copy link
Copy Markdown
Contributor

This is the new dependabot PR for this update: #8527

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies This issue is a problem in a dependency. v2

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants