Skip to content

chore(deps): bump setuptools from 62.0.0 to 65.6.3 in /dev_requirements #531

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Dec 1, 2022

Bumps setuptools from 62.0.0 to 65.6.3.

Release notes

Sourced from setuptools's releases.

v65.6.3

No release notes provided.

v65.6.2

No release notes provided.

v65.6.1

No release notes provided.

v65.6.0

No release notes provided.

v65.5.1

No release notes provided.

v65.5.0

No release notes provided.

v65.4.1

No release notes provided.

v65.4.0

No release notes provided.

v65.3.0

No release notes provided.

v65.2.0

No release notes provided.

v65.1.1

No release notes provided.

v65.1.0

No release notes provided.

v65.0.2

No release notes provided.

v65.0.1

No release notes provided.

v65.0.0

No release notes provided.

v64.0.3

No release notes provided.

v64.0.2

No release notes provided.

... (truncated)

Changelog

Sourced from setuptools's changelog.

v65.6.3

Misc ^^^^

  • #3709: Fix condition to patch distutils.dist.log to only apply when using distutils from the stdlib.

v65.6.2

No significant changes.

v65.6.1

Documentation changes ^^^^^^^^^^^^^^^^^^^^^

  • #3689: Documented that distutils.cfg might be ignored unless SETUPTOOLS_USE_DISTUTILS=stdlib.

Misc ^^^^

  • #3678: Improve clib builds reproducibility by sorting sources -- by :user:danigm
  • #3684: Improved exception/traceback when invalid entry-points are specified.
  • #3690: Fixed logging errors: 'underlying buffer has been detached' (issue #1631).
  • #3693: Merge pypa/distutils@3e9d47e with compatibility fix for distutils.log.Log.
  • #3695, #3697, #3698, #3699: Changed minor text details (spelling, spaces ...)
  • #3696: Removed unnecessary coding: utf-8 annotations
  • #3704: Fixed temporary build directories interference with auto-discovery.

v65.6.0

Changes ^^^^^^^

v65.5.1

Misc

... (truncated)

Commits
  • 6f7dd7c Bump version: 65.6.2 → 65.6.3
  • 0f513c1 Merge pull request #3709 from abravalheri/issue-3707
  • a4db65f Remove wrong comment
  • 5801753 Add news fragment
  • 4c267c7 Replace condition to patch distutils.dist.log
  • 7049c73 Add simple regression test for logging patches
  • e515641 Bump version: 65.6.1 → 65.6.2
  • bd60014 Minor adjustments in changelog
  • 00f59ef Bump version: 65.6.0 → 65.6.1
  • b0f42b9 Adequate news fragment file names
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot requested a review from a team as a code owner December 1, 2022 13:07
@dependabot dependabot bot added dependency breaking change python Pull requests that update Python code labels Dec 1, 2022
@dependabot dependabot bot force-pushed the dependabot/pip/dev_requirements/setuptools-65.6.3 branch from 918d43a to a146a11 Compare December 1, 2022 22:32
@dependabot dependabot bot force-pushed the dependabot/pip/dev_requirements/setuptools-65.6.3 branch from a146a11 to ee5a1b2 Compare December 15, 2022 17:20
@lucasmcdonald3
Copy link
Contributor

@dependabot rebase

Bumps [setuptools](https://github.com/pypa/setuptools) from 62.0.0 to 65.6.3.
- [Release notes](https://github.com/pypa/setuptools/releases)
- [Changelog](https://github.com/pypa/setuptools/blob/main/CHANGES.rst)
- [Commits](pypa/setuptools@v62.0.0...v65.6.3)

---
updated-dependencies:
- dependency-name: setuptools
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot force-pushed the dependabot/pip/dev_requirements/setuptools-65.6.3 branch from ee5a1b2 to 6a7b5c4 Compare January 5, 2023 21:51
@texastony
Copy link
Contributor

@lucasmcdonald3 From the buildspec.yml and what I have read of .github/workflows,
our CI does not test releasing to CodeArtifact.

In the tox.ini, that is done via the test-release environment,
which is only used in the codebuild/release/test-release.yml,
which is not part of the CI batch build.

As such, this setuptools change is only partially tested
(via the build environment in tox.ini).

I recommend running the test-release tox env with appropriate environmental variables/credentials to validate nothing is broken in releasing this in this PR
or in #536 .

(I would apply both PRs to local branch,
fetch permissions to write to a CodeArtifact,
and then run the commands from codebuild/release/test-release.yml).

Once that passes and all is well, you can merge both this and #536.

@texastony
Copy link
Contributor

That all being said, I have read the Changelog for Setuptools and found the following deprecations and breaking changes:

Looking at our setup.py, none of these changes SHOULD effect us.

@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Jan 12, 2023

Superseded by #542.

@dependabot dependabot bot closed this Jan 12, 2023
@dependabot dependabot bot deleted the dependabot/pip/dev_requirements/setuptools-65.6.3 branch January 12, 2023 13:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependency breaking change python Pull requests that update Python code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants