Bump the dependabot group with 4 updates #375
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the dependabot group with 4 updates: setuptools, certifi, pip and importlib-metadata.
Updates
setuptools
from 79.0.0 to 80.0.0Changelog
Sourced from setuptools's changelog.
Commits
aeea792
Bump version: 79.0.1 → 80.0.02c874e7
Merge pull request #4962 from pypa/bugfix/4961-validated-eps82c588a
Update test to honor new behavior in importlib_metadata 8.7ef4cd29
Merge pull request #2908 from pypa/debt/remove-easy-install85bbad4
Merge branch 'main' into debt/remove-easy-install9653305
Merge pull request #4955 from pypa/debt/develop-uses-pipda119e7
Set a due date 6 months in advance.a7603da
Rename news fragment to reference the pull request for better precise locality.018a20c
Restore a few of the options to develop.a5f02fe
Remove another test relying on setup.py develop.Updates
certifi
from 2025.1.31 to 2025.4.26Commits
275c9eb
2025.04.26 (#347)3788331
Bump actions/setup-python from 5.4.0 to 5.5.0 (#346)9d1f1b7
Bump actions/download-artifact from 4.1.9 to 4.2.1 (#344)96b97a5
Bump actions/upload-artifact from 4.6.1 to 4.6.2 (#343)c054ed3
Bump peter-evans/create-pull-request from 7.0.7 to 7.0.8 (#342)44547fc
Bump actions/download-artifact from 4.1.8 to 4.1.9 (#341)5ea5124
Bump actions/upload-artifact from 4.6.0 to 4.6.1 (#340)2f142b7
Bump peter-evans/create-pull-request from 7.0.6 to 7.0.7 (#339)80d2ebd
Bump actions/setup-python from 5.3.0 to 5.4.0 (#337)Updates
pip
from 25.0.1 to 25.1Changelog
Sourced from pip's changelog.
... (truncated)
Commits
daa7e54
Bump for release06c3182
Update AUTHORS.txtb88324f
Add a news file for the pip lock command38253a6
Merge pull request #13319 from sbidoul2791a8b
Merge pull request #13344 from pypa/dependabot/pip/build-project/setuptools-7...24f4600
Remove LRU cache from methods [ruff rule cached-instance-method] (#13306)d852ebd
Merge pull request #12308d35c08d
Clarify what the removal of the pkg_ressources backend impliese879422
Rename find_linked to find_legacy_editables4a76560
Fix uninstallation of zipped eggsUpdates
importlib-metadata
from 8.6.1 to 8.7.0Changelog
Sourced from importlib-metadata's changelog.
Commits
708dff4
Finalizeb3065f0
Merge pull request #519 from python/bugfix/493-metadata-missinge4351c2
Add a new test capturing the new expectation.5a65705
Refactor the casting into a wrapper for brevity and to document its purpose.0830c39
Add news fragment.22bb567
Fix type errors where metadata could be None.57f31d7
Allow metadata to return None when there is no metadata present.b9c4be4
Merge pull request #518 from python/bugfix/488-bad-ep-value9f8af01
Prefer a cached property, as the property is likely to be retrieved at least ...f179e28
Also raise ValueError on construction if the value is invalid.Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major version
will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor version
will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>
will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>
will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>
will remove the ignore condition of the specified dependency and ignore conditions