← Back to issue list

build(deps): bump pip from 22.0.2 to 23.3 in /docs

View original Github issue

Metadata

Project
snapcraft
Number
#4776
Type
pull request
State
merged
Author
dependabot[bot]
Labels
Created
Updated
Closed

Current evaluation

Dependabot merged an automated dependency update bumping pip from 22.0.2 to 23.3 in /docs. Approved by two reviewers, passed CI checks, and applied cleanly without conflicts or review comments.

Suggested action:

No scores available.

Issue body

Bumps [pip](https://github.com/pypa/pip) from 22.0.2 to 23.3. <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/pypa/pip/blob/main/NEWS.rst">pip's changelog</a>.</em></p> <blockquote> <h1>23.3 (2023-10-15)</h1> <h2>Process</h2> <ul> <li>Added reference to <code>vulnerability reporting guidelines &lt;https://www.python.org/dev/security/&gt;</code>_ to pip's security policy.</li> </ul> <h2>Deprecations and Removals</h2> <ul> <li>Drop a fallback to using SecureTransport on macOS. It was useful when pip detected OpenSSL older than 1.0.1, but the current pip does not support any Python version supporting such old OpenSSL versions. (<code>[#12175](https://github.com/pypa/pip/issues/12175) &lt;https://github.com/pypa/pip/issues/12175&gt;</code>_)</li> </ul> <h2>Features</h2> <ul> <li>Improve extras resolution for multiple constraints on same base package. (<code>[#11924](https://github.com/pypa/pip/issues/11924) &lt;https://github.com/pypa/pip/issues/11924&gt;</code>_)</li> <li>Improve use of datastructures to make candidate selection 1.6x faster. (<code>[#12204](https://github.com/pypa/pip/issues/12204) &lt;https://github.com/pypa/pip/issues/12204&gt;</code>_)</li> <li>Allow <code>pip install --dry-run</code> to use platform and ABI overriding options. (<code>[#12215](https://github.com/pypa/pip/issues/12215) &lt;https://github.com/pypa/pip/issues/12215&gt;</code>_)</li> <li>Add <code>is_yanked</code> boolean entry to the installation report (<code>--report</code>) to indicate whether the requirement was yanked from the index, but was still selected by pip conform to :pep:<code>592</code>. (<code>[#12224](https://github.com/pypa/pip/issues/12224) &lt;https://github.com/pypa/pip/issues/12224&gt;</code>_)</li> </ul> <h2>Bug Fixes</h2> <ul> <li>Ignore errors in temporary directory cleanup (show a warning instead). (<code>[#11394](https://github.com/pypa/pip/issues/11394) &lt;https://github.com/pypa/pip/issues/11394&gt;</code>_)</li> <li>Normalize extras according to :pep:<code>685</code> from package metadata in the resolver for comparison. This ensures extras are correctly compared and merged as long as the package providing the extra(s) is built with values normalized according to the standard. Note, however, that this <em>does not</em> solve cases where the package itself contains unnormalized extra values in the metadata. (<code>[#11649](https://github.com/pypa/pip/issues/11649) &lt;https://github.com/pypa/pip/issues/11649&gt;</code>_)</li> <li>Prevent downloading sdists twice when :pep:<code>658</code> metadata is present. (<code>[#11847](https://github.com/pypa/pip/issues/11847) &lt;https://github.com/pypa/pip/issues/11847&gt;</code>_)</li> <li>Include all requested extras in the install report (<code>--report</code>). (<code>[#11924](https://github.com/pypa/pip/issues/11924) &lt;https://github.com/pypa/pip/issues/11924&gt;</code>_)</li> <li>Removed uses of <code>datetime.datetime.utcnow</code> from non-vendored code. (<code>[#12005](https://github.com/pypa/pip/issues/12005) &lt;https://github.com/pypa/pip/issues/12005&gt;</code>_)</li> <li>Consistently report whether a dependency comes from an extra. (<code>[#12095](https://github.com/pypa/pip/issues/12095) &lt;https://github.com/pypa/pip/issues/12095&gt;</code>_)</li> <li>Fix completion script for zsh (<code>[#12166](https://github.com/pypa/pip/issues/12166) &lt;https://github.com/pypa/pip/issues/12166&gt;</code>_)</li> <li>Fix improper handling of the new onexc argument of <code>shutil.rmtree()</code> in Python 3.12. (<code>[#12187](https://github.com/pypa/pip/issues/12187) &lt;https://github.com/pypa/pip/issues/12187&gt;</code>_)</li> <li>Filter out yanked links from the available versions error message: &quot;(from versions: 1.0, 2.0, 3.0)&quot; will not contain yanked versions conform PEP 592. The yanked versions (if any) will be mentioned in a separate error message. (<code>[#12225](https://github.com/pypa/pip/issues/12225) &lt;https://github.com/pypa/pip/issues/12225&gt;</code>_)</li> <li>Fix crash when the git version number contains something else than digits and dots. (<code>[#12280](https://github.com/pypa/pip/issues/12280) &lt;https://github.com/pypa/pip/issues/12280&gt;</code>_)</li> <li>Use <code>-r=...</code> instead of <code>-r ...</code> to specify references with Mercurial. (<code>[#12306](https://github.com/pypa/pip/issues/12306) &lt;https://github.com/pypa/pip/issues/12306&gt;</code>_)</li> <li>Redact password from URLs in some additional places. (<code>[#12350](https://github.com/pypa/pip/issues/12350) &lt;https://github.com/pypa/pip/issues/12350&gt;</code>_)</li> <li>pip uses less memory when caching large packages. As a result, there is a new on-disk cache format stored in a new directory ($PIP_CACHE_DIR/http-v2). (<code>[#2984](https://github.com/pypa/pip/issues/2984) &lt;https://github.com/pypa/pip/issues/2984&gt;</code>_)</li> </ul> <h2>Vendored Libraries</h2> <ul> <li>Upgrade certifi to 2023.7.22</li> <li>Add truststore 0.8.0</li> <li>Upgrade urllib3 to 1.26.17</li> </ul> <p>Improved Documentation</p> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/pypa/pip/commit/e3dc91dad93a020b3034a87ebe59027f63370fe8"><code>e3dc91d</code></a> Bump for release</li> <li><a href="https://github.com/pypa/pip/commit/3e85558b10722598fb3353126e2f19979f7cf7dd"><code>3e85558</code></a> Update AUTHORS.txt</li> <li><a href="https://github.com/pypa/pip/commit/8d0278771c7325b04f02cb073c8ef02827cbeb93"><code>8d02787</code></a> Reclassify news fragment</li> <li><a href="https://github.com/pypa/pip/commit/f6ecf406c3929b3127ddb480ef4350542d102338"><code>f6ecf40</code></a> Merge pull request <a href="https://redirect.github.com/pypa/pip/issues/12350">#12350</a> from sbidoul/readact-collecting-url</li> <li><a href="https://github.com/pypa/pip/commit/306086513bd1a6500126057492ee8b0f9a2e79dd"><code>3060865</code></a> Merge pull request <a href="https://redirect.github.com/pypa/pip/issues/12335">#12335</a> from edmorley/patch-1</li> <li><a href="https://github.com/pypa/pip/commit/8f0ed32413daa411a728b50cd7776b9c02b010d5"><code>8f0ed32</code></a> Redact URLs in Collecting... logs</li> <li><a href="https://github.com/pypa/pip/commit/d1659b87e46abd0a2dcc74f2160dd52e6190e13b"><code>d1659b8</code></a> Correct issue number for NEWS entry added by <a href="https://redirect.github.com/pypa/pip/issues/12197">#12197</a></li> <li><a href="https://github.com/pypa/pip/commit/2333ef3b53a71fb7acc9e76d6ff90409576b2250"><code>2333ef3</code></a> Upgrade urllib3 to 1.26.17 (<a href="https://redirect.github.com/pypa/pip/issues/12343">#12343</a>)</li> <li><a href="https://github.com/pypa/pip/commit/496b268c1b9ce3466c08eb4819e5460a943d1793"><code>496b268</code></a> Update &quot;Running Tests&quot; documentation (<a href="https://redirect.github.com/pypa/pip/issues/12334">#12334</a>)</li> <li><a href="https://github.com/pypa/pip/commit/d1f0981cb2af3c72ff871b54a8a98581ccb2890a"><code>d1f0981</code></a> Merge pull request <a href="https://redirect.github.com/pypa/pip/issues/12331">#12331</a> from sbidoul/update-egg-deprecation-message</li> <li>Additional commits viewable in <a href="https://github.com/pypa/pip/compare/22.0.2...23.3">compare view</a></li> </ul> </details> <br /> [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=pip&package-manager=pip&previous-version=22.0.2&new-version=23.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/canonical/snapcraft/network/alerts). </details>

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.6-35b-a3b Dependabot merged an automated dependency update bumping pip from 22.0.2 to 23.3 in /docs. Approved by two reviewers, passed CI checks, and applied cleanly without conflicts or review comments.
qwen3.6-35b-a3b-mtp-q6 Dependabot successfully merged the automated update, bumping pip from 22.0.2 to 23.3 in the /docs directory. The dependency upgrade was applied without conflicts and integrated into the repository.
qwen3.6-35b-a3b-mtp-q6 Successfully merged Dependabot update bumping pip from 22.0.2 to 23.3 in /docs. The upgrade integrates pip 23.3 performance improvements, bug fixes, and security enhancements into the documentation build environment.

Update history

No update history recorded yet.

Related issues

Issue Project State Summary Similarity
#6286 build(deps): bump pip snapcraft merged Merged a dependency update bumping pip from v26.1 to v26.1.2 to resolve an OSV security vulnerability. Approved by reviewers and integrated after passing CI checks.
81%
#6221 build(deps): bump pip snapcraft merged Merged a dependency update to bump pip, resolving an OSV security vulnerability. Approved by two reviewers, the change was accepted after passing CI checks and involved a minor version bump in one file.
80%
#6008 build(deps-dev): bump pip from 25.3 to 26.0 snapcraft closed Superseded by PR #6011. Dependabot closed this pip version bump after the update was resolved in another pull request.
77%
#4775 build(deps): bump setuptools from 59.6.0 to 65.5.1 in /docs snapcraft merged Merged Dependabot update bumping setuptools from 59.6.0 to 65.5.1 in the docs directory. Approved by two reviewers, passed CI checks, and applied a single dependency file change.
76%
#4896 build(deps): bump certifi from 2023.11.17 to 2024.7.4 snapcraft merged Dependabot updated certifi from 2023.11.17 to 2024.7.4. Approved by two reviewers and passing CI, the dependency bump was successfully merged.
75%
#959 build(deps): update dependency pip to v24.3.1 (main) - autoclosed craft-parts closed Dependency update for pip to v24.3.1 was autoclosed without merging. Despite passing CI checks and receiving approvals, the pull request was automatically closed due to inactivity or configuration rules.
75%
#106 build(deps): bump requests from 2.32.5 to 2.33.0 debcraft merged Merged Dependabot update bumping requests from 2.32.5 to 2.33.0. Includes CVE-2026-25645 security fix, PEP 517 migration, and Python 3.9 removal. Approved by two reviewers with all CI checks passing before merge.
75%
#1322 build(deps): update dependency docutils to v0.22.2 (main) craft-parts merged Merged automated dependency update for docutils from v0.21.2 to v0.22.2. Approved by three reviewers and passed all CI checks before merging into main.
74%
#122 build(deps): bump requests from 2.32.5 to 2.33.0 starflow merged Merged Dependabot update bumping requests from 2.32.5 to 2.33.0. Includes CVE-2026-25645 security fix and Python 3.9 removal. All CI checks passed and two reviewers approved the change prior to merge.
74%
#6127 build(deps): bump requests from 2.32.5 to 2.33.0 snapcraft merged Merged Dependabot PR bumping requests from 2.32.5 to 2.33.0. The update addresses CVE-2026-25645, migrates to PEP 517, and drops Python 3.9 support. Approved by reviewers and merged after CI checks.
74%