Skip to content

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Mar 6, 2023

Bumps pex from 2.1.105 to 2.1.126.

Release notes

Sourced from pex's releases.

pex 2.1.126


2.1.126

This release fixes a long standing (> 4 years old!) concurrency bug when building the same sdist for the 1st time and racing another Pex process doing the same sdist build.

  • Guard against racing sdist builds. (#2080)

pex 2.1.125


2.1.125

This release makes --platform and --complete-platform resolves and locks as permissive as possible. If such a resolve or lock only has an sdist available for a certain project, that sdist will now be used if it builds to a wheel compatible with the specified foreign platform(s).

  • Attempt "cross-builds" of sdists for foreign platforms. (#2075)

pex 2.1.124


2.1.124

This release adds support for specifying --non-hermetic-venv-scripts when building a --venv PEX. This can be useful when integrating with frameworks that do setup via PYTHONPATH manipulation.

Support for Pip 23.0.1 and setuptools 67.4.0 is added via --pip-version 23.0.1.

Additionally, more work towards hardening Pex against rare concurrency issues in its atomic directory handling is included.

  • Introduce --non-hermetic-venv-scripts. (#2068)
  • Wrap inter-process locks in in-process locks. (#2070)
  • Add support for Pip 23.0.1. (#2072)

pex 2.1.123


2.1.123

This release fixes a few pex3 lock create bugs.

There was a regression introduced in Pex 2.1.122 where projects that

... (truncated)

Changelog

Sourced from pex's changelog.

2.1.126

This release fixes a long standing (> 4 years old!) concurrency bug when building the same sdist for the 1st time and racing another Pex process doing the same sdist build.

  • Guard against racing sdist builds. (#2080) PR [#2080](https://github.com/pantsbuild/pex/issues/2080) <https://github.com/pantsbuild/pex/pull/2080>_

2.1.125

This release makes --platform and --complete-platform resolves and locks as permissive as possible. If such a resolve or lock only has an sdist available for a certain project, that sdist will now be used if it builds to a wheel compatible with the specified foreign platform(s).

  • Attempt "cross-builds" of sdists for foreign platforms. (#2075) PR [#2075](https://github.com/pantsbuild/pex/issues/2075) <https://github.com/pantsbuild/pex/pull/2075>_

2.1.124

This release adds support for specifying --non-hermetic-venv-scripts when building a --venv PEX. This can be useful when integrating with frameworks that do setup via PYTHONPATH manipulation.

Support for Pip 23.0.1 and setuptools 67.4.0 is added via --pip-version 23.0.1.

Additionally, more work towards hardening Pex against rare concurrency issues in its atomic directory handling is included.

  • Introduce --non-hermetic-venv-scripts. (#2068) PR [#2068](https://github.com/pantsbuild/pex/issues/2068) <https://github.com/pantsbuild/pex/pull/2068>_

  • Wrap inter-process locks in in-process locks. (#2070) PR [#2070](https://github.com/pantsbuild/pex/issues/2070) <https://github.com/pantsbuild/pex/pull/2070>_

  • Add support for Pip 23.0.1. (#2072) PR [#2072](https://github.com/pantsbuild/pex/issues/2072) <https://github.com/pantsbuild/pex/pull/2072>_

2.1.123

This release fixes a few pex3 lock create bugs.

There was a regression introduced in Pex 2.1.122 where projects that used a PEP-518 [build-system] requires but specified no

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [pex](https://github.com/pantsbuild/pex) from 2.1.105 to 2.1.126.
- [Release notes](https://github.com/pantsbuild/pex/releases)
- [Changelog](https://github.com/pantsbuild/pex/blob/main/CHANGES.rst)
- [Commits](pex-tool/pex@v2.1.105...v2.1.126)

---
updated-dependencies:
- dependency-name: pex
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Mar 6, 2023
@codecov
Copy link

codecov bot commented Mar 6, 2023

Codecov Report

Merging #265 (f71b86d) into main (0c43ff5) will not change coverage.
The diff coverage is n/a.

@@            Coverage Diff            @@
##              main      #265   +/-   ##
=========================================
  Coverage   100.00%   100.00%           
=========================================
  Files            6         6           
  Lines          472       472           
  Branches        90        90           
=========================================
  Hits           472       472           

Help us with your feedback. Take ten seconds to tell us how you rate us. Have a feature suggestion? Share it here.

@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Mar 8, 2023

Superseded by #267.

@dependabot dependabot bot closed this Mar 8, 2023
@dependabot dependabot bot deleted the dependabot/pip/pex-2.1.126 branch March 8, 2023 05:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants