allenai / allennlp-demo

Code for the AllenNLP demo.
https://demo.allennlp.org
Apache License 2.0
196 stars 80 forks source link

Update itsdangerous requirement from <=2.0.1 to <2.1.3 in /api #1261

Closed dependabot[bot] closed 2 years ago

dependabot[bot] commented 2 years ago

Updates the requirements on itsdangerous to permit the latest version.

Release notes

Sourced from itsdangerous's releases.

2.1.2

Changelog

Sourced from itsdangerous's changelog.

Version 2.1.2

Released 2022-03-24

  • Handle date overflow in timed unsign on 32-bit systems. :pr:299

Version 2.1.1

Released 2022-03-09

  • Handle date overflow in timed unsign. :pr:296

Version 2.1.0

Released 2022-02-17

  • Drop support for Python 3.6. :pr:272

  • Remove previously deprecated code. :pr:273

    • JWS functionality: Use a dedicated library such as Authlib instead.
    • import itsdangerous.json: Import json from the standard library instead.

Version 2.0.1

Released 2021-05-18

  • Mark top-level names as exported so type checking understands imports in user projects. :pr:240
  • The salt argument to Serializer and Signer can be None again. :issue:237

Version 2.0.0

Released 2021-05-11

  • Drop support for Python 2 and 3.5.
  • JWS support (JSONWebSignatureSerializer, TimedJSONWebSignatureSerializer) is deprecated. Use a dedicated JWS/JWT library such as authlib instead. :issue:129

... (truncated)

Commits
  • 49d263f Merge pull request #301 from pallets/release-2.1.2
  • 8c75d07 release version 2.1.2
  • 64cd581 Merge pull request #299 from dirkmueller/main
  • 3edfbbb handle OverflowError in timed unsign on 32-bit systems
  • faa28bc start version 2.1.2
  • 38e9d8a Merge pull request #298 from pallets/release-2.1.1
  • ff13147 release version 2.1.1
  • 25494a8 Merge pull request #296 from alanhamlett/main
  • 177196d catch OSError on Windows
  • 37f0997 catching year overflow ValueError
  • Additional commits viewable in compare view


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)