Closed dependabot[bot] closed 11 months ago
@boomanaiden154 I assume werkzeug is because of a development library, not a strict requirement, so safe to patch?
As long as the tests pass, it's probably fine. It still doesn't bump any of the top-level dependencies which we need to do at some point, but there were test failures associated with that.
@boomanaiden154 I assume werkzeug is because of a development library, not a strict requirement, so safe to patch?
Nevermind, discovered pipenv graph
and apparently tensorboard needs it.
I'd be inclined to punt until we change the version of tensorflow.
Ah, didn't realize that. SGTM. We should probably bump Tensorflow sooner rather than later, but I guess that's a different PR (and fixing associated fallout that was there at least last time I hacked on it).
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version
or @dependabot ignore this minor version
.
If you change your mind, just re-open this PR and I'll resolve any conflicts on it.
Ah, didn't realize that. SGTM. We should probably bump Tensorflow sooner rather than later, but I guess that's a different PR (and fixing associated fallout that was there at least last time I hacked on it).
@petrhosek are you guys using docker now, or would bumps like these be OK?
Even if they're using a container image, the container image still contains the exact same transitive closure of dependencies, so they need to be consistent in both places. The only issue I could think of for Fuchsia would be Python version support. Last time we bumped things we had issues as they were still using 3.8.
Bumps werkzeug from 2.3.3 to 2.3.8.
Release notes
Sourced from werkzeug's releases.
Changelog
Sourced from werkzeug's changelog.
... (truncated)
Commits
dc90943
Release version 2.3.8f230020
Fix: slow multipart parsing for huge files with few CR/LF characters26f3e95
reformat lines828bab4
Start version 2.3.83c2ba3d
Release version 2.3.7ac9974c
Fix qvalue parsing (#2753)88f4ed6
qvalue parsing accepts float without decimaldd1f137
Fix: Improve Error Message (#2750)fdc295a
clearer url rule slash errora0f4bf4
fix: improve error messageDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show