olympus-fergus / dvpwa

Damn Vulnerable Python Web App
MIT License
0 stars 1 forks source link

Bump jinja2 from 2.10 to 3.0.3 #31

Closed dependabot[bot] closed 2 years ago

dependabot[bot] commented 2 years ago

Bumps jinja2 from 2.10 to 3.0.3.

Release notes

Sourced from jinja2's releases.

3.0.3

What's Changed

New Contributors

Full Changelog: https://github.com/pallets/jinja/compare/3.0.2...3.0.3

3.0.2

3.0.1

3.0.0

New major versions of all the core Pallets libraries, including Jinja 3.0, have been released! :tada:

This represents a significant amount of work, and there are quite a few changes. Be sure to carefully read the changelog, and use tools such as pip-compile and Dependabot to pin your dependencies and control your updates.

3.0.0rc2

Fixes an issue with the deprecated Markup subclass, #1401.

3.0.0rc1

... (truncated)

Changelog

Sourced from jinja2's changelog.

Version 3.0.3

Released 2021-11-09

  • Fix traceback rewriting internals for Python 3.10 and 3.11. :issue:1535
  • Fix how the native environment treats leading and trailing spaces when parsing values on Python 3.10. :pr:1537
  • Improve async performance by avoiding checks for common types. :issue:1514
  • Revert change to hash(Node) behavior. Nodes are hashed by id again :issue:1521
  • PackageLoader works when the package is a single module file. :issue:1512

Version 3.0.2

Released 2021-10-04

  • Fix a loop scoping bug that caused assignments in nested loops to still be referenced outside of it. :issue:1427
  • Make compile_templates deterministic for filter and import names. :issue:1452, 1453
  • Revert an unintended change that caused Undefined to act like StrictUndefined for the in operator. :issue:1448
  • Imported macros have access to the current template globals in async environments. :issue:1494
  • PackageLoader will not include a current directory (.) path segment. This allows loading templates from the root of a zip import. :issue:1467

Version 3.0.1

Released 2021-05-18

  • Update MarkupSafe dependency to >= 2.0. :pr:1418
  • Mark top-level names as exported so type checking understands imports in user projects. :issue:1426
  • Fix some types that weren't available in Python 3.6.0. :issue:1433
  • The deprecation warning for unneeded autoescape and with_ extensions shows more relevant context. :issue:1429
  • Fixed calling deprecated jinja2.Markup without an argument. Use markupsafe.Markup instead. :issue:1438
  • Calling sync render for an async template uses asyncio.run on Python >= 3.7. This fixes a deprecation that Python 3.10

... (truncated)

Commits
  • 2a48dd8 Merge pull request #1543 from pallets/release-3.0.3
  • ce1a539 release version 3.0.3
  • 199b6d5 Merge pull request #1542 from pallets/package-loader-file
  • eec0db8 PackageLoader works with single module file
  • 46f3a68 Merge pull request #1541 from pallets/docs-pow-order
  • 0d19990 document chained pow order
  • 99daa2a Merge pull request #1540 from pallets/docs-macro-defaults
  • a6162da rewrite docs about extending template objects
  • cab5545 Merge pull request #1539 from pallets/docs-macro-defaults
  • 369ff03 remove reference to macro.defaults
  • Additional commits viewable in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
dependabot[bot] commented 2 years ago

Superseded by #41.