rclim95 / PlayingWHAT

A Python app that allows you to connect your Spotify account and show what you're playing on the Inky wHAT screen
MIT License
1 stars 0 forks source link

Bump spotipy from 2.18.0 to 2.22.1 #9

Open dependabot[bot] opened 5 months ago

dependabot[bot] commented 5 months ago

Bumps spotipy from 2.18.0 to 2.22.1.

Release notes

Sourced from spotipy's releases.

2.22.1: CVE-2023-23608

Fixed

Changed

  • Modified docstring for deprecated playlist_add_items() to accept "only URIs or URLs", with intended fix for IDs in v3.
    • The bug still exists for developers dealing with episodes IDs rather than just track IDs. However it is recommended to use the new playlist_add_tracks() or playlist_add_episodes() if dealing with episodes or simply to avoid confusion. See spotipy-dev/spotipy#919 by @​oliveraw for context

2.22: Get queue endpoint

Added

  • Integration tests via GHA (non-user endpoints)
  • Unit tests for new releases, passing limit parameter with minimum and maximum values of 1 and 50
  • Unit tests for categories, omitting country code to test global releases
  • Added CODE_OF_CONDUCT.md

Fixed

  • Incorrect category_id input for test_category
  • Assertion value for test_categories_limit_low and test_categories_limit_high
  • Pin Github Actions Runner to Ubuntu 20 for Py27
  • Fixed potential error where found variable in test_artist_related_artists is undefined if for loop never evaluates to true
  • Fixed false positive test test_new_releases which looks up the wrong property of the JSON response object and always evaluates to true

2.21: Flask cache handler

Added

  • Added market parameter to album and albums to address #753 by @​ivyadam
  • Added 'show_featured_artists.py' to 'examples'.
  • Expanded contribution and license sections of the documentation.
  • Added FlaskSessionCacheHandler, a cache handler that stores the token info in a flask session.
  • Added Python 3.10 in GitHub Actions

Fixed

  • Updated the documentation to specify ISO-639-1 language codes.
  • Fix AttributeError for text attribute of the Response object, spotipy-dev/spotipy#811 by @​rtcq
  • Require redis v3 if python2.7 (fixes readthedocs)

2.20: Redis cache handler

Added

  • Added RedisCacheHandler, a cache handler that stores the token info in Redis.
  • Changed URI handling in client.Spotify._get_id() to remove qureies if provided by error.
  • Added a new parameter to RedisCacheHandler to allow custom keys (instead of the default token_info key)
  • Simplify check for existing token in RedisCacheHandler

Changed

... (truncated)

Changelog

Sourced from spotipy's changelog.

[2.22.1] - 2023-01-23

Added

  • Add alternative module installation instruction to README
  • Added Comment to README - Getting Started for user to add URI to app in Spotify Developer Dashboard.
  • Added playlist_add_tracks.py to example folder

Changed

  • Modified docstring for playlist_add_items() to accept "only URIs or URLs", with intended deprecation for IDs in v3

Fixed

  • Path traversal vulnerability that may lead to type confusion in URI handling code
  • Update contributing.md

[2.22.0] - 2022-12-10

Added

  • Integration tests via GHA (non-user endpoints)
  • Unit tests for new releases, passing limit parameter with minimum and maximum values of 1 and 50
  • Unit tests for categories, omitting country code to test global releases
  • Added CODE_OF_CONDUCT.md

Fixed

  • Incorrect category_id input for test_category
  • Assertion value for test_categories_limit_low and test_categories_limit_high
  • Pin GitHub Actions Runner to Ubuntu 20 for Py27
  • Fixed potential error where found variable in test_artist_related_artists is undefined if for loop never evaluates to true
  • Fixed false positive test test_new_releases which looks up the wrong property of the JSON response object and always evaluates to true

[2.21.0] - 2022-09-26

Added

  • Added market parameter to album and albums to address (#753
  • Added show_featured_artists.py to /examples.
  • Expanded contribution and license sections of the documentation.
  • Added FlaskSessionCacheHandler, a cache handler that stores the token info in a flask session.
  • Added Python 3.10 in GitHub Actions

Fixed

  • Updated the documentation to specify ISO-639-1 language codes.
  • Fix AttributeError for text attribute of the Response object
  • Require redis v3 if python2.7 (fixes readthedocs)

... (truncated)

Commits
  • c53511b Bump to 2.22.1
  • beec3da Fix flake8
  • b1db0b6 Merge pull request from GHSA-q764-g6fm-555v
  • 262e7a0 Rename simple files (#933)
  • d884ae1 Fix typo in start_playback function (#930)
  • f669966 Update SECURITY.md
  • 0b90627 Create SECURITY.md
  • d0bbe67 Add additional video tutorial reference to documentation. (#921)
  • 922d51d modified docstring for playlist_add_items to no longer accept IDs
  • edd3f29 Getting Started Clarifications and Example Code File (#904)
  • Additional commits viewable in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/rclim95/PlayingWHAT/network/alerts).