Skip to content

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github May 30, 2022

Bumps itsdangerous from 0.24 to 1.1.0.

Changelog

Sourced from itsdangerous's changelog.

Version 1.1.0

Released 2018-10-26

  • Change default signing algorithm back to SHA-1. :pr:113
  • Added a default SHA-512 fallback for users who used the yanked 1.0.0 release which defaulted to SHA-512. :pr:114
  • Add support for fallback algorithms during deserialization to support changing the default in the future without breaking existing signatures. :pr:113
  • Changed capitalization of packages back to lowercase as the change in capitalization broke some tooling. :pr:113

Version 1.0.0

Released 2018-10-18

YANKED

Note: This release was yanked from PyPI because it changed the default algorithm to SHA-512. This decision was reverted in 1.1.0 and it remains at SHA1.

  • Drop support for Python 2.6 and 3.3.

  • Refactor code from a single module to a package. Any object in the API docs is still importable from the top-level itsdangerous name, but other imports will need to be changed. A future release will remove many of these compatibility imports. :pr:107

  • Optimize how timestamps are serialized and deserialized. :pr:13

  • base64_decode raises BadData when it is passed invalid data. :pr:27

  • Ensure value is bytes when signing to avoid a TypeError on Python 3. :issue:29

  • Add a serializer_kwargs argument to Serializer, which is passed to dumps during dump_payload. :pr:36

  • More compact JSON dumps for unicode strings. :issue:38

  • Use the full timestamp rather than an offset, allowing dates before 2011. :issue:46

    To retain compatibility with signers from previous versions, consider using this shim <https://github.com/pallets/itsdangerous /issues/120#issuecomment-456913331>_ when unsigning.

  • Detect a sep character that may show up in the signature itself and raise a ValueError. :issue:62

  • Use a consistent signature for keyword arguments for Serializer.load_payload in subclasses. :issue:74, :pr:75

  • Change default intermediate hash from SHA-1 to SHA-512. :pr:80

... (truncated)

Commits
  • 6e63598 release 1.1.0
  • 66c9319 link #114 changelog
  • 8561891 test iter_unsigners
  • e529593 add compat import for itsdangerous.want_bytes
  • 920993c Added SHA-512 fallback by default
  • d79c74a Added SHA-512 fallback by default
  • ef8fd98 more name cleanup, parametrize fallback test
  • af4856a Added fallback signers and switch back to sha1
  • 92a6423 Document change to lowercase
  • 2fd3237 Change package back to lowercase
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels May 30, 2022
Bumps [itsdangerous](https://github.com/pallets/itsdangerous) from 0.24 to 1.1.0.
- [Release notes](https://github.com/pallets/itsdangerous/releases)
- [Changelog](https://github.com/pallets/itsdangerous/blob/main/CHANGES.rst)
- [Commits](pallets/itsdangerous@0.24...1.1.0)

---
updated-dependencies:
- dependency-name: itsdangerous
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot force-pushed the dependabot/pip/itsdangerous-1.1.0 branch from 513ca0b to 2e6e8e1 Compare September 12, 2022 18:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file python Pull requests that update Python code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants