Skip to content

build(deps): bump aioquic from 0.9.25 to 1.0.0 in /tools/base - #1174

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/tools/base/aioquic-1.0.0
Closed

build(deps): bump aioquic from 0.9.25 to 1.0.0 in /tools/base#1174
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/tools/base/aioquic-1.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Mar 13, 2024

Copy link
Copy Markdown

Bumps aioquic from 0.9.25 to 1.0.0.

Changelog

Sourced from aioquic's changelog.

1.0.0

  • Ensure no data is sent after a stream reset.
  • Make :class:~aioquic.h3.connection.H3Connection's :meth:~aioquic.h3.connection.H3Connection.send_datagram and :meth:~aioquic.h3.connection.H3Connection.send_push_promise methods raise an :class:~aioquic.h3.exceptions.InvalidStreamTypeError exception if an invalid stream ID is specified.
  • Improve the documentation for :class:~aioquic.asyncio.QuicConnectionProtocol's :meth:~aioquic.asyncio.QuicConnectionProtocol.transmit method.
  • Fix :meth:~datetime.datetime.utcnow deprecation warning on Python 3.12 by using cryptography_ 42.0 and timezone-aware :class:~datetime.datetime instances when validating TLS certificates.
  • Build binary wheels against OpenSSL_ 3.2.0.
  • Ignore any non-ASCII ALPN values received.
  • Perform more extensive HTTP/3 header validation in :class:~aioquic.h3.connection.H3Connection.
  • Fix exceptions when draining stream writers in the :doc:asyncio API <asyncio>.
  • Set the :class:~aioquic.quic.connection.QuicConnection idle timer according to :rfc:9000 section 10.1.
  • Implement fairer stream scheduling in :class:~aioquic.quic.connection.QuicConnection to avoid head-of-line blocking.
  • Only load certifi_ root certificates if none was specified in the :class:~aioquic.quic.configuration.QuicConfiguration.
  • Improve padding of UDP datagrams containing Initial packets to comply with :rfc:9000 section 14.1.
  • Limit the number of pending connection IDs marked for retirement to prevent a possible DoS attack.

.. _certifi: https://github.com/certifi/python-certifi .. _cryptography: https://cryptography.io/ .. _OpenSSL: https://www.openssl.org/

Commits
  • 072eb4b 1.0.0
  • 4f73f18 Limit the number of pending connection IDs marked for retirement.
  • c32862a Comply with RFC 9000 section 14.1 (#481)
  • 766645f Update GitHub actions to their latest versions
  • 8b14b90 Only load certifi if none of cadata, cafile, or capath have been specified. [...
  • ae282aa Reformat code using latest ruff version
  • e728bc2 Fairer stream write scheduling #125. (#475)
  • fecdd59 Set the idle timer according to RFC 9000 section 10.1 #466. (#474)
  • 2b3d9b8 Fix stream writer draining exceptions. (#477)
  • a5cdaa8 More H3 header validation #465. (#472)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [aioquic](https://github.com/aiortc/aioquic) from 0.9.25 to 1.0.0.
- [Changelog](https://github.com/aiortc/aioquic/blob/main/docs/changelog.rst)
- [Commits](aiortc/aioquic@0.9.25...1.0.0)

---
updated-dependencies:
- dependency-name: aioquic
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Mar 13, 2024
@dependabot @github

dependabot Bot commented on behalf of github Jun 19, 2024

Copy link
Copy Markdown
Author

Superseded by #1410.

@dependabot dependabot Bot closed this Jun 19, 2024
@dependabot
dependabot Bot deleted the dependabot/pip/tools/base/aioquic-1.0.0 branch June 19, 2024 06:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants