Skip to content

build(deps): bump github.com/posit-dev/go-python-packaging from 0.7.0 to 0.10.0 - #57

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/posit-dev/go-python-packaging-0.9.0
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/posit-dev/go-python-packaging-0.9.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

Bumps github.com/posit-dev/go-python-packaging from 0.7.0 to 0.10.0.

Changelog

Sourced from github.com/posit-dev/go-python-packaging's changelog.

[0.10.0] - 2026-09-18

Added

  • wheelname: ParseTags reads a wheel's compatibility tags without requiring its version to parse, returning a WheelTags of name, build tag and tags.

    Parse rejects the whole filename when only the version segment fails PEP 440, and the version contributes nothing to a PEP 425 tag. PEP 427 escapes runs of non-alphanumeric characters to _, so a legal local version like 1.0+cpu reaches disk as 1.0_cpu and does not parse. Measured over a full-corpus sweep of 14.3M mirrored PyPI wheels, 221 of the 299 rejected filenames failed on the version alone with their tags fully readable — and that silently understated real platform compatibility for the affected releases.

    Un-escaping inside Parse was considered and rejected: the escaping is not losslessly invertible. Both 2.5.0+post1_cpu and 2.5.0_post1+cpu parse from the escaped 2.5.0_post1_cpu and only the second is correct, so un-escaping would return a plausible wrong version with no error. Parse's behaviour is unchanged.

    ⚠️ One trade-off worth knowing: dropping version validation also drops the only signal that rejected some malformed names. too-few-py3-none-any.whl has five fields and few where a version belongs, so ParseTags accepts it while Parse does not. Re-validating the version to close that gap would defeat the function's purpose. Use Parse when you need the version.

[0.9.0] - 2026-08-28

Added

  • marker: Marker.EvaluateUndecidable reports whether a marker is satisfied and which of its comparisons could not be decided, and Marker.Variables reports the environment variables a marker references.

    Evaluate returns a bare bool, so a caller cannot distinguish "false" from "could not tell". Two things produce the latter: ~= and === reaching the generic string-operator table, which has no semantics for them (pypa/packaging raises UndefinedComparison), and an environment variable that resolves to "", which EnvironmentFromTarget legitimately does for platform_release and platform_version, since a declared target has no kernel to report.

    A consumer that must not discard a dependency edge (building a mirror or an offline bundle, where a dropped edge means a missing package and no fallback) previously had to scan Marker.String() for those operators and variable names, with false positives on quoted literals and a token list to keep in sync by hand.

    Variables covers the half this library cannot decide for the caller: a declared 3.13 forces the caller to invent a PythonFullVersion, and an

... (truncated)

Commits
  • 68c7c5c chore(release): date 0.10.0 (#57)
  • b8ef6ef feat(wheelname): add ParseTags, which does not require a parseable version (#56)
  • a9c99ee chore(release): date 0.9.0
  • 2a1fc87 chore(deps): bump testify, x/text, and x/crypto (#50)
  • 7231c32 reqtxt: record entry provenance, and close three pip-parity gaps (#49)
  • b9a950b tags: accept newer platforms than declared, any-libc targets, exported arch l...
  • fc63895 marker: report which comparisons could not be decided (#44) (#47)
  • fd79ab2 tags: floor riscv64 and loongarch64 at glibc 2.17 like every other arch (#42)...
  • cb5d9cd chore(release): date 0.8.0
  • 9c866d5 license: derive a license from the free-form License field (#40)
  • See full diff in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Sep 7, 2026
Bumps [github.com/posit-dev/go-python-packaging](https://github.com/posit-dev/go-python-packaging) from 0.7.0 to 0.10.0.
- [Release notes](https://github.com/posit-dev/go-python-packaging/releases)
- [Changelog](https://github.com/posit-dev/go-python-packaging/blob/main/CHANGELOG.md)
- [Commits](posit-dev/go-python-packaging@v0.7.0...v0.10.0)

---
updated-dependencies:
- dependency-name: github.com/posit-dev/go-python-packaging
  dependency-version: 0.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title build(deps): bump github.com/posit-dev/go-python-packaging from 0.7.0 to 0.9.0 build(deps): bump github.com/posit-dev/go-python-packaging from 0.7.0 to 0.10.0 Sep 24, 2026
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/github.com/posit-dev/go-python-packaging-0.9.0 branch from fa42022 to 2a1a338 Compare September 24, 2026 20:18
@dependabot @github

dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #65.

@dependabot dependabot Bot closed this Sep 28, 2026
@dependabot
dependabot Bot deleted the dependabot/go_modules/github.com/posit-dev/go-python-packaging-0.9.0 branch September 28, 2026 09:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants