Commit Graph

117 Commits

Author SHA1 Message Date
Nate Prewitt
781cabaf83 Fix accidental reversions during squash
Lost commits from 4bd79e39...0e4ae38f in the squash. This readds them.
2026-03-17 18:16:38 -07:00
Nate Prewitt
412bc3d04f Add inline types to Requests 2026-03-17 18:01:44 -07:00
dependabot[bot]
392b01f26e Bump actions/download-artifact from 7.0.0 to 8.0.0
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 7.0.0 to 8.0.0.
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](37930b1c2a...70fc10c6e5)

---
updated-dependencies:
- dependency-name: actions/download-artifact
  dependency-version: 8.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-03-02 13:45:19 -07:00
dependabot[bot]
27f8b40d5c Bump actions/upload-artifact from 6.0.0 to 7.0.0
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 6.0.0 to 7.0.0.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](b7c566a772...bbbca2ddaa)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-03-02 13:33:25 -07:00
Nate Prewitt
da9113c046 Add CODEOWNERS file to repo (#7208) 2026-02-13 18:06:57 -06:00
Nate Prewitt
a2ce3d8ace Remove harden runner from publish workflow (#7207) 2026-02-13 16:48:20 -06:00
Nate Prewitt
00600b38f4 Update publish workflow and add test pypi option 2026-02-13 13:23:44 -07:00
dependabot[bot]
514b3f2345 Bump step-security/harden-runner from 2.13.0 to 2.14.2
Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.13.0 to 2.14.2.
- [Release notes](https://github.com/step-security/harden-runner/releases)
- [Commits](ec9f2d5744...5ef0c079ce)

---
updated-dependencies:
- dependency-name: step-security/harden-runner
  dependency-version: 2.14.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-02-11 00:23:00 +00:00
dependabot[bot]
7112775514 Bump dessant/lock-threads from 5.0.0 to 6.0.0
Bumps [dessant/lock-threads](https://github.com/dessant/lock-threads) from 5.0.0 to 6.0.0.
- [Release notes](https://github.com/dessant/lock-threads/releases)
- [Changelog](https://github.com/dessant/lock-threads/blob/main/CHANGELOG.md)
- [Commits](d42e5f4980...7266a7ce5c)

---
updated-dependencies:
- dependency-name: dessant/lock-threads
  dependency-version: 6.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-02-10 23:59:55 +00:00
Nate Prewitt
0c2bbe7398 Drop support for Python 3.9 (#7196) 2026-02-06 08:02:46 -07:00
Nate Prewitt
32e26af3af Start testing Python 3.15 Alpha (#7195)
* Add optional 3.15-dev runners to test matrix

* Set PYO3_USE_ABI3_FORWARD_COMPATIBILITY for 3.15 builds
2026-02-04 19:01:16 -06:00
dependabot[bot]
968863678b Bump github/codeql-action from 4.30.8 to 4.31.6
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.30.8 to 4.31.6.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](f443b600d9...fe4161a26a)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: 4.31.6
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-01-30 20:00:02 -07:00
dependabot[bot]
42eaeb4da8 Bump actions/setup-python from 6.0.0 to 6.1.0
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 6.0.0 to 6.1.0.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](e797f83bcb...83679a892e)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-version: 6.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-01-30 19:53:54 -07:00
dependabot[bot]
8e398336f8 Bump actions/checkout from 5.0.0 to 6.0.0
Bumps [actions/checkout](https://github.com/actions/checkout) from 5.0.0 to 6.0.0.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](08c6903cd8...1af3b93b68)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 6.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-01-30 19:46:03 -07:00
dependabot[bot]
ca78ca9611 Bump actions/download-artifact from 5.0.0 to 6.0.0
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 5.0.0 to 6.0.0.
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](634f93cb29...018cc2cf5b)

---
updated-dependencies:
- dependency-name: actions/download-artifact
  dependency-version: 6.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-01-30 19:38:25 -07:00
dependabot[bot]
6c88b6b09f Bump actions/upload-artifact from 4.6.2 to 5.0.0
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4.6.2 to 5.0.0.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](ea165f8d65...330a01c490)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-01-31 02:31:13 +00:00
Nate Prewitt
f8bec2f7ca Fix CI and build failures (#7190)
* Migrate linting from various tooling to Ruff

* Run ruff over codebase

* Drop support for pypy-3.10
2026-01-30 15:10:27 -06:00
dependabot[bot]
6e4134b204 Bump github/codeql-action from 3.30.0 to 4.30.8
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 3.30.0 to 4.30.8.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](2d92b76c45...f443b600d9)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: 4.30.8
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-10-13 16:16:05 +00:00
dependabot[bot]
3c8decb92f Bump actions/setup-python from 5.6.0 to 6.0.0
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 5.6.0 to 6.0.0.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](a26af69be9...e797f83bcb)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-version: 6.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-09-09 00:09:47 +00:00
dependabot[bot]
7d8df1df57 Bump pypa/gh-action-pypi-publish from 1.12.4 to 1.13.0
Bumps [pypa/gh-action-pypi-publish](https://github.com/pypa/gh-action-pypi-publish) from 1.12.4 to 1.13.0.
- [Release notes](https://github.com/pypa/gh-action-pypi-publish/releases)
- [Commits](76f52bc884...ed0c53931b)

---
updated-dependencies:
- dependency-name: pypa/gh-action-pypi-publish
  dependency-version: 1.13.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-09-08 16:18:37 +00:00
dependabot[bot]
1c49660b84 Bump github/codeql-action from 3.29.0 to 3.30.0
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 3.29.0 to 3.30.0.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](ce28f5bb42...2d92b76c45)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: 3.30.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-09-02 03:15:01 -05:00
dependabot[bot]
b336cb2bc6 Bump actions/checkout from 4.2.0 to 5.0.0
Bumps [actions/checkout](https://github.com/actions/checkout) from 4.2.0 to 5.0.0.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v4.2.0...08c6903cd8c0fde910a37f88322edcfb5dd907a8)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-08-11 22:15:22 +00:00
Grant Birkinbine
46e939b552 Update publish workflow to use artifact-id instead of name
Added artifact-id output to publish workflow and updated download-artifact action version to `v5.0.0`. Also hardens the workflow a bit by adding `persist-credentials: false` to the checkout step
2025-08-06 07:36:19 -05:00
dependabot[bot]
7618dbef01 Bump step-security/harden-runner from 2.12.0 to 2.13.0
Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.12.0 to 2.13.0.
- [Release notes](https://github.com/step-security/harden-runner/releases)
- [Commits](0634a2670c...ec9f2d5744)

---
updated-dependencies:
- dependency-name: step-security/harden-runner
  dependency-version: 2.13.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-07-28 19:01:25 +00:00
Nate Prewitt
2edca11103 Add support for Python 3.14 and drop support for Python 3.8 (#6993)
* Add testing for Python 3.14 preview build

* Add trove classifier for Python 3.14

* Remove support for Python 3.8
2025-07-25 14:42:15 -06:00
dependabot[bot]
91a3eabd3d Bump github/codeql-action from 3.28.5 to 3.29.0
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 3.28.5 to 3.29.0.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](f6091c0113...ce28f5bb42)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: 3.29.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-06-16 14:10:36 -05:00
Ian Stapleton Cordasco
e57b5bf05c Add Trusted Publishing Release Workflow
Rather than rely on manual releases from a developer laptop, let's use
tag pushes to trigger a workflow to publish artifacts to PyPI. This will
leverage trusted publishing and upload attestations as well.
2025-06-09 21:32:45 -05:00
Nate Prewitt
579cd9f233 Drop pypy 3.9 and add pypy 3.11 support 2025-05-01 21:54:57 -05:00
dependabot[bot]
991f05dcd9 Bump actions/setup-python from 5.5.0 to 5.6.0
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 5.5.0 to 5.6.0.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](8d9ed9ac5c...a26af69be9)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-version: 5.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-04-28 17:28:05 +00:00
Robin
4ce9520a1c Update lint workflow to ubuntu-24.04
Ubuntu 20.04 was the old default and is no longer supported by GitHub Actions
2025-04-23 07:44:05 -05:00
dependabot[bot]
a5cb4284e1 Bump actions/setup-python from 5.4.0 to 5.5.0
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 5.4.0 to 5.5.0.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](42375524e2...8d9ed9ac5c)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-03-31 16:31:10 +00:00
dependabot[bot]
11f63a330b Bump actions/setup-python from 5.3.0 to 5.4.0
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 5.3.0 to 5.4.0.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](0b93645e9f...42375524e2)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-02-03 16:27:40 +00:00
dependabot[bot]
8c36da656d Bump github/codeql-action from 3.27.0 to 3.28.5
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 3.27.0 to 3.28.5.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](662472033e...f6091c0113)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-01-27 16:56:12 +00:00
Nate Prewitt
ad959acfcf Remove old macOS runners 2024-11-09 22:50:30 -07:00
Nate Prewitt
a6cf27a77f Update vulnerability disclosure process (#6820)
* Update contact point for Vulnerability disclosures

* Fix RedHat Contact

* Point vulnerabilities.rst to our .SECURITY file
2024-11-02 13:13:02 -07:00
Nate Prewitt
ed0b1b5802 Merge pull request #6817 from psf/dependabot/github_actions/actions/setup-python-5.3.0
Bump actions/setup-python from 5.2.0 to 5.3.0
2024-10-28 10:24:23 -06:00
dependabot[bot]
9787d0c09c Bump github/codeql-action from 3.26.0 to 3.27.0
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 3.26.0 to 3.27.0.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](eb055d739a...662472033e)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-10-28 16:05:20 +00:00
dependabot[bot]
26664fa578 Bump actions/setup-python from 5.2.0 to 5.3.0
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 5.2.0 to 5.3.0.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](f677139bbe...0b93645e9f)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-10-28 16:05:11 +00:00
dependabot[bot]
0bff2d94e6 Bump actions/checkout from 4.1.0 to 4.2.0
Bumps [actions/checkout](https://github.com/actions/checkout) from 4.1.0 to 4.2.0.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](8ade135a41...d632683dd7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-09-30 16:34:20 +00:00
Thomas Grainger
83e67c4485 use allow-prereleases: true instead of 3.13-dev 2024-09-18 15:04:08 +01:00
Thomas Grainger
0f5ef1be8c Merge branch 'main' of github.com:psf/requests into 3.13 2024-09-18 15:03:08 +01:00
dependabot[bot]
173890a48e Bump actions/setup-python from 5.1.0 to 5.2.0
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 5.1.0 to 5.2.0.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](82c7e631bb...f677139bbe)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-09-02 16:56:26 +00:00
dependabot[bot]
877892e67e Bump github/codeql-action from 3.25.0 to 3.26.0
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 3.25.0 to 3.26.0.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](df5a14dc28...eb055d739a)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-08-12 16:23:16 +00:00
Nate Prewitt
f8aa36b92d Test on urllib3 1.26.x 2024-07-01 18:08:04 -07:00
Nate Prewitt
2e1452234d Start testing on 3.13 beta 2024-05-23 11:51:07 -07:00
Nate Prewitt
555b870eb1 Allow character detection dependencies to be optional in post-packaging steps 2024-05-14 15:26:04 -07:00
Nate Prewitt
2d5f54779a Pin 3.8 and 3.9 runners back to macos-13 (#6688) 2024-04-23 10:50:19 -07:00
dependabot[bot]
60047ade64 Bump github/codeql-action from 3.24.0 to 3.25.0
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 3.24.0 to 3.25.0.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](e8893c57a1...df5a14dc28)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-04-15 16:40:35 +00:00
dependabot[bot]
2daa7b52a7 Bump actions/setup-python from 5.0.0 to 5.1.0
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 5.0.0 to 5.1.0.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](0a5c615913...82c7e631bb)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-04-01 17:00:20 +00:00
Nate Prewitt
58cea7a728 Drop support for CPython 3.7 2024-02-20 15:37:46 -08:00