[pull] master from aio-libs:master - #784
Merged
Merged
Conversation
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.38.1 to 4.38.2. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/github/codeql-action/releases">github/codeql-action's releases</a>.</em></p> <blockquote> <h2>v4.38.2</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1">2.27.1</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4160">#4160</a></li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action's changelog</a>.</em></p> <blockquote> <h2>4.38.2 - 24 Sept 2026</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1">2.27.1</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4160">#4160</a></li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/github/codeql-action/commit/2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2"><code>2892aa5</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4168">#4168</a> from github/update-v4.38.2-a6ef2c96f</li> <li><a href="https://github.com/github/codeql-action/commit/8ad03a333eb88de8ad6833eda208d0fc51a9c571"><code>8ad03a3</code></a> Trigger workflows</li> <li><a href="https://github.com/github/codeql-action/commit/98af865db5041cee73c7185896319367f8c0adf2"><code>98af865</code></a> Update changelog for v4.38.2</li> <li><a href="https://github.com/github/codeql-action/commit/a6ef2c96fc0e37d0b44fb2bd0b32db4bcb89ae24"><code>a6ef2c9</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4156">#4156</a> from github/mario-campos/fix-validate-cmd</li> <li><a href="https://github.com/github/codeql-action/commit/1ef28a1b7603ca158fd774d1ab328cbd6a40b84b"><code>1ef28a1</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4166">#4166</a> from github/dependabot/github_actions/dot-github/wor...</li> <li><a href="https://github.com/github/codeql-action/commit/26cb08bab0037de74cc66ad9ec0dca31d6d9e8a7"><code>26cb08b</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4163">#4163</a> from github/mbg/fix-getCommitOid-stubs</li> <li><a href="https://github.com/github/codeql-action/commit/f035ce3a985a1223a9f59fb719542598640160b2"><code>f035ce3</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4165">#4165</a> from github/dependabot/npm_and_yarn/npm-minor-8eaed9...</li> <li><a href="https://github.com/github/codeql-action/commit/5e4e2550b48d7f3de205c9d752eb5176bf07f6d9"><code>5e4e255</code></a> Rebuild</li> <li><a href="https://github.com/github/codeql-action/commit/b13f5f47d5398d0fb982942ced6fdfc4e3951804"><code>b13f5f4</code></a> Bump ruby/setup-ruby</li> <li><a href="https://github.com/github/codeql-action/commit/c87fe5756c0c0bcd5e0005d2169945cfee9a232f"><code>c87fe57</code></a> Rebuild</li> <li>Additional commits viewable in <a href="https://github.com/github/codeql-action/compare/v4.38.1...v4.38.2">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [platformdirs](https://github.com/tox-dev/platformdirs) from 4.11.12 to 4.11.14. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/tox-dev/platformdirs/releases">platformdirs's releases</a>.</em></p> <blockquote> <h2>4.11.14</h2> <!-- raw HTML omitted --> <h2>What's Changed</h2> <ul> <li>🐛 fix(dirs): only create configured media dirs by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/platformdirs/pull/561">tox-dev/platformdirs#561</a></li> <li>🧪 test(appdirs): clear XDG variables in compatibility test by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/platformdirs/pull/570">tox-dev/platformdirs#570</a></li> <li>🐛 fix(unix): ignore XDG_RUNTIME_DIR when redirecting root by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/platformdirs/pull/562">tox-dev/platformdirs#562</a></li> <li>🐛 fix(android): find the app folder for packages named files* by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/platformdirs/pull/565">tox-dev/platformdirs#565</a></li> <li>🐛 fix(unix): apply use_site_for_root changes after first read by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/platformdirs/pull/567">tox-dev/platformdirs#567</a></li> <li>🐛 fix(unix): read user-dirs.dirs like os.fsdecode by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/platformdirs/pull/568">tox-dev/platformdirs#568</a></li> <li>🐛 fix(api): accept roaming in user_log_dir and user_log_path by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/platformdirs/pull/572">tox-dev/platformdirs#572</a></li> <li>🐛 fix(api): check app arguments on assignment by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/platformdirs/pull/566">tox-dev/platformdirs#566</a></li> <li>🐛 fix(unix): keep colons in site_cache_path under multipath by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/platformdirs/pull/574">tox-dev/platformdirs#574</a></li> <li>🐛 fix(windows): drop 8.3 short names from folder paths by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/platformdirs/pull/575">tox-dev/platformdirs#575</a></li> <li>📝 docs(platforms): fix Windows user_preference_dir path by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/platformdirs/pull/577">tox-dev/platformdirs#577</a></li> <li>🐛 fix(macos): detect Homebrew Python by its opt/ framework path by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/platformdirs/pull/573">tox-dev/platformdirs#573</a></li> <li>🐛 fix(android): use Download as the downloads folder name by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/platformdirs/pull/563">tox-dev/platformdirs#563</a></li> <li>🐛 fix(windows): ignore relative WIN_PD_OVERRIDE values by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/platformdirs/pull/564">tox-dev/platformdirs#564</a></li> <li>🐛 fix(windows): treat empty PUBLIC and fallback env vars as unset by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/platformdirs/pull/571">tox-dev/platformdirs#571</a></li> <li>🐛 fix(unix): keep the temporary runtime dir fallback private by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/platformdirs/pull/576">tox-dev/platformdirs#576</a></li> <li>🐛 fix(dirs): refuse to create a literal ~ dir without a home by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/platformdirs/pull/578">tox-dev/platformdirs#578</a></li> <li>📝 docs(macos): name the XDG variables the state dirs skip by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/platformdirs/pull/579">tox-dev/platformdirs#579</a></li> <li>🐛 fix(unix): drop trailing comment after unquoted user dir by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/platformdirs/pull/569">tox-dev/platformdirs#569</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/tox-dev/platformdirs/compare/4.11.13...4.11.14">https://github.com/tox-dev/platformdirs/compare/4.11.13...4.11.14</a></p> <h2>4.11.13</h2> <!-- raw HTML omitted --> <h2>What's Changed</h2> <ul> <li>🐛 fix(dirs): create media dirs when ensure_exists is set by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/platformdirs/pull/560">tox-dev/platformdirs#560</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/tox-dev/platformdirs/compare/4.11.12...4.11.13">https://github.com/tox-dev/platformdirs/compare/4.11.12...4.11.13</a></p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/tox-dev/platformdirs/blob/main/docs/changelog.rst">platformdirs's changelog</a>.</em></p> <blockquote> <p>########### Changelog ###########</p> <p>.. towncrier-draft-entries:: Unreleased</p> <p>.. towncrier release notes start</p> <hr /> <p>4.12.1 (2026-09-28)</p> <hr /> <ul> <li>Avoid <code>PytestAssertRewriteWarning</code> when importing <code>platformdirs</code> before invoking pytest. :pr:<code>601</code></li> </ul> <hr /> <p>4.12.0 (2026-09-26)</p> <hr /> <ul> <li>Add <code>place_*_file</code> methods that return a file path under a user directory and create its missing parents with mode <code>0o700</code>. :pr:<code>585</code></li> <li>Add <code>find_<kind>_file</code> and <code>find_<kind>_files</code> to look up an existing file across the user and site directories of each kind that has an <code>iter_<kind>_paths</code> method. :pr:<code>586</code></li> <li>Add :func:<code>platformdirs.testing.isolated_dirs</code> and the <code>platformdirs_isolated</code> pytest fixture to resolve every directory under one test root. :pr:<code>590</code></li> <li>Emit :class:<code>~platformdirs.RuntimeDirWarning</code> when the Unix :func:<code>~platformdirs.user_runtime_dir</code> falls back from <code>XDG_RUNTIME_DIR</code>. :pr:<code>599</code></li> <li>Read <code>user_templates_dir</code>, <code>user_publicshare_dir</code> and <code>user_bin_dir</code> on Windows from their known folders. :pr:<code>587</code></li> <li>Create missing user app directories and their parents with mode <code>0700</code> under <code>ensure_exists</code> on POSIX platforms. :pr:<code>588</code></li> <li>Raise <code>RuntimeError</code> for a Unix or macOS directory under the home when no home resolves, and read the password database for an empty <code>HOME</code>. :pr:<code>589</code></li> <li>Skip an <code>XDG_RUNTIME_DIR</code> or <code>/run/user/<uid></code> that is not a private directory of the user, and reject a symlink or file as the <code>runtime-<uid></code> fallback. :pr:<code>599</code></li> <li>Use the app container layout on iOS, such as <code>~/Library/Application Support</code> for data. :pr:<code>600</code></li> <li>Document that a Homebrew Python puts the Homebrew prefix first in the macOS shared directories, with or without <code>multipath</code>. :pr:<code>591</code></li> <li>Document that the macOS media directories honor the <code>XDG_*_DIR</code> variables. :pr:<code>592</code></li> <li>Document the <code>WIN_PD_OVERRIDE_COMMON_PROGRAMS</code> variable. :pr:<code>593</code></li> <li>Document <code>/usr/local/share/applications</code> as the Linux <code>site_applications_dir</code> default. :pr:<code>594</code></li> <li>Correct the BSD <code>user_runtime_dir</code> defaults and describe the temporary directory fallback. :pr:<code>595</code></li> <li>Describe how platformdirs detects Android, finds the app folder and places the shared folders. :pr:<code>596</code></li> <li>Document that Microsoft Store Python redirects only new files and folders under <code>AppData</code>. :pr:<code>597</code></li> <li>Show how to load a font on Windows after copying it into <code>user_fonts_dir</code>. :pr:<code>598</code></li> </ul> <hr /> <p>4.11.15 (2026-09-26)</p> <hr /> <ul> <li>Fix the pyjnius lookup of the Android app folder and media directories, which always failed. :pr:<code>580</code></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/tox-dev/platformdirs/commit/e12a8483c2481bdb5bb0c1d36631efae18ad50b6"><code>e12a848</code></a> Release 4.11.14</li> <li><a href="https://github.com/tox-dev/platformdirs/commit/26372da5f430548ba3b08f46f14bd36cca8519fb"><code>26372da</code></a> 🐛 fix(unix): drop trailing comment after unquoted user dir (<a href="https://redirect.github.com/tox-dev/platformdirs/issues/569">#569</a>)</li> <li><a href="https://github.com/tox-dev/platformdirs/commit/73d35082e6d4c7f7b04f2762a2c6b994c82598f0"><code>73d3508</code></a> 📝 docs(macos): name the XDG variables the state dirs skip (<a href="https://redirect.github.com/tox-dev/platformdirs/issues/579">#579</a>)</li> <li><a href="https://github.com/tox-dev/platformdirs/commit/4ac34b881f62da5210fc0583162353c7eaa595ab"><code>4ac34b8</code></a> 🐛 fix(dirs): refuse to create a literal ~ dir without a home (<a href="https://redirect.github.com/tox-dev/platformdirs/issues/578">#578</a>)</li> <li><a href="https://github.com/tox-dev/platformdirs/commit/49a065be4e9608c99b1dabbc79db1080468f36d4"><code>49a065b</code></a> 🐛 fix(unix): keep the temporary runtime dir fallback private (<a href="https://redirect.github.com/tox-dev/platformdirs/issues/576">#576</a>)</li> <li><a href="https://github.com/tox-dev/platformdirs/commit/c78e917390d491019d983f1f61f468b217afce79"><code>c78e917</code></a> 🐛 fix(windows): treat empty PUBLIC and fallback env vars as unset (<a href="https://redirect.github.com/tox-dev/platformdirs/issues/571">#571</a>)</li> <li><a href="https://github.com/tox-dev/platformdirs/commit/0d8898800e74e119dae08a7bc4abe66b8246904a"><code>0d88988</code></a> 🐛 fix(windows): ignore relative WIN_PD_OVERRIDE values (<a href="https://redirect.github.com/tox-dev/platformdirs/issues/564">#564</a>)</li> <li><a href="https://github.com/tox-dev/platformdirs/commit/7dc1ec07087dc8392009b14061ed9144e2d99e97"><code>7dc1ec0</code></a> 🐛 fix(android): use Download as the downloads folder name (<a href="https://redirect.github.com/tox-dev/platformdirs/issues/563">#563</a>)</li> <li><a href="https://github.com/tox-dev/platformdirs/commit/4ee597e807c253252c33871179d7db134c7b4f31"><code>4ee597e</code></a> 🐛 fix(macos): detect Homebrew Python by its opt/ framework path (<a href="https://redirect.github.com/tox-dev/platformdirs/issues/573">#573</a>)</li> <li><a href="https://github.com/tox-dev/platformdirs/commit/53d50eb88392c3273c2b79e8b8a84cd3aecb9dc5"><code>53d50eb</code></a> 📝 docs(platforms): fix Windows user_preference_dir path (<a href="https://redirect.github.com/tox-dev/platformdirs/issues/577">#577</a>)</li> <li>Additional commits viewable in <a href="https://github.com/tox-dev/platformdirs/compare/4.11.12...4.11.14">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [virtualenv](https://github.com/pypa/virtualenv) from 21.9.1 to 21.12.1. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/pypa/virtualenv/releases">virtualenv's releases</a>.</em></p> <blockquote> <h2>21.12.1</h2> <!-- raw HTML omitted --> <h2>What's Changed</h2> <ul> <li>🐛 fix(create): limit .venv redirect to projects by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3316">pypa/virtualenv#3316</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/pypa/virtualenv/compare/21.12.0...21.12.1">https://github.com/pypa/virtualenv/compare/21.12.0...21.12.1</a></p> <h2>21.12.0</h2> <!-- raw HTML omitted --> <h2>What's Changed</h2> <ul> <li>✨ feat(create): point a .venv redirect per PEP 832 by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3204">pypa/virtualenv#3204</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/pypa/virtualenv/compare/21.11.1...21.12.0">https://github.com/pypa/virtualenv/compare/21.11.1...21.12.0</a></p> <h2>21.11.1</h2> <!-- raw HTML omitted --> <h2>What's Changed</h2> <ul> <li>📝 docs(security): close threat items resolved by 21.11.0 by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3313">pypa/virtualenv#3313</a></li> <li>🐛 fix(build): ship test inputs in the sdist and check it by <a href="https://github.com/Gonghan-Princess"><code>@Gonghan-Princess</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3315">pypa/virtualenv#3315</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/Gonghan-Princess"><code>@Gonghan-Princess</code></a> made their first contribution in <a href="https://redirect.github.com/pypa/virtualenv/pull/3315">pypa/virtualenv#3315</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/pypa/virtualenv/compare/21.11.0...21.11.1">https://github.com/pypa/virtualenv/compare/21.11.0...21.11.1</a></p> <h2>21.11.0</h2> <!-- raw HTML omitted --> <h2>What's Changed</h2> <ul> <li>ci(pre-release): disable the uv cache by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3288">pypa/virtualenv#3288</a></li> <li>ci: pass expressions to run scripts via env by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3292">pypa/virtualenv#3292</a></li> <li>ci(release): audit egress in build and publish by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3289">pypa/virtualenv#3289</a></li> <li>📝 docs: define maintainer roles and access by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3290">pypa/virtualenv#3290</a></li> <li>ci: resolve zizmor auditor findings by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3297">pypa/virtualenv#3297</a></li> <li>ci(pre-commit): freeze hook revs to commit SHAs by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3298">pypa/virtualenv#3298</a></li> <li>docs: link docs and pyvideo over https by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3300">pypa/virtualenv#3300</a></li> <li>docs(development): add a one-year roadmap by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3304">pypa/virtualenv#3304</a></li> <li>🐛 fix(seed): fail closed when PyPI digest is unknown by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3302">pypa/virtualenv#3302</a></li> <li>✨ feat(release): publish SBOMs as release assets by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3299">pypa/virtualenv#3299</a></li> <li>docs(security): describe the project under the CRA by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3295">pypa/virtualenv#3295</a></li> <li>docs(template): name the trust boundary crossed by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3296">pypa/virtualenv#3296</a></li> <li>♻️ refactor(sbom): type the SPDX renderer by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3307">pypa/virtualenv#3307</a></li> <li>✨ feat(zipapp): publish an SBOM for the zipapp by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3310">pypa/virtualenv#3310</a></li> <li>👷 ci(check): pin test tool downloads and bump them weekly by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3293">pypa/virtualenv#3293</a></li> <li>📝 docs: explain what a release publishes and how to verify it by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3305">pypa/virtualenv#3305</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/pypa/virtualenv/blob/main/docs/changelog.rst">virtualenv's changelog</a>.</em></p> <blockquote> <h1>Bugfixes - 21.12.1</h1> <ul> <li> <p>Limit the :PEP:<code>832</code> <code>.venv</code> redirect to folders holding a <code>pyproject.toml</code> and no <code>.venv</code> yet, so <code>virtualenv foo</code> in a scratch folder, and tools such as tox or nox building environments through virtualenv, no longer claim a folder's default environment - by :user:<code>gaborbernat</code>.</p> <ul> <li><code>--venv-redirect</code> writes the redirect in any folder and replaces an earlier virtualenv redirect.</li> <li>A flag on the command line overrides the environment variable and the config file in either direction. (:issue:<code>3316</code>)</li> </ul> </li> </ul> <hr /> <p>v21.12.0 (2026-09-24)</p> <hr /> <h1>Features - 21.12.0</h1> <ul> <li> <p>Write the <code>PEP 838 <https://peps.python.org/pep-0838/></code>_ <code>python-version</code> key into <code>pyvenv.cfg</code>, holding the target interpreter's feature release. The new :doc:<code>reference/files</code> page covers it alongside every other file a created environment holds - by :user:<code>konstin</code>. (:issue:<code>3193</code>)</p> </li> <li> <p>Point a <code>.venv</code> redirect file in the parent folder at the created environment, per <code>PEP 832 <https://peps.python.org/pep-0832/></code>_, so editors and type checkers can find it - by :user:<code>gaborbernat</code>.</p> <ul> <li>virtualenv leaves a <code>.venv</code> folder alone, and a redirect pointing at an environment it did not create.</li> <li>Pass <code>--no-venv-redirect</code> to opt out.</li> <li>The feature is provisional while PEP 832 is a draft: a minor or patch release may change it in backward incompatible ways to follow the PEP. (:issue:<code>3204</code>)</li> </ul> </li> </ul> <hr /> <p>v21.11.1 (2026-09-23)</p> <hr /> <h1>Bugfixes - 21.11.1</h1> <ul> <li>Include the pre-commit configuration and the zipapp lock file in the source distribution, so downstream packagers can run the test suite from it. (:issue:<code>3314</code>)</li> </ul> <hr /> <p>v21.11.0 (2026-09-23)</p> <hr /> <h1>Features - 21.11.0</h1> <ul> <li>Attach the CycloneDX SBOM and an SPDX 2.3 rendering of it (<code>virtualenv.cdx.json</code>, <code>virtualenv.spdx.json</code>) to each GitHub release, and attest the SPDX document against the sdist and wheel. (:issue:<code>3299</code>)</li> <li>Describe the zipapp in its own CycloneDX SBOM, which lists virtualenv, the embedded pip and setuptools wheels, and each bundled dependency with the Python versions that load it, down to a SHA-256 per file. The SBOM sits at the root</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/pypa/virtualenv/commit/befec5eae075d1c4cb00a41d0c72bcdb91bf4586"><code>befec5e</code></a> release 21.12.1</li> <li><a href="https://github.com/pypa/virtualenv/commit/572d15982880cbd4b412048e233f15522138d9c8"><code>572d159</code></a> 🐛 fix(create): limit .venv redirect to projects (<a href="https://redirect.github.com/pypa/virtualenv/issues/3316">#3316</a>)</li> <li><a href="https://github.com/pypa/virtualenv/commit/f19165be525a9f4e7d4ccf374bfb47090ee4a397"><code>f19165b</code></a> release 21.12.0</li> <li><a href="https://github.com/pypa/virtualenv/commit/554bc8f65c3dc1eeca4aaa7150fa00f670818a30"><code>554bc8f</code></a> ✨ feat(create): point a .venv redirect per PEP 832 (<a href="https://redirect.github.com/pypa/virtualenv/issues/3204">#3204</a>)</li> <li><a href="https://github.com/pypa/virtualenv/commit/4c13875f0967e872f5e0708bdccfcd45aa175f0a"><code>4c13875</code></a> release 21.11.1</li> <li><a href="https://github.com/pypa/virtualenv/commit/ae073fbb0927f16a13e3fbf2561cd31439b2f3fa"><code>ae073fb</code></a> 🐛 fix(build): ship test inputs in the sdist and check it (<a href="https://redirect.github.com/pypa/virtualenv/issues/3315">#3315</a>)</li> <li><a href="https://github.com/pypa/virtualenv/commit/fc912de38475681b5ddd1e3ab3d04224f5e18f69"><code>fc912de</code></a> 📝 docs(security): close threat items resolved by 21.11.0 (<a href="https://redirect.github.com/pypa/virtualenv/issues/3313">#3313</a>)</li> <li><a href="https://github.com/pypa/virtualenv/commit/49077e788f2b22bfc7c00616e2008b250905846b"><code>49077e7</code></a> release 21.11.0</li> <li><a href="https://github.com/pypa/virtualenv/commit/5d9dc5843f5fca7669e7998868cca450dee1bf70"><code>5d9dc58</code></a> 🐛 fix(sbom): keep the build machine out of the SBOMs (<a href="https://redirect.github.com/pypa/virtualenv/issues/3311">#3311</a>)</li> <li><a href="https://github.com/pypa/virtualenv/commit/bcb0fa61f4d6364f5c8be923871dcfca3fccba22"><code>bcb0fa6</code></a> 📝 docs(security): sync threat model with merged fixes (<a href="https://redirect.github.com/pypa/virtualenv/issues/3312">#3312</a>)</li> <li>Additional commits viewable in <a href="https://github.com/pypa/virtualenv/compare/21.9.1...21.12.1">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
See Commits and Changes for more details.
Created by
pull[bot] (v2.0.0-alpha.4)
Can you help keep this open source service alive? 💖 Please sponsor : )