The 0.5.6 source tarball on PyPI now uses the PEP 625 name
python_gnupg-0.5.6.tar.gz.
- Set PYPI_PACKAGE to "python_gnupg"
- Set S explicitly, since the archive still unpacks to
python-gnupg-${PV}
- Set CVE_PRODUCT to "python:python-gnupg" so CVE matching still
works after the PYPI_PACKAGE change
Changelog:
https://github.com/vsajip/python-gnupg/releases/tag/0.5.6
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Add python3-crypt to RDEPENDS: the library now imports hashlib
(_identity.py, pulled in by "import filelock" through the soft and
strict locks).
Changelog: https://github.com/tox-dev/filelock/blob/4.0.4/docs/changelog.rst
4.0.4
- Hostnames differing only past their first 253 escaped characters now
publish distinct soft-lock owners.
4.0.3
- Skip the fork-safety audit hook on CPython 3.10/3.11, where it broke
thread creation under coverage or a debugger.
4.0.2
- Fix OS lock leaks, double closes and false deadlocks from concurrent
acquire()/release() on thread_local=False locks.
- Async read-write locks give each asyncio task its own hold.
4.0.1
- Validate poll_interval at construction, on the setter and on acquire().
4.0.0 (breaking)
- SoftReadWriteLock uses a new on-disk generation-log protocol under
<path>.rw that earlier releases do not see; all participants on a lock
path must be upgraded together. It now requires os.link.
- SoftReadWriteLock exposes a generation fencing token, reports lost
holds through on_compromise, and no longer deadlocks when a holder on
another host dies mid-transition.
AI-Generated: Uses Claude Code
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
test_close_all_fds closes the socket through the IOLoop's shadow socket
and then reads s.closed. pyzmq implements that by calling
zmq_getsockopt() on the handle, which libzmq's reaper thread may already
have freed. With glibc the memory stays mapped, libzmq's tag check fails
and ENOTSOCK comes back; musl's allocator can unmap it, so the ptest run
segfaults intermittently and loses every result after it:
File ".../tests/test_future.py", line 319 in test_close_all_fds
Segmentation fault (core dumped)
Closing a socket via a shadow and then querying .closed on the original
segfaults on musl every time in a standalone reproducer and survives on
glibc. Skip the test for musl.
Tested with meta-python-image-ptest-python3-pyzmq on qemux86-64 with
yoe-musl-systemd-wayland.
AI-Generated: Uses Claude Code
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Upgrade to release 2.13.5:
- Allow reuse of validators when plugins are set
- Fix missing GC traversal on some pydantic-core struct fields
- Fix missing GC traversal in pydantic-core for
GeneralFieldsSerializer
- Count validated model fields once in smart unions
This work was sponsored by GOVCERT.LU.
Signed-off-by: Leon Anavi <leon.anavi@konsulko.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Upgrade to release 2.46.5 and keep all crates encapsulated in file
python3-pydantic-core-crates.inc. Drop the patch that enables
getrandom on all musl platforms because it has been merged in the
upstrea.
Release 2.46.5 brings the following changes:
- Fix missing GC traversal in pydantic-core for
GeneralFieldsSerializer
- Fix missing GC traversal on some pydantic-core struct fields
- Count validated model fields once in smart unions
This work was sponsored by GOVCERT.LU.
Signed-off-by: Leon Anavi <leon.anavi@konsulko.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Upgrade to release 0.16.8:
Bug fixes
- Visit functional TypedDict keyword arguments correctly
- [flake8-simplify] Detect nested async with under sync parent
(SIM117)
- [flake8-simplify] Preserve operand order in SIM109 fix
- [pyupgrade] Preserve required parentheses in multiline UP040
fixes
- [pyupgrade] Skip TypeVarTuple and ParamSpec conversions with
bounds or constraints (UP040, UP046, UP047)
Rule changes
- Add support for __lazy_modules__
- Recognize PEP-728 TypedDict class keywords
- Recognize quoted types in typing.TypeForm
- Support conditional assignment to __lazy_modules__
- [flake8-type-checking] Prefer lazy imports over TYPE_CHECKING on
Python 3.15 and later (TC001, TC002, TC003)
- [pyupgrade] Make the fix for UP040 always unsafe
- [pyupgrade] Stop recommending deprecated ByteString aliases
(UP035)
- [ruff, flake8-use-pathlib] Recognize the parent_mode argument
(RUF064, PTH103)
- [ruff] Detect \Z in pytest.raises() match patterns (RUF043)
This work was sponsored by GOVCERT.LU.
Signed-off-by: Leon Anavi <leon.anavi@konsulko.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Upgrade to release 3.1.0:
- Support for Python 3.8 was removed. The minimum supported version
is now Python 3.9.
- Support for MSVC 2017 has been dropped. #6110
- Changed strict-mode numeric conversions for PEP 484 compatibility:
float now accepts int, and complex now accepts int and float.
- Small extra features added to the pybind11 command line tool
based on python-config.
- Added subinterpreter_thread_state, an RAII wrapper that owns a
reusable PyThreadState for a sub-interpreter, together with a
subinterpreter_scoped_activate overload that activates it. This
lets an OS thread re-enter one or more sub-interpreters without
creating and destroying a PyThreadState on every activation.
- Add py::mod_gil_used() as replacement spelling to
py::mod_gil_not_used(false).
- Fixed a crash in py::subinterpreter::create() when called without
a current PyThreadState, which its documentation explicitly allows
- for example from an embedder that ended initialization with
PyEval_SaveThread(), or from a worker thread that has never
touched Python. error_scope is now constructed after a thread
state has been attached instead of before.
- Make py::print delegate to the current frame/interpreter built-ins
print entry, fixing handling of sys.stdout = None, following the
active runtime's stream, keyword, and error semantics, and
remaining a no-op if the entry is unavailable during teardown.
- Include the builtin complex type in the input annotation of the
std::complex<T> type caster.
- String views (e.g. std::string_view) are now kept alive only when
loaded from a transient source (such as a generator), fixing both
a use-after-free and a regression where casting a view from a
durable object outside a bound function would throw.
- Drop Python 2 prepend to evaluated source, causing errors to be
off by one.
- Fix data race on last_storage_ptr_ cache in
gil_safe_call_once_and_store.
- Allow user defined __str__ on enum_.
- Fix generated Callable type annotations for Python callbacks
passed into C++ by inverting the callback's argument/return I/O
context relative to the enclosing function signature.
- Correct __delitem__ for negative-step slices and re-enable
contiguous erase fast path.
- Do not pass -fno-fat-lto-objects to GCC on macOS, which made all
LTO probes fail and silently disabled LTO.
- Fixed cross-compilation to Emscripten/Pyodide with CMake >= 4.1
by no longer overriding an explicitly set
PYBIND11_USE_CROSSCOMPILING when CMAKE_CROSSCOMPILING_EMULATOR
is defined.
- Unset stale PYTHON_MODULE_DEBUG_POSTFIX and correct
USE_PYTHON_INCLUDE_DIR variable.
- Apply -undefined dynamic_lookup to all Apple platforms.
This work was sponsored by GOVCERT.LU.
Signed-off-by: Leon Anavi <leon.anavi@konsulko.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Upgrade to release 3.1.0:
- Python subclasses can now combine one nanobind base with
additional :ref:`Python mixins <python_mixins>`, including
cooperative super() calls on CPython and PyPy. Inheriting from
multiple nanobind bases remains unsupported.
- The low-level instance API gained
:cpp:func:`nb::inst_python_derived() <inst_python_derived>`,
which reports whether a nanobind instance belongs to a
Python subclass of the bound type.
- Added new low-level functions :cpp:func:`nb::keep_alive_obj()
<keep_alive_obj>` and :cpp:func:`nb::keep_alive_cb()
<keep_alive_cb>`, which expose the mechanism behind the
:cpp:class:`nb::keep_alive <keep_alive>` annotation.
- The new function :cpp:func:`intrusive_counter::ref_count()`
returns the reference count of an intrusively reference-counted
object while it is owned by C++.
- Fixed stale trampoline override caches on PyPy. Changing an
attribute of a nanobind type now correctly invalidates the caches
of its Python subclasses.
- The std::map/std::unordered_map and std::set type casters can now
also handle containers like std::flat_map whose iterators return
temporary values.
- The :ref:`Bazel documentation <bazel>` was rewritten and now
presents an approach based on the Bazel Central Registry.
- Miscellaneous minor improvements.
This work was sponsored by GOVCERT.LU.
Signed-off-by: Leon Anavi <leon.anavi@konsulko.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Upgrade to release 10.13.0.post1:
- Behavior change: pikepdf.DataDecodingError now derives from
pikepdf.PdfError. A stream that will not decode is a defect in
the document, and the same call that raises it -
Object.read_bytes() - already raised PdfError for other kinds of
damage, so except PdfError was a handler that looked correct,
passed on healthy files, and let a traceback escape on damaged
ones. Code catching DataDecodingError by name is unaffected. Code
that orders except PdfError before except DataDecodingError will
now take the first branch; if the distinction matters, reverse
the order.
- Behavior change: pikepdf.PdfParsingError now derives from
pikepdf.PdfError, for the same reason.
- pikepdf.PasswordError remains a sibling of PdfError, not a
subclass. A wrong password does not mean the document is
defective, and handlers that report the two separately depend on
except PdfError not catching it.
- pikepdf.NotExtractableError is now exported. It was already the
base class of the exported HifiPrintImageNotTranscodableError but
could not be caught by name.
- Fixed the exceptions documentation, which referenced a nonexistent
FormCopyWarning (the class is PageCopyWarning) and omitted
ReferenceCycleError, PageCopyWarning and NotExtractableError.
- XMP assigns a type to every standard property, and software that
reads XMP discards a property whose type is wrong - Ghostscript
strips these silently, and PDF/A validators reject them. pikepdf
used to choose the RDF container from the Python type of the
value it was handed, so meta['dc:subject'] = ['a', 'b'] wrote an
rdf:Seq where the specification requires an rdf:Bag, and
meta['dc:creator'] = 'Author' wrote a bare string where an
rdf:Seq belongs. pikepdf now knows the type of the properties in
the standard schemas and converts values to it.
This work was sponsored by GOVCERT.LU.
Signed-off-by: Leon Anavi <leon.anavi@konsulko.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Upgrade to release 2026.4:
- Canada's Northwest Territories moved to permanent -06 on
2026-08-21.
- Obsolescent settings like TZ="EST5EDT" now conform better to
POSIX.
- Fix security, performance and porting bugs in zic and localtime.
This work was sponsored by GOVCERT.LU.
Signed-off-by: Leon Anavi <leon.anavi@konsulko.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
The 1.3.3 snapshot on release/v1.3.x uses six in 68 files. Upstream has
removed six on main, so take a snapshot from there instead of carrying a
large local patch. main also replaces the cucumber-tag-expressions-only
matcher setup with cucumber-expressions and drops the tomli dependency
for Python 3.11 and newer.
Sent as RFC because main has not been released yet: its own version file
still says 1.4.0.dev0, so the version the recipe claims may still change
before upstream tags 1.4.0.
Built for intel-corei7-64.
AI-Generated: Uses Claude Code (Claude Opus 5)
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
cucumber-expressions provides the step-matcher expression parser that
behave requires from 1.4 onwards. Pure Python, no runtime dependencies
beyond the standard library, built with the uv backend that is already
used for python3-cucumber-tag-expressions.
Built for intel-corei7-64.
AI-Generated: Uses Claude Code (Claude Opus 5)
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Patch txdbus to use the dict methods, int, str, bytes indexing, next and
io.StringIO instead of the six helpers, and drop the runtime dependency.
Built for intel-corei7-64.
AI-Generated: Uses Claude Code (Claude Opus 5)
Signed-off-by: Markus Volk <f_l_k@t-online.de>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Patch transitions to use the Python 3 equivalents of the six helpers and
drop the runtime dependency.
Built for intel-corei7-64.
AI-Generated: Uses Claude Code (Claude Opus 5)
Signed-off-by: Markus Volk <f_l_k@t-online.de>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Patch smpplib to use dict.items, a bytes literal and a latin-1 encode
instead of six.iteritems, six.int2byte and six.b, and drop the runtime
dependency.
Built for intel-corei7-64.
AI-Generated: Uses Claude Code (Claude Opus 5)
Signed-off-by: Markus Volk <f_l_k@t-online.de>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Patch slip to use the metaclass keyword argument in the class statement
instead of six.with_metaclass, and drop the runtime dependency.
Built for intel-corei7-64.
AI-Generated: Uses Claude Code (Claude Opus 5)
Signed-off-by: Markus Volk <f_l_k@t-online.de>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
qface declares six in install_requires but does not import it anywhere.
Patch it out and drop the dependency from the recipe.
Built for intel-corei7-64.
AI-Generated: Uses Claude Code (Claude Opus 5)
Signed-off-by: Markus Volk <f_l_k@t-online.de>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Patch pyu2f to use queue, range and the input builtin instead of the
six.moves aliases, and drop the runtime dependency.
Built for intel-corei7-64.
AI-Generated: Uses Claude Code (Claude Opus 5)
Signed-off-by: Markus Volk <f_l_k@t-online.de>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
pyperf no longer uses six at build time; the native dependency is stale.
Built for intel-corei7-64.
AI-Generated: Uses Claude Code (Claude Opus 5)
Signed-off-by: Markus Volk <f_l_k@t-online.de>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
pymemcache no longer uses six at build time; the native dependency is
stale.
Built for intel-corei7-64.
AI-Generated: Uses Claude Code (Claude Opus 5)
Signed-off-by: Markus Volk <f_l_k@t-online.de>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
pathlib2 is a backport of the Python 3 pathlib module for Python 2 and
early Python 3, and it pulls in six. Nothing in the layers depends on it
any more, so drop it rather than carry a Python 2 compatibility package.
Verified that no recipe references python3-pathlib2.
AI-Generated: Uses Claude Code (Claude Opus 5)
Signed-off-by: Markus Volk <f_l_k@t-online.de>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Patch parse_type to use str instead of six.string_types and drop six from
the requirement lists and from the ptest dependencies.
Built for intel-corei7-64.
AI-Generated: Uses Claude Code (Claude Opus 5)
Signed-off-by: Markus Volk <f_l_k@t-online.de>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
nocaselist has not imported six since the 2.x series; the runtime
dependency is stale.
Built for intel-corei7-64.
AI-Generated: Uses Claude Code (Claude Opus 5)
Signed-off-by: Markus Volk <f_l_k@t-online.de>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
nocasedict has not imported six since the 2.x series; the runtime
dependency is stale.
Built for intel-corei7-64.
AI-Generated: Uses Claude Code (Claude Opus 5)
Signed-off-by: Markus Volk <f_l_k@t-online.de>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Patch jsonpath-rw to use int, str and range instead of six.integer_types,
six.string_types and six.moves.xrange, and drop the runtime dependency.
Built for intel-corei7-64.
AI-Generated: Uses Claude Code (Claude Opus 5)
Signed-off-by: Markus Volk <f_l_k@t-online.de>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Patch ecdsa to use the Python 3 equivalents of the six helpers and drop
the runtime dependency.
Built for intel-corei7-64.
AI-Generated: Uses Claude Code (Claude Opus 5)
Signed-off-by: Markus Volk <f_l_k@t-online.de>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>