[PATCH] packaging: update dulwich to drop the certifi dependency (fixes #5825)

5 views
Skip to first unread message

Matt Harbison

unread,
Sep 6, 2022, 2:53:26 PM9/6/22
to thg...@googlegroups.com
# HG changeset patch
# User Matt Harbison <matt_h...@yahoo.com>
# Date 1662481453 14400
# Tue Sep 06 12:24:13 2022 -0400
# Branch stable
# Node ID 3f839cf2b0679987211178f91f97ee76b44d8c1c
# Parent 2418587e8fd5c314a79c52408744476155e1ea93
packaging: update dulwich to drop the certifi dependency (fixes #5825)

This version of `dulwich` raises the minimum `urllib3` to a version (1.25) that
does certificate verification by default, without the help of `certifi`[1]. We
already bundle a newer version of `urllib3`. The other `dulwich` references are
for py2 builds.

[1] https://github.com/jelmer/dulwich/issues/1025

diff --git a/contrib/packaging/requirements-windows-pyqt5-installer.txt b/contrib/packaging/requirements-windows-pyqt5-installer.txt
--- a/contrib/packaging/requirements-windows-pyqt5-installer.txt
+++ b/contrib/packaging/requirements-windows-pyqt5-installer.txt
@@ -8,10 +8,6 @@
--hash=sha256:486471dfa8799eb7ec503a8059e263db000cdda20075ce5e48903087f79d5fd6 \
--hash=sha256:8fecd4203a38af17928be7b90689d8083603073622229ca7077b72d8e5a976e4
# via py2exe
-certifi==2022.6.15 \
- --hash=sha256:84c85a9078b11105f04f3036a9482ae10e4621616db313fe045dd24743a0820d \
- --hash=sha256:fe86415d55e84719d75f8b69414f6438ac3547d2078ab91b67e779ef69378412
- # via dulwich
cffi==1.15.0 \
--hash=sha256:00c878c90cb53ccfaae6b8bc18ad05d2036553e6d9d1d9dbcf323bbe83854ca3 \
--hash=sha256:0104fb5ae2391d46a4cb082abdd5c69ea4eab79d8d44eaaf79f1b1fd806ee4c2 \
@@ -68,28 +64,38 @@
--hash=sha256:5c4c4832dce61de44b956c8cfafcca7e94f5016d564632c2b25846e88820c7f8 \
--hash=sha256:bc4fd1c20bdd960cdf1763020c0480332c2382f70260aa424fc019f5ce27263b
# via -r contrib/packaging/venv_py3/requirements_win32.txt.in
-dulwich==0.20.44 \
- --hash=sha256:0a227684997f94518de53041503f4d467ef711319a09b85479a564c751ced65c \
- --hash=sha256:0e324240007fb2bb5f8c2b92244146cc02a8c451890e3b75257dbc1b14e4fe93 \
- --hash=sha256:10e8d73763dd30c86a99a15ade8bfcf3ab8fe96532cdf497e8cb1d11832352b8 \
- --hash=sha256:29f56137a686e956dfa84242f12a79f2c13a0f0840646884de230f3ad07ccc50 \
- --hash=sha256:2f6e35487963296894f2a2fcc49cc1340c24592ea465962f96a33f1527afd3f7 \
- --hash=sha256:45a069407630b60d85345da9c9bed07fe9a3d0b55fc3705815ddac1f31ce97be \
- --hash=sha256:46273dd4b6fc80f7bd3cdfe35ed1e7ed5cbd9850735b12b1a64f81058f337351 \
- --hash=sha256:4784e480c6368e1199e5292aca558455b65dbc1b5b0f06341e5702041c5e275a \
- --hash=sha256:496fa0298285d5e442e858d742ed3fc721a15452b736a03c89124acd08f169a7 \
- --hash=sha256:5f9130827f89bbf013fa169d25fc113503e6536e2759b246db086300bf0caf05 \
- --hash=sha256:61eb4633410ed7e6b49a0ce0f0a4a0604206fc1532ea119b948ff3cf974a0d02 \
- --hash=sha256:63bdfc0b8d762b66053f3dadbbb4b57ac65d201b9863140b6aefc742a4c94814 \
- --hash=sha256:68e46a462d7686f440ef849947b7284412a2715e084090c8f5624d871758bf98 \
- --hash=sha256:6aa185f04dfba6ab15c36c06ff5f0e8b44f05268011699c25e18b320a76d2d3f \
- --hash=sha256:6ac93e78eb19f65d958e339818316af07579cdf826257562d3f7310d7535d205 \
- --hash=sha256:a6a224c28aa47e960c0fa388ad7acc93346bf36cc8bae6f7b4524b14b0c30b7a \
- --hash=sha256:cbe9c167f3a591ac308a8dd54eef901db42cb898dd7f343479ef3badec4b96cc \
- --hash=sha256:d18029b40faa09848cb9a9e5a1b5fcc5365f0c959e9fcb3ec63ec78720dfe5e1 \
- --hash=sha256:d97c739bfa8b99dfe40075b5928b16224aa22d739cba57855cccb4d8ee325654 \
- --hash=sha256:e7a884dd92bbfe66e4662a71d302b22b7910cc694d45f6e32acd1ae5da877183 \
- --hash=sha256:f6d9822ce617de1836256808f43dceb80fb343d634d28aef170e87ca47176f83
+dulwich==0.20.46 \
+ --hash=sha256:0a1ca555a3eafe7388d6cb81bb08f34608a1592500f0bd4c26734c91d208a546 \
+ --hash=sha256:100d39bc18196a07c521fd5f60f78f397493303daa0b8690216864bbc621cd5d \
+ --hash=sha256:1162fdafb2abdfe66649617061f3853cb26384fade1f6884f6fe6e9c570a7552 \
+ --hash=sha256:153c7512587384a290c60fef330f1ab397a59559e19e8b02a0169ff21b4c69fb \
+ --hash=sha256:3e16376031466848e44aabf3489fafb054482143744b21167dbd168731041c74 \
+ --hash=sha256:42fa5a68908556eb6c40f231a67caf6a4660588aad707a9d6b334fa1d8f04bf7 \
+ --hash=sha256:4f0e88ffff5db1523d93d92f1525fe5fa161318ffbaad502c1b9b3be7a067172 \
+ --hash=sha256:525115c4d1fbf60a5fe98f340b4ca597ba47b2c75d9c5ec750dd0e9115ef8ec6 \
+ --hash=sha256:6676196e9cf377cde62aa2f5d741e93207437343e0c62368bd0d784c322a3c49 \
+ --hash=sha256:669c6b3d82996518a7fec4604771bd285e23f0860f41f565fef5987265d431d9 \
+ --hash=sha256:6826512f778eaa47e2e8c0a46cdc555958f9f5286771490b8642b4b508ea5d25 \
+ --hash=sha256:6eed5a3194d64112605fc0f638f4fa91771495e8674fa3e6d6b33bf150d297d5 \
+ --hash=sha256:73e2585a9fcf1f8cdad8597a0c384c0b365b2e8346463130c96d9ea1478587ae \
+ --hash=sha256:769442c9657b10fc35ac625beeaf440540c9288c96fcfaba3e58adf745c5cafd \
+ --hash=sha256:8d6fee82cedb2362942d9ef94061901f7e07d7d8674e4c7b6fceeef7822ae275 \
+ --hash=sha256:90a075aeb0fdbad7e18b9db3af161e3d635e2b7697b7a4b467e6844a13b0b210 \
+ --hash=sha256:92024f572d32680e021219f77015c8b443c38022e502b7f51ad7cf51a6285a36 \
+ --hash=sha256:9ca4d73987f5b0e2e843497876f9bb39a47384a2e50597a85542285f5c890293 \
+ --hash=sha256:9fc7a4f633f5468453d5dd84a753cd99d4433f0397437229a0a8b10347935591 \
+ --hash=sha256:a5b68bd815cd2769c75e5a78708eb0440612df19b370a977aa9e01a056baa9ed \
+ --hash=sha256:a5d1b7a3a7d84a5dedbb90092e00097357106b9642ac08a96c2ae89ccd8afd9a \
+ --hash=sha256:b1339bca70764eb8e780d80c72e7c1cb4651201dc9e43ec5d616bf51eb3bb3a6 \
+ --hash=sha256:b739d759c10e2af7c964dcc97fd4e5dc49e8567d080eed8906fc422c79b7fdcf \
+ --hash=sha256:b9f49de83911eed7adbe83136229837ef9d102e42dbe6aacb1a18be45c997ace \
+ --hash=sha256:c4cd2cd7baa81246bdc8c5272d4e9224e2255da7a0618a220aab5e07b9888e9b \
+ --hash=sha256:d38be7d3a78d608ecab3348f7920d6b9002e7972dd245206dc8075cfdb91621d \
+ --hash=sha256:d928de1eba0326a2a8a52ed94c9bf7c315ff4db606a1aa3ae688d39574f93267 \
+ --hash=sha256:dd3eac228117487a959ac8f49ea2787eac34acc69999fe7adae70b23e3c3571c \
+ --hash=sha256:de22a54f68c6c4e97f9b924abd46da4618536d7934b9849066be9fc5cd31205d \
+ --hash=sha256:f4b7a7feb966a4669c254b18385fe0b3c639f3b1f5ddef0d9e083364cc762847 \
+ --hash=sha256:f9552ac246bceab1c5cdd1ec3cfe9446fe76b9853eaf59d3244df03eb27fd3fe
# via hg-git
future==0.18.2 \
--hash=sha256:b1bead90b70cf6ec3f0710ae53a525360fa360d306a86583adc6bf83a4db537d

Yuya Nishihara

unread,
Sep 6, 2022, 9:00:45 PM9/6/22
to Matt Harbison, thg...@googlegroups.com
On Tue, 06 Sep 2022 14:53:23 -0400, Matt Harbison wrote:
> # HG changeset patch
> # User Matt Harbison <matt_h...@yahoo.com>
> # Date 1662481453 14400
> # Tue Sep 06 12:24:13 2022 -0400
> # Branch stable
> # Node ID 3f839cf2b0679987211178f91f97ee76b44d8c1c
> # Parent 2418587e8fd5c314a79c52408744476155e1ea93
> packaging: update dulwich to drop the certifi dependency (fixes #5825)

Queued for stable, thanks.
Reply all
Reply to author
Forward
0 new messages