dependabot[bot] opened a new pull request, #20187:
URL: https://github.com/apache/nuttx/pull/20187

   Bumps [anyio](https://github.com/agronholm/anyio) from 4.14.0 to 4.14.2.
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/agronholm/anyio/releases";>anyio's 
releases</a>.</em></p>
   <blockquote>
   <h2>4.14.2</h2>
   <ul>
   <li>Changed <code>ByteReceiveStream.receive()</code> implementations to 
raise a <code>ValueError</code> when <code>max_bytes</code> is not a positive 
integer (<a 
href="https://redirect.github.com/agronholm/anyio/pull/1191";>#1191</a>)</li>
   <li>Fixed <code>CapacityLimiter.total_tokens</code> rejecting 
<code>float(&quot;inf&quot;)</code> when the limiter was instantiated outside 
of an event loop. The adapter setter checked for infinity by identity 
(<code>value is math.inf</code>), so only the exact <code>math.inf</code> 
singleton was accepted, while every backend setter (using 
<code>math.isinf()</code>) accepts any positive infinity (<a 
href="https://redirect.github.com/agronholm/anyio/pull/1189";>#1189</a>; PR by 
<a href="https://github.com/greymoth-jp";><code>@​greymoth-jp</code></a>).</li>
   <li>Fixed <code>to_process.run_sync()</code> deadlocking when the worker 
function writes enough data to <code>sys.stderr</code> to fill the (undrained) 
pipe buffer. The worker process now redirects <code>sys.stderr</code> to 
<code>os.devnull</code> as well, matching the documented behavior</li>
   <li>Fixed <code>TLSStream.wrap()</code> matching an internationalized 
(unicode) host name against the peer certificate using IDNA 2003 (via the 
standard library) instead of IDNA 2008, which could cause the host name to be 
matched against the wrong certificate (<a 
href="https://redirect.github.com/agronholm/anyio/pull/1208";>#1208</a>)</li>
   <li>Fixed <code>anyio.open_process()</code> (and <code>run_process()</code>) 
ignoring the <code>extra_groups</code> argument, as it mistakenly passed the 
value of the <code>group</code> argument instead (<a 
href="https://redirect.github.com/agronholm/anyio/pull/1209";>#1209</a>)</li>
   <li>Fixed <code>CapacityLimiter.acquire_nowait()</code> and 
<code>CapacityLimiter.acquire_nowait_on_behalf_of()</code> raising 
<code>trio.WouldBlock</code> instead of <code>anyio.WouldBlock</code> on the 
<code>trio</code> backend when there are no tokens available (<a 
href="https://redirect.github.com/agronholm/anyio/pull/1218";>#1218</a>)</li>
   <li>Fixed <code>CapacityLimiter</code> on the asyncio backend over-granting 
tokens (<code>borrowed_tokens</code> exceeding <code>total_tokens</code> and 
<code>available_tokens</code> going negative) when a non-blocking acquire was 
made in the window between a token being released and the notified waiter 
resuming. The freed token is now reserved for the woken waiter right away, so 
the non-blocking acquire correctly raises <code>WouldBlock</code> (<a 
href="https://redirect.github.com/agronholm/anyio/issues/1170";>#1170</a>; PR by 
<a href="https://github.com/gaoflow";><code>@​gaoflow</code></a>)</li>
   <li>Fixed unnecessary CPU spin when delivering cancellation from 
<code>CancelScope</code> on asyncio under certain conditions, including 
improper cancel scope nesting (<a 
href="https://redirect.github.com/agronholm/anyio/issues/1111";>#1111</a>)</li>
   </ul>
   <h2>4.14.1</h2>
   <ul>
   <li>Fixed teardown of higher-scoped async fixtures failing on asyncio with 
<code>RuntimeError: Attempted to exit cancel scope in a different task than it 
was entered in</code> when an async test raise an outcome exception (e.g., 
<code>pytest.skip()</code>, <code>pytest.xfail()</code>, or 
<code>pytest.fail()</code>) (<a 
href="https://redirect.github.com/agronholm/anyio/issues/1179";>#1179</a>; PR by 
<a 
href="https://github.com/EmmanuelNiyonshuti";><code>@​EmmanuelNiyonshuti</code></a>)</li>
   <li>Fixed <code>CapacityLimiter.total_tokens</code> rejecting a value of 
<code>0</code> when the limiter was instantiated outside of an event loop, 
contradicting the documented behavior of allowing 0 total tokens (<a 
href="https://redirect.github.com/agronholm/anyio/pull/1183";>#1183</a>; PR by 
<a href="https://github.com/nyxst4ck";><code>@​nyxst4ck</code></a>)</li>
   </ul>
   </blockquote>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/agronholm/anyio/commit/c384f99687c64c59ed8a11c3a0f11a2d57daff71";><code>c384f99</code></a>
 Bumped up the version</li>
   <li><a 
href="https://github.com/agronholm/anyio/commit/dbba29d1ade7936f18fb71ba24aa92978673482a";><code>dbba29d</code></a>
 Fixed 100% CPU spin on cancel scope misuse (<a 
href="https://redirect.github.com/agronholm/anyio/issues/1217";>#1217</a>)</li>
   <li><a 
href="https://github.com/agronholm/anyio/commit/6bbc6c33caabc13af5bc4256f745027cf8d5d7b8";><code>6bbc6c3</code></a>
 Fix CapacityLimiter over-granting tokens on asyncio (<a 
href="https://redirect.github.com/agronholm/anyio/issues/1172";>#1172</a>)</li>
   <li><a 
href="https://github.com/agronholm/anyio/commit/6f82b2537cbbe98f3df3f295499056ab7de0b15b";><code>6f82b25</code></a>
 Refactored TestTLSStream.test_receive_invalid_max_bytes() to be less flaky</li>
   <li><a 
href="https://github.com/agronholm/anyio/commit/be24b0414f67f604bcbdd5ea3bcc56ab920d872e";><code>be24b04</code></a>
 Relaxed timeouts to fix test flakiness</li>
   <li><a 
href="https://github.com/agronholm/anyio/commit/81135065749b4f60c06619b9caaf0a11871c1ddf";><code>8113506</code></a>
 Fix test flakiness caused by slow callback duration logging</li>
   <li><a 
href="https://github.com/agronholm/anyio/commit/1e988b617b69588e33fecb75e36a9837245f562f";><code>1e988b6</code></a>
 Fixed CapacityLimiter raising trio.WouldBlock instead of anyio.WouldBlock (<a 
href="https://redirect.github.com/agronholm/anyio/issues/1";>#1</a>...</li>
   <li><a 
href="https://github.com/agronholm/anyio/commit/44713f345cd29dd4e7d76553c134543a1296cc62";><code>44713f3</code></a>
 Pin setup-uv to a commit sha across downstream jobs (<a 
href="https://redirect.github.com/agronholm/anyio/issues/1213";>#1213</a>)</li>
   <li><a 
href="https://github.com/agronholm/anyio/commit/f1b7301c8264b0d2e8d24a5788fd29e93dea4040";><code>f1b7301</code></a>
 Fixed stderr writes in a worker subprocess causing a deadlock (<a 
href="https://redirect.github.com/agronholm/anyio/issues/1207";>#1207</a>)</li>
   <li><a 
href="https://github.com/agronholm/anyio/commit/212be93c2cf2c841e753e95e5e2c543ee7feca90";><code>212be93</code></a>
 Fix flaky test_tcp_listener_same_port using a hardcoded port (<a 
href="https://redirect.github.com/agronholm/anyio/issues/1206";>#1206</a>)</li>
   <li>Additional commits viewable in <a 
href="https://github.com/agronholm/anyio/compare/4.14.0...4.14.2";>compare 
view</a></li>
   </ul>
   </details>
   <br />
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=anyio&package-manager=pip&previous-version=4.14.0&new-version=4.14.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot show <dependency name> ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   You can disable automated security fix PRs for this repo from the [Security 
Alerts page](https://github.com/apache/nuttx/network/alerts).
   
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to