hi-ml icon indicating copy to clipboard operation
hi-ml copied to clipboard

Bump numpy from 1.21.6 to 1.22.0 in /hi-ml-cpath

Open dependabot[bot] opened this issue 2 years ago • 8 comments

Bumps numpy from 1.21.6 to 1.22.0.

Release notes

Sourced from numpy's releases.

v1.22.0

NumPy 1.22.0 Release Notes

NumPy 1.22.0 is a big release featuring the work of 153 contributors spread over 609 pull requests. There have been many improvements, highlights are:

  • Annotations of the main namespace are essentially complete. Upstream is a moving target, so there will likely be further improvements, but the major work is done. This is probably the most user visible enhancement in this release.
  • A preliminary version of the proposed Array-API is provided. This is a step in creating a standard collection of functions that can be used across application such as CuPy and JAX.
  • NumPy now has a DLPack backend. DLPack provides a common interchange format for array (tensor) data.
  • New methods for quantile, percentile, and related functions. The new methods provide a complete set of the methods commonly found in the literature.
  • A new configurable allocator for use by downstream projects.

These are in addition to the ongoing work to provide SIMD support for commonly used functions, improvements to F2PY, and better documentation.

The Python versions supported in this release are 3.8-3.10, Python 3.7 has been dropped. Note that 32 bit wheels are only provided for Python 3.8 and 3.9 on Windows, all other wheels are 64 bits on account of Ubuntu, Fedora, and other Linux distributions dropping 32 bit support. All 64 bit wheels are also linked with 64 bit integer OpenBLAS, which should fix the occasional problems encountered by folks using truly huge arrays.

Expired deprecations

Deprecated numeric style dtype strings have been removed

Using the strings "Bytes0", "Datetime64", "Str0", "Uint32", and "Uint64" as a dtype will now raise a TypeError.

(gh-19539)

Expired deprecations for loads, ndfromtxt, and mafromtxt in npyio

numpy.loads was deprecated in v1.15, with the recommendation that users use pickle.loads instead. ndfromtxt and mafromtxt were both deprecated in v1.17 - users should use numpy.genfromtxt instead with the appropriate value for the usemask parameter.

(gh-19615)

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page.

dependabot[bot] avatar Jul 19 '22 21:07 dependabot[bot]

Codecov Report

Merging #526 (a9ba49b) into main (0d66cec) will not change coverage. The diff coverage is n/a.

Impacted file tree graph

Flag Coverage Δ
hi-ml-cpath 77.39% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

codecov[bot] avatar Jul 19 '22 21:07 codecov[bot]

I wonder why Dependabot is trying to upgrade NumPy. I thought the settings are only for GitHub actions...

fepegar avatar Aug 03 '22 08:08 fepegar

I wonder why Dependabot is trying to upgrade NumPy. I thought the settings are only for GitHub actions...

Dependabot tries to help us keep all dependencies up to date (see here). We could change this in .github/dependabot.yml if we don't want to be alerted of potential updates

mebristo avatar Aug 03 '22 09:08 mebristo

I thought this would make it look only at the GHAs versions:

https://github.com/microsoft/hi-ml/blob/c73103a0755bacdf2f6627e522167c5066f0fc54/.github/dependabot.yml#L6

fepegar avatar Aug 03 '22 09:08 fepegar

I wonder why Dependabot is trying to upgrade NumPy. I thought the settings are only for GitHub actions...

There is a security alert for numpy. There is a string comparison bug in our current version. Check the security tab.

javier-alvarez avatar Sep 01 '22 13:09 javier-alvarez

Our Python version is too old in the failing test:

ERROR: Ignored the following versions that require a different python version: 1.22.0 Requires-Python >=3.8

Any suggestions?

fepegar avatar Sep 01 '22 15:09 fepegar

Related:

  • https://github.com/microsoft/hi-ml/pull/484
  • https://github.com/microsoft/hi-ml/pull/446

Have we considered moving to Python 3.9 instead of jumping to 3.10 directly?

fepegar avatar Sep 01 '22 15:09 fepegar

@fepegar , good point about jumping to 3.9, will get going with that.

ant0nsc avatar Sep 02 '22 08:09 ant0nsc

Superseded by #589

ant0nsc avatar Sep 06 '22 08:09 ant0nsc

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

dependabot[bot] avatar Sep 06 '22 08:09 dependabot[bot]