Commit Graph

9774 Commits

Author SHA1 Message Date
Sebastian Rittau
f266dc226a Change RawIOBase return types from None to MaybeNone (#12686) 2024-10-02 07:11:23 -07:00
Robsdedude
e05f3f083f Fix: pytz: is_dst parameter (#12723) 2024-10-02 13:11:12 +02:00
Stephen Morton
719ddd1774 move re.error into re.pyi (#11188) 2024-10-02 11:26:44 +02:00
Sebastian Rittau
6ba6589144 Support environment markers in requires fields (#12711) 2024-10-02 10:14:33 +02:00
Jelle Zijlstra
213ca9eb81 Update vobject (#12721) 2024-10-02 08:27:21 +01:00
renovate[bot]
481230077b Update dependency pyright to v1.1.383 (#12722)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2024-10-02 07:33:36 +01:00
Pradeep Kumar
b54dcc6783 [str] Add LiteralString overload for __getitem__ (#12714)
In PEP 675, Graham Bleaney and I had specified a list of `LiteralString`-preserving [overloads](https://peps.python.org/pep-0675/#appendix-c-str-methods-that-preserve-literalstring) for `str`. However, we didn't specify an overload for `__getitem__` and didn't give any rationale either. IIRC this was an edge case we didn't want to take a strong decision on unless users wanted it.

Carl Meyer brought this up yesterday, so I think it's worth discussing.

Pro: `my_literal_string[i]` or `my_literal_string[i:j]` should technically be compatible with `LiteralString`, since it is a substring of a literal-derived string.

Con: The main downside is that an attacker might control the indexes and try to access a specific substring from a literal string in the code. For example, they might narrow down the string to `rm foo` or `SELECT *`.

It's true that `join` and other methods could also construct dangerous strings from `LiteralString`s, and we even call that out as an accepted tradeoff in the PEP:

> 4. Trivial functions could be constructed to convert a str to a LiteralString:
>
>     def make_literal(s: str) -> LiteralString:
>         letters: Dict[str, LiteralString] = {
>             "A": "A",
>             "B": "B",
>             ...
>         }
>         output: List[LiteralString] = [letters[c] for c in s]
>         return "".join(output)
>
> We could mitigate the above using linting, code review, etc., but ultimately a clever, malicious developer attempting to circumvent the protections offered by LiteralString will always succeed. The important thing to remember is that LiteralString is not intended to protect against malicious developers; it is meant to protect against benign developers accidentally using sensitive APIs in a dangerous way (without getting in their way otherwise).
>
> Without LiteralString, the best enforcement tool API authors have is documentation, which is easily ignored and often not seen. With LiteralString, API misuse requires conscious thought and artifacts in the code that reviewers and future developers can notice.
>
> -- [PEP 675 - Appendix B: Limitations](https://peps.python.org/pep-0675/#appendix-b-limitations)

`__getitem__`, however, seems a bit different, because it (and `split`, `zfill`, etc.) accept an index or width that could be used to construct a dangerous query or a humongous string. So, we need to clarify the intent a little.

What was the intent of these overloads? We wanted to forbid "arbitrary user-supplied strings" while allowing methods that preserved literal strings. We were not trying to prevent every possible exploit on the string. Since `__getitem__` forbids arbitrary user-supplied strings and preserves literal strings, I think we should add an overload for it.
2024-10-01 20:29:00 -07:00
Stephen Morton
4f37d8fff8 add _ssl module (#11155)
Really all I needed for fixing the inheritance was _ssl._SSLContext.
But then I needed all the other stuff in _ssl, and if I was doing that
I wanted to do a thorough job of it.

Motivation was originally related to https://github.com/python/typeshed/issues/3968 ,
but we're well beyond that now, really.

Co-authored-by: Jelle Zijlstra <jelle.zijlstra@gmail.com>
2024-10-01 20:10:51 -07:00
Stephen Morton
c43894568f resort weakref classes (#11165)
This improves fidelity of naming and inheritance on 3.11+

related to https://github.com/python/typeshed/issues/3968 and https://github.com/python/typeshed/issues/11141

Co-authored-by: Jelle Zijlstra <jelle.zijlstra@gmail.com>
2024-10-01 19:50:10 -07:00
Stephen Morton
6bc1884577 follow implementation more closely in zoneinfo (#11189)
Co-authored-by: Alex Waygood <Alex.Waygood@Gmail.com>
Co-authored-by: Jelle Zijlstra <jelle.zijlstra@gmail.com>
2024-10-01 19:49:01 -07:00
github-actions[bot]
e9c7346b0e [stubsabot] Bump reportlab to 4.2.5 (#12719)
Release: https://pypi.org/pypi/reportlab/4.2.5
Homepage: https://www.reportlab.com/
Repository: https://github.com/MrBitBucket/reportlab-mirror
Typeshed stubs: https://github.com/python/typeshed/tree/main/stubs/reportlab

If stubtest fails for this PR:
- Leave this PR open (as a reminder, and to prevent stubsabot from opening another PR)
- Fix stubtest failures in another PR, then close this PR

Note that you will need to close and re-open the PR in order to trigger CI

Co-authored-by: stubsabot <>
2024-10-01 18:50:57 -07:00
github-actions[bot]
a1088d09b0 [stubsabot] Bump qrcode to 8.0.* (#12718)
Release: https://pypi.org/pypi/qrcode/8.0
Homepage: https://github.com/lincolnloop/python-qrcode
Repository: https://github.com/lincolnloop/python-qrcode
Typeshed stubs: https://github.com/python/typeshed/tree/main/stubs/qrcode
Diff: https://github.com/lincolnloop/python-qrcode/compare/v7.4.2...v8.0

Stubsabot analysis of the diff between the two releases:
 - 2 public Python files have been added: `qrcode/compat/png.py`, `qrcode/tests/consts.py`.
 - 0 files included in typeshed's stubs have been deleted.
 - 12 files included in typeshed's stubs have been modified or renamed.
 - Total lines of Python code added: 669.
 - Total lines of Python code deleted: 727.

If stubtest fails for this PR:
- Leave this PR open (as a reminder, and to prevent stubsabot from opening another PR)
- Fix stubtest failures in another PR, then close this PR

Note that you will need to close and re-open the PR in order to trigger CI

Co-authored-by: stubsabot <>
2024-10-01 18:50:48 -07:00
Stephen Morton
ddb57608fd move pyexpat.ExpatError to xml.parsers.expat.ExpatError (#11168)
This matches the name reported by the cass at runtime.

related to https://github.com/python/typeshed/issues/11141

Co-authored-by: Jelle Zijlstra <jelle.zijlstra@gmail.com>
2024-10-01 18:45:11 -07:00
Avasam
bdb5b52d50 Make multiprocessing pipes generic (#11137) 2024-10-01 18:11:42 -07:00
renovate[bot]
44aa63330b Update most test/lint dependencies (#12713) 2024-10-01 14:38:01 +02:00
DinhHuy2010
1c96234848 add stubs for m3u8 (#12683) 2024-10-01 14:05:59 +02:00
github-actions[bot]
302e83f003 [stubsabot] Bump Flask-SocketIO to 5.4.* (#12712)
Release: https://pypi.org/pypi/Flask-SocketIO/5.4.0
Homepage: https://github.com/miguelgrinberg/flask-socketio
Repository: https://github.com/miguelgrinberg/flask-socketio
Typeshed stubs: https://github.com/python/typeshed/tree/main/stubs/Flask-SocketIO
Diff: https://github.com/miguelgrinberg/flask-socketio/compare/v5.3.7...v5.4.0

Stubsabot analysis of the diff between the two releases:
 - Total lines of Python code added: 40.
 - Total lines of Python code deleted: 11.

If stubtest fails for this PR:
- Leave this PR open (as a reminder, and to prevent stubsabot from opening another PR)
- Fix stubtest failures in another PR, then close this PR

Note that you will need to close and re-open the PR in order to trigger CI

Co-authored-by: stubsabot <>
2024-10-01 09:23:44 +01:00
Dima Tisnek
c47650323e fix: correct headers= kwarg in HTTP[S]Connection (#12704) 2024-10-01 08:59:46 +02:00
Sebastian Rittau
91a58b07cd Amend third-party removal policy (#12710)
Upstream annotations should have a similar standard as typeshed's.
2024-09-30 22:04:29 +02:00
Sebastian Rittau
3b385903a1 Pass Requirement objects around (#12709)
This allows us to keep metadata like python_version and platform_system
and use it to conditionally install packages.
2024-09-30 17:45:58 +02:00
Semyon Pupkov
06b50fcc27 Fix yeardatescalendar, yeardays2calendar, yeardayscalendar return types (#12703) 2024-09-30 13:47:49 +02:00
Sebastian Rittau
7ce17a95f6 Document to stubtest_requirements field in the proper place. (#12707) 2024-09-30 13:46:48 +02:00
Victorien
db265afec5 Use Mapping for local Python namespace parameters (#12705) 2024-09-30 11:26:41 +02:00
David Salvisberg
6990bb64a9 Bump reportlab to 4.2.4 (#12701) 2024-09-29 13:35:05 +02:00
renovate[bot]
119cd09655 Update dependency pyright to v1.1.382.post1 (#12699)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2024-09-27 17:34:39 -07:00
Jinzhe Zeng
d828a5ef92 paramiko: add ProxyCommand to _SocketLike (#12697) 2024-09-27 22:36:10 +02:00
Matthias Schoettle
283ff95ea0 [fpdf2] fix link type to support internal links (#12695) 2024-09-26 20:56:54 +02:00
renovate[bot]
5a89c481dc Update dependency pyright to v1.1.382.post0 (#12692)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2024-09-26 20:33:59 +02:00
github-actions[bot]
a94c927642 [stubsabot] Bump braintree to 4.30.* (#12681)
Release: https://pypi.org/pypi/braintree/4.30.0
Homepage: https://developer.paypal.com/braintree/docs/reference/overview
Repository: https://github.com/braintree/braintree_python
Typeshed stubs: https://github.com/python/typeshed/tree/main/stubs/braintree
Diff: https://github.com/braintree/braintree_python/compare/4.29.0...4.30.0

Stubsabot analysis of the diff between the two releases:
 - 0 public Python files have been added.
 - 0 files included in typeshed's stubs have been deleted.
 - 4 files included in typeshed's stubs have been modified or renamed: `braintree/error_codes.py`, `braintree/transaction.py`, `braintree/version.py`, `braintree/webhook_testing_gateway.py`.
 - Total lines of Python code added: 317.
 - Total lines of Python code deleted: 278.
2024-09-24 23:08:38 -07:00
Akuli
13a74a5211 Update tkinter.Text.count() for Python 3.13 (Akuli's version) (#12629) 2024-09-24 23:08:11 -07:00
kasium
6cddd30ff2 Add basic jwcrypto stubs (#12687) 2024-09-24 10:30:58 +02:00
Alex Waygood
9f033bf439 Fixup some pyright CI configuration details (#12690) 2024-09-23 13:07:57 -07:00
github-actions[bot]
bfaa3d2d5a [stubsabot] Bump hdbcli to 2.22.* (#12676)
Co-authored-by: stubsabot <>
2024-09-23 12:15:59 -07:00
github-actions[bot]
4fc5d158ff [stubsabot] Bump greenlet to 3.1.* (#12636)
Co-authored-by: stubsabot <>
2024-09-23 12:15:48 -07:00
Avasam
f0e16b8743 Add --threads argument to pyright cli (#12688) 2024-09-23 19:19:28 +02:00
Avasam
bb981771ed Bump protobuf to 5.28.* (#12689) 2024-09-23 19:14:28 +02:00
Martin Huschenbett
46512118ea Return coroutine from AsyncGenerator.__anext__ (#12685)
The `__anext__` method of an asynchronous generator defined using the
`async def`/`yield` syntax returns an actual coroutine not just any
awaitable. Let the definition of the `AsyncGenerator` protocol reflect
this circumstance.

See https://discuss.python.org/t/types-for-asynchronous-generators-too-general/64515
for the motivation behind this change.
2024-09-23 11:34:56 +02:00
Martijn Pieters
bde71c575f Complete coverage for the qrcode package (#12675) 2024-09-20 15:36:25 +02:00
kasium
f1bf1c01fe Add stubs for python-jenkins (#12582)
Co-authored-by: Jelle Zijlstra <jelle.zijlstra@gmail.com>
2024-09-19 20:12:09 -07:00
Avasam
c025e37bbb Rewrote protobuf generation scripts in Python (#12527) 2024-09-19 08:11:21 +02:00
renovate[bot]
0689736dce Update dependency pyright to v1.1.381 (#12678)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2024-09-18 21:12:36 -04:00
João Henrique
0610a79fdb fix: fpdf2: Allow "BI" for _FontStyle in fpdf.pyi (#12677) 2024-09-18 18:02:29 +02:00
Kanishk Pachauri
eb7df6d118 fix: weight parameter type for networkx.algorithms.shortest_paths (#12663) 2024-09-17 21:37:51 +02:00
Alexander Zinov
0015ce8855 openpyxl: fix Worksheet.values annotation (#12674) 2024-09-17 17:14:06 +02:00
sobolevn
d3070c5845 Bump xdgenvpy to 3.0.* (#12671) 2024-09-17 13:19:28 +02:00
sobolevn
0a0ba2f4d0 Bump paramiko to 3.5.* (#12672) 2024-09-17 13:17:06 +02:00
Avasam
d34ef50754 Optional pytype install on Windows (no CI) (#12669) 2024-09-17 10:58:31 +02:00
github-actions[bot]
3266319a76 [stubsabot] Bump setuptools to 75.1.* (#12670)
Co-authored-by: stubsabot <>
2024-09-16 21:59:15 -04:00
Max Muoto
85121de466 Update importlib resources for 3.13 (#12298) 2024-09-16 20:21:35 +02:00
Sebastian Rittau
94889897ca [setuptools] Bump to 75.0.* (#12668)
Co-authored-by: Avasam <samuel.06@hotmail.com>
2024-09-16 19:17:52 +02:00