Skip to content

Update idna requirement from >=3.6 to >=3.19 - #19

Closed
dependabot[bot] wants to merge 48 commits into
mainfrom
dependabot/pip/idna-gte-3.19
Closed

dependabot[bot] wants to merge 48 commits into
mainfrom
dependabot/pip/idna-gte-3.19

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 1, 2026

Copy link
Copy Markdown
Contributor

Updates the requirements on idna to permit the latest version.

Release notes

Sourced from idna's releases.

v3.19

  • Restore the std3_rules option, which had no effect since changes to UTS #46 processing in Unicode 16. Note that uts46_remap() defaults to enabling STD3 rules, so direct callers will see input containing non-LDH ASCII characters rejected again.
  • Performance improvements to UTS #46 mapping, particularly for ASCII-only domains.
  • Test on free-threaded CPython with the GIL disabled and document thread safety.
  • Expose the Unicode version of the generated tables as idna.unicode_version, and show it in idna --version.
  • Add code, text, codepoint and position attributes to IDNAError so that the failed rule and the offending character can be identified without parsing the exception message.
  • The deprecated transitional argument to encode() and uts46_remap() is now completely ignored, and gives a deprecation warning for the latter.
  • Reject A-labels that are not the canonical Punycode encoding of their U-label.
  • Fix CONTEXTJ violations raising IDNAError instead of InvalidCodepointContext.
  • Consistently raise IDNAError for empty labels and non-ASCII bytes passed to label helper functions and the incremental codec.
  • Add property-based tests, extended fuzzing targets, coverage measurement, and CI checks that the data tables match the generator output.
  • Various code quality and tooling improvements.

Thanks to stefan6419846, LouieLuNZ, and Salvatore Corvaglia for contributions to this release.

Changelog

Sourced from idna's changelog.

3.19 (2026-08-18)

  • Restore the std3_rules option, which had no effect since changes to UTS #46 processing in Unicode 16. Note that uts46_remap() defaults to enabling STD3 rules, so direct callers will see input containing non-LDH ASCII characters rejected again.
  • Performance improvements to UTS #46 mapping, particularly for ASCII-only domains.
  • Test on free-threaded CPython with the GIL disabled and document thread safety.
  • Expose the Unicode version of the generated tables as idna.unicode_version, and show it in idna --version.
  • Add code, text, codepoint and position attributes to IDNAError so that the failed rule and the offending character can be identified without parsing the exception message.
  • The deprecated transitional argument to encode() and uts46_remap() is now completely ignored, and gives a deprecation warning for the latter.
  • Reject A-labels that are not the canonical Punycode encoding of their U-label.
  • Fix CONTEXTJ violations raising IDNAError instead of InvalidCodepointContext.
  • Consistently raise IDNAError for empty labels and non-ASCII bytes passed to label helper functions and the incremental codec.
  • Add property-based tests, extended fuzzing targets, coverage measurement, and CI checks that the data tables match the generator output.
  • Various code quality and tooling improvements.

Thanks to stefan6419846, LouieLuNZ, and Salvatore Corvaglia for contributions to this release.

3.18 (2026-06-02)

  • When decoding a domain, add a display argument that will pass through invalid labels rather than raising an exception.

3.17 (2026-05-28)

  • Substantial 75% reduction in memory usage through new data structures and some optimization in processing speed.
  • Added a general 1024-character input length cap to the public validation, conversion, and codec entry points. This is well above any legitimate domain or label and guards against pathological inputs.

3.16 (2026-05-22)

  • Add a command-line interface (python -m idna, also available as the idna script). Encodes or decodes one or more domains supplied

... (truncated)

Commits
  • 03a9a11 Release 3.19
  • 2d2a7ef Pre-release 3.19rc0
  • 5cce130 Merge pull request #268 from kjd/fix-std3-regex-alert
  • 3914b75 Split the STD3 disallowed-character range so uppercase is explicit
  • ce9fd98 Merge pull request #267 from kjd/housekeeping
  • 809240c Fail CI when the license copyright year is behind the current year
  • d9e16c5 Consolidate test fixtures, prune stale gitignore entries, and fix doc typos
  • ef30fee Remove dead code and pare back superfluous comments
  • b907913 Tighten the version support and Unicode notes in the README
  • 6204cbe Ignore local build artifacts and stop packaging stray tooling config
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

YukinoshitaSherry and others added 18 commits September 13, 2025 22:54
The repo documented the CLI but never said what CellForge is for or what it
achieved. This makes the paper's contribution legible from the front page and
adds the project infrastructure a research tool needs to take contributions.

README
- Lead with the result: PCC 0.9883 on Adamson, MSE_DE 0.1736 on Norman,
  first in 14/15 blinded judge comparisons, 6 datasets across 3 modalities.
- Map the three paper stages (Formulation/Ideation/Execution) onto the
  package layout, and document the coordination score and its convergence
  criterion.
- Summarise the six generated architectures, the benchmark datasets with GEO
  accessions, per-run token and GPU cost, and the measured failure-mode
  distribution.
- State the weak results (0.535 DEG recall, 0.420 protein recall) rather than
  omit them.

docs/
- QUICKSTART, ARCHITECTURE, RESULTS, MODELS, DATASETS, FAQ, ROADMAP.

Infrastructure
- CI: pytest on Python 3.9-3.12, lint, sdist/wheel build, CITATION.cff
  validation, secret scan. requirements-ci.txt carries the minimal set the
  43 tests actually need, so CI skips the full scientific stack.
- Issue templates (bug, bad research plan, feature), PR template, dependabot.
- CONTRIBUTING, CODE_OF_CONDUCT, SECURITY, CHANGELOG.
- pyproject.toml for the build backend and black/isort/ruff/mypy/pytest
  config. Package metadata stays in setup.py to avoid a second source of
  truth for dependencies.

Data and examples
- scripts/download_datasets.py fetches all six benchmark datasets from the
  scPerturb Zenodo records with md5 verification. Filenames, sizes, and
  checksums were read from the live Zenodo API; one download was verified
  end to end.
- examples/ carries a task description per benchmark.

CITATION.cff listed "CellForge authors" and no paper. It now carries the full
author roster and arXiv:2508.02276 as the preferred citation.

Verified: 43/43 tests pass, twine check passes, CITATION.cff validates against
schema 1.2.0, all .github YAML parses, no broken relative links across the 15
markdown files.
Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v4...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@openai/codex-sdk](https://github.com/openai/codex/tree/HEAD/sdk/typescript) from 0.116.0 to 0.146.0.
- [Commits](https://github.com/openai/codex/commits/rust-v0.146.0/sdk/typescript)

---
updated-dependencies:
- dependency-name: "@openai/codex-sdk"
  dependency-version: 0.146.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Updates the requirements on [referencing](https://github.com/python-jsonschema/referencing) to permit the latest version.
- [Release notes](https://github.com/python-jsonschema/referencing/releases)
- [Changelog](https://github.com/python-jsonschema/referencing/blob/main/docs/changes.rst)
- [Commits](python-jsonschema/referencing@v0.30.2...v0.37.0)

---
updated-dependencies:
- dependency-name: referencing
  dependency-version: 0.37.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
A run costs roughly 80k prompt / 400k completion tokens plus 4-8 GPU-hours.
Nothing in the repository showed what you get for that, so the decision to try
CellForge had to be made blind.

examples/outputs/adamson_crispri/ is a complete worked bundle laid out the way a
run leaves one: task analysis report, research plan (md/json/mmd), and the
generated training script with its metrics and verification output.

On provenance, stated per file in PROVENANCE.md and in every README that points
at the bundle. This was assembled without an LLM provider key, without the Codex
CLI and without the dataset, so it is not the transcript of a live run:

- task_analysis_report.md and research_plan.* are hand-written to match the
  schemas the code actually serialises, section for section
  (TaskAnalysisReport.to_markdown, refinement.py's five top-level plan keys)
- result.py is real, working code. It passes the repository's own deterministic
  verifier: file, compile, --help, --selftest, and metrics.json structure
- metrics.json and verification.json are the genuine output of really executing
  result.py and really running CodeGenerationVerifier, on synthetic data

The synthetic numbers (pcc 0.618, pcc_de 0.218) are a smoke test and are not
comparable to the paper's 0.9883 on real Adamson data. PROVENANCE.md says so,
explains why genome-wide PCC is inflated on real data, why r2_de is legitimately
negative, and notes that the synthetic generator is sympathetic to the
architecture it demonstrates.

result.py is not a sketch. It conditions the perturbation on the target gene's
embedding tied to the decoder output weights, rather than a free lookup table,
because held-out rows in a lookup table never receive gradient and the
unseen-perturbation split is then unsolvable in principle. torch/numpy/anndata
are imported lazily so --help and --selftest run in a bare interpreter.

scripts/export_example_run.py packages a genuine run into this layout, scrubbing
API keys, absolute paths, usernames and hostnames, and aborting rather than
writing a file that still matches a credential pattern. A real bundle should
replace this one; CONTRIBUTING.md now asks for exactly that.

.gitignore needed an explicit !examples/outputs/ because `outputs/` matched it
and git will not descend into an excluded directory.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…ons/checkout-7

Bump actions/checkout from 4 to 7
…i/codex-sdk-0.146.0

Bump @openai/codex-sdk from 0.116.0 to 0.146.0
…e-0.37.0

Update referencing requirement from >=0.30.2 to >=0.37.0
Updates the requirements on [idna](https://github.com/kjd/idna) to permit the latest version.
- [Release notes](https://github.com/kjd/idna/releases)
- [Changelog](https://github.com/kjd/idna/blob/master/HISTORY.md)
- [Commits](kjd/idna@v3.6...v3.19)

---
updated-dependencies:
- dependency-name: idna
  dependency-version: '3.19'
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 1, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot @github

dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/pip/idna-gte-3.19 branch October 2, 2026 16:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants