ssi-code
ssi-code copied to clipboard
Bump numexpr from 2.7.1 to 2.8.5
Bumps numexpr from 2.7.1 to 2.8.5.
Changelog
Sourced from numexpr's changelog.
Changes from 2.8.5 to 2.8.6
The sanitization can be turned off by default by setting an environment variable,
set NUMEXPR_SANITIZE=0Improved behavior of the blacklist to avoid triggering on private variables and scientific notation numbers.
Changes from 2.8.4 to 2.8.5
- A
validatefunction has been added. This function checks the inputs, returningNoneon success or raising an exception on invalid inputs. This function was added as numerous projects seem to be using NumExpr for parsing user inputs.re_evaluatemay be called directly followingvalidate.- As an addendum to the use of NumExpr for parsing user inputs, is that NumExpr calls
evalon the inputs. A regular expression is now applied to help sanitize the input expression string, forbidding '__', ':', and ';'. Attribute access is also banned except for '.r' for real and '.i' for imag.- Thanks to timbrist for a fix to behavior of NumExpr with integers to negative powers. NumExpr was pre-checking integer powers for negative values, which was both inefficient and caused parsing errors in some situations. Now NumExpr will simply return 0 as a result for such cases. While NumExpr generally tries to follow NumPy behavior, performance is also critical.
- Thanks to peadar for some fixes to how NumExpr launches threads for embedded applications.
- Thanks to de11n for making parsing of the
site.cfgfor MKL consistent among all shared platforms.Changes from 2.8.3 to 2.8.4
- Support for Python 3.11 has been added.
- Thanks to Tobias Hangleiter for an improved accuracy complex
expm1function. While it is 25 % slower, it is significantly more accurate for the real component over a range of values and matches NumPy outputs much more closely.- Thanks to Kirill Kouzoubov for a range of fixes to constants parsing that was resulting in duplicated constants of the same value.
- Thanks to Mark Harfouche for noticing that we no longer need
numpyversion checks.packagingis no longer a requirement as a result.Changes from 2.8.1 to 2.8.3
- 2.8.2 was skipped due to an error in uploading to PyPi.
- Support for Python 3.6 has been dropped due to the need to substitute the flag
NPY_ARRAY_WRITEBACKIFCOPYforNPY_ARRAY_UPDATEIFCOPY. This flag change was
... (truncated)
Commits
298134aGetting ready for release 2.8.51c6bce1Merge branch 'master' of https://github.com/pydata/numexpr00b035cMake more difficult sanitize of the expression string before eval67a1221Merge pull request #443 from de11n/fix-libraries-parsingc2dd659Fix setup.py to respect numpy's parsing of libraries in site.cfg4b2d89cAdd in protections against call toeval(expression)74d5973Adding tests forvalidateand noticed thatre_evaluatetests using `local...0032150Apparentlysphinx_rtd_themeis only compatible with Sphinx < 7.06b6fd1dAlso pinsphinx-rtd-theme0c22ea7Try and pin Sphinx version for ReadtheDocs- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency -
@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page.