Date 1 - 4 of 4
[PATCH v2 1/1] pip: bump antlr4-python3-runtime from 4.7.1 to 4.11.1
From: Michael Kubacki <michael.kubacki@...>
from 4.7.1 to 4.11.1.
Original automated dependabot PR:
Cc: Sean Brogan <sean.brogan@...>
Cc: Michael D Kinney <michael.d.kinney@...>
Cc: Liming Gao <gaoliming@...>
Co-authored-by: dependabot[bot] <support@...>
Signed-off-by: Michael Kubacki <michael.kubacki@...>
pip-requirements.txt | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/pip-requirements.txt b/pip-requirements.txt
index be8c7a1c37e6..597cb674c573 100644
@@ -15,4 +15,4 @@
Michael D Kinney
Hi Michael,toggle quoted message Show quoted text
Dependabot did not pick up the change list between those two versions.
I think this is a link to the release notes that contains the change
list from 4.7.1.to 4.11.1.
This update pulls in 5 years of changes. That is a large leap.
I recommend this be added to the commit message and for the reviewers
to review the change list to make sure there are not changes that
might impact edk2 repo use of this component.
I am looking at the edk2 sources and I only see 2 python tools using
antlr. These are ecc and eot. I recommend the BaseTools maintainers
verify that the functionality of these tools are not impacted by
Sure. Dependabot was added to find these old dependencies and keep the project on more current releases in the future.toggle quoted message Show quoted text
Bob and Christine, I filed the following BZ to track your feedback:
If you approve the changes, please go ahead and send your R-b on the list so I can capture that.
On 11/29/2022 10:37 AM, Michael D Kinney wrote:
Updated patch with antlr4 release info in commit message here:toggle quoted message Show quoted text
On 11/29/2022 11:37 AM, Michael Kubacki wrote:
Sure. Dependabot was added to find these old dependencies and keep the project on more current releases in the future.
|1 - 4 of 4|