2892aa5
Merge pull request #4168
from github/update-v4.38.2-a6ef2c96f8ad03a3
Trigger workflows98af865
Update changelog for v4.38.2a6ef2c9
Merge pull request #4156
from github/mario-campos/fix-validate-cmd1ef28a1
Merge pull request #4166
from github/dependabot/github_actions/dot-github/wor...26cb08b
Merge pull request #4163
from github/mbg/fix-getCommitOid-stubsf035ce3
Merge pull request #4165
from github/dependabot/npm_and_yarn/npm-minor-8eaed9...5e4e255
Rebuildb13f5f4
Bump ruby/setup-rubyc87fe57
RebuildSourced from platformdirs's releases.
4.11.14
What's Changed
- 🐛 fix(dirs): only create configured media dirs by
@gaborbernatin tox-dev/platformdirs#561- 🧪 test(appdirs): clear XDG variables in compatibility test by
@gaborbernatin tox-dev/platformdirs#570- 🐛 fix(unix): ignore XDG_RUNTIME_DIR when redirecting root by
@gaborbernatin tox-dev/platformdirs#562- 🐛 fix(android): find the app folder for packages named files* by
@gaborbernatin tox-dev/platformdirs#565- 🐛 fix(unix): apply use_site_for_root changes after first read by
@gaborbernatin tox-dev/platformdirs#567- 🐛 fix(unix): read user-dirs.dirs like os.fsdecode by
@gaborbernatin tox-dev/platformdirs#568- 🐛 fix(api): accept roaming in user_log_dir and user_log_path by
@gaborbernatin tox-dev/platformdirs#572- 🐛 fix(api): check app arguments on assignment by
@gaborbernatin tox-dev/platformdirs#566- 🐛 fix(unix): keep colons in site_cache_path under multipath by
@gaborbernatin tox-dev/platformdirs#574- 🐛 fix(windows): drop 8.3 short names from folder paths by
@gaborbernatin tox-dev/platformdirs#575- 📝 docs(platforms): fix Windows user_preference_dir path by
@gaborbernatin tox-dev/platformdirs#577- 🐛 fix(macos): detect Homebrew Python by its opt/ framework path by
@gaborbernatin tox-dev/platformdirs#573- 🐛 fix(android): use Download as the downloads folder name by
@gaborbernatin tox-dev/platformdirs#563- 🐛 fix(windows): ignore relative WIN_PD_OVERRIDE values by
@gaborbernatin tox-dev/platformdirs#564- 🐛 fix(windows): treat empty PUBLIC and fallback env vars as unset by
@gaborbernatin tox-dev/platformdirs#571- 🐛 fix(unix): keep the temporary runtime dir fallback private by
@gaborbernatin tox-dev/platformdirs#576- 🐛 fix(dirs): refuse to create a literal ~ dir without a home by
@gaborbernatin tox-dev/platformdirs#578- 📝 docs(macos): name the XDG variables the state dirs skip by
@gaborbernatin tox-dev/platformdirs#579- 🐛 fix(unix): drop trailing comment after unquoted user dir by
@gaborbernatin tox-dev/platformdirs#569Full Changelog: https://github.com/tox-dev/platformdirs/compare/4.11.13...4.11.14
4.11.13
What's Changed
- 🐛 fix(dirs): create media dirs when ensure_exists is set by
@gaborbernatin tox-dev/platformdirs#560Full Changelog: https://github.com/tox-dev/platformdirs/compare/4.11.12...4.11.13
Sourced from platformdirs's changelog.
########### Changelog ###########
.. towncrier-draft-entries:: Unreleased
.. towncrier release notes start
4.12.1 (2026-09-28)
- Avoid
PytestAssertRewriteWarningwhen importingplatformdirsbefore invoking pytest. :pr:601
4.12.0 (2026-09-26)
- Add
place_*_filemethods that return a file path under a user directory and create its missing parents with mode0o700. :pr:585- Add
find_<kind>_fileandfind_<kind>_filesto look up an existing file across the user and site directories of each kind that has aniter_<kind>_pathsmethod. :pr:586- Add :func:
platformdirs.testing.isolated_dirsand theplatformdirs_isolatedpytest fixture to resolve every directory under one test root. :pr:590- Emit :class:
~platformdirs.RuntimeDirWarningwhen the Unix :func:~platformdirs.user_runtime_dirfalls back fromXDG_RUNTIME_DIR. :pr:599- Read
user_templates_dir,user_publicshare_diranduser_bin_diron Windows from their known folders. :pr:587- Create missing user app directories and their parents with mode
0700underensure_existson POSIX platforms. :pr:588- Raise
RuntimeErrorfor a Unix or macOS directory under the home when no home resolves, and read the password database for an emptyHOME. :pr:589- Skip an
XDG_RUNTIME_DIRor/run/user/<uid>that is not a private directory of the user, and reject a symlink or file as theruntime-<uid>fallback. :pr:599- Use the app container layout on iOS, such as
~/Library/Application Supportfor data. :pr:600- Document that a Homebrew Python puts the Homebrew prefix first in the macOS shared directories, with or without
multipath. :pr:591- Document that the macOS media directories honor the
XDG_*_DIRvariables. :pr:592- Document the
WIN_PD_OVERRIDE_COMMON_PROGRAMSvariable. :pr:593- Document
/usr/local/share/applicationsas the Linuxsite_applications_dirdefault. :pr:594- Correct the BSD
user_runtime_dirdefaults and describe the temporary directory fallback. :pr:595- Describe how platformdirs detects Android, finds the app folder and places the shared folders. :pr:
596- Document that Microsoft Store Python redirects only new files and folders under
AppData. :pr:597- Show how to load a font on Windows after copying it into
user_fonts_dir. :pr:598
4.11.15 (2026-09-26)
- Fix the pyjnius lookup of the Android app folder and media directories, which always failed. :pr:
580
... (truncated)
e12a848
Release 4.11.1426372da
🐛 fix(unix): drop trailing comment after unquoted user dir (#569)73d3508
📝 docs(macos): name the XDG variables the state dirs skip (#579)4ac34b8
🐛 fix(dirs): refuse to create a literal ~ dir without a home (#578)49a065b
🐛 fix(unix): keep the temporary runtime dir fallback private (#576)c78e917
🐛 fix(windows): treat empty PUBLIC and fallback env vars as unset (#571)0d88988
🐛 fix(windows): ignore relative WIN_PD_OVERRIDE values (#564)7dc1ec0
🐛 fix(android): use Download as the downloads folder name (#563)4ee597e
🐛 fix(macos): detect Homebrew Python by its opt/ framework path (#573)53d50eb
📝 docs(platforms): fix Windows user_preference_dir path (#577)Sourced from virtualenv's releases.
21.12.1
What's Changed
- 🐛 fix(create): limit .venv redirect to projects by
@gaborbernatin pypa/virtualenv#3316Full Changelog: https://github.com/pypa/virtualenv/compare/21.12.0...21.12.1
21.12.0
What's Changed
- ✨ feat(create): point a .venv redirect per PEP 832 by
@gaborbernatin pypa/virtualenv#3204Full Changelog: https://github.com/pypa/virtualenv/compare/21.11.1...21.12.0
21.11.1
What's Changed
- 📝 docs(security): close threat items resolved by 21.11.0 by
@gaborbernatin pypa/virtualenv#3313- 🐛 fix(build): ship test inputs in the sdist and check it by
@Gonghan-Princessin pypa/virtualenv#3315New Contributors
@Gonghan-Princessmade their first contribution in pypa/virtualenv#3315Full Changelog: https://github.com/pypa/virtualenv/compare/21.11.0...21.11.1
21.11.0
What's Changed
- ci(pre-release): disable the uv cache by
@gaborbernatin pypa/virtualenv#3288- ci: pass expressions to run scripts via env by
@gaborbernatin pypa/virtualenv#3292- ci(release): audit egress in build and publish by
@gaborbernatin pypa/virtualenv#3289- 📝 docs: define maintainer roles and access by
@gaborbernatin pypa/virtualenv#3290- ci: resolve zizmor auditor findings by
@gaborbernatin pypa/virtualenv#3297- ci(pre-commit): freeze hook revs to commit SHAs by
@gaborbernatin pypa/virtualenv#3298- docs: link docs and pyvideo over https by
@gaborbernatin pypa/virtualenv#3300- docs(development): add a one-year roadmap by
@gaborbernatin pypa/virtualenv#3304- 🐛 fix(seed): fail closed when PyPI digest is unknown by
@gaborbernatin pypa/virtualenv#3302- ✨ feat(release): publish SBOMs as release assets by
@gaborbernatin pypa/virtualenv#3299- docs(security): describe the project under the CRA by
@gaborbernatin pypa/virtualenv#3295- docs(template): name the trust boundary crossed by
@gaborbernatin pypa/virtualenv#3296- ♻️ refactor(sbom): type the SPDX renderer by
@gaborbernatin pypa/virtualenv#3307- ✨ feat(zipapp): publish an SBOM for the zipapp by
@gaborbernatin pypa/virtualenv#3310- 👷 ci(check): pin test tool downloads and bump them weekly by
@gaborbernatin pypa/virtualenv#3293- 📝 docs: explain what a release publishes and how to verify it by
@gaborbernatin pypa/virtualenv#3305
... (truncated)
Sourced from virtualenv's changelog.
Bugfixes - 21.12.1
Limit the :PEP:
832.venvredirect to folders holding apyproject.tomland no.venvyet, sovirtualenv fooin a scratch folder, and tools such as tox or nox building environments through virtualenv, no longer claim a folder's default environment - by :user:gaborbernat.
--venv-redirectwrites the redirect in any folder and replaces an earlier virtualenv redirect.- A flag on the command line overrides the environment variable and the config file in either direction. (:issue:
3316)
v21.12.0 (2026-09-24)
Features - 21.12.0
Write the
PEP 838 <https://peps.python.org/pep-0838/>_python-versionkey intopyvenv.cfg, holding the target interpreter's feature release. The new :doc:reference/filespage covers it alongside every other file a created environment holds - by :user:konstin. (:issue:3193)Point a
.venvredirect file in the parent folder at the created environment, perPEP 832 <https://peps.python.org/pep-0832/>_, so editors and type checkers can find it - by :user:gaborbernat.
- virtualenv leaves a
.venvfolder alone, and a redirect pointing at an environment it did not create.- Pass
--no-venv-redirectto opt out.- The feature is provisional while PEP 832 is a draft: a minor or patch release may change it in backward incompatible ways to follow the PEP. (:issue:
3204)
v21.11.1 (2026-09-23)
Bugfixes - 21.11.1
- Include the pre-commit configuration and the zipapp lock file in the source distribution, so downstream packagers can run the test suite from it. (:issue:
3314)
v21.11.0 (2026-09-23)
Features - 21.11.0
- Attach the CycloneDX SBOM and an SPDX 2.3 rendering of it (
virtualenv.cdx.json,virtualenv.spdx.json) to each GitHub release, and attest the SPDX document against the sdist and wheel. (:issue:3299)- Describe the zipapp in its own CycloneDX SBOM, which lists virtualenv, the embedded pip and setuptools wheels, and each bundled dependency with the Python versions that load it, down to a SHA-256 per file. The SBOM sits at the root
... (truncated)
befec5e
release 21.12.1572d159
🐛 fix(create): limit .venv redirect to projects (#3316)f19165b
release 21.12.0554bc8f
✨ feat(create): point a .venv redirect per PEP 832 (#3204)4c13875
release 21.11.1ae073fb
🐛 fix(build): ship test inputs in the sdist and check it (#3315)fc912de
📝 docs(security): close threat items resolved by 21.11.0 (#3313)49077e7
release 21.11.05d9dc58
🐛 fix(sbom): keep the build machine out of the SBOMs (#3311)bcb0fa6
📝 docs(security): sync threat model with merged fixes (#3312)