Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump the classical-ml group across 1 directory with 4 updates #605

Merged
merged 4 commits into from
Jan 29, 2025

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jan 20, 2025

Bumps the classical-ml group with 4 updates in the /classical-ml directory: jupyterlab, notebook, scikit-learn-intelex and nbconvert.

Updates jupyterlab from 4.3.3 to 4.3.4

Release notes

Sourced from jupyterlab's releases.

v4.3.4

4.3.4

(Full Changelog)

Bugs fixed

Maintenance and upkeep improvements

Contributors to this release

(GitHub contributors page for this release)

@​bollwyvl | @​Darshan808 | @​davidbrochart | @​jtpio | @​jupyterlab-probot | @​krassowski | @​meeseeksmachine

Changelog

Sourced from jupyterlab's changelog.

4.3.4

(Full Changelog)

Bugs fixed

Maintenance and upkeep improvements

Contributors to this release

(GitHub contributors page for this release)

@​bollwyvl | @​Darshan808 | @​davidbrochart | @​jtpio | @​jupyterlab-probot | @​krassowski | @​meeseeksmachine

Commits

Updates notebook from 7.3.1 to 7.3.2

Release notes

Sourced from notebook's releases.

v7.3.2

7.3.2

(Full Changelog)

Maintenance and upkeep improvements

Documentation improvements

Contributors to this release

(GitHub contributors page for this release)

@​Carreau | @​dependabot | @​ericsnekbytes | @​github-actions | @​itsmevichu | @​jtpio | @​krassowski

Changelog

Sourced from notebook's changelog.

7.3.2

(Full Changelog)

Maintenance and upkeep improvements

Documentation improvements

Contributors to this release

(GitHub contributors page for this release)

@​Carreau | @​dependabot | @​ericsnekbytes | @​github-actions | @​itsmevichu | @​jtpio | @​krassowski

Commits

Updates scikit-learn-intelex from 2025.0.1 to 2025.1.0

Release notes

Sourced from scikit-learn-intelex's releases.

Intel® Extension for Scikit-learn* 2025.1.0

Intel® Extension for Scikit-learn* is happy to introduce 2025.1.0 release!

🚨 What's New

  • Introduced new Intel® Extension for Scikit-learn* functionality:
    • Enabled accelerated Linear Regression for overdetermined systems
    • Enabled hyperparameter support for Random Forest classifier inference
    • Enabled serialization in daal4py algorithm classes

🪲 Bug Fixes

  • Fixed int overflow in FTI model convertor
  • Updated BasicStatistics and IncrementalBasicStatistics to follow additional sklearn conventions
  • Fixed n_jobs support coverage to indirectly-supported oneDAL methods
  • Fixed KMeans score check in _onedal_*_supported and n_jobs support for score
  • Corrected skips in design rule checks (test_common.py) caused by fragile whitelist_to_blacklist
  • Fixed test_estimators[LogisticRegression()-check_estimators_unfitted] conformance for gpu support
  • Updated functional support fallback logic for a DPNP/DPCTL ndarray inputs
  • Fixed an issue in aliased _onedal_cpu_supported and _onedal_gpu_supported in fit_check_before_support_check
  • Fixed logic of k-NN algos kneighbors() call when algorithm='brute' and fit with GPU

🔨 Library Engineering

  • Added Python 3.13 support for Intel® Extension for Scikit-learn* packages
  • Added Sklearn 1.6 support for Intel® Extension for Scikit-learn* packages

Acknowledgements

Thanks to everyone who helped us make 2025.1.0 release possible!

@​Alexsandruss, @​Alexandr-Solovev, @​Vika-F, @​david-cortes-intel, @​icfaust, @​napetrov, @​maria-Petrova, @​homksei, @​ahuber21, @​ethanglaser, @​samir-nasibli, @​olegkkruglov, @​razdoburdin, @​avolkov-intel, @​md-shafiul-alam

Full Changelog: uxlfoundation/scikit-learn-intelex@2025.0.0...2025.1.0

Commits

Updates nbconvert from 7.16.4 to 7.16.5

Release notes

Sourced from nbconvert's releases.

v7.16.5

7.16.5

(Full Changelog)

Enhancements made

Bugs fixed

Maintenance and upkeep improvements

Contributors to this release

(GitHub contributors page for this release)

@​bollwyvl | @​fcollonval | @​krassowski | @​pre-commit-ci | @​stuaxo | @​t-makaro | @​takluyver | @​thomasjm | @​timkpaine | @​xiacunshun

Changelog

Sourced from nbconvert's changelog.

7.16.5

(Full Changelog)

Enhancements made

Bugs fixed

Maintenance and upkeep improvements

Contributors to this release

(GitHub contributors page for this release)

@​bollwyvl | @​fcollonval | @​krassowski | @​pre-commit-ci | @​stuaxo | @​t-makaro | @​takluyver | @​thomasjm | @​timkpaine | @​xiacunshun

Commits
  • 5f508eb Publish 7.16.5
  • 18e10f6 Add support for mistune 3.1.0 (#2199)
  • 6e5fdb3 Do not display mathjax overlay (#2181)
  • e159962 Allow including text/x-rst outputs in rst conversion, transition away from ...
  • 55ff3e9 Don't die if template path cannot be read (#2162)
  • 9c65025 Fix markdown2asciidoc function for pandoc >= 3.0 (closes #2017) (#2152)
  • bc0a0ed Directly depend on bleach[css], instead of pulling in tinycss2.
  • c3e2683 Work around pip 24.1 bug which prevents installing pandocfilters 1.4.1
  • fc6766f chore: update pre-commit hooks (#2146)
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Jan 20, 2025
@dependabot dependabot bot requested a review from sharvil10 as a code owner January 20, 2025 13:55
@dependabot dependabot bot added the python Pull requests that update Python code label Jan 20, 2025
Copy link

github-actions bot commented Jan 20, 2025

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
pip/jupyterlab 4.3.4 🟢 5.6
Details
CheckScoreReason
Code-Review🟢 9Found 24/25 approved changesets -- score normalized to 9
Maintained🟢 1030 commit(s) and 9 issue activity found in the last 90 days -- score normalized to 10
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
License🟢 9license file detected
CII-Best-Practices⚠️ 2badge detected: InProgress
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Binary-Artifacts🟢 10no binaries found in the repo
Security-Policy🟢 10security policy file detected
Fuzzing⚠️ 0project is not fuzzed
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Signed-Releases⚠️ 0Project has not signed or included provenance with any releases.
Branch-Protection⚠️ -1internal error: error during GetBranch(4.2.x): error during branchesHandler.query: internal error: githubv4.Query: Resource not accessible by integration
SAST🟢 10SAST tool is run on all commits
Vulnerabilities⚠️ 020 existing vulnerabilities detected
pip/notebook 7.3.2 🟢 4.2
Details
CheckScoreReason
Code-Review⚠️ 2Found 6/26 approved changesets -- score normalized to 2
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Packaging⚠️ -1packaging workflow not detected
Binary-Artifacts🟢 10no binaries found in the repo
Maintained🟢 1030 commit(s) and 10 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Security-Policy🟢 10security policy file detected
Signed-Releases⚠️ 0Project has not signed or included provenance with any releases.
Branch-Protection⚠️ -1internal error: error during GetBranch(7.2.x): error during branchesHandler.query: internal error: githubv4.Query: Resource not accessible by integration
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Vulnerabilities⚠️ 025 existing vulnerabilities detected
pip/nbconvert 7.16.5 🟢 5.2
Details
CheckScoreReason
Code-Review🟢 4Found 12/27 approved changesets -- score normalized to 4
Maintained🟢 44 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 4
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Binary-Artifacts🟢 10no binaries found in the repo
Packaging⚠️ -1packaging workflow not detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Vulnerabilities🟢 100 existing vulnerabilities detected
License🟢 10license file detected
Fuzzing🟢 10project is fuzzed
Branch-Protection🟢 3branch protection is not maximal on development and all release branches
Signed-Releases⚠️ 0Project has not signed or included provenance with any releases.
Security-Policy🟢 10security policy file detected
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
pip/scikit-learn-intelex 2025.1.0 UnknownUnknown

Scanned Files

  • classical-ml/jupyter-requirements.txt
  • classical-ml/requirements.txt

@sharvil10
Copy link
Contributor

@dependabot rebase

Copy link
Contributor Author

dependabot bot commented on behalf of github Jan 23, 2025

Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry!

If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

@sharvil10
Copy link
Contributor

@dependabot recreate

Bumps the classical-ml group with 4 updates in the /classical-ml directory: [jupyterlab](https://github.com/jupyterlab/jupyterlab), [notebook](https://github.com/jupyter/notebook), [scikit-learn-intelex](https://github.com/intel/scikit-learn-intelex) and [nbconvert](https://github.com/jupyter/nbconvert).


Updates `jupyterlab` from 4.3.3 to 4.3.4
- [Release notes](https://github.com/jupyterlab/jupyterlab/releases)
- [Changelog](https://github.com/jupyterlab/jupyterlab/blob/@jupyterlab/[email protected]/CHANGELOG.md)
- [Commits](https://github.com/jupyterlab/jupyterlab/compare/@jupyterlab/[email protected]...@jupyterlab/[email protected])

Updates `notebook` from 7.3.1 to 7.3.2
- [Release notes](https://github.com/jupyter/notebook/releases)
- [Changelog](https://github.com/jupyter/notebook/blob/main/CHANGELOG.md)
- [Commits](https://github.com/jupyter/notebook/compare/@jupyter-notebook/[email protected]...@jupyter-notebook/[email protected])

Updates `scikit-learn-intelex` from 2025.0.1 to 2025.1.0
- [Release notes](https://github.com/intel/scikit-learn-intelex/releases)
- [Commits](https://github.com/intel/scikit-learn-intelex/commits/2025.1.0)

Updates `nbconvert` from 7.16.4 to 7.16.5
- [Release notes](https://github.com/jupyter/nbconvert/releases)
- [Changelog](https://github.com/jupyter/nbconvert/blob/main/CHANGELOG.md)
- [Commits](jupyter/nbconvert@v7.16.4...v7.16.5)

---
updated-dependencies:
- dependency-name: jupyterlab
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: classical-ml
- dependency-name: notebook
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: classical-ml
- dependency-name: scikit-learn-intelex
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: classical-ml
- dependency-name: nbconvert
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: classical-ml
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot force-pushed the dependabot/pip/classical-ml/classical-ml-d4c66b0f19 branch from 240d3fb to 5debfd7 Compare January 23, 2025 18:44
@github-advanced-security
Copy link

This pull request sets up GitHub code scanning for this repository. Once the scans have completed and the checks have passed, the analysis results for this pull request branch will appear on this overview. Once you merge this pull request, the 'Security' tab will show more code scanning analysis results (for example, for the default branch). Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results. For more information about GitHub code scanning, check out the documentation.

@sharvil10
Copy link
Contributor

@dependabot rebase

Copy link
Contributor Author

dependabot bot commented on behalf of github Jan 28, 2025

Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry!

If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

Copy link

Integration Test Results

Groups Tested: classical-ml/tests

Results
Test-Group Test Status
classical-ml/tests classical-ml-import-idp PASS
classical-ml/tests classical-ml-import-pip PASS
classical-ml/tests classical-ml-import-idp-jupyter PASS
classical-ml/tests classical-ml-import-pip-jupyter PASS
classical-ml/tests classical-ml-performance-idp PASS
classical-ml/tests classical-ml-performance-pip PASS

Overall Result: PASS ✅

Copy link
Contributor

@sharvil10 sharvil10 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@jitendra42 jitendra42 merged commit 73c057c into main Jan 29, 2025
38 checks passed
@jitendra42 jitendra42 deleted the dependabot/pip/classical-ml/classical-ml-d4c66b0f19 branch January 29, 2025 04:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file python Pull requests that update Python code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants