Skip to content

Conversation

@dependabot
Copy link

@dependabot dependabot bot commented on behalf of github Jul 8, 2024

Bumps aioquic from 1.0.0 to 1.2.0.

Changelog

Sourced from aioquic's changelog.

1.2.0

  • Add support for compatible version handling as defined in :rfc:9368.
  • Add support for QUIC Version 2, as defined in :rfc:9369.
  • Drop support for draft QUIC versions which were obsoleted by :rfc:9000.
  • Improve datagram padding to allow better packet coalescing and reduce the number of roundtrips during connection establishement.
  • Fix server anti-amplification checks during address validation to take into account invalid packets, such as datagram-level padding.
  • Allow asyncio clients to make efficient use of 0-RTT by passing wait_connected=False to :meth:~aioquic.asyncio.connect.
  • Add command-line arguments to the http3_client example for client certificates and negotiating QUIC Version 2.

1.1.0

  • Improve path challenge handling and compliance with :rfc:9000.
  • Limit the amount of buffered CRYPTO data to avoid memory exhaustion.
  • Enable SHA-384 based signature algorithms and SECP384R1 key exchange.
  • Build binary wheels against OpenSSL_ 3.3.0.
Commits
  • 9bc1e43 1.2.0
  • 7ee141f Try to fix retransmission test flakiness
  • 2f2a77a Allow 0-RTT data to be coalesced with the INITIAL using asyncio API
  • e189d29 Fix typing errors in examples, check with mypy
  • 7ad382f Allow the asyncio protocol to specify the close code / reason
  • 6987588 Improve padding of coalesced datagrams containing INITIAL
  • afe5525 During address validation, count the entire received datagram
  • 79a8caf Check Chosen Version matches the version in use by the connection
  • aadd4be Improve connection establishment tests
  • c411453 Add command line option for http3_client to negotiate QUIC v2
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [aioquic](https://github.com/aiortc/aioquic) from 1.0.0 to 1.2.0.
- [Changelog](https://github.com/aiortc/aioquic/blob/main/docs/changelog.rst)
- [Commits](aiortc/aioquic@1.0.0...1.2.0)

---
updated-dependencies:
- dependency-name: aioquic
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Jul 8, 2024
@dependabot @github
Copy link
Author

dependabot bot commented on behalf of github Nov 17, 2025

Superseded by #720.

@dependabot dependabot bot closed this Nov 17, 2025
@dependabot dependabot bot deleted the dependabot/pip/tools/base/aioquic-1.2.0 branch November 17, 2025 14:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant