Skip to content

Bump django-haystack from 2.8.1 to 3.4.0 in /codalab/requirements#3651

Open
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/pip/codalab/requirements/django-haystack-3.4.0
Open

Bump django-haystack from 2.8.1 to 3.4.0 in /codalab/requirements#3651
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/pip/codalab/requirements/django-haystack-3.4.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 15, 2026

Copy link
Copy Markdown

Bumps django-haystack from 2.8.1 to 3.4.0.

Release notes

Sourced from django-haystack's releases.

Test improvements and patching Patch GHSA-r3hx-x5rh-p9vv

What's Changed

New Contributors

Full Changelog: django-haystack/django-haystack@v3.3.0...v3.4.0

v3.3.0: Django v5 support

The marquee feature in this release is official support for Django v4 and v5 but this also coincided with a number of changes behind the scenes to make Haystack easier to support and several volunteers have stepped up to help work on Haystack. Especial thanks to @​cclauss and @​claudep for helping move things forward.

Major changes

  • Django versions 3-5 are supported, running on Python 3.8-3.12.
  • Releases are now created in GitHub Actions and published directly to PyPI, improving visibility into the build process.

New Contributors

... (truncated)

Changelog

Sourced from django-haystack's changelog.

Changelog

%%version%% (unreleased)

  • Docs: don't tell people how to install Python packages. [Chris Adams]

    It's 2018, "pip install " is the only thing we should volunteer.

  • Update Elasticsearch documentation. [Chris Adams]

    • Add 5.x to supported versions
    • Replace configuration and installation information with pointers to the official docs
    • Stop mentioning pyes since it’s fallen behind the official client in awareness
    • Don’t tell people how to install Python packages
  • Fix get_coords() calls. [Chris Adams]

  • Update README & contributor guide. [Chris Adams]

  • Blacken. [Chris Adams]

  • Isort everything. [Chris Adams]

  • Update code style settings. [Chris Adams]

    Prep for Blackening

  • Remove PyPy / Django 2 targets. [Chris Adams]

    We'll restore these when pypy3 is more mainstream

  • Use default JRE rather than requiring Oracle. [Chris Adams]

    OpenJDK is also supported and that does not require accepting a license.

  • Changed ES5.x test skip message to match the friendlier 2.x one. [Bruno Marques]

  • Fixed faceted search and autocomplete test. [Bruno Marques]

  • Removed ES5 code that actually never runs. [Bruno Marques]

  • Fixed kwargs in ES5's build_search_query. [Bruno Marques]

  • ES5: fixed MLT, within and dwithin. [Bruno Marques]

  • Assorted ES5.x fixes. [Bruno Marques]

  • Re-added sorting, highlighting and suggesting to ES5.x backend. [Bruno Marques]

  • Fixed filters and fuzziness on ES5.x backend. [Bruno Marques]

  • Added Java 8 to Travis dependencies. [Bruno Marques]

  • Started Elasticsearch 5.x support. [Bruno Marques]

  • Style change to avoid ternary logic on the end of a line. [Chris Adams]

    This is unchanged from #1475 but avoids logic at the end of the line

  • Do not raise when model cannot be searched. [benvand]

    • Return empty string.

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [django-haystack](https://github.com/django-haystack/django-haystack) from 2.8.1 to 3.4.0.
- [Release notes](https://github.com/django-haystack/django-haystack/releases)
- [Changelog](https://github.com/django-haystack/django-haystack/blob/master/docs/changelog.rst)
- [Commits](django-haystack/django-haystack@v2.8.1...v3.4.0)

---
updated-dependencies:
- dependency-name: django-haystack
  dependency-version: 3.4.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added Dependencies Pull requests that update a dependency file Python Pull requests that update Python code labels Jul 15, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Dependencies Pull requests that update a dependency file Python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants