Skip to content

Bump geopy from 1.21.0 to 2.5.0 - #185

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/pip/geopy-2.5.0
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/pip/geopy-2.5.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown

Bumps geopy from 1.21.0 to 2.5.0.

Release notes

Sourced from geopy's releases.

2.5.0

Security Advisory

GitHub Security advisory: GHSA-mhvh-fq92-pfmr.

Regular Expression Denial of Service (ReDoS) in geopy.Point: geopy.Point.from_string may take excessive CPU time when parsing long, malformed coordinate strings due to inefficient regular-expression behavior.

The numeric geopy.Point constructor is not affected.

Geocoders' reverse methods called with string inputs exercise the vulnerable path.

Reported by Younghun Lee in #608, fix contributed by Apoorv Darshan in #610.

The fix rejects any inputs longer than 256 chars unconditionally, which may start falsely rejecting previously valid Point strings with long irrelevant prefixes.

Bugfixes

  • .Geocodio: fix GeocoderQueryError being raised for empty results.
  • .GoogleV3: fix utcnow deprecation warnings.

Packaging Changes

  • Drop support for Python 3.7.
  • Add support for Python 3.13, 3.14, and 3.15.
  • Migrate build metadata from setup.py to setup.cfg. Remove download_url from the metadata. Contributed by Mike Taves. #535
  • Replace distutils with packaging in tests (fixes Python 3.12+).

Code Improvements

  • Remove Python 2 relics. Contributed by Miroslav Šedivý. #552

Test Improvements

  • Fix applying pytest marks to fixtures (pytest >= 9.1 compatibility). Contributed by Tomáš Hrnčiar. #609
  • Fix unclosed event loop warning in tests.
  • Fix pytest classmethod warning.
  • .Nominatim: fix test_reverse_near_zero which was failing due to locale-specific response formatting. Contributed by Alfredo Tupone. #606

Docs Improvements

... (truncated)

Changelog

Sourced from geopy's changelog.

:orphan:

Changelog of the 1.x series

1.23.0

2020-06-27

This is the last feature release for the 1.x series, as geopy 2.0 has been released. The 1.x series will not receive any new features or bugfixes unless explicitly asked on the issue tracker.

  • ADDED: Units Conversion docs section.

  • ADDED: Docs now explicitly clarify that geocoding services don't consider altitudes. (#165)

  • ADDED: Point.format_unicode method. It was always present as __unicode__ magic for Python 2.7, and now it can be accessed as a public method.

  • ADDED: geopy.__version_info__ tuple which can be used to dynamically compare geopy version.

  • ADDED: pytest --skip-tests-requiring-internet switch (might be useful for downstream package maintainers). (#413)

  • CHANGED: Points with different altitudes now emit a warning in distance computations. In geopy 2.0 the warning would become an exception. (#387)

  • CHANGED: Improved Point docs: added missing public methods, added more examples.

  • CHANGED: Nominatim started emitting warnings for a number of sample user agents mentioned in the docs, such as specify_your_app_name_here.

  • FIXED: IGNFrance ignored proxies with username + password auth. (#289)

1.22.0

2020-05-11

  • ADDED: AlgoliaPlaces geocoder. Contributed by Álvaro Mondéjar. (#405)

  • ADDED: BaiduV3 geocoder. (#394)

... (truncated)

Commits
  • 402cbba 2.5.0
  • f8c0dbd Makefile: fix make dist broken after 9af8380
  • 46c9eef Add versionchanged
  • 160aec2 Update changelog
  • 106ff54 AUTHORS: update an email per user's request
  • f35e84e Pull up AUTHORS
  • 2c3df74 Improve English grammar
  • 7f176f0 tests: fix pytest error in 3.13+ caused by ce21fb7
  • 547eb9b Geocodio: fix GeocoderQueryError being raised for empty result
  • fbca44f GoogleV3: fix utcnow deprecation warnings
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [geopy](https://github.com/geopy/geopy) from 1.21.0 to 2.5.0.
- [Release notes](https://github.com/geopy/geopy/releases)
- [Changelog](https://github.com/geopy/geopy/blob/master/docs/changelog_1xx.rst)
- [Commits](geopy/geopy@1.21.0...2.5.0)

---
updated-dependencies:
- dependency-name: geopy
  dependency-version: 2.5.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Oct 9, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants