fastapi_sqlalchemy_mysql
fastapi_sqlalchemy_mysql copied to clipboard
Bump starlette from 0.37.2 to 0.49.1
Bumps starlette from 0.37.2 to 0.49.1.
Release notes
Sourced from starlette's releases.
Version 0.49.1
This release fixes a security vulnerability in the parsing logic of the
Rangeheader inFileResponse.You can view the full security advisory: GHSA-7f5h-v6xp-fcq8
Fixed
- Optimize the HTTP ranges parsing logic 4ea6e22b489ec388d6004cfbca52dd5b147127c5
Full Changelog: https://github.com/Kludex/starlette/compare/0.49.0...0.49.1
Version 0.49.0
Added
- Add
encodingparameter toConfigclass #2996.- Support multiple cookie headers in
Request.cookies#3029.- Use
Literaltype forWebSocketEndpointencoding values #3027.Changed
- Do not pollute exception context in
Middlewarewhen usingBaseHTTPMiddleware#2976.
New Contributors
@TheWesDiasmade their first contribution in Kludex/starlette#3017@gmos2104made their first contribution in Kludex/starlette#3027@secrett2633made their first contribution in Kludex/starlette#2996@adam-sikoramade their first contribution in Kludex/starlette#2976Full Changelog: https://github.com/Kludex/starlette/compare/0.48.0...0.49.0
Version 0.48.0
Added
- Add official Python 3.14 support #3013.
Changed
New Contributors
@yakimkamade their first contribution in Kludex/starlette#2943@mbeijenmade their first contribution in Kludex/starlette#2939Full Changelog: https://github.com/Kludex/starlette/compare/0.47.3...0.48.0
... (truncated)
Changelog
Sourced from starlette's changelog.
0.49.1 (October 28, 2025)
This release fixes a security vulnerability in the parsing logic of the
Rangeheader inFileResponse.You can view the full security advisory: GHSA-7f5h-v6xp-fcq8
Fixed
- Optimize the HTTP ranges parsing logic 4ea6e22b489ec388d6004cfbca52dd5b147127c5
0.49.0 (October 28, 2025)
Added
- Add
encodingparameter toConfigclass #2996.- Support multiple cookie headers in
Request.cookies#3029.- Use
Literaltype forWebSocketEndpointencoding values #3027.Changed
- Do not pollute exception context in
Middlewarewhen usingBaseHTTPMiddleware#2976.0.48.0 (September 13, 2025)
Added
- Add official Python 3.14 support #3013.
Changed
0.47.3 (August 24, 2025)
Fixed
- Use
asyncio.iscoroutinefunctionfor Python 3.12 and older #2984.0.47.2 (July 20, 2025)
Fixed
- Make
UploadFilecheck for future rollover #2962.0.47.1 (June 21, 2025)
Fixed
... (truncated)
Commits
7e4b742Version 0.49.1 (#3047)4ea6e22Merge commit from fork7d88ea6Version 0.49.0 (#3046)26d66bbDo not pollute exception context in Middleware (#2976)a59397dSet encodings when reading config files (#2996)3b7f0cbtest: add test for unknown status (#3035)b09ce1adocs: fix legibility issues on sponsorship page (#3039)0f0edcfRevert "Add Marcelo Trylesinski to the license (#3025)" (#3044)3912d63docs: add social icons (#3038)4915a93Add discord to README/docs (#3034)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page.