flask-wtform-tutorial
flask-wtform-tutorial copied to clipboard
Bump werkzeug from 2.1.1 to 2.2.3
Bumps werkzeug from 2.1.1 to 2.2.3.
Release notes
Sourced from werkzeug's releases.
2.2.3
This is a fix release for the 2.2.x release branch.
- Changes: https://werkzeug.palletsprojects.com/en/2.2.x/changes/#version-2-2-3
- Milestone: https://github.com/pallets/werkzeug/milestone/26?closed=1
This release contains security fixes for:
- https://github.com/pallets/werkzeug/security/advisories/GHSA-xg9f-g7g7-2323
- https://github.com/pallets/werkzeug/security/advisories/GHSA-px8h-6qxv-m22q
2.2.2
This is a fix release for the 2.2.0 feature release.
- Changes: https://werkzeug.palletsprojects.com/en/2.2.x/changes/#version-2-2-2
- Milestone: https://github.com/pallets/werkzeug/milestone/25?closed=1
2.2.1
This is a fix release for the 2.2.0 feature release.
- Changes: https://werkzeug.palletsprojects.com/en/2.2.x/changes/#version-2-2-1
- Milestone: https://github.com/pallets/werkzeug/milestone/24?closed=1
2.2.0
This is a feature release, which includes new features and removes previously deprecated features. The 2.2.x branch is now the supported bugfix branch, the 2.1.x branch will become a tag marking the end of support for that branch. We encourage everyone to upgrade, and to use a tool such as pip-tools to pin all dependencies and control upgrades.
- Changes: https://werkzeug.palletsprojects.com/en/2.2.x/changes/#version-2-2-0
- Milestone: https://github.com/pallets/werkzeug/milestone/20?closed=1
2.1.2
This is a fix release for the 2.1.0 feature release.
Changelog
Sourced from werkzeug's changelog.
Version 2.2.3
Released 2023-02-14
- Ensure that URL rules using path converters will redirect with strict slashes when the trailing slash is missing. :issue:
2533- Type signature for
get_jsonspecifies that return type is not optional whensilent=False. :issue:2508parse_content_range_headerreturnsNonefor a value likebytes */-1where the length is invalid, instead of raising anAssertionError. :issue:2531- Address remaining
ResourceWarningrelated to the socket used byrun_simple. Removeprepare_socket, which now happens when creating the server. :issue:2421- Update pre-existing headers for
multipart/form-datarequests with the test client. :issue:2549- Fix handling of header extended parameters such that they are no longer quoted. :issue:
2529LimitedStream.readworks correctly when wrapping a stream that may not return the requested size in onereadcall. :issue:2558- A cookie header that starts with
=is treated as an empty key and discarded, rather than stripping the leading==.- Specify a maximum number of multipart parts, default 1000, after which a
RequestEntityTooLargeexception is raised on parsing. This mitigates a DoS attack where a larger number of form/file parts would result in disproportionate resource use.Version 2.2.2
Released 2022-08-08
- Fix router to restore the 2.1
strict_slashes == Falsebehaviour whereby leaf-requests match branch rules and vice versa. :pr:2489- Fix router to identify invalid rules rather than hang parsing them, and to correctly parse
/within converter arguments. :pr:2489- Update subpackage imports in :mod:
werkzeug.routingto use theimport assyntax for explicitly re-exporting public attributes. :pr:2493- Parsing of some invalid header characters is more robust. :pr:
2494- When starting the development server, a warning not to use it in a production deployment is always shown. :issue:
2480LocalProxy.__wrapped__is always set to the wrapped object when the proxy is unbound, fixing an issue in doctest that would cause it to fail. :issue:2485- Address one
ResourceWarningrelated to the socket used byrun_simple. :issue:2421
... (truncated)
Commits
22a254frelease version 2.2.3517cac5Merge pull request from GHSA-xg9f-g7g7-2323babc8d9rewrite docs about request data limits09449eeclean up docsfe899d0limit the maximum number of multipart form partscf275f4Merge pull request from GHSA-px8h-6qxv-m22q8c2b4b8don't strip leading = when parsing cookie7c7ce5c[pre-commit.ci] pre-commit autoupdate (#2585)19ae03e[pre-commit.ci] auto fixes from pre-commit.com hooksa83d3b8[pre-commit.ci] pre-commit autoupdate- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)