label-studio-ml-backend
label-studio-ml-backend copied to clipboard
chore(deps): bump werkzeug from 2.0.2 to 2.3.8 in /label_studio_ml/examples/substring_matching
Bumps werkzeug from 2.0.2 to 2.3.8.
Release notes
Sourced from werkzeug's releases.
2.3.8
This is a security release for the 2.3.x feature branch.
2.3.7
This is a fix release for the 2.3.x feature branch.
- Changes: https://werkzeug.palletsprojects.com/en/2.3.x/changes/#version-2-3-7
- Milestone: https://github.com/pallets/werkzeug/milestone/33?closed=1
2.3.6
This is a fix release for the 2.3.x feature branch.
- Changes: https://werkzeug.palletsprojects.com/en/2.3.x/changes/#version-2-3-6
- Milestone: https://github.com/pallets/werkzeug/milestone/32?closed=1
2.3.5
This is a fix release for the 2.3.x feature branch.
- Changes: https://werkzeug.palletsprojects.com/en/2.3.x/changes/#version-2-3-5
- Milestone: https://github.com/pallets/werkzeug/milestone/31?closed=1
2.3.4
This is a fix release for the 2.3.x release branch.
- Changes: https://werkzeug.palletsprojects.com/en/2.3.x/changes/#version-2-3-4
- Milestone: https://github.com/pallets/werkzeug/milestone/30?closed=1
2.3.3
This is a fix release for the 2.3.x release branch.
- Changes: https://werkzeug.palletsprojects.com/en/2.3.x/changes/#version-2-3-3
- Milestone: https://github.com/pallets/werkzeug/milestone/29?closed=1
2.3.2
This is a fix release for the 2.3.x release branch.
- Changes: https://werkzeug.palletsprojects.com/en/2.3.x/changes/#version-2-3-2
- Milestone: https://github.com/pallets/werkzeug/milestone/28?closed=1
2.3.1
This is a fix release for the 2.3.x release branch.
- Changes: https://werkzeug.palletsprojects.com/en/2.3.x/changes/#version-2-3-1
- Milestone: https://github.com/pallets/werkzeug/milestone/27?closed=1
2.3.0
This is a feature release, which includes new features, removes previously deprecated code, and adds new deprecations. The 2.3.x branch is now the supported fix branch, the 2.2.x branch will become a tag marking the end of support for that branch. We encourage everyone to upgrade, and to use a tool such as pip-tools to pin all dependencies and control upgrades. Test with warnings treated as errors to be able to adapt to deprecation warnings early.
... (truncated)
Changelog
Sourced from werkzeug's changelog.
Version 2.3.8
Released 2023-11-08
- Fix slow multipart parsing for large parts potentially enabling DoS attacks. :cwe:
CWE-407
Version 2.3.7
Released 2023-08-14
- Use
flit_core
instead ofsetuptools
as build backend.- Fix parsing of multipart bodies. :issue:
2734
- Adjust index of last newline in data start. :issue:
2761
- Parsing ints from header values strips spacing first. :issue:
2734
- Fix empty file streaming when testing. :issue:
2740
- Clearer error message when URL rule does not start with slash. :pr:
2750
Accept
q
value can be a float without a decimal part. :issue:2751
Version 2.3.6
Released 2023-06-08
FileStorage.content_length
does not fail if the form data did not provide a value. :issue:2726
Version 2.3.5
Released 2023-06-07
- Python 3.12 compatibility. :issue:
2704
- Fix handling of invalid base64 values in
Authorization.from_header
. :issue:2717
- The debugger escapes the exception message in the page title. :pr:
2719
- When binding
routing.Map
, a long IDNAserver_name
with a port does not fail encoding. :issue:2700
iri_to_uri
shows a deprecation warning instead of an error when passing bytes. :issue:2708
- When parsing numbers in HTTP request headers such as
Content-Length
, only ASCII digits are accepted rather than any format that Python'sint
andfloat
accept. :issue:2716
Version 2.3.4
... (truncated)
Commits
dc90943
Release version 2.3.8f230020
Fix: slow multipart parsing for huge files with few CR/LF characters26f3e95
reformat lines828bab4
Start version 2.3.83c2ba3d
Release version 2.3.7ac9974c
Fix qvalue parsing (#2753)88f4ed6
qvalue parsing accepts float without decimaldd1f137
Fix: Improve Error Message (#2750)fdc295a
clearer url rule slash errora0f4bf4
fix: improve error message- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page.
Dependabot couldn't find any dependency files in the directory. Because of this, Dependabot cannot update this pull request.
@dependabot rebase
Dependabot couldn't find any dependency files in the directory. Because of this, Dependabot cannot update this pull request.
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version
or @dependabot ignore this minor version
. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore
condition with the desired update_types
to your config file.
If you change your mind, just re-open this PR and I'll resolve any conflicts on it.