subdah
subdah copied to clipboard
Bump starlette from 0.25.0 to 0.27.0
Bumps starlette from 0.25.0 to 0.27.0.
Release notes
Sourced from starlette's releases.
Version 0.27.0
This release fixes a path traversal vulnerability in
StaticFiles
. You can view the full security advisory: https://github.com/encode/starlette/security/advisories/GHSA-v5gw-mw7f-84pxAdded
- Minify JSON websocket data via
send_json
encode/starlette#2128Fixed
- Replace
commonprefix
bycommonpath
onStaticFiles
1797de4.- Convert ImportErrors into ModuleNotFoundError #2135.
- Correct the RuntimeError message content in websockets #2141.
Full Changelog: https://github.com/encode/starlette/compare/0.26.1...0.27.0
Version 0.26.1
Fixed
- Fix typing of Lifespan to allow subclasses of Starlette #2077.
Version 0.26.0.post1
Fixed
- Replace reference from Events to Lifespan on the mkdocs.yml #2072.
Version 0.26.0
Added
- Support lifespan state #2060, #2065 and #2064.
Changed
- Change
url_for
signature to return aURL
instance #1385.Fixed
- Allow "name" argument on
url_for()
andurl_path_for()
#2050.Deprecated
- Deprecate
on_startup
andon_shutdown
events #2070.Full Changelog: https://github.com/encode/starlette/compare/0.25.0...0.26.0
Changelog
Sourced from starlette's changelog.
0.27.0
May 16, 2023
This release fixes a path traversal vulnerability in
StaticFiles
. You can view the full security advisory: https://github.com/encode/starlette/security/advisories/GHSA-v5gw-mw7f-84pxAdded
- Minify JSON websocket data via
send_json
encode/starlette#2128Fixed
- Replace
commonprefix
bycommonpath
onStaticFiles
1797de4.- Convert ImportErrors into ModuleNotFoundError #2135.
- Correct the RuntimeError message content in websockets #2141.
0.26.1
March 13, 2023
Fixed
- Fix typing of Lifespan to allow subclasses of Starlette #2077.
0.26.0.post1
March 9, 2023
Fixed
- Replace reference from Events to Lifespan on the mkdocs.yml #2072.
0.26.0
March 9, 2023
Added
- Support lifespan state #2060, #2065 and #2064.
Changed
- Change
url_for
signature to return aURL
instance #1385.Fixed
- Allow "name" argument on
url_for()
andurl_path_for()
#2050.Deprecated
- Deprecate
on_startup
andon_shutdown
events #2070.
Commits
0c4b68a
Version 0.27.0 (#2147)1797de4
Merge pull request from GHSA-v5gw-mw7f-84px24c1fac
add 3rd party middleware link for secure-cookie (#2144)4bab981
Run black before ruff (#2143)7c4fd9c
Correct the RuntimeError message content in websockets (#2141)9ebfafa
Bump ruff from 0.0.260 to 0.0.263 (#2136)b784599
Bump mkdocs-material from 9.0.15 to 9.1.8 (#2139)7d8892d
Bump mypy from 1.0.1 to 1.2.0 (#2137)8fd1b19
Bump coverage from 7.1.0 to 7.2.5 (#2138)c7385f0
Bump pytest from 7.2.2 to 7.3.1 (#2140)- Additional commits viewable in compare view
You can trigger a rebase of this PR by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page.