mecab-web-api
mecab-web-api copied to clipboard
Bump django-cors-headers from 3.13.0 to 4.3.1
Bumps django-cors-headers from 3.13.0 to 4.3.1.
Changelog
Sourced from django-cors-headers's changelog.
4.3.1 (2023-11-14)
Fixed ASGI compatibility on Python 3.12.
Thanks to Adrian Capitanu for the report in
Issue [#908](https://github.com/adamchainz/django-cors-headers/issues/908) <https://github.com/adamchainz/django-cors-headers/issues/908>
__ and Rooyal inPR [#911](https://github.com/adamchainz/django-cors-headers/issues/911) <https://github.com/adamchainz/django-cors-headers/pull/911>
__.4.3.0 (2023-10-11)
Avoid adding the
access-control-allow-credentials
header to unallowed responses.Thanks to Adam Romanek in
PR [#888](https://github.com/adamchainz/django-cors-headers/issues/888) <https://github.com/adamchainz/django-cors-headers/pull/888>
__.Support Django 5.0.
4.2.0 (2023-07-10)
- Drop Python 3.7 support.
4.1.0 (2023-06-14)
- Support Python 3.12.
4.0.0 (2023-05-12)
Add
CORS_ALLOW_PRIVATE_NETWORK
setting, which enables support for the Local Network Access draft specification.Thanks to Issac Kelly in
PR [#745](https://github.com/adamchainz/django-cors-headers/issues/745) <https://github.com/adamchainz/django-cors-headers/pull/745>
__ and jjurgens0 inPR [#833](https://github.com/adamchainz/django-cors-headers/issues/833) <https://github.com/adamchainz/django-cors-headers/pull/833>
__.Remove three headers from the default "accept list":
accept-encoding
,dnt
, andorigin
. These areForbidden header names <https://developer.mozilla.org/en-US/docs/Glossary/Forbidden_header_name>
__, which means requests JavaScript can never set them. Consequently, allowing them via CORS has no effect.Thanks to jub0bs for the report in
Issue [#842](https://github.com/adamchainz/django-cors-headers/issues/842) <https://github.com/adamchainz/django-cors-headers/issues/842>
__.Drop the
CORS_REPLACE_HTTPS_REFERER
setting andCorsPostCsrfMiddleware
. Since Django 1.9, theCSRF_TRUSTED_ORIGINS
setting has been the preferred solution to making CSRF checks pass for CORS requests. The removed setting and middleware only existed as a workaround for Django versions before 1.9.Add async support to the middleware, reducing overhead on async views.
3.14.0 (2023-02-25)
- Support Django 4.2.
... (truncated)
Commits
ca77119
Version 4.3.17fe1d62
Fix ASGI compatibliity on Python 3.12 (#911)5a0b51b
[pre-commit.ci] pre-commit autoupdate (#912)f5aa2a2
[pre-commit.ci] pre-commit autoupdate (#910)36d4d47
Upgrade requirements (#909)67ddccd
[pre-commit.ci] pre-commit autoupdate (#907)5dce59d
Migrate setuptools to use pyproject.toml (#906)2bdcf6d
Upgrade requirements (#905)0e4ec07
Upgrade django-stubs9f39b32
[pre-commit.ci] pre-commit autoupdate (#904)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)