Google-Scraper
Google-Scraper copied to clipboard
Bump fastapi from 0.59.0 to 0.65.2
Bumps fastapi from 0.59.0 to 0.65.2.
Release notes
Sourced from fastapi's releases.
0.65.2
Security fixes
- 🔒 Check Content-Type request header before assuming JSON. Initial PR #2118 by
@patrickkwang
.This change fixes a CSRF security vulnerability when using cookies for authentication in path operations with JSON payloads sent by browsers.
In versions lower than
0.65.2
, FastAPI would try to read the request payload as JSON even if thecontent-type
header sent was not set toapplication/json
or a compatible JSON media type (e.g.application/geo+json
).So, a request with a content type of
text/plain
containing JSON data would be accepted and the JSON data would be extracted.But requests with content type
text/plain
are exempt from CORS preflights, for being considered Simple requests. So, the browser would execute them right away including cookies, and the text content could be a JSON string that would be parsed and accepted by the FastAPI application.See CVE-2021-32677 for more details.
Thanks to Dima Boger for the security report! 🙇🔒
Internal
- 🔧 Update sponsors badge, course bundle. PR #3340 by
@tiangolo
.- 🔧 Add new gold sponsor Jina 🎉. PR #3291 by
@tiangolo
.- 🔧 Add new banner sponsor badge for FastAPI courses bundle. PR #3288 by
@tiangolo
.- 👷 Upgrade Issue Manager GitHub Action. PR #3236 by
@tiangolo
.0.65.1
Security fixes
- 📌 Upgrade pydantic pin, to handle security vulnerability CVE-2021-29510. PR #3213 by
@tiangolo
.0.65.0
Breaking Changes - Upgrade
- ⬆️ Upgrade Starlette to
0.14.2
, including internalUJSONResponse
migrated from Starlette. This includes several bug fixes and features from Starlette. PR #2335 by@hanneskuettner
.Translations
- 🌐 Initialize new language Polish for translations. PR #3170 by
@neternefer
.Internal
- 👷 Add GitHub Action cache to speed up CI installs. PR #3204 by
@tiangolo
.- ⬆️ Upgrade setup-python GitHub Action to v2. PR #3203 by
@tiangolo
.- 🐛 Fix docs script to generate a new translation language with
overrides
boilerplate. PR #3202 by@tiangolo
.- ✨ Add new Deta banner badge with new sponsorship tier 🙇. PR #3194 by
@tiangolo
.- 👥 Update FastAPI People. PR #3189 by
@github-actions[bot]
.- 🔊 Update FastAPI People to allow better debugging. PR #3188 by
@tiangolo
.0.64.0
Features
... (truncated)
Commits
4d91f97
🔖 Release version 0.65.2aabe2c7
📝 Update release notes377234a
🔒 Create Security Policy38b7858
📝 Update release notesfa7e3c9
🐛 Check Content-Type request header before assuming JSON (#2118)90120dd
📝 Update release notes3677254
🔧 Update sponsors badge, course bundle (#3340)40bb0c5
📝 Update release notes60918d2
🔧 Add new gold sponsor Jina 🎉 (#3291)3afce2c
📝 Update release notes- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) -
@dependabot use these labels
will set the current labels as the default for future PRs for this repo and language -
@dependabot use these reviewers
will set the current reviewers as the default for future PRs for this repo and language -
@dependabot use these assignees
will set the current assignees as the default for future PRs for this repo and language -
@dependabot use this milestone
will set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the Security Alerts page.