Bump werkzeug from 0.15.3 to 3.0.2
Bumps werkzeug from 0.15.3 to 3.0.2.
Release notes
Sourced from werkzeug's releases.
3.0.2
This is a fix release for the 3.0.x feature branch.
3.0.1
This is a security release for the 3.0.x feature branch.
3.0.0
This is a feature release, which includes new features, removes previously deprecated code, and adds new deprecations. The 3.0.x branch is now the supported fix branch, the 2.3.x branch will become a tag marking the end of support for that branch. We encourage everyone to upgrade, and to use a tool such as pip-tools to pin all dependencies and control upgrades. Test with warnings treated as errors to be able to adapt to deprecation warnings early.
- Changes: https://werkzeug.palletsprojects.com/en/3.0.x/changes/#version-3-0-0
- Milestone: https://github.com/pallets/werkzeug/milestone/21?closed=1
2.3.8
This is a security release for the 2.3.x feature branch.
2.3.7
This is a fix release for the 2.3.x feature branch.
- Changes: https://werkzeug.palletsprojects.com/en/2.3.x/changes/#version-2-3-7
- Milestone: https://github.com/pallets/werkzeug/milestone/33?closed=1
2.3.6
This is a fix release for the 2.3.x feature branch.
- Changes: https://werkzeug.palletsprojects.com/en/2.3.x/changes/#version-2-3-6
- Milestone: https://github.com/pallets/werkzeug/milestone/32?closed=1
2.3.5
This is a fix release for the 2.3.x feature branch.
- Changes: https://werkzeug.palletsprojects.com/en/2.3.x/changes/#version-2-3-5
- Milestone: https://github.com/pallets/werkzeug/milestone/31?closed=1
2.3.4
This is a fix release for the 2.3.x release branch.
- Changes: https://werkzeug.palletsprojects.com/en/2.3.x/changes/#version-2-3-4
- Milestone: https://github.com/pallets/werkzeug/milestone/30?closed=1
2.3.3
This is a fix release for the 2.3.x release branch.
... (truncated)
Changelog
Sourced from werkzeug's changelog.
Version 3.0.2
Released 2024-04-01
- Ensure setting merge_slashes to False results in NotFound for repeated-slash requests against single slash routes. :issue:
2834- Fix handling of TypeError in TypeConversionDict.get() to match ValueErrors. :issue:
2843- Fix response_wrapper type check in test client. :issue:
2831- Make the return type of
MultiPartParser.parsemore precise. :issue:2840- Raise an error if converter arguments cannot be parsed. :issue:
2822Version 3.0.1
Released 2023-10-24
- Fix slow multipart parsing for large parts potentially enabling DoS attacks. :cwe:
CWE-407Version 3.0.0
Released 2023-09-30
- Remove previously deprecated code. :pr:
2768- Deprecate the
__version__attribute. Use feature detection, orimportlib.metadata.version("werkzeug"), instead. :issue:2770generate_password_hashuses scrypt by default. :issue:2769- Add the
"werkzeug.profiler"item to the WSGIenvirondictionary passed toProfilerMiddleware'sfilename_formatfunction. It contains theelapsedandtimevalues for the profiled request. :issue:2775- Explicitly marked the PathConverter as non path isolating. :pr:
2784Version 2.3.8
Released 2023-11-08
- Fix slow multipart parsing for large parts potentially enabling DoS attacks. :cwe:
CWE-407Version 2.3.7
... (truncated)
Commits
d70dceaRelease version 3.0.2ad703fdBump the slsa-github-generator action version5741398Raise an error if the converter arguments cannot be parsed0b47237Fix issue with repeated-slash requests redirectingf516c40Handle TypeError in TypeConversionDict4c09d1bAdd missing CHANGES entry for #28327ab3823Fix: Useissubclassinstead ofisinstance4e5bdcaMake the exception tests more robust70ad4d6Use more precise type for formparser.MultiPartParser.parse return6eafc0eMerge branch '2.3.x' into 3.0.x- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency -
@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)