fix(deps): update all non-major dependencies - autoclosed #59
No reviewers
Labels
No labels
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
dawid/local-flight-map!59
Loading…
Reference in a new issue
No description provided.
Delete branch "renovate/all-minor-patch"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
==3.14.1→==3.14.3==0.139.2→==0.141.1==6.1.1→==6.1.3==3.11.9→==3.12.0==2.13.4→==2.13.5==2.14.2→==2.15.0v1.14.0→v1.14.2==0.51.0→==0.52.4Release Notes
aio-libs/aiohttp (aiohttp)
v3.14.3Compare Source
===================
Bug fixes
Fixed the client dropping only the first
Authorization,CookieandProxy-Authorizationheader when a redirect crossed an origin -- by :user:arshsmith1.Related issues and pull requests on GitHub:
:issue:
13180.Fixed error message construction in the C HTTP parser -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
13222.v3.14.2Compare Source
===================
Bug fixes
Fixed :py:attr:
~aiohttp.web.StreamResponse.last_modifiedrounding a:class:
datetime.datetimewith a fractional second down.Related issues and pull requests on GitHub:
:issue:
5303.Fixed resolving
localhoston Windows to fall back withoutAI_ADDRCONFIGwhen the first lookup fails, so
localhoststill works without an activenetwork.
Related issues and pull requests on GitHub:
:issue:
5357.Rejected multipart body parts whose
Content-Lengthheader is not aplain sequence of digits (e.g.
+5,-1,1_0), matching thestrictness of the main request parser per :rfc:
9110#section-8.6-- by :user:
dxbjavid.Related issues and pull requests on GitHub:
:issue:
12794.Fixed
GunicornWebWorkerendlessly reloading when app fails during startup -- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
12879.Fixed some inconsistent case sensitivity on request methods -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
12931.Fixed
IndexError: string index out of rangeinparse_content_dispositionwhen a header parameter has an empty value (e.g.
filename=).-- by :user:
JSap0914.Related issues and pull requests on GitHub:
:issue:
12948.Fixed the
sock_readtimeout being re-armed on a keep-alive connection afterit had been returned to the pool. An idle pooled connection could be left with a
pending read timeout that fired and poisoned it, so the next request reusing the
connection failed immediately with :exc:
aiohttp.SocketTimeoutError. The readtimeout is now only rescheduled when resuming a transport that was actually
paused -- by :user:
daragok.Related issues and pull requests on GitHub:
:issue:
12953, :issue:12954.Fixed the client decompressing frames when
permessage-deflatewas not negotiated -- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
12976.Fixed
DigestAuthMiddlewareraising anIndexErroron empty domain -- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
12983.Fixed :class:
~aiohttp.DigestAuthMiddlewarecorrupting theDigestchallenge when a
WWW-Authenticateresponse offered more than oneauthentication scheme -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
12984.Fixed client not closing cleanly after an exception -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
12985.Fixed control frames breaking fragmented WebSocket messages -- by :user:
arshsmith1.Related issues and pull requests on GitHub:
:issue:
12988.Fixed
parse_content_dispositionrejecting otherwise-validContent-Dispositionheader values that contain optional whitespace (OWS)around the disposition type (e.g.
"form-data ; name=\"field\"").The disposition type is now stripped before token validation, consistent with
how parameter keys are already handled -- by :user:
JSap0914.Related issues and pull requests on GitHub:
:issue:
12996.Fixed an :exc:
IndexErrorin the pure-Python HTTP parser -- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
13001.Fixed parsing optional whitespace in Content-Disposition -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
13002.Fixed request body not being read on rejected WebSocket upgrades -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
13016.Fixed :exc:
LookupError(and an unguarded :exc:UnicodeDecodeError) escapingContent-Dispositionparsing when a multipart part supplies an extendedparameter with an unknown charset
-- by :user:
arshsmith1.Related issues and pull requests on GitHub:
:issue:
13042.Fixed
escape_quotesin the Digest authentication middleware not escapingbackslashes, so a
WWW-Authenticatechallenge value containing a backslashcould break out of its quoted-string in the generated
Authorizationheader-- by :user:
dxbjavid.Related issues and pull requests on GitHub:
:issue:
13054.Fixed Python parser not rejecting a bare
LFin the request line -- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
13136.Fixed the C HTTP parser folding the fragment into the query string for an
origin-form request target with an empty query (e.g.
/path?#frag),which diverged from the pure-Python parser -- by :user:
GiulioDER.Related issues and pull requests on GitHub:
:issue:
13171.Fixed the C parser reporting newer HTTP methods such as
QUERYas<unknown>;the method table is now derived from the vendored llhttp instead of a hand-maintained count
-- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
13174.Packaging updates and notes for downstreams
Upgraded
llhttpto v9.4.2 -- by :user:Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
12956.Contributor-facing changes
Added admin documentation on incident response and on running reproducer code
safely, covering security vulnerability handling and supply-chain, account, and
CI/infrastructure compromise -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
12914.fastapi/fastapi (fastapi)
v0.141.1Compare Source
Fixes
app.frontend(). PR #16105 by @tiangolo.Docs
FASTAPI_ENVin FastAPI CLI guide. PR #16104 by @tiangolo.v0.141.0Compare Source
Features
app.frontend(check_dir="auto"), to make local development more convenient withfastapi dev. PR #16102 by @tiangolo.v0.140.13Compare Source
Fixes
status_codebeing ignored for SSE and JSONL streaming endpoints. PR #15937 by @SAURABHSALVE.Docs
format_sse_eventdocstring rendering of\n\nterminator. PR #15613 by @AshNicolus.v0.140.12Compare Source
Fixes
format_sse_eventto comply with SSE spec. PR #15515 by @Zawwarsami16.v0.140.11Compare Source
v0.140.10Compare Source
Fixes
Internal
v0.140.9Compare Source
Fixes
exclude_defaultsnot propagated to dict keys and values injsonable_encoder. PR #16043 by @MBGrao.Internal
v0.140.8Compare Source
Fixes
include_router(). PR #15077 by @alex-raw.v0.140.7Compare Source
Refactors
Internal
v0.140.6Compare Source
Refactors
v0.140.5Compare Source
Refactors
v0.140.4Compare Source
v0.140.3Compare Source
Refactors
v0.140.2Compare Source
Refactors
Internal
v0.140.1Compare Source
Refactors
v0.140.0Compare Source
Refactors
Docs
Internal
lxml/lxml (lxml)
v6.1.3Compare Source
v6.1.2Compare Source
==================
GH#526: Some build files were missing in the sdist.
Patch by Nicola Soranzo.
Some minor corrections for error handling cases.
Other changes
ijl/orjson (orjson)
v3.12.0Compare Source
Changed
manylinux_2_39(2024) is targeted instead ofmanylinux_2_17(2012).pydantic/pydantic (pydantic)
v2.13.5Compare Source
pydantic/pydantic-settings (pydantic-settings)
v2.15.0Compare Source
What's Changed
New Contributors
Full Changelog: https://github.com/pydantic/pydantic-settings/compare/v2.14.1...v2.15.0
pypa/gh-action-pypi-publish (pypa/gh-action-pypi-publish)
v1.14.2Compare Source
This one probably won't touch you visibly so just bookmark @webknjaz's EuroPython 2026 “AI” slop rant for when it's published on YouTube or encourage him to come back with more to share next year!
🛠️ Urgh… Another release!? Again? Explain yourself!
Looking at the diff, you'll only witness updates across the dependency tree. That's it! It's not a security fix or anything like that even, no. But you'll want this update.
🧐 Tell me why..
The rest of the updates bump things related to
pypi-attestationsandsigstore, which has the most interesting backstory here. @facutuesca💰 sent a patch in #417 but a bunch more helped out.TL;DR non-pure-python projects with C-extensions tend to have dozens (sometimes hundreds) wheels to upload to PyPI per release. They are often quite big and take time to transfer over the network. People started noticing problems and coming up with DIY sharding workarounds like aio-libs/aiohttp#13226 around July 23.
On this date, projects with a good amount of bytes to publish would start getting timeouts 5 minutes after the PyPI publishing job begun. The same job that worked just fine before.
I had to start pinging upstream library and ecosystem people, on GitHub and privately, to start making sense of what was happening. Eventually, we collectively concluded that GitHub must've shortened the lifetime of their OIDC identity — it seems to have used to be 10 minutes long (at some point in the past) and is now 5 minutes, apparently. It's not documented clearly, and we have not been able to get any clarity by attempting to contact GitHub through private channels, using personal connections.
Over the course of investigation, @facutuesca💰 found and fixed a related underlying cache invalidation bug in sigstore/sigstore-python#1838, which he then coordinated propagation through the dependency chain updates in sigstore-python, pypi-attestations, gh-action-pypi-publish and gh-action-sigstore-python.
Mike's also discovered that Sigstore's Rekor slowdown seems to have become the main contributing cause of the last week's incident. He's collected some data to support this claim: https://publishing-five-minute-timeout.tiiny.site.
🫶 New Contributors
🪞 Full Diff: https://github.com/pypa/gh-action-pypi-publish/compare/v1.14.1...v1.14.2
🧔♂️ Release Manager: @webknjaz 🇺🇦
🙏 Special Thanks to @davidbrochart💰 and @Dreamsorcerer💰 for turning my attention (in #415 and in private) to the newly surfaced corner case in GitHub's behavior that only affected a narrow category of projects while many others remained blissfully unaware. @bdraco💰 came up with a DIY sharding workaround for aiohttp that served as a demo for other projects. @miketheman💰 confirmed the Warehouse-side details. Also, @jku💰 and @woodruffw💰 helped work through, review and release the Sigstore ecosystem upstream libs.
💬 Discuss on Bluesky 🦋, on Mastodon 🐘 and on GitHub.
v1.14.1Compare Source
This release was cut at EuroPython 2026 Sprints
🛠️ Internal Dependencies
@adisivaprasad💰 helped get rid of the GitHub Actions runner warning about the old Node 20 runtime being used by updating
actions/setup-pythonfrom v5.6.0 to v6.2.0 in #408.💪 New Contributors
🪞 Full Diff: https://github.com/pypa/gh-action-pypi-publish/compare/v1.14.0...v1.14.1
🧔♂️ Release Manager: @webknjaz 🇺🇦
🙏 Special Thanks to @jylenhof💰 for reminding me to work on this release!
💬 Discuss on Bluesky 🦋, on Mastodon 🐘 and on GitHub.
Kludex/uvicorn (uvicorn)
v0.52.4: Version 0.52.4Compare Source
Fixed
Dateheaders from accepted WebSocket handshakes withwebsockets-sansio(#3078)Full Changelog: https://github.com/Kludex/uvicorn/compare/0.52.3...0.52.4
v0.52.3: Version 0.52.3Compare Source
Changed
zttpto 0.0.24 and use its combined receive path, improving HTTP/1.1 request parsing performance (#3067)Full Changelog: https://github.com/Kludex/uvicorn/compare/0.52.2...0.52.3
v0.52.2: Version 0.52.2Compare Source
Fixed
zttpto 0.0.22, fixing bodyless request receives and improving HTTP/1 request parsing performance (#3063)Full Changelog: https://github.com/Kludex/uvicorn/compare/0.52.1...0.52.2
v0.52.1: Version 0.52.1Compare Source
Fixed
websockets-sansioandwsprotoimplementations, waiting for the client's close reply with a 10 second timeout instead of resetting the connection (#3053)websockets-sansioimplementation, preventing data truncation on server-initiated closes with large in-flight payloads (#3048)Content-TypeandContent-Lengthheaders from WebSocket denial responses on thewebsockets-sansioimplementation, and deliver non-UTF-8 denial bodies intact (#3041)Full Changelog: https://github.com/Kludex/uvicorn/compare/0.52.0...0.52.1
v0.52.0: Version 0.52.0Compare Source
This release adds an experimental HTTP/1.1 implementation backed by zttp, a sans-IO HTTP parser I've been developing on the side: a core written in Zig, with bindings to Python. It has been running under a fuzzer for some weeks now, and has been through multiple rounds of security auditing.
It is still experimental, so don't put it in front of production traffic yet. Try it with
--http zttp, and please send any feedback to the issue tracker.Added
zttpHTTP/1.1 implementation, selectable with--http zttp(#2979)Fixed
Full Changelog: https://github.com/Kludex/uvicorn/compare/0.51.0...0.52.0
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.