This repository was archived by the owner on Nov 21, 2025. It is now read-only.
Update all dependencies #77
Open
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
==1.1.0->==1.6.5==0.14.3->==0.18.0==3.1.2->==3.1.6==3.4.1->==3.10==1.4.43->==2.0.44==2.2.2->==3.1.3v3->v6==22.1.0->==25.1.0==3.8.3->==3.13.2==1.8.1->==1.17.2==3.5.2->==3.11.0==1.7.7->==2.3.1==4.0.1->==5.0.0==4.11.1->==4.14.2==22.10.0->==25.11.0==5.0.1->==6.3.0==6.5.0->==7.12.0==1.3.0->==2.3.0==1.10.0->==2.32.1==0.86.0->==0.121.3==0.9.0->==1.0.0==3.8.0->==3.20.0==5.0.4->==7.3.0==20.1.0->==23.0.011.5.0->11.11.1==0.23.0->==0.28.1==5.10.1->==7.0.0==2.1.2->==2.2.0==4.9.1->==6.0.2==0.5.2->==0.8.1==2.1.1->==2.2.7==3.8.1->==3.11.4==0.5.6->==0.5.7==1.0.5->==1.3.2==5.9.1->==7.1.0==4.21.9->==6.33.1==0.10.6->==0.10.12==1.10.1->==1.19.0==7.2.0->==9.0.1==0.20.1->==1.3.0==4.0.0->==7.0.0==3.3->==3.5==3.0.2->==3.8.0==0.0.5->==0.0.20==4.3.4->==7.1.0==2.28.1->==2.32.5==1.10.1->==2.45.0==0.19.0->==0.38.0Release Notes
authlib/authlib (Authlib)
v1.6.5Compare Source
What's Changed
requestparam to RFC7591generate_client_infoandgenerate_client_secretmethods by @azmeuk in #825New Contributors
Full Changelog: authlib/authlib@v1.6.4...v1.6.5
v1.6.4Compare Source
What's Changed
InsecureTransportErrorraising by @azmeuk in #810New Contributors
Full Changelog: authlib/authlib@v1.6.3...v1.6.4
v1.6.3: Version 1.6.3Compare Source
What's Changed
id_token_signed_response_algclient metadata by @azmeuk in #802Full Changelog: authlib/authlib@v1.6.2...v1.6.3
v1.6.2: Version 1.6.2Compare Source
What's Changed
Full Changelog: authlib/authlib@v1.6.1...v1.6.2
v1.6.1: Version 1.6.1Compare Source
v1.6.0: Version 1.6.0Compare Source
v1.5.2: Version 1.5.2Compare Source
Released on Apr 1, 2025
claims_clsparameter for client's parse_id_token method. #725v1.5.1: Version 1.5.1Compare Source
Released on Feb 28, 2025
v1.5.0: Version 1.5.0Compare Source
v1.4.1: Version 1.4.1Compare Source
v1.4.0: Version 1.4.0Compare Source
Bugfixes
Breaking changes
v1.3.2: Version 1.3.2Compare Source
quoteclient id and secret.unquotebasic auth header for authorization server.v1.3.1: Version 1.3.1Compare Source
Prevent
OctKeyto import ssh and PEM strings.v1.3.0: Version 1.3.0Compare Source
Bug fixes
Breaking changes
v1.2.1: Version 1.2.1Compare Source
ClientSecretJWT.signmethod, via #552authorize_redirectfor Starlette v0.26.0, via #533has_client_secretmethod and documentation, via #513request_invalidandtoken_revokedremaining occurencesand documentation. #514
grant_typesandresponse_typesdefault values, via #509v1.2.0: Version 1.2.0Compare Source
request.bodytoResourceProtector, #485.flask.ginstead of_app_ctx_stack, #482.headersparameter back toClientSecretJWT, #457.realmparameter in OAuth 1 clients, #339.default_timeoutfor requestsOAuth2SessionandAssertionSession.jwk.loadsandjwk.dumpspallets/jinja (Jinja2)
v3.1.6Compare Source
Released 2025-03-05
|attrfilter does not bypass the environment's attribute lookup,allowing the sandbox to apply its checks. :ghsa:
cpwx-vrp4-4pq7v3.1.5Compare Source
Released 2024-12-21
str.format, such asby passing a stored reference to a filter that calls its argument.
:ghsa:
q2x7-8rv6-6q7hissues with names that contain f-string syntax.
:issue:
1792, :ghsa:gmj6-6f8f-6699clearandpopon known mutable sequencetypes. :issue:
2032renderfor an async template usesasyncio.run.:pr:
1952auto_aiterwarnings. :pr:1960aclose-ableAsyncGeneratorfromTemplate.generate_async. :pr:1960root_render_func()unclosed inTemplate.generate_async. :pr:1960:pr:
1960concatfunction for the current environmentwhen calling block references. :issue:
1701|uniqueasync-aware, allowing it to be used after anotherasync-aware filter. :issue:
1781|intfilter handlesOverflowErrorfrom scientific notation.:issue:
1921{% set ... %}call. :issue:
2021copy/pickle/etc) interaction withUndefinedobjects. :issue:
2025copy/picklesupport for the internalmissingobject.:issue:
2027Environment.overlay(enable_async)is applied correctly. :pr:2061FileSystemLoaderincludes the paths that weresearched. :issue:
1661PackageLoadershows a clearer error message when the package does notcontain the templates directory. :issue:
17051880urlizedoes not addmailto:to values like@a@b. :pr:1870@pass_context`` can be used with the ``|select`` filter. :issue:1624`setfor multiple assignment (a, b = 1, 2) does not fail when thetarget is a namespace attribute. :issue:
1413setin all branches of{% if %}{% elif %}{% else %}blocksdoes not cause the variable to be considered initially undefined.
:issue:
1253v3.1.4Compare Source
Released 2024-05-05
xmlattrfilter does not allow keys with/solidus,>greater-than sign, or
=equals sign, in addition to disallowing spaces.Regardless of any validation done by Jinja, user input should never be used
as keys to this filter, or must be separately validated first.
:ghsa:
h75v-3vvj-5mfjv3.1.3Compare Source
Released 2024-01-10
empty. :pr:
1858xmlattrfilter does not allow keys with spaces. :ghsa:h5c8-rqwp-cp95{% trans %}blocksmore helpful. :pr:
1918Python-Markdown/markdown (Markdown)
v3.10Compare Source
v3.9Compare Source
v3.8.2Compare Source
Fixed
codecsdeprecation in Python 3.14.<fooand Python 3.14.v3.8.1Compare Source
Fixed
md_in_html(#1526).v3.8Compare Source
Changed
abbrextension by introducing methodcreate_element(#1483).non-redundant cases to the newer test framework.
Fixed
attr_listontoc(#1493).md_in_htmlprocesses content inside "markdown" blocks as they areparsed outside of "markdown" blocks to keep things more consistent for
third-party extensions (#1503).
md_in_htmlhandle tags within inline code blocks better (#1075).md_in_htmlfix handling of one-liner block HTML handling (#1074).<center>is treated like a block-level element (#1481).abbrextension respectsAtomicStringand does not processperceived abbreviations in these strings (#1512).
smartyextension correctly renders nested closing quotes (#1514).v3.7Compare Source
Changed
Refactor
abbrExtensionA new
AbbrTreeprocessorhas been introduced, which replaces the now deprecatedAbbrInlineProcessor. Abbreviation processing now happens after Attribute Lists,avoiding a conflict between the two extensions (#1460).
The
AbbrPreprocessorclass has been renamed toAbbrBlockprocessor, whichbetter reflects what it is.
AbbrPreprocessorhas been deprecated.A call to
Markdown.reset()now clears all previously defined abbreviations.Abbreviations are now sorted by length before executing
AbbrTreeprocessorto ensure that multi-word abbreviations are implemented even if an abbreviation
exists for one of those component words. (#1465)
Abbreviations without a definition are now ignored. This avoids applying
abbr tags to text without a title value.
Added an optional
glossaryconfiguration option to the abbreviations extension.This provides a simple and efficient way to apply a dictionary of abbreviations
to every page.
Abbreviations can now be disabled by setting their definition to
""or''.This can be useful when using the
glossaryoption.Fixed
v3.6Compare Source
Changed
Refactor TOC Sanitation
striptagsis provided to convert headings to plain text.Unlike, the
markupsafeimplementation, HTML entities are not unescaped.name, richhtml, and unescaped rawdata-toc-labelaresaved to
toc_tokens, allowing users to access the full rich text content ofthe headings directly from
toc_tokens.data-toc-labelis sanitized separate from heading contentbefore being written to
name. This fixes a bug which allowed markup throughin certain circumstances. To access the raw unsanitized data, retrieve the
value from
token['data-toc-label']directly.html.unescapecall is made just prior to callingslugifyso thatslugifyonly operates on Unicode characters. Note thathtml.unescapeisnot run on
name,html, ordata-toc-label.get_nameandstashedHTML2textdefined in thetocextensionare both deprecated. Instead, third party extensions should use some
combination of the new functions
run_postprocessors,render_inner_htmlandstriptags.Fixed
scripts/*.pyin the generated source tarballs (#1430).^) and square brackets (]) but explicitly excludebackslashes (
\) from abbreviations (#1444).attr_list,fenced_code), quoted attribute values arenow allowed to contain curly braces (
}) (#1414).v3.5.2Compare Source
Fixed
convertFile- it accepts only bytes-based buffers.Also remove legacy checks from Python 2 (#1400)
AdmonitionProcessor.content_indentunset(#1404)
InlineProcessorwithAtomicString(#1406).codehilitewith an emptycodetag (#1405).v3.5.1Compare Source
Fixed
trigger quadratic line counting behavior (#1392).
v3.5Compare Source
v3.4.4Compare Source
v3.4.3Compare Source
v3.4.2Compare Source
actions/checkout (actions/checkout)
v6Compare Source
v5Compare Source
v4Compare Source
url-helper.tsnow leverages well-known environment variables by @jww3 in #1941isGhesby @jww3 in #1946Tinche/aiofiles (aiofiles)
v25.1.0Compare Source
(#219)
ruffformatter and linter.#216
#204
v24.1.0Compare Source
os.linkconditionally to fix importing on android.#175
aiofiles.os.__all__when running on Windows.aiofiles.os.path.abspathandaiofiles.os.getcwd.#174
#184
v23.2.1Compare Source
os.statvfsconditionally to fix importing on non-UNIX systems.#171 #172
v23.2.0Compare Source
#166 #168
aiofiles.tempfile.NamedTemporaryFilenow accepts adelete_on_closeargument, just like the stdlib version.aiofiles.tempfile.NamedTemporaryFileno longer exposes adeleteattribute, just like the stdlib version.aiofiles.os.statvfsandaiofiles.os.path.ismount.#162
#169
v23.1.0Compare Source
aiofiles.os.access.#146
aiofiles.tempfile.temptypes.AsyncSpooledTemporaryFile.softspace.#151
aiofiles.stdin,aiofiles.stdin_bytes, and other stdio streams.#154
asyncio.get_running_loop(vsasyncio.get_event_loop) internally.aio-libs/aiohttp (aiohttp)
v3.13.2: 3.13.2Compare Source
Bug fixes
Fixed cookie parser to continue parsing subsequent cookies when encountering a malformed cookie that fails regex validation, such as Google's
g_statecookie with unescaped quotes -- by :user:bdraco.Related issues and pull requests on GitHub:
#11632.
Fixed loading netrc credentials from the default :file:
~/.netrc(:file:~/_netrcon Windows) location when the :envvar:NETRCenvironment variable is not set -- by :user:bdraco.Related issues and pull requests on GitHub:
#11713, #11714.
Fixed WebSocket compressed sends to be cancellation safe. Tasks are now shielded during compression to prevent compressor state corruption. This ensures that the stateful compressor remains consistent even when send operations are cancelled -- by :user:
bdraco.Related issues and pull requests on GitHub:
#11725.
v3.13.1Compare Source
===================
Features
Make configuration options in
AppRunneralso available inrun_app()-- by :user:
Cycloctane.Related issues and pull requests on GitHub:
:issue:
11633.Bug fixes
Switched to
backports.zstdfor Python <3.14 and fixed zstd decompression for chunked zstd streams -- by :user:ZhaoMJ.Note: Users who installed
zstandardfor support on Python <3.14 will now need to installbackports.zstdinstead (installingaiohttp[speedups]will do this automatically).Related issues and pull requests on GitHub:
:issue:
11623.Updated
Content-Typeheader parsing to returnapplication/octet-streamwhen header contains invalid syntax.See :rfc:
9110#section-8.3-5.-- by :user:
sgaist.Related issues and pull requests on GitHub:
:issue:
10889.Fixed Python 3.14 support when built without
zstdsupport -- by :user:JacobHenner.Related issues and pull requests on GitHub:
:issue:
11603.Fixed blocking I/O in the event loop when using netrc authentication by moving netrc file lookup to an executor -- by :user:
bdraco.Related issues and pull requests on GitHub:
:issue:
11634.Fixed routing to a sub-application added via
.add_domain()not workingif the same path exists on the parent app. -- by :user:
Dreamsorcerer.Related issues and pull requests on GitHub:
:issue:
11673.Packaging updates and notes for downstreams
Moved core packaging metadata from :file:
setup.cfgto :file:pyproject.tomlper :pep:621-- by :user:
cdce8p.Related issues and pull requests on GitHub:
:issue:
9951.v3.13.0Compare Source
===================
Features
Added support for Python 3.14.
Related issues and pull requests on GitHub:
:issue:
10851, :issue:10872.Added support for free-threading in Python 3.14+ -- by :user:
kumaraditya303.*Related issues and pull
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.