Skip to content
This repository was archived by the owner on Aug 28, 2023. It is now read-only.

Bump starlette from 0.26.1 to 0.28.0#99

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/starlette-0.28.0
Closed

Bump starlette from 0.26.1 to 0.28.0#99
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/starlette-0.28.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 8, 2023

Copy link
Copy Markdown
Contributor

Bumps starlette from 0.26.1 to 0.28.0.

Release notes

Sourced from starlette's releases.

Version 0.28.0

Changed

  • Reuse Request's body buffer for call_next in BaseHTTPMiddleware #1692.
  • Move exception handling logic to Route #2026.

Added

  • Add env parameter to Jinja2Templates, and deprecate **env_options #2159.
  • Add clear error message when httpx is not installed #2177.

Fixed

  • Allow "name" argument on templates url_for() #2127.

Full Changelog: Kludex/starlette@0.27.0...0.28.0

Version 0.27.0

This release fixes a path traversal vulnerability in StaticFiles. You can view the full security advisory: GHSA-v5gw-mw7f-84px

Added

Fixed

  • Replace commonprefix by commonpath on StaticFiles 1797de4.
  • Convert ImportErrors into ModuleNotFoundError #2135.
  • Correct the RuntimeError message content in websockets #2141.

Full Changelog: Kludex/starlette@0.26.1...0.27.0

Changelog

Sourced from starlette's changelog.

0.28.0

June 7, 2023

Changed

  • Reuse Request's body buffer for call_next in BaseHTTPMiddleware #1692.
  • Move exception handling logic to Route #2026.

Added

  • Add env parameter to Jinja2Templates, and deprecate **env_options #2159.
  • Add clear error message when httpx is not installed #2177.

Fixed

  • Allow "name" argument on templates url_for() #2127.

0.27.0

May 16, 2023

This release fixes a path traversal vulnerability in StaticFiles. You can view the full security advisory: GHSA-v5gw-mw7f-84px

Added

Fixed

  • Replace commonprefix by commonpath on StaticFiles 1797de4.
  • Convert ImportErrors into ModuleNotFoundError #2135.
  • Correct the RuntimeError message content in websockets #2141.
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [starlette](https://github.com/encode/starlette) from 0.26.1 to 0.28.0.
- [Release notes](https://github.com/encode/starlette/releases)
- [Changelog](https://github.com/encode/starlette/blob/master/docs/release-notes.md)
- [Commits](Kludex/starlette@0.26.1...0.28.0)

---
updated-dependencies:
- dependency-name: starlette
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Jun 8, 2023
@github-actions github-actions Bot enabled auto-merge (squash) June 8, 2023 02:06
@codecov-commenter

Copy link
Copy Markdown

Codecov Report

Merging #99 (ac77bd8) into main (ce294fd) will not change coverage.
The diff coverage is n/a.

❗ Your organization is not using the GitHub App Integration. As a result you may experience degraded service beginning May 15th. Please install the Github App Integration for your organization. Read more.

Impacted file tree graph

@@           Coverage Diff           @@
##             main      #99   +/-   ##
=======================================
  Coverage   97.09%   97.09%           
=======================================
  Files          20       20           
  Lines         344      344           
=======================================
  Hits          334      334           
  Misses         10       10           

Continue to review full report in Codecov by Sentry.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 53d9d5e...ac77bd8. Read the comment docs.

@dependabot @github

dependabot Bot commented on behalf of github Jul 14, 2023

Copy link
Copy Markdown
Contributor Author

Superseded by #106.

@dependabot dependabot Bot closed this Jul 14, 2023
auto-merge was automatically disabled July 14, 2023 01:23

Pull request was closed

@dependabot dependabot Bot deleted the dependabot/pip/starlette-0.28.0 branch July 14, 2023 01:23
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependencies Pull requests that update a dependency file python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant