Skip to content

deps-dev: update werkzeug requirement from >=3.1.6 to >=3.1.8 - #133

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/werkzeug-gte-3.1.8
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/werkzeug-gte-3.1.8

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown

Updates the requirements on werkzeug to permit the latest version.

Release notes

Sourced from werkzeug's releases.

3.1.8

This is the Werkzeug 3.1.8 fix release, which fixes bugs but does not otherwise change behavior and should not result in breaking changes compared to the latest feature release.

PyPI: https://pypi.org/project/Werkzeug/3.1.8/ Changes: https://werkzeug.palletsprojects.com/page/changes/#version-3-1-8 Milestone: https://github.com/pallets/werkzeug/milestone/45?closed=1

  • Request.host and get_host return the empty string if the header is missing or has invalid characters. #3142
Changelog

Sourced from werkzeug's changelog.

Version 3.1.8

Released 2026-04-02

  • Request.host and get_host return the empty string if the header is missing or has invalid characters. :issue:3142

Version 3.1.7

Released 2026-03-23

  • parse_list_header preserves partially quoted items, discards empty items, and returns empty for unclosed quoted values. :pr:3128
  • WWWAuthenticate.to_header does not produce a trailing space when there are no parameters. :issue:3127
  • Transfer-Encoding is parsed as a set. :pr:3134
  • Request.host, get_host, and host_is_trusted validate the characters of the value. An empty value is no longer allowed. A Unix socket server address is ignored. The trusted_list argument to host_is_trusted is optional. :pr:3113
  • Fix multipart form parser handling of newline at boundary. :issue:3088
  • Response.make_conditional sets the Accept-Ranges header even if it is not a satisfiable range request. :issue:3108
  • merge_slashes merges any number of consecutive slashes. :issue:3121

Version 3.1.6

Released 2026-02-19

  • safe_join on Windows does not allow special devices names in multi-segment paths. :ghsa:29vq-49wr-vm6x
  • Response.make_conditional sets the Accept-Ranges header even if it is not a satisfiable range request. :issue:3108

Version 3.1.5

Released 2026-01-08

  • safe_join on Windows does not allow more special device names, regardless of extension or surrounding spaces. :ghsa:87hc-h4r5-73f7
  • The multipart form parser handles a \r\n sequence at a chunk boundary. This fixes the previous attempt, which caused incorrect content lengths. :issue:3065 :issue:3077

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Updates the requirements on [werkzeug](https://github.com/pallets/werkzeug) to permit the latest version.
- [Release notes](https://github.com/pallets/werkzeug/releases)
- [Changelog](https://github.com/pallets/werkzeug/blob/main/CHANGES.rst)
- [Commits](pallets/werkzeug@3.1.6...3.1.8)

---
updated-dependencies:
- dependency-name: werkzeug
  dependency-version: 3.1.8
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@github-actions

Copy link
Copy Markdown

Dependency Security Audit

Scanned: requirements.txt + requirements-dev.txt, resolved at Python 3.10 (the current resolution, and the lowest versions the published specs permit under each pydantic major)

✅ No known vulnerabilities found.

Both the resolved dependency set and the lowest versions the published specs permit are clean at HIGH and CRITICAL.

zeevmoney added a commit that referenced this pull request Sep 28, 2026
The offline tests import packaging directly to evaluate the runtime
requirements' markers, so it is listed rather than left to arrive
through pytest. This folds in the Dependabot updates for the removed
requirements-dev.txt: #131 (packaging 26.3) lands here, and the dev
group already pins what #129 (pytest 9.1.1), #132 (pytest-httpserver
1.1.5) and #133 (werkzeug 3.1.8) raise the floors to.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QoCAyNyBAmzgSkofgvKjEg
@zeevmoney

Copy link
Copy Markdown
Contributor

Included in #127, which moves the dev dependencies from requirements-dev.txt to the dev group in pyproject.toml, pinned exactly: werkzeug==3.1.8. requirements-dev.txt is removed there, so closing this in favour of #127.

@zeevmoney zeevmoney closed this Sep 28, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/pip/werkzeug-gte-3.1.8 branch September 28, 2026 14:00
zeevmoney added a commit that referenced this pull request Sep 29, 2026
Move packaging, dependencies and CI from setup.py and requirements*.txt to uv.
No SDK code changes.

Packaging:
- pyproject.toml holds the PEP 621 metadata and builds with uv_build. The
  runtime requirements match main's requirements.txt line for line.
- uv.lock is committed. setup.py, requirements*.txt, MANIFEST.in, pytest.ini
  and the Makefile are removed.

Dependencies:
- Dev tools are exact pins in a PEP 735 dev group. pydantic-v1 and
  pydantic-v2 are conflicting groups, so both lanes are locked.
- tomli is added for Python 3.10 only.
- Includes Dependabot's dev updates from #129, #131, #132 and #133.

uv version:
- CI runs the uv pinned as uv==0.12.17 in the dev group; every setup-uv step
  reads it from uv.lock. The release build job pins its own uv by version and
  checksum.
- [tool.uv] required-version is a floor, and exclude-newer is 7 days.

CI and hooks:
- Test, compatibility, audit, pre-commit and schema-drift jobs run through
  uv. Job names are unchanged.
- The publish workflow sets the version with `uv version` and builds with
  `uv build`. Build, scan and publish are unchanged.
- Dependabot uses the uv ecosystem and ignores pydantic and uv_build, which
  are updated by hand.
- A local uv-lock pre-commit hook runs `uv lock --check` with the uv on PATH.

Docs:
- New CONTRIBUTING.md. Model generation moves to scripts/generate_models.sh.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant