Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Jan 18, 2024

This PR contains the following updates:

Package Change Age Confidence
Flask (changelog) ==3.0.0==3.1.2 age confidence

Release Notes

pallets/flask (Flask)

v3.1.2

Compare Source

Released 2025-08-19

  • stream_with_context does not fail inside async views. :issue:5774
  • When using follow_redirects in the test client, the final state
    of session is correct. :issue:5786
  • Relax type hint for passing bytes IO to send_file. :issue:5776

v3.1.1

Compare Source

Released 2025-05-13

  • Fix signing key selection order when key rotation is enabled via
    SECRET_KEY_FALLBACKS. :ghsa:4grg-w6v8-c28g
  • Fix type hint for cli_runner.invoke. :issue:5645
  • flask --help loads the app and plugins first to make sure all commands
    are shown. :issue:5673
  • Mark sans-io base class as being able to handle views that return
    AsyncIterable. This is not accurate for Flask, but makes typing easier
    for Quart. :pr:5659

v3.1.0

Compare Source

Released 2024-11-13

  • Drop support for Python 3.8. :pr:5623
  • Update minimum dependency versions to latest feature releases.
    Werkzeug >= 3.1, ItsDangerous >= 2.2, Blinker >= 1.9. :pr:5624,5633
  • Provide a configuration option to control automatic option
    responses. :pr:5496
  • Flask.open_resource/open_instance_resource and
    Blueprint.open_resource take an encoding parameter to use when
    opening in text mode. It defaults to utf-8. :issue:5504
  • Request.max_content_length can be customized per-request instead of only
    through the MAX_CONTENT_LENGTH config. Added
    MAX_FORM_MEMORY_SIZE and MAX_FORM_PARTS config. Added documentation
    about resource limits to the security page. :issue:5625
  • Add support for the Partitioned cookie attribute (CHIPS), with the
    SESSION_COOKIE_PARTITIONED config. :issue:5472
  • -e path takes precedence over default .env and .flaskenv files.
    load_dotenv loads default files in addition to a path unless
    load_defaults=False is passed. :issue:5628
  • Support key rotation with the SECRET_KEY_FALLBACKS config, a list of old
    secret keys that can still be used for unsigning. Extensions will need to
    add support. :issue:5621
  • Fix how setting host_matching=True or subdomain_matching=False
    interacts with SERVER_NAME. Setting SERVER_NAME no longer restricts
    requests to only that domain. :issue:5553
  • Request.trusted_hosts is checked during routing, and can be set through
    the TRUSTED_HOSTS config. :issue:5636

v3.0.3

Compare Source

Released 2024-04-07

  • The default hashlib.sha1 may not be available in FIPS builds. Don't
    access it at import time so the developer has time to change the default.
    :issue:5448
  • Don't initialize the cli attribute in the sansio scaffold, but rather in
    the Flask concrete class. :pr:5270

v3.0.2

Compare Source

Released 2024-02-03

  • Correct type for jinja_loader property. :issue:5388
  • Fix error with --extra-files and --exclude-patterns CLI options.
    :issue:5391

v3.0.1

Compare Source

Released 2024-01-18

  • Correct type for path argument to send_file. :issue:5336
  • Fix a typo in an error message for the flask run --key option. :pr:5344
  • Session data is untagged without relying on the built-in json.loads
    object_hook. This allows other JSON providers that don't implement that.
    :issue:5381
  • Address more type findings when using mypy strict mode. :pr:5383

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the type/dependencies Issue or PR related to dependencies label Jan 18, 2024
@renovate renovate bot changed the title chore(deps): update dependency flask to v3.0.1 chore(deps): update dependency flask to v3.0.2 Feb 3, 2024
@renovate renovate bot force-pushed the renovate/flask-3.x branch from 3057ab0 to 8207bff Compare February 3, 2024 22:07
@renovate renovate bot changed the title chore(deps): update dependency flask to v3.0.2 chore(deps): update dependency flask to v3.0.3 Apr 7, 2024
@renovate renovate bot force-pushed the renovate/flask-3.x branch from 8207bff to 01d1496 Compare April 7, 2024 20:28
@renovate renovate bot changed the title chore(deps): update dependency flask to v3.0.3 chore(deps): update dependency flask to v3.1.0 Nov 13, 2024
@renovate renovate bot force-pushed the renovate/flask-3.x branch 5 times, most recently from 5a8ce6b to 3024053 Compare November 15, 2024 01:09
@renovate renovate bot changed the title chore(deps): update dependency flask to v3.1.0 chore(deps): update dependency flask to v3.1.1 May 13, 2025
@renovate renovate bot force-pushed the renovate/flask-3.x branch from 3024053 to 0188d55 Compare May 13, 2025 19:19
@renovate renovate bot changed the title chore(deps): update dependency flask to v3.1.1 chore(deps): update dependency flask to v3.1.2 Aug 19, 2025
@renovate renovate bot force-pushed the renovate/flask-3.x branch from 0188d55 to 9033974 Compare August 19, 2025 22:05
@renovate renovate bot force-pushed the renovate/flask-3.x branch from 9033974 to be95d46 Compare September 11, 2025 14:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type/dependencies Issue or PR related to dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant