Sourced from werkzeug's releases.
3.0.1
This is a security release for the 3.0.x feature branch.
3.0.0
This is a feature release, which includes new features, removes previously deprecated code, and adds new deprecations. The 3.0.x branch is now the supported fix branch, the 2.3.x branch will become a tag marking the end of support for that branch. We encourage everyone to upgrade, and to use a tool such as pip-tools to pin all dependencies and control upgrades. Test with warnings treated as errors to be able to adapt to deprecation warnings early.
- Changes: https://werkzeug.palletsprojects.com/en/3.0.x/changes/#version-3-0-0
- Milestone: https://github.com/pallets/werkzeug/milestone/21?closed=1
2.3.7
This is a fix release for the 2.3.x feature branch.
- Changes: https://werkzeug.palletsprojects.com/en/2.3.x/changes/#version-2-3-7
- Milestone: https://github.com/pallets/werkzeug/milestone/33?closed=1
2.3.6
This is a fix release for the 2.3.x feature branch.
- Changes: https://werkzeug.palletsprojects.com/en/2.3.x/changes/#version-2-3-6
- Milestone: https://github.com/pallets/werkzeug/milestone/32?closed=1
2.3.5
This is a fix release for the 2.3.x feature branch.
- Changes: https://werkzeug.palletsprojects.com/en/2.3.x/changes/#version-2-3-5
- Milestone: https://github.com/pallets/werkzeug/milestone/31?closed=1
2.3.4
This is a fix release for the 2.3.x release branch.
Sourced from werkzeug's changelog.
Version 3.0.1
Released 2023-10-24
- Fix slow multipart parsing for large parts potentially enabling DoS attacks. :cwe:
CWE-407
Version 3.0.0
Released 2023-09-30
- Remove previously deprecated code. :pr:
2768
- Deprecate the
__version__
attribute. Use feature detection, orimportlib.metadata.version("werkzeug")
, instead. :issue:2770
generate_password_hash
uses scrypt by default. :issue:2769
- Add the
"werkzeug.profiler"
item to the WSGIenviron
dictionary passed toProfilerMiddleware
'sfilename_format
function. It contains theelapsed
andtime
values for the profiled request. :issue:2775
- Explicitly marked the PathConverter as non path isolating. :pr:
2784
Version 2.3.8
Unreleased
Version 2.3.7
Released 2023-08-14
- Use
flit_core
instead ofsetuptools
as build backend.- Fix parsing of multipart bodies. :issue:
2734
Adjust index of last newline in data start. :issue:2761
- Parsing ints from header values strips spacing first. :issue:
2734
- Fix empty file streaming when testing. :issue:
2740
- Clearer error message when URL rule does not start with slash. :pr:
2750
Accept
q
value can be a float without a decimal part. :issue:2751
Version 2.3.6
Released 2023-06-08
FileStorage.content_length
does not fail if the form data did not provide a value. :issue:2726
... (truncated)
ce4eff5
Release version 3.0.1b1916c0
Fix: slow multipart parsing for huge files with few CR/LF
characters726eaa2
Release version 3.0.06427542
Default the PathConverter (and descendants) to be non part
isolating4820d8c
Provide elapsed and timestamp info to filename_format599993d
Bump pypa/gh-action-pypi-publish from 1.8.8 to 1.8.10 (#2780)a2394ed
Bump slsa-framework/slsa-github-generator from 1.7.0 to 1.9.0 (#2779)1efd6f3
Bump actions/checkout from 3.5.3 to 3.6.0 (#2778)76a5419
Bump pypa/gh-action-pypi-publish from 1.8.8 to 1.8.10ce8cfe7
Bump slsa-framework/slsa-github-generator from 1.7.0 to 1.9.0