Bump flask from 2.0.2 to 2.3.3
Bumps flask from 2.0.2 to 2.3.3.
Release notes
Sourced from flask's releases.
2.3.3
This is a fix release for the 2.3.x feature branch.
- Changes: https://flask.palletsprojects.com/en/2.3.x/changes/#version-2-3-3
- Milestone: https://github.com/pallets/flask/milestone/31?closed=1
2.3.2
This is a security fix release for the 2.3.x release branch.
- Security advisory: https://github.com/pallets/flask/security/advisories/GHSA-m2qf-hxjv-5gpq, CVE-2023-30861
- Changes: https://flask.palletsprojects.com/en/2.3.x/changes/#version-2-3-2
- Milestone: https://github.com/pallets/flask/milestone/29?closed=1
2.3.1
This is a fix release for the 2.3.x release branch.
- Changes: https://flask.palletsprojects.com/en/2.3.x/changes/#version-2-3-1
- Milestone: https://github.com/pallets/flask/milestone/28?closed=1
2.3.0
This is a feature release, which includes new features, removes previously deprecated code, and adds new deprecations. The 2.3.x branch is now the supported fix branch, the 2.2.x branch will become a tag marking the end of support for that branch. We encourage everyone to upgrade, and to use a tool such as pip-tools to pin all dependencies and control upgrades. Test with warnings treated as errors to be able to adapt to deprecation warnings early.
- Changes: https://flask.palletsprojects.com/en/2.3.x/changes/#version-2-3-0
- Milestone: https://github.com/pallets/flask/milestone/24?closed=1
2.2.5
This is a security fix release for the 2.2.x release branch. Note that 2.3.x is the currently supported release branch; please upgrade to the latest version if possible.
- Security advisory: https://github.com/pallets/flask/security/advisories/GHSA-m2qf-hxjv-5gpq, CVE-2023-30861
- Changes: https://flask.palletsprojects.com/en/2.2.x/changes/#version-2-2-5
- Milestone: https://github.com/pallets/flask/milestone/30?closed=1
2.2.4
This is a fix release for the 2.2.x release branch.
- Changes: https://flask.palletsprojects.com/en/2.2.x/changes/#version-2-2-4
- Milestone: https://github.com/pallets/flask/milestone/27?closed=1
2.2.3
This is a fix release for the 2.2.x release branch.
- Changes: https://flask.palletsprojects.com/en/2.2.x/changes/#version-2-2-3
- Milestone: https://github.com/pallets/flask/milestone/26?closed=1
2.2.2
This is a fix release for the 2.2.0 feature release.
... (truncated)
Changelog
Sourced from flask's changelog.
Version 2.3.3
Unreleased
- Python 3.12 compatibility.
- Require Werkzeug >= 2.3.7.
- Use
flit_coreinstead ofsetuptoolsas build backend.- Refactor how an app's root and instance paths are determined. :issue:
5160Version 2.3.2
Released 2023-05-01
- Set
Vary: Cookieheader when the session is accessed, modified, or refreshed.- Update Werkzeug requirement to >=2.3.3 to apply recent bug fixes.
Version 2.3.1
Released 2023-04-25
- Restore deprecated
from flask import Markup. :issue:5084Version 2.3.0
Released 2023-04-25
Drop support for Python 3.7. :pr:
5072Update minimum requirements to the latest versions: Werkzeug>=2.3.0, Jinja2>3.1.2, itsdangerous>=2.1.2, click>=8.1.3.
Remove previously deprecated code. :pr:
4995
- The
pushandpopmethods of the deprecated_app_ctx_stackand_request_ctx_stackobjects are removed.topstill exists to give extensions more time to update, but it will be removed.- The
FLASK_ENVenvironment variable,ENVconfig key, andapp.envproperty are removed.- The
session_cookie_name,send_file_max_age_default,use_x_sendfile,propagate_exceptions, andtemplates_auto_reloadproperties onappare removed.- The
JSON_AS_ASCII,JSON_SORT_KEYS,JSONIFY_MIMETYPE, andJSONIFY_PRETTYPRINT_REGULARconfig keys are removed.- The
app.before_first_requestandbp.before_app_first_requestdecorators are removed.
... (truncated)
Commits
3205b53release version 2.3.39f95502bump werkzeug 2.3.70273664Update dispatch by path example (#5217)a887e17clean upaa6d4c3update dispatch-by-path example826514bfix flake8 bugbear findings6d266f6Pass maxsplit via kwarg to re.split (#5215)17e146aPass maxsplit via kwarg to re.split8a72b74[pre-commit.ci] pre-commit autoupdate (#5211)7255be9[pre-commit.ci] pre-commit autoupdate- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency -
@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)