Bump waitress from 2.1.2 to 3.0.1 in /src/ch4-first-site/final/pypi
Bumps waitress from 2.1.2 to 3.0.1.
Release notes
Sourced from waitress's releases.
v3.0.0
3.0.0 (2024-02-04)
Rename "master" git branch to "main"
Fix a bug that would appear on macOS whereby if we accept() a socket that is already gone, setting socket options would fail and take down the server. See Pylons/waitress#399
Fixed testing of vendored asyncore code to not rely on particular naming for errno's. See Pylons/waitress#397
HTTP Request methods and versions are now validated to meet the HTTP standards thereby dropping invalid requests on the floor. See Pylons/waitress#423
No longer close the connection when sending a HEAD request response. See Pylons/waitress#428
Always attempt to send the Connection: close response header when we are going to close the connection to let the remote know in more instances. Pylons/waitress#429
Python 3.7 is no longer supported. Add support for Python 3.11, 3.12 and PyPy 3.9, 3.10. See Pylons/waitress#412
Document that trusted_proxy may be set to a wildcard value to trust all proxies. See Pylons/waitress#431
Updated Defaults
- clear_untrusted_proxy_headers is set to True by default. See Pylons/waitress#370
Changelog
Sourced from waitress's changelog.
3.0.1 (2024-11-28)
Security
- Fix a bug that would lead to Waitress busy looping on select() on a half-open socket due to a race condition that existed when creating a new HTTPChannel. See https://github.com/Pylons/waitress/pull/435, https://github.com/Pylons/waitress/issues/418 and https://github.com/Pylons/waitress/security/advisories/GHSA-3f84-rpwh-47g6With thanks to Dylan Jay and Dieter Maurer for their extensive debugging and
helping track this down.
No longer strip the header values before passing them to the WSGI environ.
See Pylons/waitress#434 and
Pylons/waitress#432Fix a race condition in Waitress when
channel_request_lookaheadis enabled
that could lead to HTTP request smuggling.See https://github.com/Pylons/waitress/security/advisories/GHSA-9298-4cf8-g4wj
3.0.0 (2024-02-04)
Rename "master" git branch to "main"
Fix a bug that would appear on macOS whereby if we accept() a socket that is
already gone, setting socket options would fail and take down the server. See
Pylons/waitress#399Fixed testing of vendored asyncore code to not rely on particular naming for
errno's. See Pylons/waitress#397HTTP Request methods and versions are now validated to meet the HTTP
standards thereby dropping invalid requests on the floor. See
Pylons/waitress#423No longer close the connection when sending a HEAD request response. See
Pylons/waitress#428Always attempt to send the Connection: close response header when we are
going to close the connection to let the remote know in more instances.
Pylons/waitress#429Python 3.7 is no longer supported. Add support for Python 3.11, 3.12 and
PyPy 3.9, 3.10. See Pylons/waitress#412</tr></table>
... (truncated)
Commits
ae949bbReady for 3.0.1e435901Merge commit from fork810a435Add documentation for channel_request_lookaheadf4ba1c2Fix a race condition on recv_bytes boundary when request is invalid7e7f11eAdd a new test to validate the lookahead race condition6943dcfMake DummySock() look more like an actual socketfdd2ecfMerge pull request #445 from Pylons/feature/support-py-3-13dcd18e7Update exclude matrix4633ea6Drop Python 3.8 and add Python 3.134584936Merge pull request #440 from Pylons/fix/ci- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency -
@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page.