Repository navigation
Bump starlette from 0.49.3 to 1.3.1 - #338
dependabot[bot] wants to merge 1 commit into
Conversation
f4c57bc to
9a24e91
Compare
rtibblesbot
left a comment
There was a problem hiding this comment.
starlette 0.49.3 → 1.3.1 — major bump, production dependency.
Semver risk: High. This crosses the 0.x → 1.x boundary and spans a large version range.
Changelog highlights (1.0.0–1.3.1):
- Security:
StaticFiles.lookup_pathnow rejects absolute paths (path-traversal hardening — positive change) - Behavioral:
HTTPEndpointonly dispatches standard HTTP verbs; non-standard verbs no longer reach handlers - Behavioral:
FormParserenforcesmax_fieldsandmax_part_sizelimits — could reject previously-accepted form submissions if morango uses multipart forms near those limits - The full changelog from 0.49.3 → 1.0.0 was not available in the PR body and was not verified; there may be additional breaking changes in that range
Note: The PR body's changelog links point to Kludex/starlette releases redirecting to encode/starlette PRs, consistent with a repository transfer rather than a fork, but this was not independently confirmed.
CI: Passing. However, the newest commits were not covered by the review passes that produced this summary — the PR head advanced after those runs.
A rebase (or @dependabot rebase) and a manual check of morango's HTTPEndpoint and form-handling usage against the 0.49.3→1.0.0 changelog would complete the assessment before merging.
@rtibblesbot's comments are generated by an LLM, and should be evaluated accordingly
How was this generated?
Ran a dependency-update review pipeline over the version bump:
- Classified the bump by semver (patch / minor / major) and dependency type (production vs. development)
- Extracted the changelog and release notes across the version range
- Assessed compatibility with this project's usage and whether any code changes are required
- Treated CI as the primary safety net
- Scaled the review depth to the update's risk
- Chose the verdict from semver risk, changelog findings, and CI status
rtibblesbot
left a comment
There was a problem hiding this comment.
starlette 0.49.3 → 1.3.1 — major semver bump, development-only (transitive dep of sphinx-autobuild docs group; not present in morango's production runtime).
Breaking changes: starlette 1.x introduces API-level changes, but none affect morango since starlette is only pulled in for the docs build toolchain. Security: StaticFiles.lookup_path path-traversal hardening added in 1.1.0 — positive even for docs-only usage. CI: passing.
All prior findings resolved or acknowledged.
Prior-finding status
RESOLVED — CI coverage on newest commits (CI all passing on 9a24e91)
RESOLVED — 0.49.3→1.0.0 changelog gap (starlette is docs-only transitive dep; behavioral API changes don't affect morango runtime)
ACKNOWLEDGED — Kludex/starlette repo transfer note (informational; CI passing confirms functional compatibility)
RESOLVED — rebase/manual compatibility check suggestion (PR is mergeable; docs-only dep makes manual audit unnecessary)
@rtibblesbot's comments are generated by an LLM, and should be evaluated accordingly
How was this generated?
Ran a dependency-update review pipeline over the version bump:
- Classified the bump by semver (patch / minor / major) and dependency type (production vs. development)
- Extracted the changelog and release notes across the version range
- Assessed compatibility with this project's usage and whether any code changes are required
- Treated CI as the primary safety net
- Scaled the review depth to the update's risk
- Chose the verdict from semver risk, changelog findings, and CI status
|
@dependabot rebase |
Bumps [starlette](https://github.com/Kludex/starlette) from 0.49.3 to 1.3.1. - [Release notes](https://github.com/Kludex/starlette/releases) - [Changelog](https://github.com/Kludex/starlette/blob/main/docs/release-notes.md) - [Commits](Kludex/starlette@0.49.3...1.3.1) --- updated-dependencies: - dependency-name: starlette dependency-version: 1.3.1 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
9a24e91 to
4dbdebf
Compare
Bumps starlette from 0.49.3 to 1.3.1.
Release notes
Sourced from starlette's releases.
... (truncated)
Changelog
Sourced from starlette's changelog.
... (truncated)
Commits
8ebffd0Version 1.3.1 (#3330)25b8e17EnforceFormParserlimits in parser callbacks (#3331)dba1c4bEnforcemax_fieldsandmax_part_sizeinFormParser(#3329)45e51dcUseStarletteDeprecationWarninginstead ofDeprecationWarning(#3119)5f8610cVersion 1.3.0 (#3327)167b585Buildrequest.urlfrom structured components (#3326)3730925Useremoveprefixto strip weak ETag indicator inis_not_modified(#3193)e6f7ad1avoid collapsing exception groups from user code (#2830)115228fAnnotate URLPath protocol parameter with Literal (#3285)113f193docs: replace inline ASGI server list with link to canonical implemen… (#3204)