Skip to content

Bump starlette from 0.49.3 to 1.3.1 - #338

Open
dependabot[bot] wants to merge 1 commit into
release-v0.9.xfrom
dependabot/uv/starlette-1.3.1
Open

dependabot[bot] wants to merge 1 commit into
release-v0.9.xfrom
dependabot/uv/starlette-1.3.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 17, 2026 •

Copy link
Copy Markdown
Contributor

Bumps starlette from 0.49.3 to 1.3.1.

Release notes

Sourced from starlette's releases.

Version 1.3.1

What's Changed

Full Changelog: Kludex/starlette@1.3.0...1.3.1

Version 1.3.0

What's Changed

New Contributors

Full Changelog: Kludex/starlette@1.2.1...1.3.0

Version 1.2.1

What's Changed

New Contributors

Full Changelog: Kludex/starlette@1.2.0...1.2.1

Version 1.2.0

What's Changed

Full Changelog: Kludex/starlette@1.1.0...1.2.0

Version 1.1.0

... (truncated)

Changelog

Sourced from starlette's changelog.

1.3.1 (June 12, 2026)

Fixed

  • Enforce max_fields and max_part_size in FormParser #3329.
  • Enforce FormParser limits in parser callbacks #3331.

1.3.0 (June 11, 2026)

Added

  • Add httpx2 to the full extra #3323.
  • Annotate the URLPath protocol parameter with Literal #3285.

Fixed

  • Build request.url from structured components #3326.
  • Clamp oversized suffix ranges in FileResponse #3307.
  • Catch OSError alongside MultiPartException when closing temp files #3191.
  • Avoid collapsing exception groups raised from user code #2830.
  • Use removeprefix to strip the weak ETag indicator in is_not_modified #3193.
  • Fix IndexError in URL.replace() on a URL with no authority #3317.
  • Adjust testclient typing and warnings #3322.

1.2.1 (May 31, 2026)

Fixed

  • Use httpx2 for type checking in the testclient module #3304.
  • Add assert error for requires() when the request parameter is not a Request type #3298.

1.2.0 (May 28, 2026)

Added

  • Support httpx2 in the test client #3291.

1.1.0 (May 23, 2026)

Added

  • Use "application/octet-stream" as the FileResponse media type fallback #3283.

Fixed

  • Only dispatch standard HTTP verbs in HTTPEndpoint #3286.
  • Reject absolute paths in StaticFiles.lookup_path #3287.

1.0.1 (May 21, 2026)

... (truncated)

Commits
  • 8ebffd0 Version 1.3.1 (#3330)
  • 25b8e17 Enforce FormParser limits in parser callbacks (#3331)
  • dba1c4b Enforce max_fields and max_part_size in FormParser (#3329)
  • 45e51dc Use StarletteDeprecationWarning instead of DeprecationWarning (#3119)
  • 5f8610c Version 1.3.0 (#3327)
  • 167b585 Build request.url from structured components (#3326)
  • 3730925 Use removeprefix to strip weak ETag indicator in is_not_modified (#3193)
  • e6f7ad1 avoid collapsing exception groups from user code (#2830)
  • 115228f Annotate URLPath protocol parameter with Literal (#3285)
  • 113f193 docs: replace inline ASGI server list with link to canonical implemen… (#3204)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Jun 17, 2026
@bjester
bjester requested a review from rtibblesbot June 26, 2026 00:14
@dependabot
dependabot Bot force-pushed the dependabot/uv/starlette-1.3.1 branch from f4c57bc to 9a24e91 Compare June 26, 2026 00:16

@rtibblesbot rtibblesbot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

starlette 0.49.3 → 1.3.1 — major bump, production dependency.

Semver risk: High. This crosses the 0.x → 1.x boundary and spans a large version range.

Changelog highlights (1.0.0–1.3.1):

  • Security: StaticFiles.lookup_path now rejects absolute paths (path-traversal hardening — positive change)
  • Behavioral: HTTPEndpoint only dispatches standard HTTP verbs; non-standard verbs no longer reach handlers
  • Behavioral: FormParser enforces max_fields and max_part_size limits — could reject previously-accepted form submissions if morango uses multipart forms near those limits
  • The full changelog from 0.49.3 → 1.0.0 was not available in the PR body and was not verified; there may be additional breaking changes in that range

Note: The PR body's changelog links point to Kludex/starlette releases redirecting to encode/starlette PRs, consistent with a repository transfer rather than a fork, but this was not independently confirmed.

CI: Passing. However, the newest commits were not covered by the review passes that produced this summary — the PR head advanced after those runs.

A rebase (or @dependabot rebase) and a manual check of morango's HTTPEndpoint and form-handling usage against the 0.49.3→1.0.0 changelog would complete the assessment before merging.


@rtibblesbot's comments are generated by an LLM, and should be evaluated accordingly

How was this generated?

Ran a dependency-update review pipeline over the version bump:

  • Classified the bump by semver (patch / minor / major) and dependency type (production vs. development)
  • Extracted the changelog and release notes across the version range
  • Assessed compatibility with this project's usage and whether any code changes are required
  • Treated CI as the primary safety net
  • Scaled the review depth to the update's risk
  • Chose the verdict from semver risk, changelog findings, and CI status

@rtibblesbot rtibblesbot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

starlette 0.49.3 → 1.3.1 — major semver bump, development-only (transitive dep of sphinx-autobuild docs group; not present in morango's production runtime).

Breaking changes: starlette 1.x introduces API-level changes, but none affect morango since starlette is only pulled in for the docs build toolchain. Security: StaticFiles.lookup_path path-traversal hardening added in 1.1.0 — positive even for docs-only usage. CI: passing.

All prior findings resolved or acknowledged.

Prior-finding status

RESOLVED — CI coverage on newest commits (CI all passing on 9a24e91)
RESOLVED — 0.49.3→1.0.0 changelog gap (starlette is docs-only transitive dep; behavioral API changes don't affect morango runtime)
ACKNOWLEDGED — Kludex/starlette repo transfer note (informational; CI passing confirms functional compatibility)
RESOLVED — rebase/manual compatibility check suggestion (PR is mergeable; docs-only dep makes manual audit unnecessary)


@rtibblesbot's comments are generated by an LLM, and should be evaluated accordingly

How was this generated?

Ran a dependency-update review pipeline over the version bump:

  • Classified the bump by semver (patch / minor / major) and dependency type (production vs. development)
  • Extracted the changelog and release notes across the version range
  • Assessed compatibility with this project's usage and whether any code changes are required
  • Treated CI as the primary safety net
  • Scaled the review depth to the update's risk
  • Chose the verdict from semver risk, changelog findings, and CI status

@rtibbles

rtibbles commented Oct 5, 2026

Copy link
Copy Markdown
Member

@dependabot rebase

Bumps [starlette](https://github.com/Kludex/starlette) from 0.49.3 to 1.3.1.
- [Release notes](https://github.com/Kludex/starlette/releases)
- [Changelog](https://github.com/Kludex/starlette/blob/main/docs/release-notes.md)
- [Commits](Kludex/starlette@0.49.3...1.3.1)

---
updated-dependencies:
- dependency-name: starlette
  dependency-version: 1.3.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/uv/starlette-1.3.1 branch from 9a24e91 to 4dbdebf Compare October 5, 2026 22:38
@dependabot
dependabot Bot requested review from a team and leq-bot October 5, 2026 22:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants