Originally created by: dependabot[bot]
Bumps the pip group with 1 update in the / directory: flask.
Updates flask from 3.0.0 to 3.1.3
Sourced from flask's releases.
3.1.3
This is the Flask 3.1.3 security fix release, which fixes a security issue but does not otherwise change behavior and should not result in breaking changes compared to the latest feature release.
PyPI: https://pypi.org/project/Flask/3.1.3/ Changes: https://flask.palletsprojects.com/page/changes/#version-3-1-3
- The session is marked as accessed for operations that only access the keys but not the values, such as
inandlen. GHSA-68rp-wp8r-47263.1.2
This is the Flask 3.1.2 fix release, which fixes bugs but does not otherwise change behavior and should not result in breaking changes compared to the latest feature release.
PyPI: https://pypi.org/project/Flask/3.1.2/ Changes: https://flask.palletsprojects.com/page/changes/#version-3-1-2 Milestone: https://github.com/pallets/flask/milestone/38?closed=1
stream_with_contextdoes not fail inside async views. #5774](https://github.com/href="https://redirect.github.com/pallets/flask/issues/5774">/issues/5774)- When using
follow_redirectsin the test client, the final state ofsessionis correct. #5786](https://github.com/href="https://redirect.github.com/pallets/flask/issues/5786">/issues/5786)- Relax type hint for passing bytes IO to
send_file. #5776](https://github.com/href="https://redirect.github.com/pallets/flask/issues/5776">/issues/5776)3.1.1
This is the Flask 3.1.1 fix release, which fixes bugs but does not otherwise change behavior and should not result in breaking changes compared to the latest feature release.
PyPI: https://pypi.org/project/Flask/3.1.1/ Changes: https://flask.palletsprojects.com/en/stable/changes/#version-3-1-1 Milestone https://github.com/pallets/flask/milestone/36?closed=1
- Fix signing key selection order when key rotation is enabled via
SECRET_KEY_FALLBACKS. GHSA-4grg-w6v8-c28g- Fix type hint for
cli_runner.invoke. #5645](https://github.com/href="https://redirect.github.com/pallets/flask/issues/5645">/issues/5645)flask --helploads the app and plugins first to make sure all commands are shown. #5673](https://github.com/href="https://redirect.github.com/pallets/flask/issues/5673">/issues/5673)- Mark sans-io base class as being able to handle views that return
AsyncIterable. This is not accurate for Flask, but makes typing easier for Quart. #5659](https://github.com/href="https://redirect.github.com/pallets/flask/issues/5659">/issues/5659)3.1.0
This is the Flask 3.1.0 feature release. A feature release may include new features, remove previously deprecated code, add new deprecations, or introduce potentially breaking changes. We encourage everyone to upgrade, and to use a tool such as pip-tools to pin all dependencies and control upgrades. Test with warnings treated as errors to be able to adapt to deprecation warnings early.
PyPI: https://pypi.org/project/Flask/3.1.0/ Changes: https://flask.palletsprojects.com/en/stable/changes/#version-3-1-0 Milestone: https://github.com/pallets/flask/milestone/33?closed=1
- Drop support for Python 3.8. #5623](https://github.com/href="https://redirect.github.com/pallets/flask/issues/5623">/issues/5623)
- Update minimum dependency versions to latest feature releases. Werkzeug >= 3.1, ItsDangerous >= 2.2, Blinker >= 1.9. #5624](https://github.com/href="https://redirect.github.com/pallets/flask/issues/5624">/issues/5624), #5633](https://github.com/href="https://redirect.github.com/pallets/flask/issues/5633">/issues/5633)
- Provide a configuration option to control automatic option responses. #5496](https://github.com/href="https://redirect.github.com/pallets/flask/issues/5496">/issues/5496)
Flask.open_resource/open_instance_resourceandBlueprint.open_resourcetake anencodingparameter to use when opening in text mode. It defaults toutf-8. #5504](https://github.com/href="https://redirect.github.com/pallets/flask/issues/5504">/issues/5504)Request.max_content_lengthcan be customized per-request instead of only through theMAX_CONTENT_LENGTHconfig. AddedMAX_FORM_MEMORY_SIZEandMAX_FORM_PARTSconfig. Added documentation about resource limits to the security page. #5625](https://github.com/href="https://redirect.github.com/pallets/flask/issues/5625">/issues/5625)- Add support for the
Partitionedcookie attribute (CHIPS), with theSESSION_COOKIE_PARTITIONEDconfig. #5472](https://github.com/href="https://redirect.github.com/pallets/flask/issues/5472">/issues/5472)-e pathtakes precedence over default.envand.flaskenvfiles.load_dotenvloads default files in addition to a path unlessload_defaults=Falseis passed. #5628](https://github.com/href="https://redirect.github.com/pallets/flask/issues/5628">/issues/5628)- Support key rotation with the
SECRET_KEY_FALLBACKSconfig, a list of old secret keys that can still be used for unsigning. Extensions will need to add support. #5621](https://github.com/href="https://redirect.github.com/pallets/flask/issues/5621">/issues/5621)- Fix how setting
host_matching=Trueorsubdomain_matching=Falseinteracts withSERVER_NAME. SettingSERVER_NAMEno longer restricts requests to only that domain. #5553](https://github.com/href="https://redirect.github.com/pallets/flask/issues/5553">/issues/5553)Request.trusted_hostsis checked during routing, and can be set through theTRUSTED_HOSTSconfig. #5636](https://github.com/href="https://redirect.github.com/pallets/flask/issues/5636">/issues/5636)3.0.3
... (truncated)
Sourced from flask's changelog.
Version 3.1.3
Released 2026-02-18
- The session is marked as accessed for operations that only access the keys but not the values, such as
inandlen. :ghsa:68rp-wp8r-4726Version 3.1.2
Released 2025-08-19
stream_with_contextdoes not fail inside async views. :issue:5774- When using
follow_redirectsin the test client, the final state ofsessionis correct. :issue:5786- Relax type hint for passing bytes IO to
send_file. :issue:5776Version 3.1.1
Released 2025-05-13
- Fix signing key selection order when key rotation is enabled via
SECRET_KEY_FALLBACKS. :ghsa:4grg-w6v8-c28g- Fix type hint for
cli_runner.invoke. :issue:5645flask --helploads the app and plugins first to make sure all commands are shown. :issue:5673- Mark sans-io base class as being able to handle views that return
AsyncIterable. This is not accurate for Flask, but makes typing easier for Quart. :pr:5659Version 3.1.0
Released 2024-11-13
- Drop support for Python 3.8. :pr:
5623- Update minimum dependency versions to latest feature releases. Werkzeug >= 3.1, ItsDangerous >= 2.2, Blinker >= 1.9. :pr:
5624,5633- Provide a configuration option to control automatic option responses. :pr:
5496Flask.open_resource/open_instance_resourceandBlueprint.open_resourcetake anencodingparameter to use when opening in text mode. It defaults toutf-8. :issue:5504Request.max_content_lengthcan be customized per-request instead of only through theMAX_CONTENT_LENGTHconfig. Added
... (truncated)
22d9247 release version 3.1.3089cb86 Merge commit from forkc17f379 request context tracks session access27be933 start version 3.1.34e652d3 Abort if the instance folder cannot be created (#5903](https://github.com/href="https://redirect.github.com/pallets/flask/issues/5903">/issues/5903))3d03098 Abort if the instance folder cannot be created407eb76 document using gevent for async (#5900](https://github.com/href="https://redirect.github.com/pallets/flask/issues/5900">/issues/5900))ac5664d document using gevent for async4f79d5b Increase required flit_core version to 3.11 (#5865](https://github.com/href="https://redirect.github.com/pallets/flask/issues/5865">/issues/5865))fe3b215 Increase required flit_core version to 3.11
Originally posted by: AutoBotSolutions
@copilot resolve the merge conflicts in this pull request