Skip to content

Comments

⬆️ Upgrade Starlette to >=0.37.2,<0.41.0#12431

Merged
tiangolo merged 1 commit intomasterfrom
upgrade-starlette
Oct 12, 2024
Merged

⬆️ Upgrade Starlette to >=0.37.2,<0.41.0#12431
tiangolo merged 1 commit intomasterfrom
upgrade-starlette

Conversation

@tiangolo
Copy link
Member

@tiangolo tiangolo commented Oct 12, 2024

⬆️ Upgrade Starlette to >=0.37.2,<0.41.0

@tiangolo tiangolo changed the title ⬆️ Upgrade Starlette ⬆️ Upgrade Starlette to >=0.37.2,<0.41.0 Oct 12, 2024
@github-actions
Copy link
Contributor

📝 Docs preview for commit 541909f at: https://e3b14dfd.fastapitiangolo.pages.dev

@tiangolo tiangolo marked this pull request as ready for review October 12, 2024 09:58
@tiangolo tiangolo merged commit b77f235 into master Oct 12, 2024
@tiangolo tiangolo deleted the upgrade-starlette branch October 12, 2024 09:59
@vfazio
Copy link

vfazio commented Oct 14, 2024

I don't see Starlette 0.40 released but it's now included in the supported range? Do they guarantee compatibility for a 2 version range? or was this supposed to be <0.40.0? (pre-coffee comment, so i could be missing something)

@musicinmybrain
Copy link
Contributor

I don't see Starlette 0.40 released but it's now included in the supported range? Do they guarantee compatibility for a 2 version range? or was this supposed to be <0.40.0? (pre-coffee comment, so i could be missing something)

Now that Starlette 0.40 has been released, and it turned out to be a security fix (GHSA-f96h-pmfr-66vw, CVE-2024-47874), this unusual “forward-compatibility” in FastAPI makes sense.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants