Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Bump werkzeug from 2.2.2 to 2.2.3 in /app (#142)
Bumps [werkzeug](https://github.com/pallets/werkzeug) from 2.2.2 to 2.2.3. ## Release notes Sourced from werkzeug's releases. 2.2.3 This is a fix release for the 2.2.x release branch. - Changes: https://werkzeug.palletsprojects.com/en/2.2.x/changes/#version-2-2-3 - Milestone: https://github.com/pallets/werkzeug/milestone/26?closed=1 This release contains security fixes for: - GHSA-xg9f-g7g7-2323 - GHSA-px8h-6qxv-m22q ## Changelog Sourced from werkzeug's changelog. Version 2.2.3 Released 2023-02-14 - Ensure that URL rules using path converters will redirect with strict slashes when the trailing slash is missing. :issue:2533 - Type signature for get_json specifies that return type is not optional when silent=False. :issue:2508 - parse_content_range_header returns None for a value like bytes */-1 where the length is invalid, instead of raising an AssertionError. :issue:2531 - Address remaining ResourceWarning related to the socket used by run_simple. Remove prepare_socket, which now happens when creating the server. :issue:2421 - Update pre-existing headers for multipart/form-data requests with the test client. :issue:2549 - Fix handling of header extended parameters such that they are no longer quoted. :issue:2529 - LimitedStream.read works correctly when wrapping a stream that may not return the requested size in one read call. :issue:2558 - A cookie header that starts with = is treated as an empty key and discarded, rather than stripping the leading ==. - Specify a maximum number of multipart parts, default 1000, after which a RequestEntityTooLarge exception is raised on parsing. This mitigates a DoS attack where a larger number of form/file parts would result in disproportionate resource use. Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Loren Yu <[email protected]>
- Loading branch information