Sourced from blockbuster's releases.
v1.5.27
What's Changed
- Fix false positive for os.sendfile via asyncio sock_sendfile path by
@agnersin cbornet/blockbuster#58- Test Python 3.14 in CI by
@cbornetin cbornet/blockbuster#64- Bump ruff to 0.16 by
@cbornetin cbornet/blockbuster#65- Bump mypy to 2.3 by
@cbornetin cbornet/blockbuster#66- Restore blocker patches after activation and context failures by
@dsfacciniin cbornet/blockbuster#62- Avoid source inspection in blocking-call wrappers by
@dsfacciniin cbornet/blockbuster#61- Add test that
blockbuster_skipis task-local by@dsfacciniin cbornet/blockbuster#67- Add exemptions for coverage with branch measurement by
@cbornetin cbornet/blockbuster#69New Contributors
@dsfaccinimade their first contribution in cbornet/blockbuster#62Full Changelog: https://github.com/cbornet/blockbuster/compare/v1.5.26...v1.5.27
419cccc
Add exemptions for coverage with branch measurement (#69)65c74b6
Add test that blockbuster_skip is task-local (#67)983589b
Bump version to 1.5.27 (#68)f18e48c
Avoid source inspection in blocking-call wrappers (#61)5fd2038
Restore blocker patches after activation and context failures (#62)da5e014
Remove unwanted ruff config07eed8c
Bump mypy to 2.3 (#66)d34275a
Bump ruff to 0.16 (#65)75269ed
Test Python 3.14 in CI (#64)eec8333
Fix false positive for os.sendfile via asyncio sock_sendfile path (#58)Sourced from github/codeql-action's changelog.
4.37.8 - 21 Aug 2026
No user facing changes.
db488dd
Merge pull request #4102
from github/update-v4.37.8-9ee088e131845f5b
Update changelog for v4.37.89ee088e
Merge pull request #4080
from github/henrymercer/studious-giggle1aef003
Address review feedback on overlay disk flags508b83b
Merge main into overlay minimum disk feature branchd97b342
Merge pull request #4098
from github/mbg/permission-error-as-configuration-error47fa622
Make EACCES a ConfigurationError45693cc
Refactor ENOSPC check into
isDiskConfigurationError functionc2fd8f5
Merge pull request #4081
from github/mario-campos/version-cache-to-diskc56f48e
Log unexpected conditions during caching CLI outputSourced from gunicorn's releases.
gunicorn 26.1.0
New Features
- Glob patterns in
reload_extra_files: entries containing*,?or[are treated as patterns, soui/*/config.jsonwatches every view's config without listing them one by one. Patterns are re-expanded on every reload check rather than once at startup, so a file created later starts being watched without restarting gunicorn, and**recurses. A pattern matching nothing warns instead of failing, since with live expansion it may match later (#1643, #3662).Security
- Dependency floors raised past known advisories: every declared floor was checked against the advisory database.
tornado,h2,setuptoolsandpymdown-extensionspermitted vulnerable versions and now require the first clean release;pytestandhttpxwere unpinned and now carry floors. Thetornadoexample pinnedtornado<6, which was both the source of several advisories and older than the>=6.5.0the tornado worker needs, so the example could not run as pinned.Bug Fixes
SIGHUP did not reload the logger configuration:
Arbiter.reload()re-read the configuration file but kept using the logger built at startup, calling onlyreopen_files()on its existing handlers. Changes tologconfig,logconfig_dict,logconfig_jsonandloglevelwere ignored until a full restart, which in containers meant replacing the pod. The existing logger now re-runs its setup on reload, so new handlers, formats and levels take effect while the process identity and its listeners are preserved, and re-running the setup no longer stacks duplicate syslog handlers. An invalid log configuration on reload is not fatal either: the error is reported on stderr, the previous working configuration is restored and the master keeps running with it (#3353).Truncated chunked bodies accepted: RFC 9112 section 7.1.2 ends a chunked body with
0 CRLF CRLF, the second CRLF being the mandatory empty trailer section.ChunkedReader.parse_chunk_size()swallowed theNoMoreDataraised while scanning for it, so a body cut short right after the last chunk line was treated as complete instead of rejected. It now raisesChunkMissingTerminator(#3382, #3685).
--spewcrashed on dynamically generated code: the trace hook indexed the 2-tuple returned byinspect.getsourcelines()by line number rather than indexing the list of lines, so a frame with no__file__raisedAttributeError: 'int' object has no attribute 'rstrip'on line 1 and
... (truncated)
71b59a7
Merge pull request #3698
from benoitc/fix/docker-health-check-readerror48287de
test: catch every transport error in the docker health check3110e8c
Merge pull request #3696
from benoitc/docs/roadmapcc56c41
Merge pull request #3693
from benoitc/release/26.1.05cf1f16
docs: surface the roadmap on the site home page7e35f72
docs: add FastCGI to the roadmap and point items at Ideas18ddc58
docs: drop the framework and reverse-proxy non-goals from the
roadmap1ecae56
docs: add a roadmap and make the chat easy to findca412e3
docs: sync the Latest changelog page with 26.1.0640936f
docs: note the dependency security work in 26.1.0