From f6b44c226a1059d295014de3aebb910544f24869 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 26 Aug 2026 00:56:21 +0000 Subject: [PATCH 1/4] Bump blockbuster from 1.5.26 to 1.5.27 (#13507) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Bumps [blockbuster](https://github.com/cbornet/blockbuster) from 1.5.26 to 1.5.27.
Release notes

Sourced from blockbuster's releases.

v1.5.27

What's Changed

New Contributors

Full Changelog: https://github.com/cbornet/blockbuster/compare/v1.5.26...v1.5.27

Commits

Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- requirements/constraints.txt | 2 +- requirements/dev.txt | 2 +- requirements/lint.txt | 2 +- requirements/test-common.txt | 2 +- requirements/test-ft.txt | 2 +- requirements/test.txt | 2 +- 6 files changed, 6 insertions(+), 6 deletions(-) diff --git a/requirements/constraints.txt b/requirements/constraints.txt index f448d8523db..8e203e61344 100644 --- a/requirements/constraints.txt +++ b/requirements/constraints.txt @@ -43,7 +43,7 @@ backports-zstd==1.3.0 ; implementation_name == "cpython" and python_version < "3 # via # -r requirements/lint.in # -r requirements/runtime-deps.in -blockbuster==1.5.26 +blockbuster==1.5.27 # via # -r requirements/lint.in # -r requirements/test-common.in diff --git a/requirements/dev.txt b/requirements/dev.txt index 134d015d456..e3974fb17b7 100644 --- a/requirements/dev.txt +++ b/requirements/dev.txt @@ -43,7 +43,7 @@ backports-zstd==1.3.0 ; platform_python_implementation == "CPython" and python_v # via # -r requirements/lint.in # -r requirements/runtime-deps.in -blockbuster==1.5.26 +blockbuster==1.5.27 # via # -r requirements/lint.in # -r requirements/test-common.in diff --git a/requirements/lint.txt b/requirements/lint.txt index 856b434a442..5e6abb9d85f 100644 --- a/requirements/lint.txt +++ b/requirements/lint.txt @@ -26,7 +26,7 @@ backports-asyncio-runner==1.2.0 # via pytest-asyncio backports-zstd==1.3.0 ; implementation_name == "cpython" and python_version < "3.14" # via -r requirements/lint.in -blockbuster==1.5.26 +blockbuster==1.5.27 # via -r requirements/lint.in cffi==2.1.1 # via diff --git a/requirements/test-common.txt b/requirements/test-common.txt index 7d6c54c83b0..4070c75cc96 100644 --- a/requirements/test-common.txt +++ b/requirements/test-common.txt @@ -18,7 +18,7 @@ attrs==26.1.0 # via aiohttp backports-asyncio-runner==1.2.0 # via pytest-asyncio -blockbuster==1.5.26 +blockbuster==1.5.27 # via -r requirements/test-common.in cffi==2.1.1 # via cryptography diff --git a/requirements/test-ft.txt b/requirements/test-ft.txt index 4474ecdecdd..3fc51e53cf2 100644 --- a/requirements/test-ft.txt +++ b/requirements/test-ft.txt @@ -30,7 +30,7 @@ backports-asyncio-runner==1.2.0 # via pytest-asyncio backports-zstd==1.3.0 ; platform_python_implementation == "CPython" and python_version < "3.14" and sys_platform != "android" and sys_platform != "ios" # via -r requirements/runtime-deps.in -blockbuster==1.5.26 +blockbuster==1.5.27 # via -r requirements/test-common.in brotli==1.2.0 ; platform_python_implementation == "CPython" and sys_platform != "android" and sys_platform != "ios" # via -r requirements/runtime-deps.in diff --git a/requirements/test.txt b/requirements/test.txt index 2f21bd246c9..e643522a5b6 100644 --- a/requirements/test.txt +++ b/requirements/test.txt @@ -30,7 +30,7 @@ backports-asyncio-runner==1.2.0 # via pytest-asyncio backports-zstd==1.3.0 ; platform_python_implementation == "CPython" and python_version < "3.14" and sys_platform != "android" and sys_platform != "ios" # via -r requirements/runtime-deps.in -blockbuster==1.5.26 +blockbuster==1.5.27 # via -r requirements/test-common.in brotli==1.2.0 ; platform_python_implementation == "CPython" and sys_platform != "android" and sys_platform != "ios" # via -r requirements/runtime-deps.in From 4602990f60241f759f861a3a4c1243ba2294ab53 Mon Sep 17 00:00:00 2001 From: Sam Bull Date: Wed, 26 Aug 2026 02:11:33 +0100 Subject: [PATCH 2/4] Fix flaky descriptor test (#13549) --- tests/test_web_functional.py | 20 +++++++++++++++++--- 1 file changed, 17 insertions(+), 3 deletions(-) diff --git a/tests/test_web_functional.py b/tests/test_web_functional.py index c834c388a06..1519a2d8aa6 100644 --- a/tests/test_web_functional.py +++ b/tests/test_web_functional.py @@ -2450,7 +2450,9 @@ async def handler(request: web.Request) -> NoReturn: assert resp.status == 413 -@pytest.mark.skipif(not os.path.isdir("/dev/fd"), reason="needs /dev/fd to count fds") +@pytest.mark.skipif( + not os.path.isdir("/proc/self/fd"), reason="needs /proc/self/fd to identify fds" +) @pytest.mark.parametrize( ("parts", "part_body", "expected_fds"), ( @@ -2464,10 +2466,22 @@ async def test_post_file_fields_descriptor_cost( ) -> None: """Only a part past the spool size may cost a descriptor.""" + def deleted_file_fds() -> set[tuple[str, str]]: + """(fd, symlink target) pairs for open fds backed by deleted files.""" + fds = set() + for name in os.listdir("/proc/self/fd"): + try: + target = os.readlink(f"/proc/self/fd/{name}") + except OSError: + continue # closed between listdir and readlink + if target.endswith("(deleted)"): + fds.add((name, target)) + return fds + async def handler(request: web.Request) -> web.Response: - before = set(await asyncio.to_thread(os.listdir, "/dev/fd")) + before = await asyncio.to_thread(deleted_file_fds) data = await request.post() - after = set(await asyncio.to_thread(os.listdir, "/dev/fd")) + after = await asyncio.to_thread(deleted_file_fds) assert len(data) == parts return web.Response(text=str(len(after - before))) From 73c7cb627acedd1d18ef9e430e52d5087d6aa40e Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 26 Aug 2026 01:41:44 +0000 Subject: [PATCH 3/4] Bump github/codeql-action from 4.37.7 to 4.37.8 (#13537) Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.37.7 to 4.37.8.
Release notes

Sourced from github/codeql-action's releases.

v4.37.8

No user facing changes.

Changelog

Sourced from github/codeql-action's changelog.

4.37.8 - 21 Aug 2026

No user facing changes.

Commits
  • db488dd Merge pull request #4102 from github/update-v4.37.8-9ee088e13
  • 1845f5b Update changelog for v4.37.8
  • 9ee088e Merge pull request #4080 from github/henrymercer/studious-giggle
  • 1aef003 Address review feedback on overlay disk flags
  • 508b83b Merge main into overlay minimum disk feature branch
  • d97b342 Merge pull request #4098 from github/mbg/permission-error-as-configuration-error
  • 47fa622 Make EACCES a ConfigurationError
  • 45693cc Refactor ENOSPC check into isDiskConfigurationError function
  • c2fd8f5 Merge pull request #4081 from github/mario-campos/version-cache-to-disk
  • c56f48e Log unexpected conditions during caching CLI output
  • Additional commits viewable in compare view

[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=github/codeql-action&package-manager=github_actions&previous-version=4.37.7&new-version=4.37.8)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) ---
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- .github/workflows/codeql.yml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 7d48a69d999..7f313586aff 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -29,17 +29,17 @@ jobs: uses: actions/checkout@v7 - name: Initialize CodeQL - uses: github/codeql-action/init@v4.37.7 + uses: github/codeql-action/init@v4.37.8 with: languages: ${{ matrix.language }} config-file: ./.github/codeql.yml queries: +security-and-quality - name: Autobuild - uses: github/codeql-action/autobuild@v4.37.7 + uses: github/codeql-action/autobuild@v4.37.8 if: ${{ matrix.language == 'python' || matrix.language == 'javascript' }} - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@v4.37.7 + uses: github/codeql-action/analyze@v4.37.8 with: category: "/language:${{ matrix.language }}" From eb38b3cad06db0111bcfc637fae5bc6dfaa88ae9 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 26 Aug 2026 01:43:04 +0000 Subject: [PATCH 4/4] Bump gunicorn from 26.0.0 to 26.1.0 (#13538) Bumps [gunicorn](https://github.com/benoitc/gunicorn) from 26.0.0 to 26.1.0.
Release notes

Sourced from gunicorn's releases.

gunicorn 26.1.0

New Features

  • Glob patterns in reload_extra_files: entries containing *, ? or [ are treated as patterns, so ui/*/config.json watches every view's config without listing them one by one. Patterns are re-expanded on every reload check rather than once at startup, so a file created later starts being watched without restarting gunicorn, and ** recurses. A pattern matching nothing warns instead of failing, since with live expansion it may match later (#1643, #3662).

Security

  • Dependency floors raised past known advisories: every declared floor was checked against the advisory database. tornado, h2, setuptools and pymdown-extensions permitted vulnerable versions and now require the first clean release; pytest and httpx were unpinned and now carry floors. The tornado example pinned tornado<6, which was both the source of several advisories and older than the >=6.5.0 the tornado worker needs, so the example could not run as pinned.

Bug Fixes

  • SIGHUP did not reload the logger configuration: Arbiter.reload() re-read the configuration file but kept using the logger built at startup, calling only reopen_files() on its existing handlers. Changes to logconfig, logconfig_dict, logconfig_json and loglevel were ignored until a full restart, which in containers meant replacing the pod. The existing logger now re-runs its setup on reload, so new handlers, formats and levels take effect while the process identity and its listeners are preserved, and re-running the setup no longer stacks duplicate syslog handlers. An invalid log configuration on reload is not fatal either: the error is reported on stderr, the previous working configuration is restored and the master keeps running with it (#3353).

  • Truncated chunked bodies accepted: RFC 9112 section 7.1.2 ends a chunked body with 0 CRLF CRLF, the second CRLF being the mandatory empty trailer section. ChunkedReader.parse_chunk_size() swallowed the NoMoreData raised while scanning for it, so a body cut short right after the last chunk line was treated as complete instead of rejected. It now raises ChunkMissingTerminator (#3382, #3685).

  • --spew crashed on dynamically generated code: the trace hook indexed the 2-tuple returned by inspect.getsourcelines() by line number rather than indexing the list of lines, so a frame with no __file__ raised AttributeError: 'int' object has no attribute 'rstrip' on line 1 and

... (truncated)

Commits
  • 71b59a7 Merge pull request #3698 from benoitc/fix/docker-health-check-readerror
  • 48287de test: catch every transport error in the docker health check
  • 3110e8c Merge pull request #3696 from benoitc/docs/roadmap
  • cc56c41 Merge pull request #3693 from benoitc/release/26.1.0
  • 5cf1f16 docs: surface the roadmap on the site home page
  • 7e35f72 docs: add FastCGI to the roadmap and point items at Ideas
  • 18ddc58 docs: drop the framework and reverse-proxy non-goals from the roadmap
  • 1ecae56 docs: add a roadmap and make the chat easy to find
  • ca412e3 docs: sync the Latest changelog page with 26.1.0
  • 640936f docs: note the dependency security work in 26.1.0
  • Additional commits viewable in compare view

[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=gunicorn&package-manager=pip&previous-version=26.0.0&new-version=26.1.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) ---
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- requirements/base-ft.txt | 4 +--- requirements/base.txt | 4 +--- requirements/constraints.txt | 3 +-- requirements/dev.txt | 3 +-- requirements/test-ft.txt | 6 ++---- requirements/test-mobile.txt | 6 ++---- requirements/test.txt | 6 ++---- 7 files changed, 10 insertions(+), 22 deletions(-) diff --git a/requirements/base-ft.txt b/requirements/base-ft.txt index fe5570f0526..4e243c86ed1 100644 --- a/requirements/base-ft.txt +++ b/requirements/base-ft.txt @@ -26,7 +26,7 @@ frozenlist==1.8.0 # via # -r requirements/runtime-deps.in # aiosignal -gunicorn==26.0.0 +gunicorn==26.1.0 # via -r requirements/base-ft.in idna==3.19 # via yarl @@ -34,8 +34,6 @@ multidict==6.7.1 # via # -r requirements/runtime-deps.in # yarl -packaging==26.3 - # via gunicorn propcache==0.5.2 # via # -r requirements/runtime-deps.in diff --git a/requirements/base.txt b/requirements/base.txt index 61a93ad1e99..14b31ce18ad 100644 --- a/requirements/base.txt +++ b/requirements/base.txt @@ -26,7 +26,7 @@ frozenlist==1.8.0 # via # -r requirements/runtime-deps.in # aiosignal -gunicorn==26.0.0 +gunicorn==26.1.0 # via -r requirements/base.in idna==3.19 # via yarl @@ -34,8 +34,6 @@ multidict==6.7.1 # via # -r requirements/runtime-deps.in # yarl -packaging==26.3 - # via gunicorn propcache==0.5.2 # via # -r requirements/runtime-deps.in diff --git a/requirements/constraints.txt b/requirements/constraints.txt index 8e203e61344..09e5be9e735 100644 --- a/requirements/constraints.txt +++ b/requirements/constraints.txt @@ -100,7 +100,7 @@ frozenlist==1.8.0 # -r requirements/runtime-deps.in # aiohttp # aiosignal -gunicorn==26.0.0 +gunicorn==26.1.0 # via -r requirements/base.in identify==2.6.19 # via pre-commit @@ -155,7 +155,6 @@ nodeenv==1.10.0 packaging==26.3 # via # build - # gunicorn # pytest # sphinx # wheel diff --git a/requirements/dev.txt b/requirements/dev.txt index e3974fb17b7..f2ce934e1b7 100644 --- a/requirements/dev.txt +++ b/requirements/dev.txt @@ -98,7 +98,7 @@ frozenlist==1.8.0 # -r requirements/runtime-deps.in # aiohttp # aiosignal -gunicorn==26.0.0 +gunicorn==26.1.0 # via -r requirements/base.in identify==2.6.19 # via pre-commit @@ -152,7 +152,6 @@ nodeenv==1.10.0 packaging==26.3 # via # build - # gunicorn # pytest # sphinx # wheel diff --git a/requirements/test-ft.txt b/requirements/test-ft.txt index 3fc51e53cf2..071ca517aa8 100644 --- a/requirements/test-ft.txt +++ b/requirements/test-ft.txt @@ -59,7 +59,7 @@ frozenlist==1.8.0 # -r requirements/runtime-deps.in # aiohttp # aiosignal -gunicorn==26.0.0 +gunicorn==26.1.0 # via -r requirements/base-ft.in idna==3.19 # via @@ -85,9 +85,7 @@ mypy==2.1.0 ; implementation_name == "cpython" mypy-extensions==1.1.0 # via mypy packaging==26.3 - # via - # gunicorn - # pytest + # via pytest pathspec==1.1.1 # via mypy pkgconfig==1.6.0 diff --git a/requirements/test-mobile.txt b/requirements/test-mobile.txt index b5397120739..5116d51f110 100644 --- a/requirements/test-mobile.txt +++ b/requirements/test-mobile.txt @@ -47,7 +47,7 @@ frozenlist==1.8.0 # -r requirements/runtime-deps.in # aiohttp # aiosignal -gunicorn==26.0.0 +gunicorn==26.1.0 # via -r requirements/base-ft.in idna==3.19 # via yarl @@ -59,9 +59,7 @@ multidict==6.7.1 # aiohttp # yarl packaging==26.3 - # via - # gunicorn - # pytest + # via pytest pkgconfig==1.6.0 # via -r requirements/test-common-base.in pluggy==1.6.0 diff --git a/requirements/test.txt b/requirements/test.txt index e643522a5b6..ff2303ad5eb 100644 --- a/requirements/test.txt +++ b/requirements/test.txt @@ -59,7 +59,7 @@ frozenlist==1.8.0 # -r requirements/runtime-deps.in # aiohttp # aiosignal -gunicorn==26.0.0 +gunicorn==26.1.0 # via -r requirements/base.in idna==3.19 # via @@ -85,9 +85,7 @@ mypy==2.1.0 ; implementation_name == "cpython" mypy-extensions==1.1.0 # via mypy packaging==26.3 - # via - # gunicorn - # pytest + # via pytest pathspec==1.1.1 # via mypy pkgconfig==1.6.0