Skip to content

pins: bump flower from 2.1.0 to 2.2.0 in /packages/flower - #13

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/packages/flower/flower-2.2.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/packages/flower/flower-2.2.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 26, 2026

Copy link
Copy Markdown

Bumps flower from 2.1.0 to 2.2.0.

Release notes

Sourced from flower's releases.

v2.2.0

Security

  • Added CSRF protection for cookie-authenticated sessions
  • Added protection against cross-site state-changing requests
  • Added an OAuth state check to all login handlers
  • Restricted the post-login redirect to local paths
  • Enabled TLS certificate validation for the RabbitMQ management API
  • Escaped all table cells on the tasks and workers pages
  • Escaped load average values in the workers grid
  • Added HttpOnly and SameSite to session cookies
  • Added the X-Content-Type-Options: nosniff header
  • Limited CORS headers to the unauthenticated API
  • Served API error messages as plain text

Features

  • Added a logout link for OAuth sessions #1074
  • Added a timeout option to the task apply API
  • Added a page size selector to the tasks page #1518
  • Linked task names to a list of all tasks with that name
  • Linked the task counts on the workers page to the matching tasks
  • Honored the column order of the tasks_columns option #1262
  • Added thousands separators to task counts #1374
  • Formatted durations and showed a dash for missing values
  • Added search examples as placeholder text
  • Made wide tables scroll sideways and shortened UUIDs on mobile
  • Limited worker page task lists to 50 entries by default #1087
  • Removed the Retried column from the workers page
  • Named browser tabs by page

Performance and reliability

  • Made persistent state saves atomic #1403
  • Fixed startup failing on a corrupt persistent state database #1398
  • Added a warning when state saving dominates the save interval
  • Reapplied --max-tasks to restored persistent state #1380
  • Honored the --purge-offline-workers grace period after worker-offline events #1190
  • Inspected a worker lazily on its first page visit #1388
  • Fetched worker task lists only when inspecting a single worker
  • Validated the --broker-api URL at startup
  • Required both --certfile and --keyfile when either is set
  • Validated task API query parameters and publish payloads

Bug fixes

  • Fixed worker task table column widths #1521 by @​ShubhAtWork
  • Fixed the default RabbitMQ management API URL to use the management port #1232
  • Fixed the theme dropdown not closing and stuck navbar tooltips
  • Fixed a server error on the task page for tasks without a name

... (truncated)

Commits
  • 4d4a9ac Set release version
  • b884844 Exclude compiled and hidden files from the sdist
  • fba84ef Merge remote-tracking branch 'origin/master' into 2.0
  • ea34f92 Fix broken and moved links in the docs
  • 1336fbd Fix the unpicklable state test on Python 3.10 to 3.13
  • 0f04846 Open the state shelves with context managers
  • 8034099 Apply the ruff style rewrites to the package
  • b14b43d Fix the ruff errors in the tests
  • b9f7189 Apply ruff's safe fixes and literal rewrites to the package
  • ff33bc8 Tidy the task API test bodies and name lookups
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [flower](https://github.com/mher/flower) from 2.1.0 to 2.2.0.
- [Release notes](https://github.com/mher/flower/releases)
- [Commits](mher/flower@v2.1.0...v2.2.0)

---
updated-dependencies:
- dependency-name: flower
  dependency-version: 2.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 26, 2026

Copy link
Copy Markdown
Author

Labels

The following labels could not be found: dependencies, downstream-pin. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants