dependabot[bot] opened a new pull request, #38168:
URL: https://github.com/apache/superset/pull/38168

   Bumps [flask](https://github.com/pallets/flask) from 2.3.3 to 3.1.3.
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/pallets/flask/releases";>flask's releases</a>.</em></p>
   <blockquote>
   <h2>3.1.3</h2>
   <p>This is the Flask 3.1.3 security fix release, which fixes a security 
issue but does not otherwise change behavior and should not result in breaking 
changes compared to the latest feature release.</p>
   <p>PyPI: <a 
href="https://pypi.org/project/Flask/3.1.3/";>https://pypi.org/project/Flask/3.1.3/</a>
   Changes: <a 
href="https://flask.palletsprojects.com/page/changes/#version-3-1-3";>https://flask.palletsprojects.com/page/changes/#version-3-1-3</a></p>
   <ul>
   <li>The session is marked as accessed for operations that only access the 
keys but not the values, such as <code>in</code> and <code>len</code>. <a 
href="https://github.com/pallets/flask/security/advisories/GHSA-68rp-wp8r-4726";>GHSA-68rp-wp8r-4726</a></li>
   </ul>
   <h2>3.1.2</h2>
   <p>This is the Flask 3.1.2 fix release, which fixes bugs but does not 
otherwise change behavior and should not result in breaking changes compared to 
the latest feature release.</p>
   <p>PyPI: <a 
href="https://pypi.org/project/Flask/3.1.2/";>https://pypi.org/project/Flask/3.1.2/</a>
   Changes: <a 
href="https://flask.palletsprojects.com/page/changes/#version-3-1-2";>https://flask.palletsprojects.com/page/changes/#version-3-1-2</a>
   Milestone: <a 
href="https://github.com/pallets/flask/milestone/38?closed=1";>https://github.com/pallets/flask/milestone/38?closed=1</a></p>
   <ul>
   <li><code>stream_with_context</code> does not fail inside async views. <a 
href="https://redirect.github.com/pallets/flask/issues/5774";>#5774</a></li>
   <li>When using <code>follow_redirects</code> in the test client, the final 
state of <code>session</code> is correct. <a 
href="https://redirect.github.com/pallets/flask/issues/5786";>#5786</a></li>
   <li>Relax type hint for passing bytes IO to <code>send_file</code>. <a 
href="https://redirect.github.com/pallets/flask/issues/5776";>#5776</a></li>
   </ul>
   <h2>3.1.1</h2>
   <p>This is the Flask 3.1.1 fix release, which fixes bugs but does not 
otherwise change behavior and should not result in breaking changes compared to 
the latest feature release.</p>
   <p>PyPI: <a 
href="https://pypi.org/project/Flask/3.1.1/";>https://pypi.org/project/Flask/3.1.1/</a>
   Changes: <a 
href="https://flask.palletsprojects.com/en/stable/changes/#version-3-1-1";>https://flask.palletsprojects.com/en/stable/changes/#version-3-1-1</a>
   Milestone <a 
href="https://github.com/pallets/flask/milestone/36?closed=1";>https://github.com/pallets/flask/milestone/36?closed=1</a></p>
   <ul>
   <li>Fix signing key selection order when key rotation is enabled via 
<code>SECRET_KEY_FALLBACKS</code>. GHSA-4grg-w6v8-c28g</li>
   <li>Fix type hint for <code>cli_runner.invoke</code>. <a 
href="https://redirect.github.com/pallets/flask/issues/5645";>#5645</a></li>
   <li><code>flask --help</code> loads the app and plugins first to make sure 
all commands are shown. <a 
href="https://redirect.github.com/pallets/flask/issues/5673";>#5673</a></li>
   <li>Mark sans-io base class as being able to handle views that return 
<code>AsyncIterable</code>. This is not accurate for Flask, but makes typing 
easier for Quart. <a 
href="https://redirect.github.com/pallets/flask/issues/5659";>#5659</a></li>
   </ul>
   <h2>3.1.0</h2>
   <p>This is the Flask 3.1.0 feature release. A feature release may include 
new features, remove previously deprecated code, add new deprecations, or 
introduce potentially breaking changes. We encourage everyone to upgrade, and 
to use a tool such as <a 
href="https://pypi.org/project/pip-tools/";>pip-tools</a> to pin all 
dependencies and control upgrades. Test with warnings treated as errors to be 
able to adapt to deprecation warnings early.</p>
   <p>PyPI: <a 
href="https://pypi.org/project/Flask/3.1.0/";>https://pypi.org/project/Flask/3.1.0/</a>
   Changes: <a 
href="https://flask.palletsprojects.com/en/stable/changes/#version-3-1-0";>https://flask.palletsprojects.com/en/stable/changes/#version-3-1-0</a>
   Milestone: <a 
href="https://github.com/pallets/flask/milestone/33?closed=1";>https://github.com/pallets/flask/milestone/33?closed=1</a></p>
   <ul>
   <li>Drop support for Python 3.8. <a 
href="https://redirect.github.com/pallets/flask/issues/5623";>#5623</a></li>
   <li>Update minimum dependency versions to latest feature releases. Werkzeug 
&gt;= 3.1, ItsDangerous &gt;= 2.2, Blinker &gt;= 1.9. <a 
href="https://redirect.github.com/pallets/flask/issues/5624";>#5624</a>, <a 
href="https://redirect.github.com/pallets/flask/issues/5633";>#5633</a></li>
   <li>Provide a configuration option to control automatic option responses. <a 
href="https://redirect.github.com/pallets/flask/issues/5496";>#5496</a></li>
   <li><code>Flask.open_resource</code>/<code>open_instance_resource</code> and 
<code>Blueprint.open_resource</code> take an <code>encoding</code> parameter to 
use when opening in text mode. It defaults to <code>utf-8</code>. <a 
href="https://redirect.github.com/pallets/flask/issues/5504";>#5504</a></li>
   <li><code>Request.max_content_length</code> can be customized per-request 
instead of only through the <code>MAX_CONTENT_LENGTH</code> config. Added 
<code>MAX_FORM_MEMORY_SIZE</code> and <code>MAX_FORM_PARTS</code> config. Added 
documentation about resource limits to the security page. <a 
href="https://redirect.github.com/pallets/flask/issues/5625";>#5625</a></li>
   <li>Add support for the <code>Partitioned</code> cookie attribute (CHIPS), 
with the <code>SESSION_COOKIE_PARTITIONED</code> config. <a 
href="https://redirect.github.com/pallets/flask/issues/5472";>#5472</a></li>
   <li><code>-e path</code> takes precedence over default <code>.env</code> and 
<code>.flaskenv</code> files. <code>load_dotenv</code> loads default files in 
addition to a path unless <code>load_defaults=False</code> is passed. <a 
href="https://redirect.github.com/pallets/flask/issues/5628";>#5628</a></li>
   <li>Support key rotation with the <code>SECRET_KEY_FALLBACKS</code> config, 
a list of old secret keys that can still be used for unsigning. Extensions will 
need to add support. <a 
href="https://redirect.github.com/pallets/flask/issues/5621";>#5621</a></li>
   <li>Fix how setting <code>host_matching=True</code> or 
<code>subdomain_matching=False</code> interacts with <code>SERVER_NAME</code>. 
Setting <code>SERVER_NAME</code> no longer restricts requests to only that 
domain. <a 
href="https://redirect.github.com/pallets/flask/issues/5553";>#5553</a></li>
   <li><code>Request.trusted_hosts</code> is checked during routing, and can be 
set through the <code>TRUSTED_HOSTS</code> config. <a 
href="https://redirect.github.com/pallets/flask/issues/5636";>#5636</a></li>
   </ul>
   <h2>3.0.3</h2>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Changelog</summary>
   <p><em>Sourced from <a 
href="https://github.com/pallets/flask/blob/main/CHANGES.rst";>flask's 
changelog</a>.</em></p>
   <blockquote>
   <h2>Version 3.1.3</h2>
   <p>Released 2026-02-18</p>
   <ul>
   <li>The session is marked as accessed for operations that only access the 
keys
   but not the values, such as <code>in</code> and <code>len</code>. 
:ghsa:<code>68rp-wp8r-4726</code></li>
   </ul>
   <h2>Version 3.1.2</h2>
   <p>Released 2025-08-19</p>
   <ul>
   <li><code>stream_with_context</code> does not fail inside async views. 
:issue:<code>5774</code></li>
   <li>When using <code>follow_redirects</code> in the test client, the final 
state
   of <code>session</code> is correct. :issue:<code>5786</code></li>
   <li>Relax type hint for passing bytes IO to <code>send_file</code>. 
:issue:<code>5776</code></li>
   </ul>
   <h2>Version 3.1.1</h2>
   <p>Released 2025-05-13</p>
   <ul>
   <li>Fix signing key selection order when key rotation is enabled via
   <code>SECRET_KEY_FALLBACKS</code>. :ghsa:<code>4grg-w6v8-c28g</code></li>
   <li>Fix type hint for <code>cli_runner.invoke</code>. 
:issue:<code>5645</code></li>
   <li><code>flask --help</code> loads the app and plugins first to make sure 
all commands
   are shown. :issue:<code>5673</code></li>
   <li>Mark sans-io base class as being able to handle views that return
   <code>AsyncIterable</code>. This is not accurate for Flask, but makes typing 
easier
   for Quart. :pr:<code>5659</code></li>
   </ul>
   <h2>Version 3.1.0</h2>
   <p>Released 2024-11-13</p>
   <ul>
   <li>Drop support for Python 3.8. :pr:<code>5623</code></li>
   <li>Update minimum dependency versions to latest feature releases.
   Werkzeug &gt;= 3.1, ItsDangerous &gt;= 2.2, Blinker &gt;= 1.9. 
:pr:<code>5624,5633</code></li>
   <li>Provide a configuration option to control automatic option
   responses. :pr:<code>5496</code></li>
   <li><code>Flask.open_resource</code>/<code>open_instance_resource</code> and
   <code>Blueprint.open_resource</code> take an <code>encoding</code> parameter 
to use when
   opening in text mode. It defaults to <code>utf-8</code>. 
:issue:<code>5504</code></li>
   <li><code>Request.max_content_length</code> can be customized per-request 
instead of only
   through the <code>MAX_CONTENT_LENGTH</code> config. Added</li>
   </ul>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/pallets/flask/commit/22d924701a6ae2e4cd01e9a15bbaf3946094af65";><code>22d9247</code></a>
 release version 3.1.3</li>
   <li><a 
href="https://github.com/pallets/flask/commit/089cb86dd22bff589a4eafb7ab8e42dc357623b4";><code>089cb86</code></a>
 Merge commit from fork</li>
   <li><a 
href="https://github.com/pallets/flask/commit/c17f379390731543eea33a570a47bd4ef76a54fa";><code>c17f379</code></a>
 request context tracks session access</li>
   <li><a 
href="https://github.com/pallets/flask/commit/27be9338405382445a7cb01151e084559b98d602";><code>27be933</code></a>
 start version 3.1.3</li>
   <li><a 
href="https://github.com/pallets/flask/commit/4e652d3f68b90d50aa2301d3b7e68c3fafd9251d";><code>4e652d3</code></a>
 Abort if the instance folder cannot be created (<a 
href="https://redirect.github.com/pallets/flask/issues/5903";>#5903</a>)</li>
   <li><a 
href="https://github.com/pallets/flask/commit/3d03098a97ddc6a908aa4a50c2ef7381f8297d0a";><code>3d03098</code></a>
 Abort if the instance folder cannot be created</li>
   <li><a 
href="https://github.com/pallets/flask/commit/407eb76b27884848383a37c7274654f0271e4bc4";><code>407eb76</code></a>
 document using gevent for async (<a 
href="https://redirect.github.com/pallets/flask/issues/5900";>#5900</a>)</li>
   <li><a 
href="https://github.com/pallets/flask/commit/ac5664d2281533eacafd64f5cc7d5edcdaccab60";><code>ac5664d</code></a>
 document using gevent for async</li>
   <li><a 
href="https://github.com/pallets/flask/commit/4f79d5b59a56bc4356a97f2e81a35f98cb18d7b3";><code>4f79d5b</code></a>
 Increase required flit_core version to 3.11 (<a 
href="https://redirect.github.com/pallets/flask/issues/5865";>#5865</a>)</li>
   <li><a 
href="https://github.com/pallets/flask/commit/fe3b215d3ade4db68262dae1a3cdc464a1fc524f";><code>fe3b215</code></a>
 Increase required flit_core version to 3.11</li>
   <li>Additional commits viewable in <a 
href="https://github.com/pallets/flask/compare/2.3.3...3.1.3";>compare 
view</a></li>
   </ul>
   </details>
   <br />
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=flask&package-manager=pip&previous-version=2.3.3&new-version=3.1.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot show <dependency name> ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   You can disable automated security fix PRs for this repo from the [Security 
Alerts page](https://github.com/apache/superset/network/alerts).
   
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to