dependabot[bot] opened a new pull request, #43609:
URL: https://github.com/apache/superset/pull/43609

   Bumps [gunicorn](https://github.com/benoitc/gunicorn) from 26.0.0 to 26.1.0.
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/benoitc/gunicorn/releases";>gunicorn's 
releases</a>.</em></p>
   <blockquote>
   <h2>gunicorn 26.1.0</h2>
   <h3>New Features</h3>
   <ul>
   <li><strong>Glob patterns in <code>reload_extra_files</code></strong>: 
entries containing <code>*</code>, <code>?</code> or <code>[</code>
   are treated as patterns, so <code>ui/*/config.json</code> watches every 
view's config
   without listing them one by one. Patterns are re-expanded on every reload
   check rather than once at startup, so a file created later starts being
   watched without restarting gunicorn, and <code>**</code> recurses. A pattern 
matching
   nothing warns instead of failing, since with live expansion it may match 
later
   (<a 
href="https://redirect.github.com/benoitc/gunicorn/issues/1643";>#1643</a>,
   <a 
href="https://redirect.github.com/benoitc/gunicorn/pull/3662";>#3662</a>).</li>
   </ul>
   <h3>Security</h3>
   <ul>
   <li><strong>Dependency floors raised past known advisories</strong>: every 
declared floor was
   checked against the advisory database. <code>tornado</code>, 
<code>h2</code>, <code>setuptools</code> and
   <code>pymdown-extensions</code> permitted vulnerable versions and now 
require the first
   clean release; <code>pytest</code> and <code>httpx</code> were unpinned and 
now carry floors. The
   <code>tornado</code> example pinned <code>tornado&lt;6</code>, which was 
both the source of several
   advisories and older than the <code>&gt;=6.5.0</code> the tornado worker 
needs, so the
   example could not run as pinned.</li>
   </ul>
   <h3>Bug Fixes</h3>
   <ul>
   <li>
   <p><strong>SIGHUP did not reload the logger configuration</strong>: 
<code>Arbiter.reload()</code>
   re-read the configuration file but kept using the logger built at startup,
   calling only <code>reopen_files()</code> on its existing handlers. Changes to
   <code>logconfig</code>, <code>logconfig_dict</code>, 
<code>logconfig_json</code> and <code>loglevel</code> were ignored
   until a full restart, which in containers meant replacing the pod. The
   existing logger now re-runs its setup on reload, so new handlers, formats
   and levels take effect while the process identity and its listeners are
   preserved, and re-running the setup no longer stacks duplicate syslog
   handlers. An invalid log configuration on reload is not fatal either: the
   error is reported on stderr, the previous working configuration is restored
   and the master keeps running with it
   (<a 
href="https://redirect.github.com/benoitc/gunicorn/issues/3353";>#3353</a>).</p>
   </li>
   <li>
   <p><strong>Truncated chunked bodies accepted</strong>: RFC 9112 section 
7.1.2 ends a chunked
   body with <code>0 CRLF CRLF</code>, the second CRLF being the mandatory 
empty trailer
   section. <code>ChunkedReader.parse_chunk_size()</code> swallowed the 
<code>NoMoreData</code> raised
   while scanning for it, so a body cut short right after the last chunk line 
was
   treated as complete instead of rejected. It now raises
   <code>ChunkMissingTerminator</code>
   (<a 
href="https://redirect.github.com/benoitc/gunicorn/issues/3382";>#3382</a>,
   <a 
href="https://redirect.github.com/benoitc/gunicorn/pull/3685";>#3685</a>).</p>
   </li>
   <li>
   <p><strong><code>--spew</code> crashed on dynamically generated 
code</strong>: the trace hook indexed the
   2-tuple returned by <code>inspect.getsourcelines()</code> by line number 
rather than
   indexing the list of lines, so a frame with no <code>__file__</code> raised
   <code>AttributeError: 'int' object has no attribute 'rstrip'</code> on line 
1 and</p>
   </li>
   </ul>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/benoitc/gunicorn/commit/71b59a75820dd4a762dc42a3280124168b4e44a8";><code>71b59a7</code></a>
 Merge pull request <a 
href="https://redirect.github.com/benoitc/gunicorn/issues/3698";>#3698</a> from 
benoitc/fix/docker-health-check-readerror</li>
   <li><a 
href="https://github.com/benoitc/gunicorn/commit/48287de8d8360825c85ac981ddfe9c80dba3b418";><code>48287de</code></a>
 test: catch every transport error in the docker health check</li>
   <li><a 
href="https://github.com/benoitc/gunicorn/commit/3110e8c37f716ca0ed63ca7f80c7c9ea0fbbdd50";><code>3110e8c</code></a>
 Merge pull request <a 
href="https://redirect.github.com/benoitc/gunicorn/issues/3696";>#3696</a> from 
benoitc/docs/roadmap</li>
   <li><a 
href="https://github.com/benoitc/gunicorn/commit/cc56c410b7103c1f2b877279f81cb3a14705315a";><code>cc56c41</code></a>
 Merge pull request <a 
href="https://redirect.github.com/benoitc/gunicorn/issues/3693";>#3693</a> from 
benoitc/release/26.1.0</li>
   <li><a 
href="https://github.com/benoitc/gunicorn/commit/5cf1f1651a40fa36afe13fde623e3437ca872463";><code>5cf1f16</code></a>
 docs: surface the roadmap on the site home page</li>
   <li><a 
href="https://github.com/benoitc/gunicorn/commit/7e35f72d135056c37da321becf22b19aeec06937";><code>7e35f72</code></a>
 docs: add FastCGI to the roadmap and point items at Ideas</li>
   <li><a 
href="https://github.com/benoitc/gunicorn/commit/18ddc586c9b9513b25e92c6ed6f818f66ff3abcd";><code>18ddc58</code></a>
 docs: drop the framework and reverse-proxy non-goals from the roadmap</li>
   <li><a 
href="https://github.com/benoitc/gunicorn/commit/1ecae56ebd096ee4f94d12c59a36f240ce348572";><code>1ecae56</code></a>
 docs: add a roadmap and make the chat easy to find</li>
   <li><a 
href="https://github.com/benoitc/gunicorn/commit/ca412e3f7134bd9f0e91851778ae6d8dd222cf41";><code>ca412e3</code></a>
 docs: sync the Latest changelog page with 26.1.0</li>
   <li><a 
href="https://github.com/benoitc/gunicorn/commit/640936fb29f7bdf5665d5b7f919783bb73e2f981";><code>640936f</code></a>
 docs: note the dependency security work in 26.1.0</li>
   <li>Additional commits viewable in <a 
href="https://github.com/benoitc/gunicorn/compare/26.0.0...26.1.0";>compare 
view</a></li>
   </ul>
   </details>
   <br />
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=gunicorn&package-manager=pip&previous-version=26.0.0&new-version=26.1.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot show <dependency name> ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   
   
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to