Skip to content

chore(deps): update dependency uvicorn to v0.54.0 - #261

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/uvicorn-0.x
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/uvicorn-0.x

Conversation

@renovate

@renovate renovate Bot commented Feb 8, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
uvicorn (changelog) ==0.37.0 → ==0.54.0 age confidence

Release Notes

Kludex/uvicorn (uvicorn)

v0.54.0: Version 0.54.0

Compare Source

📨 Send metadata after the response body

uvicorn 0.54.0 adds response trailers and 103 Early Hints to its experimental HTTP/2 implementation through zttp.

uv add uvicorn==0.54.0 "zttp>=0.0.34"
  • Send HTTP/2 response trailers (#​3146). The ASGI http.response.trailers extension lets applications send metadata, such as checksums, after the response body. Clients must send TE: trailers to receive them. Multiple trailer messages are combined before completing the response.
  • HTTP/2 remains experimental and opt-in. Enable it with --http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 remain unsupported.

💡 Hint at resources before the final response

  • Send 103 Early Hints over HTTP/2 (#​3137). Applications can use the ASGI http.response.early_hint extension to send resource hints before the final response. Each supplied link becomes a separate Link header.

Full changelog: 0.53.0...0.54.0

v0.53.0: Version 0.53.0

Compare Source

🌐 Opt-in HTTP/2 support

uvicorn 0.53.0 adds experimental HTTP/2 through zttp, alongside a new zuvloop integration and connection-handling improvements.

uv add uvicorn==0.53.0
  • Serve HTTP/1.1 and HTTP/2 with zttp (#​2982, #​3101). Install zttp, then enable HTTP/2 with --http zttp --http2. Uvicorn negotiates HTTP/2 over TLS with ALPN and supports cleartext prior knowledge.
  • HTTP/2 remains experimental. Upgrade-based h2c and WebSockets over HTTP/2 are not supported.

⚙️ More event loop choice

  • Run Uvicorn with zuvloop (#​3104). Install zuvloop separately and select it explicitly with --loop zuvloop on CPython 3.14 or newer.

🛡️ More reliable connections and proxies

  • Honor Connection: close token lists (#​3103). Uvicorn now parses comma-separated tokens case-insensitively across HTTP implementations.
  • Trust IPv6 loopback proxies by default (#​3119). The default FORWARDED_ALLOW_IPS value now includes ::1.
  • Keep upgraded WebSockets alive (#​3107). Uvicorn cancels the HTTP keep-alive timer when the connection becomes a WebSocket.

Full changelog: 0.52.4...0.53.0

v0.52.4: Version 0.52.4

Compare Source

Fixed
  • Remove duplicate Date headers from accepted WebSocket handshakes with websockets-sansio (#​3078)

Full Changelog: Kludex/uvicorn@0.52.3...0.52.4

v0.52.3: Version 0.52.3

Compare Source

Changed
  • Update zttp to 0.0.24 and use its combined receive path, improving HTTP/1.1 request parsing performance (#​3067)

Full Changelog: Kludex/uvicorn@0.52.2...0.52.3

v0.52.2: Version 0.52.2

Compare Source

Fixed
  • Update zttp to 0.0.22, fixing bodyless request receives and improving HTTP/1 request parsing performance (#​3063)

Full Changelog: Kludex/uvicorn@0.52.1...0.52.2

v0.52.1: Version 0.52.1

Compare Source

Fixed
  • Complete the closing handshake on server-initiated WebSocket closes in the websockets-sansio and wsproto implementations, waiting for the client's close reply with a 10 second timeout instead of resetting the connection (#​3053)
  • Add missing write flow control to the websockets-sansio implementation, preventing data truncation on server-initiated closes with large in-flight payloads (#​3048)
  • Handle connection loss while a WebSocket write is waiting on backpressure (#​3050)
  • Remove duplicate Content-Type and Content-Length headers from WebSocket denial responses on the websockets-sansio implementation, and deliver non-UTF-8 denial bodies intact (#​3041)

Full Changelog: Kludex/uvicorn@0.52.0...0.52.1

v0.52.0: Version 0.52.0

Compare Source

This release adds an experimental HTTP/1.1 implementation backed by zttp, a sans-IO HTTP parser I've been developing on the side: a core written in Zig, with bindings to Python. It has been running under a fuzzer for some weeks now, and has been through multiple rounds of security auditing.

It is still experimental, so don't put it in front of production traffic yet. Try it with --http zttp, and please send any feedback to the issue tracker.

Added
  • Add an experimental zttp HTTP/1.1 implementation, selectable with --http zttp (#​2979)
Fixed
  • Keep non-ASCII WebSocket request headers intact with websockets 17.0, which encodes them with ISO-8859-1 (#​3036)

Full Changelog: Kludex/uvicorn@0.51.0...0.52.0

v0.51.0: Version 0.51.0

Compare Source

What's Changed

Full Changelog: Kludex/uvicorn@0.50.2...0.51.0

v0.50.2: Version 0.50.2

Compare Source

What's Changed

  • Require websockets>=13.0 for the default sansio implementation by @​Kludex in #​3021

Full Changelog: Kludex/uvicorn@0.50.1...0.50.2

v0.50.1: Version 0.50.1

Compare Source

What's Changed

  • Split comma-separated Sec-WebSocket-Protocol values in the websockets-sansio implementation by @​Aayush7352 in #​3019

New Contributors

Full Changelog: Kludex/uvicorn@0.50.0...0.50.1

v0.50.0: Version 0.50.0

Compare Source

What's Changed
  • Memoize trusted host checks to avoid re-parsing the client IP per request by @​Kludex in #​2970
  • Cache the asgi scope sub-dict per connection by @​Kludex in #​2976
  • Build a fresh asgi scope dict per request by @​Kludex in #​2977
  • Replace click.style with an internal ANSI style helper by @​Kludex in #​2981
  • Avoid copying single-frame WebSocket payloads in websockets-sansio by @​Kludex in #​2983
  • Deprecate the legacy websockets implementation and default auto to websockets-sansio by @​Kludex in #​2985
  • Exit with a dedicated code on startup failure and stop the supervisor when a worker can't boot by @​Kludex in #​3001
  • Skip the eager app import in the parent when spawning workers by @​Kludex in #​3012

Full Changelog: Kludex/uvicorn@0.49.0...0.50.0

v0.49.0: Version 0.49.0

Compare Source

What's Changed

  • Bump httptools minimum version to 0.8.0 by @​Kludex in #​2962
  • Consume duplicate forwarding headers in ProxyHeadersMiddleware (reverses the 0.48.0 behavior of ignoring them) by @​Kludex in #​2971

Full Changelog: Kludex/uvicorn@0.48.0...0.49.0

v0.48.0: Version 0.48.0

Compare Source

What's Changed

Full Changelog: Kludex/uvicorn@0.47.0...0.48.0

v0.47.0: Version 0.47.0

Compare Source

What's Changed

Full Changelog: Kludex/uvicorn@0.46.0...0.47.0

v0.46.0: Version 0.46.0

Compare Source

What's Changed

Full Changelog: Kludex/uvicorn@0.45.0...0.46.0

v0.45.0: Version 0.45.0

Compare Source

What's Changed

New Contributors

Full Changelog: Kludex/uvicorn@0.44.0...0.45.0

v0.44.0: Version 0.44.0

Compare Source

What's Changed

Full Changelog: Kludex/uvicorn@0.43.0...0.44.0

v0.43.0: Version 0.43.0

Compare Source

Changed

  • Emit http.disconnect ASGI receive() event on server shutting down for streaming responses (#​2829)
  • Use native context parameter for create_task on Python 3.11+ (#​2859)
  • Drop cast in ASGI types (#​2875)

Full Changelog: Kludex/uvicorn@0.42.0...0.43.0

v0.42.0: Version 0.42.0

Compare Source

Changed

  • Use bytearray for request body accumulation to avoid O(n^2) allocation on fragmented bodies (#​2845)

Fixed

  • Escape brackets and backslash in httptools HEADER_RE regex (#​2824)
  • Fix multiple issues in websockets sans-io implementation (#​2825)

New Contributors


Full Changelog: Kludex/uvicorn@0.41.0...0.42.0

v0.41.0: Version 0.41.0

Compare Source

Added

  • Add --limit-max-requests-jitter to stagger worker restarts (#​2707)
  • Add socket path to scope["server"] (#​2561)

Changed

  • Rename LifespanOn.error_occured to error_occurred (#​2776)

Fixed

  • Ignore permission denied errors in watchfiles reloader (#​2817)
  • Ensure lifespan shutdown runs when should_exit is set during startup (#​2812)
  • Reduce the log level of 'request limit exceeded' messages (#​2788)

New Contributors


Full Changelog: Kludex/uvicorn@0.40.0...0.41.0

v0.40.0: Version 0.40.0

Compare Source

What's Changed

Full Changelog: Kludex/uvicorn@0.39.0...0.40.0

v0.39.0: Version 0.39.0

Compare Source

What's Changed

New Contributors

Full Changelog: Kludex/uvicorn@0.38.0...0.39.0

v0.38.0: Version 0.38.0

Compare Source

What's Changed


New Contributors

Full Changelog: Kludex/uvicorn@0.37.0...0.38.0


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot changed the title chore(deps): update dependency uvicorn to v0.40.0 chore(deps): update dependency uvicorn to v0.41.0 Feb 17, 2026
@renovate
renovate Bot force-pushed the renovate/uvicorn-0.x branch from b457c5a to 30075f9 Compare February 17, 2026 01:15
@renovate
renovate Bot force-pushed the renovate/uvicorn-0.x branch from 30075f9 to 5b3a134 Compare March 13, 2026 16:55
@renovate renovate Bot changed the title chore(deps): update dependency uvicorn to v0.41.0 chore(deps): update dependency uvicorn to v0.42.0 Mar 16, 2026
@renovate
renovate Bot force-pushed the renovate/uvicorn-0.x branch from 5b3a134 to 84fc26c Compare March 16, 2026 09:32
@renovate renovate Bot changed the title chore(deps): update dependency uvicorn to v0.42.0 chore(deps): update dependency uvicorn to v0.43.0 Apr 3, 2026
@renovate
renovate Bot force-pushed the renovate/uvicorn-0.x branch from 84fc26c to ceff13b Compare April 3, 2026 21:55
@renovate renovate Bot changed the title chore(deps): update dependency uvicorn to v0.43.0 chore(deps): update dependency uvicorn to v0.44.0 Apr 6, 2026
@renovate
renovate Bot force-pushed the renovate/uvicorn-0.x branch from ceff13b to cab32be Compare April 6, 2026 09:33
@renovate renovate Bot changed the title chore(deps): update dependency uvicorn to v0.44.0 chore(deps): update dependency uvicorn to v0.45.0 Apr 21, 2026
@renovate
renovate Bot force-pushed the renovate/uvicorn-0.x branch from cab32be to 7d62036 Compare April 21, 2026 16:14
@renovate renovate Bot changed the title chore(deps): update dependency uvicorn to v0.45.0 chore(deps): update dependency uvicorn to v0.46.0 Apr 23, 2026
@renovate
renovate Bot force-pushed the renovate/uvicorn-0.x branch from 7d62036 to 3069247 Compare April 23, 2026 09:35
@renovate renovate Bot changed the title chore(deps): update dependency uvicorn to v0.46.0 chore(deps): update dependency uvicorn to v0.47.0 May 14, 2026
@renovate
renovate Bot force-pushed the renovate/uvicorn-0.x branch from 3069247 to 9ecca7c Compare May 14, 2026 21:59
@renovate renovate Bot changed the title chore(deps): update dependency uvicorn to v0.47.0 chore(deps): update dependency uvicorn to v0.48.0 May 24, 2026
@renovate
renovate Bot force-pushed the renovate/uvicorn-0.x branch from 9ecca7c to 1f31fa3 Compare May 24, 2026 12:57
@renovate renovate Bot changed the title chore(deps): update dependency uvicorn to v0.48.0 chore(deps): update dependency uvicorn to v0.49.0 Jun 3, 2026
@renovate
renovate Bot force-pushed the renovate/uvicorn-0.x branch from 1f31fa3 to e13db91 Compare June 3, 2026 22:38
@renovate renovate Bot changed the title chore(deps): update dependency uvicorn to v0.49.0 chore(deps): update dependency uvicorn to v0.50.0 Jul 4, 2026
@renovate
renovate Bot force-pushed the renovate/uvicorn-0.x branch from e13db91 to 9c82047 Compare July 4, 2026 05:14
@renovate renovate Bot changed the title chore(deps): update dependency uvicorn to v0.50.0 chore(deps): update dependency uvicorn to v0.50.2 Jul 6, 2026
@renovate
renovate Bot force-pushed the renovate/uvicorn-0.x branch 2 times, most recently from 6f938c4 to d358d5e Compare July 8, 2026 15:45
@renovate renovate Bot changed the title chore(deps): update dependency uvicorn to v0.50.2 chore(deps): update dependency uvicorn to v0.51.0 Jul 8, 2026
@renovate renovate Bot changed the title chore(deps): update dependency uvicorn to v0.51.0 chore(deps): update dependency uvicorn to v0.52.0 Jul 29, 2026
@renovate
renovate Bot force-pushed the renovate/uvicorn-0.x branch from d358d5e to d2c2578 Compare July 29, 2026 11:01
@renovate renovate Bot changed the title chore(deps): update dependency uvicorn to v0.52.0 chore(deps): update dependency uvicorn to v0.52.1 Aug 1, 2026
@renovate
renovate Bot force-pushed the renovate/uvicorn-0.x branch from d2c2578 to 9116579 Compare August 1, 2026 22:26
@renovate renovate Bot changed the title chore(deps): update dependency uvicorn to v0.52.1 chore(deps): update dependency uvicorn to v0.52.2 Aug 13, 2026
@renovate
renovate Bot force-pushed the renovate/uvicorn-0.x branch from 9116579 to 37a20c3 Compare August 13, 2026 11:55
@renovate renovate Bot changed the title chore(deps): update dependency uvicorn to v0.52.2 chore(deps): update dependency uvicorn to v0.52.3 Aug 13, 2026
@renovate
renovate Bot force-pushed the renovate/uvicorn-0.x branch 2 times, most recently from f9b072f to 10ca118 Compare August 19, 2026 06:59
@renovate renovate Bot changed the title chore(deps): update dependency uvicorn to v0.52.3 chore(deps): update dependency uvicorn to v0.52.4 Aug 19, 2026
@renovate
renovate Bot force-pushed the renovate/uvicorn-0.x branch from 10ca118 to 613f2a3 Compare September 14, 2026 10:50
@renovate renovate Bot changed the title chore(deps): update dependency uvicorn to v0.52.4 chore(deps): update dependency uvicorn to v0.53.0 Sep 14, 2026
@renovate renovate Bot changed the title chore(deps): update dependency uvicorn to v0.53.0 chore(deps): update dependency uvicorn to v0.54.0 Sep 25, 2026
@renovate
renovate Bot force-pushed the renovate/uvicorn-0.x branch from 613f2a3 to 5845f41 Compare September 25, 2026 13:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants