Skip to content

Update fastapi to 0.139.2 - #598

Closed
pyup-bot wants to merge 1 commit into
masterfrom
pyup-update-fastapi-0.6.4-to-0.139.2
Closed

Update fastapi to 0.139.2#598
pyup-bot wants to merge 1 commit into
masterfrom
pyup-update-fastapi-0.6.4-to-0.139.2

Conversation

@pyup-bot

@pyup-bot pyup-bot commented Jul 16, 2026

Copy link
Copy Markdown
Collaborator

This PR updates fastapi from 0.6.4 to 0.139.2.

Changelog

0.139.2

Fixes

* 🐛 Refactor router route building to make it thread-safe, mainly relevant for tests running in parallel threads (uncommon). PR [16013](https://github.com/fastapi/fastapi/pull/16013) by [tiangolo](https://github.com/tiangolo).

0.139.1

Fixes

* 🐛 Fix frontend fallback support for doted paths like `/users/john.doe`. PR [16011](https://github.com/fastapi/fastapi/pull/16011) by [tiangolo](https://github.com/tiangolo).

Docs

* 📝 Fix topic repository list not being displayed and `skip_users` not being applied. PR [15995](https://github.com/fastapi/fastapi/pull/15995) by [YuriiMotov](https://github.com/YuriiMotov).

Translations

* 🌐 Update translations for tr (update-outdated). PR [16005](https://github.com/fastapi/fastapi/pull/16005) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for zh-hant (update-outdated). PR [15996](https://github.com/fastapi/fastapi/pull/15996) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for fr (update-outdated). PR [16006](https://github.com/fastapi/fastapi/pull/16006) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for de (update-outdated). PR [15999](https://github.com/fastapi/fastapi/pull/15999) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for ko (update-outdated). PR [16004](https://github.com/fastapi/fastapi/pull/16004) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for zh (update-outdated). PR [16001](https://github.com/fastapi/fastapi/pull/16001) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for uk (update-outdated). PR [16003](https://github.com/fastapi/fastapi/pull/16003) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for ja (update-outdated). PR [15998](https://github.com/fastapi/fastapi/pull/15998) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for pt (update-outdated). PR [16000](https://github.com/fastapi/fastapi/pull/16000) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for es (update-outdated). PR [15997](https://github.com/fastapi/fastapi/pull/15997) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for ru (update-outdated). PR [16002](https://github.com/fastapi/fastapi/pull/16002) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for hi (add-missing). PR [15990](https://github.com/fastapi/fastapi/pull/15990) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for hi (add-missing). PR [15925](https://github.com/fastapi/fastapi/pull/15925) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for hi (add-missing). PR [15797](https://github.com/fastapi/fastapi/pull/15797) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update `llm-prompt.md` for Hindi. PR [15810](https://github.com/fastapi/fastapi/pull/15810) by [YuriiMotov](https://github.com/YuriiMotov).
* 🌐 Fix language-specific translation prompt for Russian language. PR [15924](https://github.com/fastapi/fastapi/pull/15924) by [YuriiMotov](https://github.com/YuriiMotov).

Internal

* ⬆ Bump the python-packages group across 1 directory with 6 updates. PR [15981](https://github.com/fastapi/fastapi/pull/15981) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump typing-extensions from 4.15.0 to 4.16.0. PR [15982](https://github.com/fastapi/fastapi/pull/15982) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump the github-actions group across 1 directory with 4 updates. PR [15983](https://github.com/fastapi/fastapi/pull/15983) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump pre-commit hooks. PR [15985](https://github.com/fastapi/fastapi/pull/15985) by [tiangolo](https://github.com/tiangolo).
* 👷 Use `FASTAPI_LATEST_CHANGES` token in `bump-pre-commit-hooks` workflow. PR [15984](https://github.com/fastapi/fastapi/pull/15984) by [YuriiMotov](https://github.com/YuriiMotov).
* 👷 Add GH workflow to bump pre-commit hook versions. PR [15873](https://github.com/fastapi/fastapi/pull/15873) by [YuriiMotov](https://github.com/YuriiMotov).
* 🔧 Set Dependabot schedule interval to "monthly". PR [15874](https://github.com/fastapi/fastapi/pull/15874) by [YuriiMotov](https://github.com/YuriiMotov).
* ⬆ Bump CodSpeedHQ/action from 4.17.6 to 4.18.1 in the github-actions group. PR [15950](https://github.com/fastapi/fastapi/pull/15950) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump the python-packages group with 8 updates. PR [15952](https://github.com/fastapi/fastapi/pull/15952) by [dependabot[bot]](https://github.com/apps/dependabot).
* 🔧 Update sponsors: add TutorCruncher. PR [15947](https://github.com/fastapi/fastapi/pull/15947) by [tiangolo](https://github.com/tiangolo).
* 👷 Fix notify translations checkout target. PR [15933](https://github.com/fastapi/fastapi/pull/15933) by [tiangolo](https://github.com/tiangolo).
* 👷 Fix latest-changes checkout target. PR [15932](https://github.com/fastapi/fastapi/pull/15932) by [tiangolo](https://github.com/tiangolo).
* 🔧 Update sponsors: remove RapidProxy. PR [15929](https://github.com/fastapi/fastapi/pull/15929) by [tiangolo](https://github.com/tiangolo).
* ⬆️ Update issue-manager to 0.8.1. PR [15928](https://github.com/fastapi/fastapi/pull/15928) by [tiangolo](https://github.com/tiangolo).
* ⬆️ Update latest-changes to 0.6.1. PR [15926](https://github.com/fastapi/fastapi/pull/15926) by [tiangolo](https://github.com/tiangolo).

0.139.0

Features

* ✨ Support dependencies in `app.frontend()`, e.g. for automatic cookie authentication for the frontend. PR [15908](https://github.com/fastapi/fastapi/pull/15908) by [tiangolo](https://github.com/tiangolo).

Translations

* 🌐 Update translations for fr (update-outdated). PR [15897](https://github.com/fastapi/fastapi/pull/15897) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for ja (update-outdated). PR [15895](https://github.com/fastapi/fastapi/pull/15895) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for zh-hant (update-outdated). PR [15896](https://github.com/fastapi/fastapi/pull/15896) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for de (update-outdated). PR [15899](https://github.com/fastapi/fastapi/pull/15899) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for es (update-outdated). PR [15892](https://github.com/fastapi/fastapi/pull/15892) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for tr (update-outdated). PR [15891](https://github.com/fastapi/fastapi/pull/15891) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for pt (update-outdated). PR [15893](https://github.com/fastapi/fastapi/pull/15893) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for zh (update-outdated). PR [15898](https://github.com/fastapi/fastapi/pull/15898) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for uk (update-outdated). PR [15900](https://github.com/fastapi/fastapi/pull/15900) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for ko (update-outdated). PR [15890](https://github.com/fastapi/fastapi/pull/15890) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for ru (update-outdated). PR [15894](https://github.com/fastapi/fastapi/pull/15894) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for ko (add-missing). PR [15888](https://github.com/fastapi/fastapi/pull/15888) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for es (add-missing). PR [15880](https://github.com/fastapi/fastapi/pull/15880) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for zh-hant (add-missing). PR [15889](https://github.com/fastapi/fastapi/pull/15889) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for pt (add-missing). PR [15883](https://github.com/fastapi/fastapi/pull/15883) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for zh (add-missing). PR [15885](https://github.com/fastapi/fastapi/pull/15885) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for ja (add-missing). PR [15882](https://github.com/fastapi/fastapi/pull/15882) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for tr (add-missing). PR [15887](https://github.com/fastapi/fastapi/pull/15887) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for uk (add-missing). PR [15886](https://github.com/fastapi/fastapi/pull/15886) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for fr (add-missing). PR [15881](https://github.com/fastapi/fastapi/pull/15881) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for de (add-missing). PR [15884](https://github.com/fastapi/fastapi/pull/15884) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for ru (add-missing). PR [15879](https://github.com/fastapi/fastapi/pull/15879) by [tiangolo](https://github.com/tiangolo).

Internal

* 👥 Update FastAPI People - Experts. PR [15909](https://github.com/fastapi/fastapi/pull/15909) by [tiangolo](https://github.com/tiangolo).
* 👥 Update FastAPI GitHub topic repositories. PR [15906](https://github.com/fastapi/fastapi/pull/15906) by [tiangolo](https://github.com/tiangolo).
* 👥 Update FastAPI People - Contributors and Translators. PR [15878](https://github.com/fastapi/fastapi/pull/15878) by [tiangolo](https://github.com/tiangolo).
* 👷 Remove not needed `allow-unsafe-pr-checkout: true`. PR [15876](https://github.com/fastapi/fastapi/pull/15876) by [YuriiMotov](https://github.com/YuriiMotov).
* ⬆ Bump the github-actions group with 5 updates. PR [15872](https://github.com/fastapi/fastapi/pull/15872) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump the python-packages group across 1 directory with 10 updates. PR [15870](https://github.com/fastapi/fastapi/pull/15870) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump CodSpeedHQ/action from 4.17.0 to 4.17.5 in the github-actions group. PR [15826](https://github.com/fastapi/fastapi/pull/15826) by [dependabot[bot]](https://github.com/apps/dependabot).

0.138.1

Refactors

* ♻️ Refactor Library Skills, make info easier to find for agents. PR [15841](https://github.com/fastapi/fastapi/pull/15841) by [tiangolo](https://github.com/tiangolo).

Internal

* 👷 Simplify pull request workflow triggers. PR [15836](https://github.com/fastapi/fastapi/pull/15836) by [tiangolo](https://github.com/tiangolo).
* 👷 Update issue-manager to 0.7.1. PR [15833](https://github.com/fastapi/fastapi/pull/15833) by [tiangolo](https://github.com/tiangolo).
* ⬆️ Update issue-manager to 0.7.0. PR [15831](https://github.com/fastapi/fastapi/pull/15831) by [tiangolo](https://github.com/tiangolo).
* 🔧 Update sponsors: Add TestMu again. PR [15830](https://github.com/fastapi/fastapi/pull/15830) by [tiangolo](https://github.com/tiangolo).
* 🔒️ Update zizmor workflow security checks. PR [15820](https://github.com/fastapi/fastapi/pull/15820) by [tiangolo](https://github.com/tiangolo).
* ⬆ Bump pydantic-settings from 2.14.1 to 2.14.2. PR [15799](https://github.com/fastapi/fastapi/pull/15799) by [dependabot[bot]](https://github.com/apps/dependabot).

0.138.0

Features

* ✨ Add support for `app.frontend("/", directory="dist")` and `router.frontend("/", directory="dist")`. PR [15800](https://github.com/fastapi/fastapi/pull/15800) by [tiangolo](https://github.com/tiangolo).
 * Read the docs: [Frontend](https://fastapi.tiangolo.com/tutorial/frontend/).

Docs

* 📝 Fix typo in release notes. PR [15807](https://github.com/fastapi/fastapi/pull/15807) by [tiangolo](https://github.com/tiangolo).
* 📝 Add `app.frontend()` instructions to Agent Library Skill. PR [15805](https://github.com/fastapi/fastapi/pull/15805) by [tiangolo](https://github.com/tiangolo).
* 📝 Update release notes link. PR [15802](https://github.com/fastapi/fastapi/pull/15802) by [tiangolo](https://github.com/tiangolo).
* ✏️ Update white space characters in bigger apps. PR [15801](https://github.com/fastapi/fastapi/pull/15801) by [tiangolo](https://github.com/tiangolo).
* ✏️ Fix grammar, typos, and broken links in docs. PR [15694](https://github.com/fastapi/fastapi/pull/15694) by [YuriiMotov](https://github.com/YuriiMotov).

Translations

* 🌐 Enable Hindi docs translations. PR [15554](https://github.com/fastapi/fastapi/pull/15554) by [YuriiMotov](https://github.com/YuriiMotov).

Internal

* 🐛 Fix failing test, update format for raised errors. PR [15804](https://github.com/fastapi/fastapi/pull/15804) by [tiangolo](https://github.com/tiangolo).
* 👷 Fix test-alls-green. PR [15803](https://github.com/fastapi/fastapi/pull/15803) by [tiangolo](https://github.com/tiangolo).
* 🔧 Enable checking `release-notes.md` for typos. PR [15796](https://github.com/fastapi/fastapi/pull/15796) by [YuriiMotov](https://github.com/YuriiMotov).
* 📝 Tweak wording about deploying to FastAPI Cloud. PR [15793](https://github.com/fastapi/fastapi/pull/15793) by [tiangolo](https://github.com/tiangolo).
* 🔨 Use `gpt-5.5` model in `translate.py`, specify `-chat` to avoid warnings. PR [15792](https://github.com/fastapi/fastapi/pull/15792) by [YuriiMotov](https://github.com/YuriiMotov).

0.137.2

Features

* ✨ Add `iter_route_contexts()` for advanced use cases that used to use `router.routes` (e.g. Jupyverse). PR [15785](https://github.com/fastapi/fastapi/pull/15785) by [tiangolo](https://github.com/tiangolo).

Translations

* 🌐 Fix broken Markdown in Korean custom response docs. PR [15774](https://github.com/fastapi/fastapi/pull/15774) by [kooqooo](https://github.com/kooqooo).
* 🌐 Update translations for fr (update-outdated). PR [15761](https://github.com/fastapi/fastapi/pull/15761) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for zh-hant (update-outdated). PR [15760](https://github.com/fastapi/fastapi/pull/15760) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for de (update-outdated). PR [15759](https://github.com/fastapi/fastapi/pull/15759) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for ko (update-outdated). PR [15757](https://github.com/fastapi/fastapi/pull/15757) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for uk (update-outdated). PR [15756](https://github.com/fastapi/fastapi/pull/15756) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for zh (update-outdated). PR [15755](https://github.com/fastapi/fastapi/pull/15755) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for tr (update-outdated). PR [15754](https://github.com/fastapi/fastapi/pull/15754) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for pt (update-outdated). PR [15753](https://github.com/fastapi/fastapi/pull/15753) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for es (update-outdated). PR [15752](https://github.com/fastapi/fastapi/pull/15752) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for ja (update-outdated). PR [15751](https://github.com/fastapi/fastapi/pull/15751) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for ru (update-outdated). PR [15758](https://github.com/fastapi/fastapi/pull/15758) by [tiangolo](https://github.com/tiangolo).

Internal

* 🔧 Update sponsors: add BairesDev. PR [15787](https://github.com/fastapi/fastapi/pull/15787) by [tiangolo](https://github.com/tiangolo).
* 🔨 Update sponsors script to simplify previews. PR [15786](https://github.com/fastapi/fastapi/pull/15786) by [tiangolo](https://github.com/tiangolo).
* ⬆ Bump the python-packages group across 1 directory with 7 updates. PR [15777](https://github.com/fastapi/fastapi/pull/15777) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump cryptography from 46.0.7 to 48.0.1. PR [15779](https://github.com/fastapi/fastapi/pull/15779) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump aiohttp from 3.14.0 to 3.14.1. PR [15781](https://github.com/fastapi/fastapi/pull/15781) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump starlette from 1.2.1 to 1.3.1. PR [15780](https://github.com/fastapi/fastapi/pull/15780) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump astral-sh/setup-uv from 8.1.0 to 8.2.0 in the github-actions group. PR [15776](https://github.com/fastapi/fastapi/pull/15776) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump https://github.com/crate-ci/typos from v1.47.1 to v1.47.2 in the pre-commit group. PR [#15775](https://github.com/fastapi/fastapi/pull/15775) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump python-multipart from 0.0.30 to 0.0.32. PR [15778](https://github.com/fastapi/fastapi/pull/15778) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⏪️ Revert removing scripts, only remove `coverage.sh`. PR [15772](https://github.com/fastapi/fastapi/pull/15772) by [tiangolo](https://github.com/tiangolo).
* 🔥 Remove unused scripts. PR [15771](https://github.com/fastapi/fastapi/pull/15771) by [tiangolo](https://github.com/tiangolo).
* 🔧 Add ty configs to check docs sources. PR [15770](https://github.com/fastapi/fastapi/pull/15770) by [tiangolo](https://github.com/tiangolo).
* 🔧 Add ty configs to check docs sources. PR [15769](https://github.com/fastapi/fastapi/pull/15769) by [tiangolo](https://github.com/tiangolo).

0.137.1

Fixes

* 🚨 Fix typing checks for APIRoute. PR [15765](https://github.com/fastapi/fastapi/pull/15765) by [tiangolo](https://github.com/tiangolo).
* 🐛 Fix bug, allow empty path in path operation in prefixless router. PR [15763](https://github.com/fastapi/fastapi/pull/15763) by [tiangolo](https://github.com/tiangolo).

0.137.0

Breaking Changes

* ♻️ Refactor internals to preserve `APIRouter` and `APIRoute` instances. PR [15745](https://github.com/fastapi/fastapi/pull/15745) by [tiangolo](https://github.com/tiangolo).

Unblocks ✨ SO MANY THINGS ✨

Before this, `router.include_router(other_router)` would take each path operation from `other_router` and "clone" it, or recreate it from scratch.

This would mean that in the end there was only one top level router, part of the app.

The way it is structured here is that there are a few additional classes to handle intermediate metadata for router and route inclusion. That way the information of "router X includes Y and Y includes Z" is stored somewhere, without affecting (recreating / clonning) the final route.

Non Objectives

Dependencies for 404: previously I intended to support dependencies that would be executed even for 404, but that would conflict with the fact that a router could _not_ find a match, but the next router _did_ find a match. Executing dependencies in the router that did not find a match would not make sense, they could consume the request, body, etc. This original idea was discarded.

Specific Breaking Changes

Now `router.routes` is no longer a plain list of `APIRoute` objects, it can contain these intermediate objects that can contain additional routers, forming a tree.

Any logic that depended on iterating on the `router.routes` directly would be affected, that logic cannot expect to be able to extract data from a plain list of routes, as it's no longer a plain list but a tree.

Additionally, any logic that iterated on `router.routes` to modify them would now also see these new objects, and would not see all the routes in the app.

`router.routes` should be considered an internal implementation detail, only passed around to the FastAPI functions that need it.

Features

* Adding routes (path operations) after a router is included now works, they are reflected as they are not copied.
* Including `subrouter` in `mainrouter` can be done before adding routes (path operations) to `subrouter`, because now the the entire object is stored instead of copying the routes.
* As routes are not copied, in some cases that might save some memory.

Alpha Features

This is not documented yet, so it's not officially supported yet and could change in the future.

But, as `APIRoute` and `APIRouter` instances are now preserved, they could be customized.

`APIRouter` has two new methods, `.matches()` and `.handle()`, counterpart to the existing ones in `APIRoute`. With this a router could customize how it matches and handles requests. For example, it could match only requests that include some specific header, for example for handling versions in headers.

Still, for now, consider this very experimental and potentially changing and breaking in the future.

Future Features Enabled

* Custom `APIRoute` subclasses (undocumented, but alraedy works as desccribed above)
* Custom `APIRouter` subclasses (undocumented, but already works as described above)
* Dependencies per router
* Exception handlers per router
* Middleware per router
* Other features planned

Docs

* 📝 Update release notes. PR [15747](https://github.com/fastapi/fastapi/pull/15747) by [tiangolo](https://github.com/tiangolo).
* 📝 Update FastAPI Cloud deployment instructions. PR [15724](https://github.com/fastapi/fastapi/pull/15724) by [alejsdev](https://github.com/alejsdev).
* ✏️ Use `Annotated` in inline example in `docs/en/docs/tutorial/body-multiple-params.md`. PR [15591](https://github.com/fastapi/fastapi/pull/15591) by [TheArchons](https://github.com/TheArchons).
* 📝 Remove "NGINX Unit" from the list of ASGI-servers in docs. PR [15475](https://github.com/fastapi/fastapi/pull/15475) by [angryfoxx](https://github.com/angryfoxx).
* 📝 Update `docs/en/docs/tutorial/security/oauth2-jwt.md`. PR [14781](https://github.com/fastapi/fastapi/pull/14781) by [zadevhub](https://github.com/zadevhub).

Translations

* 🌐 Update translations for zh-hant (update-outdated). PR [15671](https://github.com/fastapi/fastapi/pull/15671) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for es (update-outdated). PR [15670](https://github.com/fastapi/fastapi/pull/15670) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for fr (update-outdated). PR [15669](https://github.com/fastapi/fastapi/pull/15669) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for ja (update-outdated). PR [15668](https://github.com/fastapi/fastapi/pull/15668) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for pt (update-outdated). PR [15667](https://github.com/fastapi/fastapi/pull/15667) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for tr (update-outdated). PR [15666](https://github.com/fastapi/fastapi/pull/15666) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for zh (update-outdated). PR [15665](https://github.com/fastapi/fastapi/pull/15665) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for ko (update-outdated). PR [15664](https://github.com/fastapi/fastapi/pull/15664) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for de (update-outdated). PR [15673](https://github.com/fastapi/fastapi/pull/15673) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for uk (update-outdated). PR [15672](https://github.com/fastapi/fastapi/pull/15672) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for ru (update-outdated). PR [15674](https://github.com/fastapi/fastapi/pull/15674) by [tiangolo](https://github.com/tiangolo).

Internal

* 🔧 Update sponsors: remove TalorData. PR [15744](https://github.com/fastapi/fastapi/pull/15744) by [tiangolo](https://github.com/tiangolo).
* 🔧 Update sponsors: remove ExoFlare. PR [15736](https://github.com/fastapi/fastapi/pull/15736) by [tiangolo](https://github.com/tiangolo).
* 🔧 Update sponsors: remove InterviewPal. PR [15735](https://github.com/fastapi/fastapi/pull/15735) by [tiangolo](https://github.com/tiangolo).
* 🔧 Update sponsors: remove Liblab. PR [15731](https://github.com/fastapi/fastapi/pull/15731) by [tiangolo](https://github.com/tiangolo).
* 🔧 Update sponsors: remove Scalar. PR [15730](https://github.com/fastapi/fastapi/pull/15730) by [tiangolo](https://github.com/tiangolo).
* ⬆ Bump the python-packages group across 1 directory with 6 updates. PR [15721](https://github.com/fastapi/fastapi/pull/15721) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump python-multipart from 0.0.29 to 0.0.30. PR [15723](https://github.com/fastapi/fastapi/pull/15723) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump the github-actions group with 3 updates. PR [15720](https://github.com/fastapi/fastapi/pull/15720) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump starlette from 1.1.0 to 1.2.1. PR [15722](https://github.com/fastapi/fastapi/pull/15722) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump https://github.com/crate-ci/typos from v1.46.0 to v1.47.1 in the pre-commit group. PR [#15719](https://github.com/fastapi/fastapi/pull/15719) by [dependabot[bot]](https://github.com/apps/dependabot).
* 🔧 Update sponsors, add Rapidproxy. PR [15689](https://github.com/fastapi/fastapi/pull/15689) by [tiangolo](https://github.com/tiangolo).
* 🔧 Update sponsors: Remove TestMu. PR [15688](https://github.com/fastapi/fastapi/pull/15688) by [tiangolo](https://github.com/tiangolo).
* ⬆ Bump the python-packages group across 1 directory with 11 updates. PR [15683](https://github.com/fastapi/fastapi/pull/15683) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump aiohttp from 3.13.4 to 3.14.0. PR [15681](https://github.com/fastapi/fastapi/pull/15681) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump the github-actions group with 2 updates. PR [15682](https://github.com/fastapi/fastapi/pull/15682) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump starlette from 1.0.0 to 1.1.0. PR [15684](https://github.com/fastapi/fastapi/pull/15684) by [dependabot[bot]](https://github.com/apps/dependabot).
* 👥 Update FastAPI People - Experts. PR [15677](https://github.com/fastapi/fastapi/pull/15677) by [tiangolo](https://github.com/tiangolo).
* 👥 Update FastAPI GitHub topic repositories. PR [15675](https://github.com/fastapi/fastapi/pull/15675) by [tiangolo](https://github.com/tiangolo).
* 👥 Update FastAPI People - Contributors and Translators. PR [15662](https://github.com/fastapi/fastapi/pull/15662) by [tiangolo](https://github.com/tiangolo).
* 👷 Automate release preparation. PR [15661](https://github.com/fastapi/fastapi/pull/15661) by [tiangolo](https://github.com/tiangolo).
* 🔥 Remove slim package stub, deprecated for a while. PR [15649](https://github.com/fastapi/fastapi/pull/15649) by [tiangolo](https://github.com/tiangolo).
* ⬆ Bump authlib from 1.6.11 to 1.7.2. PR [15512](https://github.com/fastapi/fastapi/pull/15512) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump pymdown-extensions from 10.21.2 to 10.21.3. PR [15569](https://github.com/fastapi/fastapi/pull/15569) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump CodSpeedHQ/action from 4.14.0 to 4.15.1. PR [15513](https://github.com/fastapi/fastapi/pull/15513) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump python-multipart from 0.0.26 to 0.0.29. PR [15595](https://github.com/fastapi/fastapi/pull/15595) by [dependabot[bot]](https://github.com/apps/dependabot).
* 🔒️ Improve GitHub actions security. PR [15607](https://github.com/fastapi/fastapi/pull/15607) by [YuriiMotov](https://github.com/YuriiMotov).
* ⚰️ Remove ruff and coverage ignores for non-existing files. PR [15610](https://github.com/fastapi/fastapi/pull/15610) by [YuriiMotov](https://github.com/YuriiMotov).
* ✅ Use custom `changing_dir` instead of `CLIRunner.isolated_filesystem` to set working dir. PR [15616](https://github.com/fastapi/fastapi/pull/15616) by [YuriiMotov](https://github.com/YuriiMotov).
* ✅ Add `httpx2` test dependency to avoid deprecation warning. PR [15603](https://github.com/fastapi/fastapi/pull/15603) by [YuriiMotov](https://github.com/YuriiMotov).
* ⬆ Bump the python-packages group with 15 updates. PR [15594](https://github.com/fastapi/fastapi/pull/15594) by [dependabot[bot]](https://github.com/apps/dependabot).
* 👷 Configure Dependabot to group updates and update weekly. PR [15560](https://github.com/fastapi/fastapi/pull/15560) by [YuriiMotov](https://github.com/YuriiMotov).

0.136.3

Refactors

* ♻️ Do not accept underscore headers when using `convert_underscores=True` (the default). PR [15589](https://github.com/fastapi/fastapi/pull/15589) by [tiangolo](https://github.com/tiangolo).

0.136.2

Refactors

* ♻️ Validate Server Sent Event fields to avoid applications from sending broken data. PR [15588](https://github.com/fastapi/fastapi/pull/15588) by [tiangolo](https://github.com/tiangolo).

Docs

* 📝 Document `--entrypoint` CLI option. PR [15464](https://github.com/fastapi/fastapi/pull/15464) by [YuriiMotov](https://github.com/YuriiMotov).
* 📝 Update and simplify docs about help and management. PR [15583](https://github.com/fastapi/fastapi/pull/15583) by [tiangolo](https://github.com/tiangolo).
* 📝 Add docs references to central contributing docs. PR [15580](https://github.com/fastapi/fastapi/pull/15580) by [tiangolo](https://github.com/tiangolo).
* 📝 Update security policy. PR [15577](https://github.com/fastapi/fastapi/pull/15577) by [tiangolo](https://github.com/tiangolo).
* 🍱 Update sponsors: TalorData image. PR [15562](https://github.com/fastapi/fastapi/pull/15562) by [tiangolo](https://github.com/tiangolo).
* 📝 Update docs, simplify usage of admonitions, only default ones. PR [15553](https://github.com/fastapi/fastapi/pull/15553) by [tiangolo](https://github.com/tiangolo).
* 📝 Fix image URLs in `index.md`. PR [15534](https://github.com/fastapi/fastapi/pull/15534) by [YuriiMotov](https://github.com/YuriiMotov).
* ✏️ Fix Azkaban spelling typo in `virtual-environments.md‎`. PR [15463](https://github.com/fastapi/fastapi/pull/15463) by [isaacbernat](https://github.com/isaacbernat).
* 💄 Improve layout and styling. PR [15462](https://github.com/fastapi/fastapi/pull/15462) by [alejsdev](https://github.com/alejsdev).
* 💄 Refactor opinions section with interactive tabs and new logos. PR [15458](https://github.com/fastapi/fastapi/pull/15458) by [alejsdev](https://github.com/alejsdev).
* 📝 Add FastAPI Conf '26 announcement to docs. PR [15457](https://github.com/fastapi/fastapi/pull/15457) by [alejsdev](https://github.com/alejsdev).

Translations

* 🌐 Improve translation consistency in `‎docs/pt/docs/advanced/generate-clients.md‎`. PR [15456](https://github.com/fastapi/fastapi/pull/15456) by [Will-thom](https://github.com/Will-thom).
* 🌐 Update translations for ja (update-outdated). PR [15530](https://github.com/fastapi/fastapi/pull/15530) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for uk (update-outdated). PR [15529](https://github.com/fastapi/fastapi/pull/15529) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for pt (update-outdated). PR [15528](https://github.com/fastapi/fastapi/pull/15528) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for de (update-outdated). PR [15527](https://github.com/fastapi/fastapi/pull/15527) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for tr (update-outdated). PR [15526](https://github.com/fastapi/fastapi/pull/15526) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for ko (update-outdated). PR [15525](https://github.com/fastapi/fastapi/pull/15525) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for zh-hant (update-outdated). PR [15524](https://github.com/fastapi/fastapi/pull/15524) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for fr (update-outdated). PR [15522](https://github.com/fastapi/fastapi/pull/15522) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for es (update-outdated). PR [15523](https://github.com/fastapi/fastapi/pull/15523) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for zh (update-outdated). PR [15520](https://github.com/fastapi/fastapi/pull/15520) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for ru (update-outdated). PR [15521](https://github.com/fastapi/fastapi/pull/15521) by [tiangolo](https://github.com/tiangolo).
* 🌐 Fix typos in Spanish LLM-prompt. PR [15472](https://github.com/fastapi/fastapi/pull/15472) by [crr004](https://github.com/crr004).

Internal

* ✅ Update tests, don't double dispose the engine. PR [15587](https://github.com/fastapi/fastapi/pull/15587) by [tiangolo](https://github.com/tiangolo).
* ⚡️ Speed up test suite via caching and fixture scopes to make it ~24% faster. PR [13583](https://github.com/fastapi/fastapi/pull/13583) by [dikos1337](https://github.com/dikos1337).
* 🔥 Remove config files now in central GitHub repo. PR [15585](https://github.com/fastapi/fastapi/pull/15585) by [tiangolo](https://github.com/tiangolo).
* ⬆ Bump urllib3 from 2.6.3 to 2.7.0. PR [15502](https://github.com/fastapi/fastapi/pull/15502) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump idna from 3.11 to 3.15. PR [15565](https://github.com/fastapi/fastapi/pull/15565) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump cloudflare/wrangler-action from 3.15.0 to 4.0.0. PR [15571](https://github.com/fastapi/fastapi/pull/15571) by [dependabot[bot]](https://github.com/apps/dependabot).
* 🔧 Migrate docs from MkDocs to Zensical. PR [15563](https://github.com/fastapi/fastapi/pull/15563) by [tiangolo](https://github.com/tiangolo).
* 🔒️ Only allow team members to modify dependencies. PR [15548](https://github.com/fastapi/fastapi/pull/15548) by [svlandeg](https://github.com/svlandeg).
* ⬆ Bump actions/add-to-project from 1.0.2 to 2.0.0. PR [15490](https://github.com/fastapi/fastapi/pull/15490) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump actions/labeler from 6.0.1 to 6.1.0. PR [15507](https://github.com/fastapi/fastapi/pull/15507) by [dependabot[bot]](https://github.com/apps/dependabot).
* 🔧 Remove Ruff ignored rule for tabs. PR [15533](https://github.com/fastapi/fastapi/pull/15533) by [tiangolo](https://github.com/tiangolo).
* 🔧 Update sponsors badge. PR [15532](https://github.com/fastapi/fastapi/pull/15532) by [tiangolo](https://github.com/tiangolo).
* 🔧 Add sponsor: TalorData. PR [15531](https://github.com/fastapi/fastapi/pull/15531) by [tiangolo](https://github.com/tiangolo).
* ⬆ Bump ty from 0.0.21 to 0.0.34. PR [15443](https://github.com/fastapi/fastapi/pull/15443) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump pydantic from 2.13.2 to 2.13.3. PR [15444](https://github.com/fastapi/fastapi/pull/15444) by [dependabot[bot]](https://github.com/apps/dependabot).
* 👷 Add pre-commit to check typos. PR [15482](https://github.com/fastapi/fastapi/pull/15482) by [tiangolo](https://github.com/tiangolo).
* 👥 Update FastAPI GitHub topic repositories. PR [15470](https://github.com/fastapi/fastapi/pull/15470) by [tiangolo](https://github.com/tiangolo).
* 👥 Update FastAPI People - Experts. PR [15471](https://github.com/fastapi/fastapi/pull/15471) by [tiangolo](https://github.com/tiangolo).
* 👥 Update FastAPI People - Contributors and Translators. PR [15467](https://github.com/fastapi/fastapi/pull/15467) by [tiangolo](https://github.com/tiangolo).
* 👷 Fix missing credentials issue in `translate` workflow. PR [15468](https://github.com/fastapi/fastapi/pull/15468) by [YuriiMotov](https://github.com/YuriiMotov).
* ⬆ Bump sqlmodel from 0.0.32 to 0.0.38. PR [15437](https://github.com/fastapi/fastapi/pull/15437) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump CodSpeedHQ/action from 4.12.1 to 4.14.0. PR [15436](https://github.com/fastapi/fastapi/pull/15436) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump pydantic from 2.12.5 to 2.13.2. PR [15439](https://github.com/fastapi/fastapi/pull/15439) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump pydantic-ai from 1.63.0 to 1.83.0. PR [15417](https://github.com/fastapi/fastapi/pull/15417) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump prek from 0.3.2 to 0.3.9. PR [15418](https://github.com/fastapi/fastapi/pull/15418) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump fastar from 0.9.0 to 0.11.0. PR [15419](https://github.com/fastapi/fastapi/pull/15419) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump astral-sh/setup-uv from 7.6.0 to 8.1.0. PR [15415](https://github.com/fastapi/fastapi/pull/15415) by [dependabot[bot]](https://github.com/apps/dependabot).

0.136.1

Upgrades

* ⬆️ Update Pydantic v2 code to address deprecations. PR [15101](https://github.com/fastapi/fastapi/pull/15101) by [svlandeg](https://github.com/svlandeg).

Internal

* 🔨 Tweak translation script. PR [15174](https://github.com/fastapi/fastapi/pull/15174) by [YuriiMotov](https://github.com/YuriiMotov).
* ⬆ Bump mkdocs-material from 9.7.1 to 9.7.6. PR [15408](https://github.com/fastapi/fastapi/pull/15408) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump inline-snapshot from 0.31.1 to 0.32.6. PR [15409](https://github.com/fastapi/fastapi/pull/15409) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump pytest-codspeed from 4.3.0 to 4.4.0. PR [15407](https://github.com/fastapi/fastapi/pull/15407) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump pytest-cov from 7.0.0 to 7.1.0. PR [15406](https://github.com/fastapi/fastapi/pull/15406) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump cloudflare/wrangler-action from 3.14.1 to 3.15.0. PR [15405](https://github.com/fastapi/fastapi/pull/15405) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump mypy from 1.19.1 to 1.20.1. PR [15410](https://github.com/fastapi/fastapi/pull/15410) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump python-dotenv from 1.2.1 to 1.2.2. PR [15400](https://github.com/fastapi/fastapi/pull/15400) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump starlette from 0.52.1 to 1.0.0. PR [15397](https://github.com/fastapi/fastapi/pull/15397) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump pygithub from 2.8.1 to 2.9.1. PR [15396](https://github.com/fastapi/fastapi/pull/15396) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump pyjwt from 2.12.0 to 2.12.1. PR [15393](https://github.com/fastapi/fastapi/pull/15393) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump zizmor from 1.23.1 to 1.24.1. PR [15394](https://github.com/fastapi/fastapi/pull/15394) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump strawberry-graphql from 0.312.3 to 0.314.3. PR [15395](https://github.com/fastapi/fastapi/pull/15395) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump python-multipart from 0.0.22 to 0.0.26. PR [15360](https://github.com/fastapi/fastapi/pull/15360) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump authlib from 1.6.9 to 1.6.11. PR [15373](https://github.com/fastapi/fastapi/pull/15373) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump aiohttp from 3.13.3 to 3.13.4. PR [15282](https://github.com/fastapi/fastapi/pull/15282) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump pygments from 2.19.2 to 2.20.0. PR [15263](https://github.com/fastapi/fastapi/pull/15263) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump pymdown-extensions from 10.20.1 to 10.21.2. PR [15391](https://github.com/fastapi/fastapi/pull/15391) by [YuriiMotov](https://github.com/YuriiMotov).
* ⬆ Bump pillow from 12.1.1 to 12.2.0. PR [15333](https://github.com/fastapi/fastapi/pull/15333) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump pytest from 9.0.2 to 9.0.3. PR [15334](https://github.com/fastapi/fastapi/pull/15334) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump actions/upload-artifact from 7.0.0 to 7.0.1. PR [15374](https://github.com/fastapi/fastapi/pull/15374) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump actions/cache from 5.0.4 to 5.0.5. PR [15385](https://github.com/fastapi/fastapi/pull/15385) by [dependabot[bot]](https://github.com/apps/dependabot).
* 🔧 Update sponsors: remove Zuplo. PR [15369](https://github.com/fastapi/fastapi/pull/15369) by [tiangolo](https://github.com/tiangolo).
* 🔧 Update sponsors: remove Speakeasy. PR [15368](https://github.com/fastapi/fastapi/pull/15368) by [tiangolo](https://github.com/tiangolo).
* 🔒️ Add zizmor and fix audit findings. PR [15316](https://github.com/fastapi/fastapi/pull/15316) by [YuriiMotov](https://github.com/YuriiMotov).

0.136.0

Upgrades

* ⬆️ Support free-threaded Python 3.14t. PR [15149](https://github.com/fastapi/fastapi/pull/15149) by [svlandeg](https://github.com/svlandeg).

0.135.4

Refactors

* 🔥 Remove April Fool's `app.vibe()` 🤪. PR [15363](https://github.com/fastapi/fastapi/pull/15363) by [tiangolo](https://github.com/tiangolo).

Internal

* ⬆ Bump cryptography from 46.0.5 to 46.0.7. PR [15314](https://github.com/fastapi/fastapi/pull/15314) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump strawberry-graphql from 0.307.1 to 0.312.3. PR [15309](https://github.com/fastapi/fastapi/pull/15309) by [dependabot[bot]](https://github.com/apps/dependabot).
* 🔨 Add pre-commit hook to ensure latest release header has date. PR [15293](https://github.com/fastapi/fastapi/pull/15293) by [YuriiMotov](https://github.com/YuriiMotov).

0.135.3

Features

* ✨ Add support for `app.vibe()`. PR [15280](https://github.com/fastapi/fastapi/pull/15280) by [tiangolo](https://github.com/tiangolo).
 * New docs: [Vibe Coding](https://fastapi.tiangolo.com/advanced/vibe/).

Docs

* ✏️ Fix typo for `client_secret` in OAuth2 form docstrings. PR [14946](https://github.com/fastapi/fastapi/pull/14946) by [bysiber](https://github.com/bysiber).

Internal

* 👥 Update FastAPI People - Experts. PR [15279](https://github.com/fastapi/fastapi/pull/15279) by [tiangolo](https://github.com/tiangolo).
* ⬆ Bump orjson from 3.11.7 to 3.11.8. PR [15276](https://github.com/fastapi/fastapi/pull/15276) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump ruff from 0.15.0 to 0.15.8. PR [15277](https://github.com/fastapi/fastapi/pull/15277) by [dependabot[bot]](https://github.com/apps/dependabot).
* 👥 Update FastAPI GitHub topic repositories. PR [15274](https://github.com/fastapi/fastapi/pull/15274) by [tiangolo](https://github.com/tiangolo).
* ⬆ Bump fastmcp from 2.14.5 to 3.2.0. PR [15267](https://github.com/fastapi/fastapi/pull/15267) by [dependabot[bot]](https://github.com/apps/dependabot).
* 👥 Update FastAPI People - Contributors and Translators. PR [15270](https://github.com/fastapi/fastapi/pull/15270) by [tiangolo](https://github.com/tiangolo).
* ⬆ Bump requests from 2.32.5 to 2.33.0. PR [15228](https://github.com/fastapi/fastapi/pull/15228) by [dependabot[bot]](https://github.com/apps/dependabot).
* 👷 Add ty check to `lint.sh`. PR [15136](https://github.com/fastapi/fastapi/pull/15136) by [svlandeg](https://github.com/svlandeg).

0.135.2

Upgrades

* ⬆️ Increase lower bound to `pydantic >=2.9.0.` and fix the test suite. PR [15139](https://github.com/fastapi/fastapi/pull/15139) by [svlandeg](https://github.com/svlandeg).

Docs

* 📝 Add missing last release notes dates. PR [15202](https://github.com/fastapi/fastapi/pull/15202) by [tiangolo](https://github.com/tiangolo).
* 📝 Update docs for contributors and team members regarding translation PRs. PR [15200](https://github.com/fastapi/fastapi/pull/15200) by [YuriiMotov](https://github.com/YuriiMotov).
* 💄 Fix code blocks in reference docs overflowing table width. PR [15094](https://github.com/fastapi/fastapi/pull/15094) by [YuriiMotov](https://github.com/YuriiMotov).
* 📝 Fix duplicated words in docstrings. PR [15116](https://github.com/fastapi/fastapi/pull/15116) by [AhsanSheraz](https://github.com/AhsanSheraz).
* 📝 Add docs for `pyproject.toml` with `entrypoint`. PR [15075](https://github.com/fastapi/fastapi/pull/15075) by [tiangolo](https://github.com/tiangolo).
* 📝 Update links in docs to no longer use the classes external-link and internal-link. PR [15061](https://github.com/fastapi/fastapi/pull/15061) by [tiangolo](https://github.com/tiangolo).
* 🔨 Add JS and CSS handling for automatic `target=_blank` for links in docs. PR [15063](https://github.com/fastapi/fastapi/pull/15063) by [tiangolo](https://github.com/tiangolo).
* 💄 Update styles for internal and external links in new tab. PR [15058](https://github.com/fastapi/fastapi/pull/15058) by [tiangolo](https://github.com/tiangolo).
* 📝  Add documentation for the FastAPI VS Code extension. PR [15008](https://github.com/fastapi/fastapi/pull/15008) by [savannahostrowski](https://github.com/savannahostrowski).
* 📝 Fix doctrings for `max_digits` and `decimal_places`. PR [14944](https://github.com/fastapi/fastapi/pull/14944) by [YuriiMotov](https://github.com/YuriiMotov).
* 📝 Add dates to release notes. PR [15001](https://github.com/fastapi/fastapi/pull/15001) by [YuriiMotov](https://github.com/YuriiMotov).

Translations

* 🌐 Update translations for zh (update-outdated). PR [15177](https://github.com/fastapi/fastapi/pull/15177) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for zh-hant (update-outdated). PR [15178](https://github.com/fastapi/fastapi/pull/15178) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for zh-hant (add-missing). PR [15176](https://github.com/fastapi/fastapi/pull/15176) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for zh (add-missing). PR [15175](https://github.com/fastapi/fastapi/pull/15175) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for ja (update-outdated). PR [15171](https://github.com/fastapi/fastapi/pull/15171) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for ko (update-outdated). PR [15170](https://github.com/fastapi/fastapi/pull/15170) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for tr (update-outdated). PR [15172](https://github.com/fastapi/fastapi/pull/15172) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for ko (add-missing). PR [15168](https://github.com/fastapi/fastapi/pull/15168) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for ja (add-missing). PR [15167](https://github.com/fastapi/fastapi/pull/15167) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for tr (add-missing). PR [15169](https://github.com/fastapi/fastapi/pull/15169) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for fr (update-outdated). PR [15165](https://github.com/fastapi/fastapi/pull/15165) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for fr (add-missing). PR [15163](https://github.com/fastapi/fastapi/pull/15163) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for uk (update-outdated). PR [15160](https://github.com/fastapi/fastapi/pull/15160) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for uk (add-missing). PR [15158](https://github.com/fastapi/fastapi/pull/15158) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for pt (add-missing). PR [15157](https://github.com/fastapi/fastapi/pull/15157) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for pt (update-outdated). PR [15159](https://github.com/fastapi/fastapi/pull/15159) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for es (update-outdated). PR [15155](https://github.com/fastapi/fastapi/pull/15155) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for es (add-missing). PR [15154](https://github.com/fastapi/fastapi/pull/15154) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for de (update-outdated). PR [15156](https://github.com/fastapi/fastapi/pull/15156) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for ru (update-and-add). PR [15152](https://github.com/fastapi/fastapi/pull/15152) by [tiangolo](https://github.com/tiangolo).
* 🌐 Update translations for de (add-missing). PR [15153](https://github.com/fastapi/fastapi/pull/15153) by [tiangolo](https://github.com/tiangolo).

Internal

* 🔨 Exclude spam comments from statistics in `scripts/people.py`. PR [15088](https://github.com/fastapi/fastapi/pull/15088) by [YuriiMotov](https://github.com/YuriiMotov).
* ⬆ Bump authlib from 1.6.7 to 1.6.9. PR [15128](https://github.com/fastapi/fastapi/pull/15128) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump pyasn1 from 0.6.2 to 0.6.3. PR [15143](https://github.com/fastapi/fastapi/pull/15143) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump ujson from 5.11.0 to 5.12.0. PR [15150](https://github.com/fastapi/fastapi/pull/15150) by [dependabot[bot]](https://github.com/apps/dependabot).
* 🔨 Tweak translation workflow and translation fixer tool. PR [15166](https://github.com/fastapi/fastapi/pull/15166) by [YuriiMotov](https://github.com/YuriiMotov).
* 🔨 Fix `commit_in_place` passed via env variable in `translate.yml` workflow. PR [15151](https://github.com/fastapi/fastapi/pull/15151) by [YuriiMotov](https://github.com/YuriiMotov).
* 🔨 Update translation general prompt to enforce link style in translation matches the original link style. PR [15148](https://github.com/fastapi/fastapi/pull/15148) by [YuriiMotov](https://github.com/YuriiMotov).
* 👷 Re-enable translation workflow run by cron in CI (twice a month). PR [15145](https://github.com/fastapi/fastapi/pull/15145) by [YuriiMotov](https://github.com/YuriiMotov).
* 👷 Add `ty` to precommit. PR [15091](https://github.com/fastapi/fastapi/pull/15091) by [svlandeg](https://github.com/svlandeg).
* ⬆ Bump dorny/paths-filter from 3 to 4. PR [15106](https://github.com/fastapi/fastapi/pull/15106) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump cairosvg from 2.8.2 to 2.9.0. PR [15108](https://github.com/fastapi/fastapi/pull/15108) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump pyjwt from 2.11.0 to 2.12.0. PR [15110](https://github.com/fastapi/fastapi/pull/15110) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump black from 26.1.0 to 26.3.1. PR [15100](https://github.com/fastapi/fastapi/pull/15100) by [dependabot[bot]](https://github.com/apps/dependabot).
* 🔨 Update script to autofix permalinks to account for headers with Markdown links. PR [15062](https://github.com/fastapi/fastapi/pull/15062) by [tiangolo](https://github.com/tiangolo).
* 📌 Pin Click for MkDocs live reload. PR [15057](https://github.com/fastapi/fastapi/pull/15057) by [tiangolo](https://github.com/tiangolo).
* ⬆ Bump werkzeug from 3.1.5 to 3.1.6. PR [14948](https://github.com/fastapi/fastapi/pull/14948) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump pydantic-ai from 1.62.0 to 1.63.0. PR [15035](https://github.com/fastapi/fastapi/pull/15035) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump pytest-codspeed from 4.2.0 to 4.3.0. PR [15034](https://github.com/fastapi/fastapi/pull/15034) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump strawberry-graphql from 0.291.2 to 0.307.1. PR [15033](https://github.com/fastapi/fastapi/pull/15033) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump typer from 0.21.1 to 0.24.1. PR [15032](https://github.com/fastapi/fastapi/pull/15032) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump actions/download-artifact from 7 to 8. PR [15020](https://github.com/fastapi/fastapi/pull/15020) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump actions/upload-artifact from 6 to 7. PR [15019](https://github.com/fastapi/fastapi/pull/15019) by [dependabot[bot]](https://github.com/apps/dependabot).

0.135.1

Fixes

* 🐛 Fix, avoid yield from a TaskGroup, only as an async context manager, closed in the request async exit stack. PR [15038](https://github.com/fastapi/fastapi/pull/15038) by [tiangolo](https://github.com/tiangolo).

Docs

* ✏️ Fix typo in `docs/en/docs/_llm-test.md`. PR [15007](https://github.com/fastapi/fastapi/pull/15007) by [adityagiri3600](https://github.com/adityagiri3600).
* 📝 Update Skill, optimize context, trim and refactor into references. PR [15031](https://github.com/fastapi/fastapi/pull/15031) by [tiangolo](https://github.com/tiangolo).

Internal

* 👥 Update FastAPI People - Experts. PR [15037](https://github.com/fastapi/fastapi/pull/15037) by [tiangolo](https://github.com/tiangolo).
* 👥 Update FastAPI People - Contributors and Translators. PR [15029](https://github.com/fastapi/fastapi/pull/15029) by [tiangolo](https://github.com/tiangolo).
* 👥 Update FastAPI GitHub topic repositories. PR [15036](https://github.com/fastapi/fastapi/pull/15036) by [tiangolo](https://github.com/tiangolo).

0.135.0

Features

* ✨ Add support for Server Sent Events. PR [15030](https://github.com/fastapi/fastapi/pull/15030) by [tiangolo](https://github.com/tiangolo).
 * New docs: [Server-Sent Events (SSE)](https://fastapi.tiangolo.com/tutorial/server-sent-events/).

0.134.0

Features

* ✨ Add support for streaming JSON Lines and binary data with `yield`. PR [15022](https://github.com/fastapi/fastapi/pull/15022) by [tiangolo](https://github.com/tiangolo).
 * This also upgrades Starlette from `>=0.40.0` to `>=0.46.0`, as it's needed to properly unrwap and re-raise exceptions from exception groups.
 * New docs: [Stream JSON Lines](https://fastapi.tiangolo.com/tutorial/stream-json-lines/).
 * And new docs: [Stream Data](https://fastapi.tiangolo.com/advanced/stream-data/).

Docs

* 📝 Update Library Agent Skill with streaming responses. PR [15024](https://github.com/fastapi/fastapi/pull/15024) by [tiangolo](https://github.com/tiangolo).
* 📝 Update docs for responses and new stream with `yield`. PR [15023](https://github.com/fastapi/fastapi/pull/15023) by [tiangolo](https://github.com/tiangolo).
* 📝 Add `await` in `StreamingResponse` code example to allow cancellation. PR [14681](https://github.com/fastapi/fastapi/pull/14681) by [casperdcl](https://github.com/casperdcl).
* 📝 Rename `docs_src/websockets` to `docs_src/websockets_` to avoid import errors. PR [14979](https://github.com/fastapi/fastapi/pull/14979) by [YuriiMotov](https://github.com/YuriiMotov).

Internal

* 🔨 Run tests with `pytest-xdist` and `pytest-cov`. PR [14992](https://github.com/fastapi/fastapi/pull/14992) by [YuriiMotov](https://github.com/YuriiMotov).

0.133.1

Features

* 🔧 Add FastAPI Agent Skill. PR [14982](https://github.com/fastapi/fastapi/pull/14982) by [tiangolo](https://github.com/tiangolo).
 * Read more about it in [Library Agent Skills](https://tiangolo.com/ideas/library-agent-skills/).

Internal

* ✅ Fix all tests are skipped on Windows. PR [14994](https://github.com/fastapi/fastapi/pull/14994) by [YuriiMotov](https://github.com/YuriiMotov).

0.133.0

Upgrades

* ⬆️ Add support for Starlette 1.0.0+. PR [14987](https://github.com/fastapi/fastapi/pull/14987) by [tiangolo](https://github.com/tiangolo).

0.132.1

Refactors

* ♻️ Refactor logic to handle OpenAPI and Swagger UI escaping data. PR [14986](https://github.com/fastapi/fastapi/pull/14986) by [tiangolo](https://github.com/tiangolo).

Internal

* 👥 Update FastAPI People - Experts. PR [14972](https://github.com/fastapi/fastapi/pull/14972) by [tiangolo](https://github.com/tiangolo).
* 👷 Allow skipping `benchmark` job in `test` workflow. PR [14974](https://github.com/fastapi/fastapi/pull/14974) by [YuriiMotov](https://github.com/YuriiMotov).

0.132.0

Breaking Changes

* 🔒️ Add `strict_content_type` checking for JSON requests. PR [14978](https://github.com/fastapi/fastapi/pull/14978) by [tiangolo](https://github.com/tiangolo).
 * Now FastAPI checks, by default, that JSON requests have a `Content-Type` header with a valid JSON value, like `application/json`, and rejects requests that don't.
 * If the clients for your app don't send a valid `Content-Type` header you can disable this with `strict_content_type=False`.
 * Check the new docs: [Strict Content-Type Checking](https://fastapi.tiangolo.com/advanced/strict-content-type/).

Internal

* ⬆ Bump flask from 3.1.2 to 3.1.3. PR [14949](https://github.com/fastapi/fastapi/pull/14949) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Update all dependencies to use `griffelib` instead of `griffe`. PR [14973](https://github.com/fastapi/fastapi/pull/14973) by [svlandeg](https://github.com/svlandeg).
* 🔨 Fix `FastAPI People` workflow. PR [14951](https://github.com/fastapi/fastapi/pull/14951) by [YuriiMotov](https://github.com/YuriiMotov).
* 👷 Do not run codspeed with coverage as it's not tracked. PR [14966](https://github.com/fastapi/fastapi/pull/14966) by [tiangolo](https://github.com/tiangolo).
* 👷 Do not include benchmark tests in coverage to speed up coverage processing. PR [14965](https://github.com/fastapi/fastapi/pull/14965) by [tiangolo](https://github.com/tiangolo).

0.131.0

Breaking Changes

* 🗑️ Deprecate `ORJSONResponse` and `UJSONResponse`. PR [14964](https://github.com/fastapi/fastapi/pull/14964) by [tiangolo](https://github.com/tiangolo).

0.130.0

Features

* ✨ Serialize JSON response with Pydantic (in Rust), when there's a Pydantic return type or response model. PR [14962](https://github.com/fastapi/fastapi/pull/14962) by [tiangolo](https://github.com/tiangolo).
 * This results in 2x (or more) performance increase for JSON responses.
 * New docs: [Custom Response - JSON Performance](https://fastapi.tiangolo.com/advanced/custom-response/#json-performance).

0.129.2

Internal

* ⬆️ Upgrade pytest. PR [14959](https://github.com/fastapi/fastapi/pull/14959) by [tiangolo](https://github.com/tiangolo).
* 👷 Fix CI, do not attempt to publish `fastapi-slim`. PR [14958](https://github.com/fastapi/fastapi/pull/14958) by [tiangolo](https://github.com/tiangolo).
* ➖ Drop support for `fastapi-slim`, no more versions will be released, use only `"fastapi[standard]"` or `fastapi`. PR [14957](https://github.com/fastapi/fastapi/pull/14957) by [tiangolo](https://github.com/tiangolo).
* 🔧 Update pyproject.toml, remove unneeded lines. PR [14956](https://github.com/fastapi/fastapi/pull/14956) by [tiangolo](https://github.com/tiangolo).

0.129.1

Fixes

* ♻️ Fix JSON Schema for bytes, use `"contentMediaType": "application/octet-stream"` instead of `"format": "binary"`. PR [14953](https://github.com/fastapi/fastapi/pull/14953) by [tiangolo](https://github.com/tiangolo).

Docs

* 🔨 Add Kapa.ai widget (AI chatbot). PR [14938](https://github.com/fastapi/fastapi/pull/14938) by [tiangolo](https://github.com/tiangolo).
* 🔥 Remove Python 3.9 specific files, no longer needed after updating translations. PR [14931](https://github.com/fastapi/fastapi/pull/14931) by [tiangolo](https://github.com/tiangolo).
* 📝 Update docs for JWT to prevent timing attacks. PR [14908](https://github.com/fastapi/fastapi/pull/14908) by [tiangolo](https://github.com/tiangolo).

Translations

* ✏️ Fix several typos in ru translations. PR [14934](https://github.com/fastapi/fastapi/pull/14934) by [argoarsiks](https://github.com/argoarsiks).
* 🌐 Update translations for ko (update-all and add-missing). PR [14923](https://github.com/fastapi/fastapi/pull/14923) by [YuriiMotov](https://github.com/YuriiMotov).
* 🌐 Update translations for uk (add-missing). PR [14922](https://github.com/fastapi/fastapi/pull/14922) by [YuriiMotov](https://github.com/YuriiMotov).
* 🌐 Update translations for zh-hant (update-all and add-missing). PR [14921](https://github.com/fastapi/fastapi/pull/14921) by [YuriiMotov](https://github.com/YuriiMotov).
* 🌐 Update translations for fr (update-all and add-missing). PR [14920](https://github.com/fastapi/fastapi/pull/14920) by [YuriiMotov](https://github.com/YuriiMotov).
* 🌐 Update translations for de (update-all) . PR [14910](https://github.com/fastapi/fastapi/pull/14910) by [YuriiMotov](https://github.com/YuriiMotov).
* 🌐 Update translations for ja (update-all). PR [14916](https://github.com/fastapi/fastapi/pull/14916) by [YuriiMotov](https://github.com/YuriiMotov).
* 🌐 Update translations for pt (update-all). PR [14912](https://github.com/fastapi/fastapi/pull/14912) by [YuriiMotov](https://github.com/YuriiMotov).
* 🌐 Update translations for es (update-all and add-missing). PR [14911](https://github.com/fastapi/fastapi/pull/14911) by [YuriiMotov](https://github.com/YuriiMotov).
* 🌐 Update translations for zh (update-all). PR [14917](https://github.com/fastapi/fastapi/pull/14917) by [YuriiMotov](https://github.com/YuriiMotov).
* 🌐 Update translations for uk (update-all). PR [14914](https://github.com/fastapi/fastapi/pull/14914) by [YuriiMotov](https://github.com/YuriiMotov).
* 🌐 Update translations for tr (update-all). PR [14913](https://github.com/fastapi/fastapi/pull/14913) by [YuriiMotov](https://github.com/YuriiMotov).
* 🌐 Update translations for ru (update-outdated). PR [14909](https://github.com/fastapi/fastapi/pull/14909) by [YuriiMotov](https://github.com/YuriiMotov).

Internal

* 👷 Always run tests on push to `master` branch and when run by scheduler. PR [14940](https://github.com/fastapi/fastapi/pull/14940) by [YuriiMotov](https://github.com/YuriiMotov).
* 🎨 Upgrade typing syntax for Python 3.10. PR [14932](https://github.com/fastapi/fastapi/pull/14932) by [tiangolo](https://github.com/tiangolo).
* ⬆ Bump cryptography from 46.0.4 to 46.0.5. PR [14892](https://github.com/fastapi/fastapi/pull/14892) by [dependabot[bot]](https://github.com/apps/dependabot).
* ⬆ Bump pillow from 12.1.0 to 12.1.1. PR [14899](https://github.com/fastapi/fastapi/pull/14899) by [dependabot[bot]](https://github.com/apps/dependabot).

0.129.0

Breaking Changes

* ➖ Drop support for Python 3.9. PR [14897](https://github.com/fastapi/fastapi/pull/14897) by [tiangolo](https://github.com/tiangolo).

Refactors

* 🎨 Update internal types for Python 3.10. PR [14898](https://github.com/fastapi/fastapi/pull/14898) by [tiangolo](https://github.com/tiangolo).

Docs

* 📝 Update highlights in webhooks docs. PR [14905](https://github.com/fastapi/fastapi/pull/14905) by [tiangolo](https://github.com/tiangolo).
* 📝 Update source examples and docs from Python 3.9 to 3.10. PR [14900](https://github.com/fastapi/fastapi/pull/14900) by [tiangolo](https://github.com/tiangolo).

Internal

* 🔨 Update docs.py scripts to migrate Python 3.9 to Python 3.10. PR [14906](https://github.com/fastapi/fastapi/pull/14906) by [tiangolo](https://github.com/tiangolo).

0.128.8

Docs

* 📝 Fix grammar in `docs/en/docs/tutorial/first-steps.md`. PR [14708](https://github.com/fastapi/fastapi/pull/14708) by [SanjanaS10](https://github.com/SanjanaS10).

Internal

* 🔨 Tweak PDM hook script. PR [14895](https://github.com/fastapi/fastapi/pull/14895) by [tiangolo](https://github.com/tiangolo).
* ♻️ Update build setup for `fastapi-slim`, deprecate it, and make it only depend on `fastapi`. PR [14894](https://github.com/fastapi/fastapi/pull/14894) by [tiangolo](https://github.com/tiangolo).

0.128.7

Features

* ✨ Show a clear error on attempt to include router into itself. PR [14258](https://github.com/fastapi/fastapi/pull/14258) by [JavierSanchezCastro](https://github.com/JavierSanchezCastro).
* ✨ Replace `dict` by `Mapping` on `HTTPException.headers`. PR [12997](https://github.com/fastapi/fastapi/pull/12997) by [rijenkii](https://github.com/rijenkii).

Refactors

* ♻️ Simplify reading files in memory, do it sequentially instead of (fake) parallel. PR [14884](https://github.com/fastapi/fastapi/pull/14884) by [tiangolo](https://github.com/tiangolo).

Docs

* 📝 Use `dfn` tag for definitions instead of `abbr` in docs. PR [14744](https://github.com/fastapi/fastapi/pull/14744) by [YuriiMotov](https://github.com/YuriiMotov).

Internal

* ✅ Tweak comment in test to reference PR. PR [14885](https://github.com/fastapi/fastapi/pull/14885) by [tiangolo](https://github.com/tiangolo).
* 🔧 Update LLM-prompt for `abbr` and `dfn` tags. PR [14747](https://github.com/fastapi/fastapi/pull/14747) by [YuriiMotov](https://github.com/Yurii

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->

## Summary by CodeRabbit

* **Chores**
* Updated the FastAPI framework dependency to version 0.139.2.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

@coderabbitai

coderabbitai Bot commented Jul 16, 2026

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

FastAPI is upgraded from version 0.6.4 to 0.139.2 in src/requirements.txt.

Changes

FastAPI dependency

Layer / File(s) Summary
Update FastAPI requirement
src/requirements.txt
Pins FastAPI to version 0.139.2 instead of 0.6.4.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: upgrading FastAPI to 0.139.2.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch pyup-update-fastapi-0.6.4-to-0.139.2

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@src/requirements.txt`:
- Line 1: Update the dependency pins in requirements.txt by pinning GitPython to
patched release 3.1.48 or later and upgrading Uvicorn to version 0.11.7 or
later; ensure the vulnerability reference targets GitPython rather than Uvicorn.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: a220d0ed-0089-4809-8309-8f5b978633f0

📥 Commits

Reviewing files that changed from the base of the PR and between d377ad0 and 4ee6f0d.

📒 Files selected for processing (1)
  • src/requirements.txt

Comment thread src/requirements.txt
@@ -1,3 +1,3 @@
fastapi==0.6.4
fastapi==0.139.2

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

git ls-files src/requirements.txt
cat -n src/requirements.txt
rg -n "gitpython|uvicorn|fastapi" -S .

Repository: salimfadhley/dockerized_python_playground

Length of output: 380


🌐 Web query:

GitHub advisory GHSA-7545-fcxq-7j24 Uvicorn HTTP response splitting affected versions fixed version

💡 Result:

GitHub advisory GHSA-7545-fcxq-7j24 does not pertain to Uvicorn, but rather to the GitPython library [1][2]. It describes a path traversal vulnerability in GitPython's reference APIs that allows for arbitrary file write and deletion outside of the repository [3][4]. Affected versions of GitPython include all versions prior to 3.1.48 [4][5]. The vulnerability was fixed in version 3.1.48 [4][6].

Citations:


🌐 Web query:

GitPython latest release PyPI security advisories unpinned dependency vulnerability

💡 Result:

As of July 16, 2026, the latest release of GitPython on PyPI is 3.1.50 [1][2], though documentation references version 3.1.51 [3]. There is no widely publicized security advisory specifically regarding an unpinned dependency vulnerability for GitPython. Security advisories for GitPython are managed through the project's official GitHub repository [4]. Recent security vulnerabilities identified in GitPython (through mid-2026) have primarily focused on input validation issues, such as: 1. Path traversal vulnerabilities in reference APIs allowing arbitrary file write/delete [5]. 2. Command injection via insecure Git options (e.g., bypasses in multi_options handling or kwarg normalization) [6][7]. 3. Remote Code Execution (RCE) via newline injection in configuration writers, which allows for poisoning .git/config and redirecting core.hooksPath [8][9]. Users are advised to check the official GitPython GitHub Security Advisories page to stay informed about the latest patches and vulnerability disclosures [4]. To mitigate risks, ensure your applications are updated to the latest available version and exercise caution when passing user-controlled input to GitPython APIs [5][6][7][8].

Citations:


🌐 Web query:

FastAPI 0.139.2 Python >=3.10 release notes

💡 Result:

As of July 16, 2026, there is no FastAPI version 0.139.2. The latest available versions are 0.139.1 (released July 16, 2026) and 0.139.0 (released July 1, 2026) [1][2]. Versions of 0.139.2 exist for other software projects (such as gitlab-org/api/client-go), which may be the source of confusion [3][4][5]. Regarding Python version requirements, FastAPI maintains a requirement of Python 3.10 or newer [6][7]. This is explicitly documented in the project's configuration (e.g., pyproject.toml) and package metadata [6][7]. For the most accurate and up-to-date information, you can always check the official FastAPI release notes at https://fastapi.tiangolo.com/release-notes/ [8].

Citations:


🌐 Web query:

Uvicorn 0.4.6 vulnerability advisory fixed version HTTP response splitting

💡 Result:

The vulnerability regarding HTTP response splitting in Uvicorn is tracked as CVE-2020-7695 [1][2]. This vulnerability affects all versions of Uvicorn prior to 0.11.7, including version 0.4.6 [1][3]. The vulnerability occurs because CRLF (Carriage Return/Line Feed) sequences were not properly escaped in the values of HTTP headers, which could allow an attacker to inject arbitrary headers or response bodies into HTTP responses [1][4]. To remediate this issue, users should upgrade to Uvicorn version 0.11.7 or higher [5][4].

Citations:


Pin the vulnerable dependency versions here gitpython should be pinned to a patched release (>=3.1.48), and uvicorn==0.4.6 needs an upgrade to at least 0.11.7. The GHSA cited here applies to GitPython, not Uvicorn.

🧰 Tools
🪛 OSV Scanner (2.4.0)

[CRITICAL] 1-1: gitpython 3.1.9: undefined

(PYSEC-2022-42992)


[CRITICAL] 1-1: gitpython 3.1.9: undefined

(PYSEC-2023-137)


[CRITICAL] 1-1: gitpython 3.1.9: undefined

(PYSEC-2023-161)


[CRITICAL] 1-1: gitpython 3.1.9: undefined

(PYSEC-2023-165)


[CRITICAL] 1-1: gitpython 3.1.9: undefined

(PYSEC-2024-4)


[CRITICAL] 1-1: gitpython 3.1.9: undefined

(PYSEC-2026-2161)


[CRITICAL] 1-1: gitpython 3.1.9: undefined

(PYSEC-2026-2162)


[CRITICAL] 1-1: gitpython 3.1.9: undefined

(PYSEC-2026-2163)


[CRITICAL] 1-1: gitpython 3.1.9: Untrusted search path under some conditions on Windows allows arbitrary code execution

(GHSA-2mqj-m65w-jghx)


[CRITICAL] 1-1: gitpython 3.1.9: GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repository

(GHSA-7545-fcxq-7j24)


[CRITICAL] 1-1: gitpython 3.1.9: GitPython blind local file inclusion

(GHSA-cwvm-v4w8-q58c)


[CRITICAL] 1-1: gitpython 3.1.9: GitPython vulnerable to Remote Code Execution due to improper user input validation

(GHSA-hcpj-qp55-gfph)


[CRITICAL] 1-1: gitpython 3.1.9: GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath

(GHSA-mv93-w799-cj2w)


[CRITICAL] 1-1: gitpython 3.1.9: GitPython vulnerable to remote code execution due to insufficient sanitization of input arguments

(GHSA-pr76-5cm5-w9cj)


[CRITICAL] 1-1: gitpython 3.1.9: GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath

(GHSA-v87r-6q3f-2j67)


[CRITICAL] 1-1: gitpython 3.1.9: GitPython untrusted search path on Windows systems leading to arbitrary code execution

(GHSA-wfm5-v35h-vwf4)


[CRITICAL] 1-1: gitpython 3.1.9: GitPython: Unsafe option check validates multi_options before shlex.split transformation

(GHSA-x2qx-6953-8485)


[HIGH] 1-1: uvicorn 0.4.6: undefined

(PYSEC-2020-150)


[HIGH] 1-1: uvicorn 0.4.6: undefined

(PYSEC-2020-151)


[HIGH] 1-1: uvicorn 0.4.6: Log injection in uvicorn

(GHSA-33c7-2mpw-hg34)


[HIGH] 1-1: uvicorn 0.4.6: HTTP response splitting in uvicorn

(GHSA-f97h-2pfx-f59f)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@src/requirements.txt` at line 1, Update the dependency pins in
requirements.txt by pinning GitPython to patched release 3.1.48 or later and
upgrading Uvicorn to version 0.11.7 or later; ensure the vulnerability reference
targets GitPython rather than Uvicorn.

Source: Linters/SAST tools

@pyup-bot

Copy link
Copy Markdown
Collaborator Author

Closing this in favor of #602

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant