🔒️ Add strict_content_type checking for JSON requests. PR #14978 by @tiangolo.
Now FastAPI checks, by default, that JSON requests have a Content-Type header with a valid JSON value, like application/json, and rejects requests that don't.
If the clients for your app don't send a valid Content-Type header you can disable this with strict_content_type=False.
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [fastapi](https://github.com/fastapi/fastapi) ([changelog](https://fastapi.tiangolo.com/release-notes/)) | project.dependencies | minor | `==0.128.4` → `==0.135.1` |
---
### Release Notes
<details>
<summary>fastapi/fastapi (fastapi)</summary>
### [`v0.135.1`](https://github.com/fastapi/fastapi/releases/tag/0.135.1)
[Compare Source](https://github.com/fastapi/fastapi/compare/0.135.0...0.135.1)
##### Fixes
- 🐛 Fix, avoid yield from a TaskGroup, only as an async context manager, closed in the request async exit stack. PR [#​15038](https://github.com/fastapi/fastapi/pull/15038) by [@​tiangolo](https://github.com/tiangolo).
##### Docs
- ✏️ Fix typo in `docs/en/docs/_llm-test.md`. PR [#​15007](https://github.com/fastapi/fastapi/pull/15007) by [@​adityagiri3600](https://github.com/adityagiri3600).
- 📝 Update Skill, optimize context, trim and refactor into references. PR [#​15031](https://github.com/fastapi/fastapi/pull/15031) by [@​tiangolo](https://github.com/tiangolo).
##### Internal
- 👥 Update FastAPI People - Experts. PR [#​15037](https://github.com/fastapi/fastapi/pull/15037) by [@​tiangolo](https://github.com/tiangolo).
- 👥 Update FastAPI People - Contributors and Translators. PR [#​15029](https://github.com/fastapi/fastapi/pull/15029) by [@​tiangolo](https://github.com/tiangolo).
- 👥 Update FastAPI GitHub topic repositories. PR [#​15036](https://github.com/fastapi/fastapi/pull/15036) by [@​tiangolo](https://github.com/tiangolo).
### [`v0.135.0`](https://github.com/fastapi/fastapi/releases/tag/0.135.0)
[Compare Source](https://github.com/fastapi/fastapi/compare/0.134.0...0.135.0)
##### Features
- ✨ Add support for Server Sent Events. PR [#​15030](https://github.com/fastapi/fastapi/pull/15030) by [@​tiangolo](https://github.com/tiangolo).
- New docs: [Server-Sent Events (SSE)](https://fastapi.tiangolo.com/tutorial/server-sent-events/).
### [`v0.134.0`](https://github.com/fastapi/fastapi/releases/tag/0.134.0)
[Compare Source](https://github.com/fastapi/fastapi/compare/0.133.1...0.134.0)
##### Features
- ✨ Add support for streaming JSON Lines and binary data with `yield`. PR [#​15022](https://github.com/fastapi/fastapi/pull/15022) by [@​tiangolo](https://github.com/tiangolo).
- This also upgrades Starlette from `>=0.40.0` to `>=0.46.0`, as it's needed to properly unrwap and re-raise exceptions from exception groups.
- New docs: [Stream JSON Lines](https://fastapi.tiangolo.com/tutorial/stream-json-lines/).
- And new docs: [Stream Data](https://fastapi.tiangolo.com/advanced/stream-data/).
##### Docs
- 📝 Update Library Agent Skill with streaming responses. PR [#​15024](https://github.com/fastapi/fastapi/pull/15024) by [@​tiangolo](https://github.com/tiangolo).
- 📝 Update docs for responses and new stream with `yield`. PR [#​15023](https://github.com/fastapi/fastapi/pull/15023) by [@​tiangolo](https://github.com/tiangolo).
- 📝 Add `await` in `StreamingResponse` code example to allow cancellation. PR [#​14681](https://github.com/fastapi/fastapi/pull/14681) by [@​casperdcl](https://github.com/casperdcl).
- 📝 Rename `docs_src/websockets` to `docs_src/websockets_` to avoid import errors. PR [#​14979](https://github.com/fastapi/fastapi/pull/14979) by [@​YuriiMotov](https://github.com/YuriiMotov).
##### Internal
- 🔨 Run tests with `pytest-xdist` and `pytest-cov`. PR [#​14992](https://github.com/fastapi/fastapi/pull/14992) by [@​YuriiMotov](https://github.com/YuriiMotov).
### [`v0.133.1`](https://github.com/fastapi/fastapi/releases/tag/0.133.1)
[Compare Source](https://github.com/fastapi/fastapi/compare/0.133.0...0.133.1)
##### Features
- 🔧 Add FastAPI Agent Skill. PR [#​14982](https://github.com/fastapi/fastapi/pull/14982) by [@​tiangolo](https://github.com/tiangolo).
- Read more about it in [Library Agent Skills](https://tiangolo.com/ideas/library-agent-skills/).
##### Internal
- ✅ Fix all tests are skipped on Windows. PR [#​14994](https://github.com/fastapi/fastapi/pull/14994) by [@​YuriiMotov](https://github.com/YuriiMotov).
### [`v0.133.0`](https://github.com/fastapi/fastapi/releases/tag/0.133.0)
[Compare Source](https://github.com/fastapi/fastapi/compare/0.132.1...0.133.0)
##### Upgrades
- ⬆️ Add support for Starlette 1.0.0+. PR [#​14987](https://github.com/fastapi/fastapi/pull/14987) by [@​tiangolo](https://github.com/tiangolo).
### [`v0.132.1`](https://github.com/fastapi/fastapi/releases/tag/0.132.1)
[Compare Source](https://github.com/fastapi/fastapi/compare/0.132.0...0.132.1)
##### Refactors
- ♻️ Refactor logic to handle OpenAPI and Swagger UI escaping data. PR [#​14986](https://github.com/fastapi/fastapi/pull/14986) by [@​tiangolo](https://github.com/tiangolo).
##### Internal
- 👥 Update FastAPI People - Experts. PR [#​14972](https://github.com/fastapi/fastapi/pull/14972) by [@​tiangolo](https://github.com/tiangolo).
- 👷 Allow skipping `benchmark` job in `test` workflow. PR [#​14974](https://github.com/fastapi/fastapi/pull/14974) by [@​YuriiMotov](https://github.com/YuriiMotov).
### [`v0.132.0`](https://github.com/fastapi/fastapi/releases/tag/0.132.0)
[Compare Source](https://github.com/fastapi/fastapi/compare/0.131.0...0.132.0)
##### Breaking Changes
- 🔒️ Add `strict_content_type` checking for JSON requests. PR [#​14978](https://github.com/fastapi/fastapi/pull/14978) by [@​tiangolo](https://github.com/tiangolo).
- Now FastAPI checks, by default, that JSON requests have a `Content-Type` header with a valid JSON value, like `application/json`, and rejects requests that don't.
- If the clients for your app don't send a valid `Content-Type` header you can disable this with `strict_content_type=False`.
- Check the new docs: [Strict Content-Type Checking](https://fastapi.tiangolo.com/advanced/strict-content-type/).
##### Internal
- ⬆ Bump flask from 3.1.2 to 3.1.3. PR [#​14949](https://github.com/fastapi/fastapi/pull/14949) by [@​dependabot\[bot\]](https://github.com/apps/dependabot).
- ⬆ Update all dependencies to use `griffelib` instead of `griffe`. PR [#​14973](https://github.com/fastapi/fastapi/pull/14973) by [@​svlandeg](https://github.com/svlandeg).
- 🔨 Fix `FastAPI People` workflow. PR [#​14951](https://github.com/fastapi/fastapi/pull/14951) by [@​YuriiMotov](https://github.com/YuriiMotov).
- 👷 Do not run codspeed with coverage as it's not tracked. PR [#​14966](https://github.com/fastapi/fastapi/pull/14966) by [@​tiangolo](https://github.com/tiangolo).
- 👷 Do not include benchmark tests in coverage to speed up coverage processing. PR [#​14965](https://github.com/fastapi/fastapi/pull/14965) by [@​tiangolo](https://github.com/tiangolo).
### [`v0.131.0`](https://github.com/fastapi/fastapi/releases/tag/0.131.0)
[Compare Source](https://github.com/fastapi/fastapi/compare/0.130.0...0.131.0)
##### Breaking Changes
- 🗑️ Deprecate `ORJSONResponse` and `UJSONResponse`. PR [#​14964](https://github.com/fastapi/fastapi/pull/14964) by [@​tiangolo](https://github.com/tiangolo).
### [`v0.130.0`](https://github.com/fastapi/fastapi/releases/tag/0.130.0)
[Compare Source](https://github.com/fastapi/fastapi/compare/0.129.2...0.130.0)
##### Features
- ✨ Serialize JSON response with Pydantic (in Rust), when there's a Pydantic return type or response model. PR [#​14962](https://github.com/fastapi/fastapi/pull/14962) by [@​tiangolo](https://github.com/tiangolo).
- This results in 2x (or more) performance increase for JSON responses.
- New docs: [Custom Response - JSON Performance](https://fastapi.tiangolo.com/advanced/custom-response/#json-performance).
### [`v0.129.2`](https://github.com/fastapi/fastapi/releases/tag/0.129.2)
[Compare Source](https://github.com/fastapi/fastapi/compare/0.129.1...0.129.2)
##### Internal
- ⬆️ Upgrade pytest. PR [#​14959](https://github.com/fastapi/fastapi/pull/14959) by [@​tiangolo](https://github.com/tiangolo).
- 👷 Fix CI, do not attempt to publish `fastapi-slim`. PR [#​14958](https://github.com/fastapi/fastapi/pull/14958) by [@​tiangolo](https://github.com/tiangolo).
- ➖ Drop support for `fastapi-slim`, no more versions will be released, use only `"fastapi[standard]"` or `fastapi`. PR [#​14957](https://github.com/fastapi/fastapi/pull/14957) by [@​tiangolo](https://github.com/tiangolo).
- 🔧 Update pyproject.toml, remove unneeded lines. PR [#​14956](https://github.com/fastapi/fastapi/pull/14956) by [@​tiangolo](https://github.com/tiangolo).
### [`v0.129.1`](https://github.com/fastapi/fastapi/releases/tag/0.129.1)
[Compare Source](https://github.com/fastapi/fastapi/compare/0.129.0...0.129.1)
##### Fixes
- ♻️ Fix JSON Schema for bytes, use `"contentMediaType": "application/octet-stream"` instead of `"format": "binary"`. PR [#​14953](https://github.com/fastapi/fastapi/pull/14953) by [@​tiangolo](https://github.com/tiangolo).
##### Docs
- 🔨 Add Kapa.ai widget (AI chatbot). PR [#​14938](https://github.com/fastapi/fastapi/pull/14938) by [@​tiangolo](https://github.com/tiangolo).
- 🔥 Remove Python 3.9 specific files, no longer needed after updating translations. PR [#​14931](https://github.com/fastapi/fastapi/pull/14931) by [@​tiangolo](https://github.com/tiangolo).
- 📝 Update docs for JWT to prevent timing attacks. PR [#​14908](https://github.com/fastapi/fastapi/pull/14908) by [@​tiangolo](https://github.com/tiangolo).
##### Translations
- ✏️ Fix several typos in ru translations. PR [#​14934](https://github.com/fastapi/fastapi/pull/14934) by [@​argoarsiks](https://github.com/argoarsiks).
- 🌐 Update translations for ko (update-all and add-missing). PR [#​14923](https://github.com/fastapi/fastapi/pull/14923) by [@​YuriiMotov](https://github.com/YuriiMotov).
- 🌐 Update translations for uk (add-missing). PR [#​14922](https://github.com/fastapi/fastapi/pull/14922) by [@​YuriiMotov](https://github.com/YuriiMotov).
- 🌐 Update translations for zh-hant (update-all and add-missing). PR [#​14921](https://github.com/fastapi/fastapi/pull/14921) by [@​YuriiMotov](https://github.com/YuriiMotov).
- 🌐 Update translations for fr (update-all and add-missing). PR [#​14920](https://github.com/fastapi/fastapi/pull/14920) by [@​YuriiMotov](https://github.com/YuriiMotov).
- 🌐 Update translations for de (update-all) . PR [#​14910](https://github.com/fastapi/fastapi/pull/14910) by [@​YuriiMotov](https://github.com/YuriiMotov).
- 🌐 Update translations for ja (update-all). PR [#​14916](https://github.com/fastapi/fastapi/pull/14916) by [@​YuriiMotov](https://github.com/YuriiMotov).
- 🌐 Update translations for pt (update-all). PR [#​14912](https://github.com/fastapi/fastapi/pull/14912) by [@​YuriiMotov](https://github.com/YuriiMotov).
- 🌐 Update translations for es (update-all and add-missing). PR [#​14911](https://github.com/fastapi/fastapi/pull/14911) by [@​YuriiMotov](https://github.com/YuriiMotov).
- 🌐 Update translations for zh (update-all). PR [#​14917](https://github.com/fastapi/fastapi/pull/14917) by [@​YuriiMotov](https://github.com/YuriiMotov).
- 🌐 Update translations for uk (update-all). PR [#​14914](https://github.com/fastapi/fastapi/pull/14914) by [@​YuriiMotov](https://github.com/YuriiMotov).
- 🌐 Update translations for tr (update-all). PR [#​14913](https://github.com/fastapi/fastapi/pull/14913) by [@​YuriiMotov](https://github.com/YuriiMotov).
- 🌐 Update translations for ru (update-outdated). PR [#​14909](https://github.com/fastapi/fastapi/pull/14909) by [@​YuriiMotov](https://github.com/YuriiMotov).
##### Internal
- 👷 Always run tests on push to `master` branch and when run by scheduler. PR [#​14940](https://github.com/fastapi/fastapi/pull/14940) by [@​YuriiMotov](https://github.com/YuriiMotov).
- 🎨 Upgrade typing syntax for Python 3.10. PR [#​14932](https://github.com/fastapi/fastapi/pull/14932) by [@​tiangolo](https://github.com/tiangolo).
- ⬆ Bump cryptography from 46.0.4 to 46.0.5. PR [#​14892](https://github.com/fastapi/fastapi/pull/14892) by [@​dependabot\[bot\]](https://github.com/apps/dependabot).
- ⬆ Bump pillow from 12.1.0 to 12.1.1. PR [#​14899](https://github.com/fastapi/fastapi/pull/14899) by [@​dependabot\[bot\]](https://github.com/apps/dependabot).
### [`v0.129.0`](https://github.com/fastapi/fastapi/releases/tag/0.129.0)
[Compare Source](https://github.com/fastapi/fastapi/compare/0.128.8...0.129.0)
##### Breaking Changes
- ➖ Drop support for Python 3.9. PR [#​14897](https://github.com/fastapi/fastapi/pull/14897) by [@​tiangolo](https://github.com/tiangolo).
##### Refactors
- 🎨 Update internal types for Python 3.10. PR [#​14898](https://github.com/fastapi/fastapi/pull/14898) by [@​tiangolo](https://github.com/tiangolo).
##### Docs
- 📝 Update highlights in webhooks docs. PR [#​14905](https://github.com/fastapi/fastapi/pull/14905) by [@​tiangolo](https://github.com/tiangolo).
- 📝 Update source examples and docs from Python 3.9 to 3.10. PR [#​14900](https://github.com/fastapi/fastapi/pull/14900) by [@​tiangolo](https://github.com/tiangolo).
##### Internal
- 🔨 Update docs.py scripts to migrate Python 3.9 to Python 3.10. PR [#​14906](https://github.com/fastapi/fastapi/pull/14906) by [@​tiangolo](https://github.com/tiangolo).
### [`v0.128.8`](https://github.com/fastapi/fastapi/releases/tag/0.128.8)
[Compare Source](https://github.com/fastapi/fastapi/compare/0.128.7...0.128.8)
##### Docs
- 📝 Fix grammar in `docs/en/docs/tutorial/first-steps.md`. PR [#​14708](https://github.com/fastapi/fastapi/pull/14708) by [@​SanjanaS10](https://github.com/SanjanaS10).
##### Internal
- 🔨 Tweak PDM hook script. PR [#​14895](https://github.com/fastapi/fastapi/pull/14895) by [@​tiangolo](https://github.com/tiangolo).
- ♻️ Update build setup for `fastapi-slim`, deprecate it, and make it only depend on `fastapi`. PR [#​14894](https://github.com/fastapi/fastapi/pull/14894) by [@​tiangolo](https://github.com/tiangolo).
### [`v0.128.7`](https://github.com/fastapi/fastapi/releases/tag/0.128.7)
[Compare Source](https://github.com/fastapi/fastapi/compare/0.128.6...0.128.7)
##### Features
- ✨ Show a clear error on attempt to include router into itself. PR [#​14258](https://github.com/fastapi/fastapi/pull/14258) by [@​JavierSanchezCastro](https://github.com/JavierSanchezCastro).
- ✨ Replace `dict` by `Mapping` on `HTTPException.headers`. PR [#​12997](https://github.com/fastapi/fastapi/pull/12997) by [@​rijenkii](https://github.com/rijenkii).
##### Refactors
- ♻️ Simplify reading files in memory, do it sequentially instead of (fake) parallel. PR [#​14884](https://github.com/fastapi/fastapi/pull/14884) by [@​tiangolo](https://github.com/tiangolo).
##### Docs
- 📝 Use `dfn` tag for definitions instead of `abbr` in docs. PR [#​14744](https://github.com/fastapi/fastapi/pull/14744) by [@​YuriiMotov](https://github.com/YuriiMotov).
##### Internal
- ✅ Tweak comment in test to reference PR. PR [#​14885](https://github.com/fastapi/fastapi/pull/14885) by [@​tiangolo](https://github.com/tiangolo).
- 🔧 Update LLM-prompt for `abbr` and `dfn` tags. PR [#​14747](https://github.com/fastapi/fastapi/pull/14747) by [@​YuriiMotov](https://github.com/YuriiMotov).
- ✅ Test order for the submitted byte Files. PR [#​14828](https://github.com/fastapi/fastapi/pull/14828) by [@​valentinDruzhinin](https://github.com/valentinDruzhinin).
- 🔧 Configure `test` workflow to run tests with `inline-snapshot=review`. PR [#​14876](https://github.com/fastapi/fastapi/pull/14876) by [@​YuriiMotov](https://github.com/YuriiMotov).
### [`v0.128.6`](https://github.com/fastapi/fastapi/releases/tag/0.128.6)
[Compare Source](https://github.com/fastapi/fastapi/compare/0.128.5...0.128.6)
##### Fixes
- 🐛 Fix `on_startup` and `on_shutdown` parameters of `APIRouter`. PR [#​14873](https://github.com/fastapi/fastapi/pull/14873) by [@​YuriiMotov](https://github.com/YuriiMotov).
##### Translations
- 🌐 Update translations for zh (update-outdated). PR [#​14843](https://github.com/fastapi/fastapi/pull/14843) by [@​tiangolo](https://github.com/tiangolo).
##### Internal
- ✅ Fix parameterized tests with snapshots. PR [#​14875](https://github.com/fastapi/fastapi/pull/14875) by [@​YuriiMotov](https://github.com/YuriiMotov).
### [`v0.128.5`](https://github.com/fastapi/fastapi/releases/tag/0.128.5)
[Compare Source](https://github.com/fastapi/fastapi/compare/0.128.4...0.128.5)
##### Refactors
- ♻️ Refactor and simplify Pydantic v2 (and v1) compatibility internal utils. PR [#​14862](https://github.com/fastapi/fastapi/pull/14862) by [@​tiangolo](https://github.com/tiangolo).
##### Internal
- ✅ Add inline snapshot tests for OpenAPI before changes from Pydantic v2. PR [#​14864](https://github.com/fastapi/fastapi/pull/14864) by [@​tiangolo](https://github.com/tiangolo).
</details>
---
### Configuration
📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4zMC4wIiwidXBkYXRlZEluVmVyIjoiNDMuMzAuMCIsInRhcmdldEJyYW5jaCI6ImRldmVsb3AiLCJsYWJlbHMiOltdfQ==-->
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
This PR contains the following updates:
==0.128.4→==0.135.1Release Notes
fastapi/fastapi (fastapi)
v0.135.1Compare Source
Fixes
Docs
docs/en/docs/_llm-test.md. PR #15007 by @adityagiri3600.Internal
v0.135.0Compare Source
Features
v0.134.0Compare Source
Features
yield. PR #15022 by @tiangolo.>=0.40.0to>=0.46.0, as it's needed to properly unrwap and re-raise exceptions from exception groups.Docs
yield. PR #15023 by @tiangolo.awaitinStreamingResponsecode example to allow cancellation. PR #14681 by @casperdcl.docs_src/websocketstodocs_src/websockets_to avoid import errors. PR #14979 by @YuriiMotov.Internal
pytest-xdistandpytest-cov. PR #14992 by @YuriiMotov.v0.133.1Compare Source
Features
Internal
v0.133.0Compare Source
Upgrades
v0.132.1Compare Source
Refactors
Internal
benchmarkjob intestworkflow. PR #14974 by @YuriiMotov.v0.132.0Compare Source
Breaking Changes
strict_content_typechecking for JSON requests. PR #14978 by @tiangolo.Content-Typeheader with a valid JSON value, likeapplication/json, and rejects requests that don't.Content-Typeheader you can disable this withstrict_content_type=False.Internal
griffelibinstead ofgriffe. PR #14973 by @svlandeg.FastAPI Peopleworkflow. PR #14951 by @YuriiMotov.v0.131.0Compare Source
Breaking Changes
ORJSONResponseandUJSONResponse. PR #14964 by @tiangolo.v0.130.0Compare Source
Features
v0.129.2Compare Source
Internal
fastapi-slim. PR #14958 by @tiangolo.fastapi-slim, no more versions will be released, use only"fastapi[standard]"orfastapi. PR #14957 by @tiangolo.v0.129.1Compare Source
Fixes
"contentMediaType": "application/octet-stream"instead of"format": "binary". PR #14953 by @tiangolo.Docs
Translations
Internal
masterbranch and when run by scheduler. PR #14940 by @YuriiMotov.v0.129.0Compare Source
Breaking Changes
Refactors
Docs
Internal
v0.128.8Compare Source
Docs
docs/en/docs/tutorial/first-steps.md. PR #14708 by @SanjanaS10.Internal
fastapi-slim, deprecate it, and make it only depend onfastapi. PR #14894 by @tiangolo.v0.128.7Compare Source
Features
dictbyMappingonHTTPException.headers. PR #12997 by @rijenkii.Refactors
Docs
dfntag for definitions instead ofabbrin docs. PR #14744 by @YuriiMotov.Internal
abbranddfntags. PR #14747 by @YuriiMotov.testworkflow to run tests withinline-snapshot=review. PR #14876 by @YuriiMotov.v0.128.6Compare Source
Fixes
on_startupandon_shutdownparameters ofAPIRouter. PR #14873 by @YuriiMotov.Translations
Internal
v0.128.5Compare Source
Refactors
Internal
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.
3144bfdcd8to5905142981