Skip to content

chore(deps): bump werkzeug from 3.1.7 to 3.1.8 in the flask group across 1 directory#8898

Open
dependabot[bot] wants to merge 1 commit intodevelopfrom
dependabot/pip/develop/flask-682ee82ea9
Open

chore(deps): bump werkzeug from 3.1.7 to 3.1.8 in the flask group across 1 directory#8898
dependabot[bot] wants to merge 1 commit intodevelopfrom
dependabot/pip/develop/flask-682ee82ea9

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Apr 8, 2026

Bumps the flask group with 1 update in the / directory: werkzeug.

Updates werkzeug from 3.1.7 to 3.1.8

Release notes

Sourced from werkzeug's releases.

3.1.8

This is the Werkzeug 3.1.8 fix release, which fixes bugs but does not otherwise change behavior and should not result in breaking changes compared to the latest feature release.

PyPI: https://pypi.org/project/Werkzeug/3.1.8/ Changes: https://werkzeug.palletsprojects.com/page/changes/#version-3-1-8 Milestone: https://github.com/pallets/werkzeug/milestone/45?closed=1

  • Request.host and get_host return the empty string if the header is missing or has invalid characters. #3142
Changelog

Sourced from werkzeug's changelog.

Version 3.1.8

Released 2026-04-02

  • Request.host and get_host return the empty string if the header is missing or has invalid characters. :issue:3142
Commits

@dependabot dependabot bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Apr 8, 2026
@dependabot dependabot bot requested a review from a team as a code owner April 8, 2026 08:17
@dependabot dependabot bot added python Pull requests that update Python code dependencies Pull requests that update a dependency file labels Apr 8, 2026
@dependabot dependabot bot changed the title chore(deps): bump werkzeug from 3.1.7 to 3.1.8 in the flask group chore(deps): bump werkzeug from 3.1.7 to 3.1.8 in the flask group across 1 directory Apr 9, 2026
@dependabot dependabot bot force-pushed the dependabot/pip/develop/flask-682ee82ea9 branch 3 times, most recently from ef56ee1 to 626a9d0 Compare April 13, 2026 08:27
@dependabot dependabot bot force-pushed the dependabot/pip/develop/flask-682ee82ea9 branch from 626a9d0 to e413448 Compare April 16, 2026 08:15
Copy link
Copy Markdown
Contributor

@github-actions github-actions bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This review has been superseded by a newer review.

Bumps the flask group with 1 update: [werkzeug](https://github.com/pallets/werkzeug).


Updates `werkzeug` from 3.1.7 to 3.1.8
- [Release notes](https://github.com/pallets/werkzeug/releases)
- [Changelog](https://github.com/pallets/werkzeug/blob/main/CHANGES.rst)
- [Commits](pallets/werkzeug@3.1.7...3.1.8)

---
updated-dependencies:
- dependency-name: werkzeug
  dependency-version: 3.1.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: flask
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/pip/develop/flask-682ee82ea9 branch from e413448 to 167baa4 Compare April 17, 2026 08:14
Copy link
Copy Markdown
Contributor

@github-actions github-actions bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review Results

Reviewed: 09c3cd5..167baa4
Files: 3
Comments: 0

✅ No issues found. The changes look good.

This is a clean dependency version bump of werkzeug from 3.1.7 to 3.1.8 across all three platform-specific reproducible requirements files (linux, mac, win). The version is pinned with exact hashes, and the change is consistent across all files.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file pr/internal python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant