Skip to content

chore(deps): Update dependency uvicorn to v0.54.0 - #162

Open
renovate[bot] wants to merge 1 commit into
developfrom
deps/uvicorn-0.x
Open

renovate[bot] wants to merge 1 commit into
developfrom
deps/uvicorn-0.x

Conversation

@renovate

@renovate renovate Bot commented Aug 1, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
uvicorn (changelog) ==0.51.0 → ==0.54.0 age confidence

Release Notes

Kludex/uvicorn (uvicorn)

v0.54.0: Version 0.54.0

Compare Source

📨 Send metadata after the response body

uvicorn 0.54.0 adds response trailers and 103 Early Hints to its experimental HTTP/2 implementation through zttp.

uv add uvicorn==0.54.0 "zttp>=0.0.34"
  • Send HTTP/2 response trailers (#​3146). The ASGI http.response.trailers extension lets applications send metadata, such as checksums, after the response body. Clients must send TE: trailers to receive them. Multiple trailer messages are combined before completing the response.
  • HTTP/2 remains experimental and opt-in. Enable it with --http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 remain unsupported.

💡 Hint at resources before the final response

  • Send 103 Early Hints over HTTP/2 (#​3137). Applications can use the ASGI http.response.early_hint extension to send resource hints before the final response. Each supplied link becomes a separate Link header.

Full changelog: 0.53.0...0.54.0

v0.53.0: Version 0.53.0

Compare Source

🌐 Opt-in HTTP/2 support

uvicorn 0.53.0 adds experimental HTTP/2 through zttp, alongside a new zuvloop integration and connection-handling improvements.

uv add uvicorn==0.53.0
  • Serve HTTP/1.1 and HTTP/2 with zttp (#​2982, #​3101). Install zttp, then enable HTTP/2 with --http zttp --http2. Uvicorn negotiates HTTP/2 over TLS with ALPN and supports cleartext prior knowledge.
  • HTTP/2 remains experimental. Upgrade-based h2c and WebSockets over HTTP/2 are not supported.

⚙️ More event loop choice

  • Run Uvicorn with zuvloop (#​3104). Install zuvloop separately and select it explicitly with --loop zuvloop on CPython 3.14 or newer.

🛡️ More reliable connections and proxies

  • Honor Connection: close token lists (#​3103). Uvicorn now parses comma-separated tokens case-insensitively across HTTP implementations.
  • Trust IPv6 loopback proxies by default (#​3119). The default FORWARDED_ALLOW_IPS value now includes ::1.
  • Keep upgraded WebSockets alive (#​3107). Uvicorn cancels the HTTP keep-alive timer when the connection becomes a WebSocket.

Full changelog: 0.52.4...0.53.0

v0.52.4: Version 0.52.4

Compare Source

Fixed
  • Remove duplicate Date headers from accepted WebSocket handshakes with websockets-sansio (#​3078)

Full Changelog: Kludex/uvicorn@0.52.3...0.52.4

v0.52.3: Version 0.52.3

Compare Source

Changed
  • Update zttp to 0.0.24 and use its combined receive path, improving HTTP/1.1 request parsing performance (#​3067)

Full Changelog: Kludex/uvicorn@0.52.2...0.52.3

v0.52.2: Version 0.52.2

Compare Source

Fixed
  • Update zttp to 0.0.22, fixing bodyless request receives and improving HTTP/1 request parsing performance (#​3063)

Full Changelog: Kludex/uvicorn@0.52.1...0.52.2

v0.52.1: Version 0.52.1

Compare Source

Fixed
  • Complete the closing handshake on server-initiated WebSocket closes in the websockets-sansio and wsproto implementations, waiting for the client's close reply with a 10 second timeout instead of resetting the connection (#​3053)
  • Add missing write flow control to the websockets-sansio implementation, preventing data truncation on server-initiated closes with large in-flight payloads (#​3048)
  • Handle connection loss while a WebSocket write is waiting on backpressure (#​3050)
  • Remove duplicate Content-Type and Content-Length headers from WebSocket denial responses on the websockets-sansio implementation, and deliver non-UTF-8 denial bodies intact (#​3041)

Full Changelog: Kludex/uvicorn@0.52.0...0.52.1

v0.52.0: Version 0.52.0

Compare Source

This release adds an experimental HTTP/1.1 implementation backed by zttp, a sans-IO HTTP parser I've been developing on the side: a core written in Zig, with bindings to Python. It has been running under a fuzzer for some weeks now, and has been through multiple rounds of security auditing.

It is still experimental, so don't put it in front of production traffic yet. Try it with --http zttp, and please send any feedback to the issue tracker.

Added
  • Add an experimental zttp HTTP/1.1 implementation, selectable with --http zttp (#​2979)
Fixed
  • Keep non-ASCII WebSocket request headers intact with websockets 17.0, which encodes them with ISO-8859-1 (#​3036)

Full Changelog: Kludex/uvicorn@0.51.0...0.52.0


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "every weekend"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies label Aug 1, 2026
@renovate
renovate Bot force-pushed the deps/uvicorn-0.x branch from 73751eb to bfbf2e5 Compare August 4, 2026 22:42
@renovate renovate Bot changed the title chore(deps): Update dependency uvicorn to v0.52.0 chore(deps): Update dependency uvicorn to v0.52.1 Aug 4, 2026
@renovate
renovate Bot force-pushed the deps/uvicorn-0.x branch 2 times, most recently from 7cfa674 to 198af96 Compare August 16, 2026 09:13
@renovate renovate Bot changed the title chore(deps): Update dependency uvicorn to v0.52.1 chore(deps): Update dependency uvicorn to v0.52.2 Aug 16, 2026
@renovate
renovate Bot force-pushed the deps/uvicorn-0.x branch from 198af96 to d7095c8 Compare August 16, 2026 16:59
@renovate renovate Bot changed the title chore(deps): Update dependency uvicorn to v0.52.2 chore(deps): Update dependency uvicorn to v0.52.3 Aug 16, 2026
@renovate
renovate Bot force-pushed the deps/uvicorn-0.x branch from d7095c8 to 648250c Compare August 22, 2026 09:32
@renovate renovate Bot changed the title chore(deps): Update dependency uvicorn to v0.52.3 chore(deps): Update dependency uvicorn to v0.52.4 Aug 22, 2026
@renovate
renovate Bot force-pushed the deps/uvicorn-0.x branch 2 times, most recently from 097c42c to 57bc62f Compare September 2, 2026 17:07
@renovate
renovate Bot force-pushed the deps/uvicorn-0.x branch from 57bc62f to 634a6d5 Compare September 7, 2026 23:34
@renovate
renovate Bot force-pushed the deps/uvicorn-0.x branch 2 times, most recently from 66c188f to 39137c7 Compare September 17, 2026 20:56
@renovate renovate Bot changed the title chore(deps): Update dependency uvicorn to v0.52.4 chore(deps): Update dependency uvicorn to v0.53.0 Sep 17, 2026
@renovate
renovate Bot force-pushed the deps/uvicorn-0.x branch from 39137c7 to 4893865 Compare September 25, 2026 04:47
@renovate
renovate Bot force-pushed the deps/uvicorn-0.x branch from 4893865 to 57d93d1 Compare September 28, 2026 23:36
@renovate renovate Bot changed the title chore(deps): Update dependency uvicorn to v0.53.0 chore(deps): Update dependency uvicorn to v0.54.0 Sep 28, 2026
@sonarqubecloud

Copy link
Copy Markdown

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants