From a9f1b4cef2a52dedbb18b5ee27494f6ee66ceeb8 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 28 Sep 2026 23:56:21 +0000 Subject: [PATCH 1/5] Bump github/codeql-action from 4.38.1 to 4.38.2 (#13843) Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.38.1 to 4.38.2.
Release notes

Sourced from github/codeql-action's releases.

v4.38.2

Changelog

Sourced from github/codeql-action's changelog.

4.38.2 - 24 Sept 2026

Commits

Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- .github/workflows/codeql.yml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 7ebfa399813..dbc88cff171 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -29,17 +29,17 @@ jobs: uses: actions/checkout@v7 - name: Initialize CodeQL - uses: github/codeql-action/init@v4.38.1 + uses: github/codeql-action/init@v4.38.2 with: languages: ${{ matrix.language }} config-file: ./.github/codeql.yml queries: +security-and-quality - name: Autobuild - uses: github/codeql-action/autobuild@v4.38.1 + uses: github/codeql-action/autobuild@v4.38.2 if: ${{ matrix.language == 'python' || matrix.language == 'javascript' }} - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@v4.38.1 + uses: github/codeql-action/analyze@v4.38.2 with: category: "/language:${{ matrix.language }}" From 8bd1fb4feccf1d6bbc0615d6088cde99b6c207e9 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 29 Sep 2026 00:27:38 +0000 Subject: [PATCH 2/5] Bump platformdirs from 4.11.12 to 4.11.14 (#13847) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Bumps [platformdirs](https://github.com/tox-dev/platformdirs) from 4.11.12 to 4.11.14.
Release notes

Sourced from platformdirs's releases.

4.11.14

What's Changed

Full Changelog: https://github.com/tox-dev/platformdirs/compare/4.11.13...4.11.14

4.11.13

What's Changed

Full Changelog: https://github.com/tox-dev/platformdirs/compare/4.11.12...4.11.13

Changelog

Sourced from platformdirs's changelog.

########### Changelog ###########

.. towncrier-draft-entries:: Unreleased

.. towncrier release notes start


4.12.1 (2026-09-28)


  • Avoid PytestAssertRewriteWarning when importing platformdirs before invoking pytest. :pr:601

4.12.0 (2026-09-26)


  • Add place_*_file methods that return a file path under a user directory and create its missing parents with mode 0o700. :pr:585
  • Add find_<kind>_file and find_<kind>_files to look up an existing file across the user and site directories of each kind that has an iter_<kind>_paths method. :pr:586
  • Add :func:platformdirs.testing.isolated_dirs and the platformdirs_isolated pytest fixture to resolve every directory under one test root. :pr:590
  • Emit :class:~platformdirs.RuntimeDirWarning when the Unix :func:~platformdirs.user_runtime_dir falls back from XDG_RUNTIME_DIR. :pr:599
  • Read user_templates_dir, user_publicshare_dir and user_bin_dir on Windows from their known folders. :pr:587
  • Create missing user app directories and their parents with mode 0700 under ensure_exists on POSIX platforms. :pr:588
  • Raise RuntimeError for a Unix or macOS directory under the home when no home resolves, and read the password database for an empty HOME. :pr:589
  • Skip an XDG_RUNTIME_DIR or /run/user/<uid> that is not a private directory of the user, and reject a symlink or file as the runtime-<uid> fallback. :pr:599
  • Use the app container layout on iOS, such as ~/Library/Application Support for data. :pr:600
  • Document that a Homebrew Python puts the Homebrew prefix first in the macOS shared directories, with or without multipath. :pr:591
  • Document that the macOS media directories honor the XDG_*_DIR variables. :pr:592
  • Document the WIN_PD_OVERRIDE_COMMON_PROGRAMS variable. :pr:593
  • Document /usr/local/share/applications as the Linux site_applications_dir default. :pr:594
  • Correct the BSD user_runtime_dir defaults and describe the temporary directory fallback. :pr:595
  • Describe how platformdirs detects Android, finds the app folder and places the shared folders. :pr:596
  • Document that Microsoft Store Python redirects only new files and folders under AppData. :pr:597
  • Show how to load a font on Windows after copying it into user_fonts_dir. :pr:598

4.11.15 (2026-09-26)


  • Fix the pyjnius lookup of the Android app folder and media directories, which always failed. :pr:580

... (truncated)

Commits

Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- requirements/constraints.txt | 2 +- requirements/dev.txt | 2 +- requirements/lint.txt | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/requirements/constraints.txt b/requirements/constraints.txt index 5a0fff5255a..9999aceae62 100644 --- a/requirements/constraints.txt +++ b/requirements/constraints.txt @@ -168,7 +168,7 @@ pip-tools==7.6.1 # via -r requirements/dev.in pkgconfig==1.6.0 # via -r requirements/test-common-base.in -platformdirs==4.11.12 +platformdirs==4.11.14 # via virtualenv pluggy==1.6.0 # via diff --git a/requirements/dev.txt b/requirements/dev.txt index e6cfed71ab9..aae07cda24c 100644 --- a/requirements/dev.txt +++ b/requirements/dev.txt @@ -165,7 +165,7 @@ pip-tools==7.6.1 # via -r requirements/dev.in pkgconfig==1.6.0 # via -r requirements/test-common-base.in -platformdirs==4.11.12 +platformdirs==4.11.14 # via virtualenv pluggy==1.6.0 # via diff --git a/requirements/lint.txt b/requirements/lint.txt index d6b73071913..7b9fba81d7f 100644 --- a/requirements/lint.txt +++ b/requirements/lint.txt @@ -86,7 +86,7 @@ packaging==26.3 # via pytest pathspec==1.1.1 # via mypy -platformdirs==4.11.12 +platformdirs==4.11.14 # via virtualenv pluggy==1.6.0 # via pytest From ed74d78659100e8ac34bc53186b7aac2d5e03887 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 29 Sep 2026 00:44:40 +0000 Subject: [PATCH 3/5] Bump virtualenv from 21.9.1 to 21.12.1 (#13844) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Bumps [virtualenv](https://github.com/pypa/virtualenv) from 21.9.1 to 21.12.1.
Release notes

Sourced from virtualenv's releases.

21.12.1

What's Changed

Full Changelog: https://github.com/pypa/virtualenv/compare/21.12.0...21.12.1

21.12.0

What's Changed

Full Changelog: https://github.com/pypa/virtualenv/compare/21.11.1...21.12.0

21.11.1

What's Changed

New Contributors

Full Changelog: https://github.com/pypa/virtualenv/compare/21.11.0...21.11.1

21.11.0

What's Changed

... (truncated)

Changelog

Sourced from virtualenv's changelog.

Bugfixes - 21.12.1

  • Limit the :PEP:832 .venv redirect to folders holding a pyproject.toml and no .venv yet, so virtualenv foo in a scratch folder, and tools such as tox or nox building environments through virtualenv, no longer claim a folder's default environment - by :user:gaborbernat.

    • --venv-redirect writes the redirect in any folder and replaces an earlier virtualenv redirect.
    • A flag on the command line overrides the environment variable and the config file in either direction. (:issue:3316)

v21.12.0 (2026-09-24)


Features - 21.12.0

  • Write the PEP 838 <https://peps.python.org/pep-0838/>_ python-version key into pyvenv.cfg, holding the target interpreter's feature release. The new :doc:reference/files page covers it alongside every other file a created environment holds - by :user:konstin. (:issue:3193)

  • Point a .venv redirect file in the parent folder at the created environment, per PEP 832 <https://peps.python.org/pep-0832/>_, so editors and type checkers can find it - by :user:gaborbernat.

    • virtualenv leaves a .venv folder alone, and a redirect pointing at an environment it did not create.
    • Pass --no-venv-redirect to opt out.
    • The feature is provisional while PEP 832 is a draft: a minor or patch release may change it in backward incompatible ways to follow the PEP. (:issue:3204)

v21.11.1 (2026-09-23)


Bugfixes - 21.11.1

  • Include the pre-commit configuration and the zipapp lock file in the source distribution, so downstream packagers can run the test suite from it. (:issue:3314)

v21.11.0 (2026-09-23)


Features - 21.11.0

  • Attach the CycloneDX SBOM and an SPDX 2.3 rendering of it (virtualenv.cdx.json, virtualenv.spdx.json) to each GitHub release, and attest the SPDX document against the sdist and wheel. (:issue:3299)
  • Describe the zipapp in its own CycloneDX SBOM, which lists virtualenv, the embedded pip and setuptools wheels, and each bundled dependency with the Python versions that load it, down to a SHA-256 per file. The SBOM sits at the root

... (truncated)

Commits
  • befec5e release 21.12.1
  • 572d159 🐛 fix(create): limit .venv redirect to projects (#3316)
  • f19165b release 21.12.0
  • 554bc8f ✨ feat(create): point a .venv redirect per PEP 832 (#3204)
  • 4c13875 release 21.11.1
  • ae073fb 🐛 fix(build): ship test inputs in the sdist and check it (#3315)
  • fc912de 📝 docs(security): close threat items resolved by 21.11.0 (#3313)
  • 49077e7 release 21.11.0
  • 5d9dc58 🐛 fix(sbom): keep the build machine out of the SBOMs (#3311)
  • bcb0fa6 📝 docs(security): sync threat model with merged fixes (#3312)
  • Additional commits viewable in compare view

Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- requirements/constraints.txt | 2 +- requirements/dev.txt | 2 +- requirements/lint.txt | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/requirements/constraints.txt b/requirements/constraints.txt index 9999aceae62..36697d2bb0a 100644 --- a/requirements/constraints.txt +++ b/requirements/constraints.txt @@ -336,7 +336,7 @@ uvloop==0.22.1 ; platform_system != "Windows" # -r requirements/lint.in valkey==6.1.1 # via -r requirements/lint.in -virtualenv==21.9.1 +virtualenv==21.12.1 # via pre-commit wheel==0.48.0 # via pip-tools diff --git a/requirements/dev.txt b/requirements/dev.txt index aae07cda24c..af815b6717e 100644 --- a/requirements/dev.txt +++ b/requirements/dev.txt @@ -326,7 +326,7 @@ uvloop==0.22.1 ; platform_system != "Windows" and implementation_name == "cpytho # -r requirements/lint.in valkey==6.1.1 # via -r requirements/lint.in -virtualenv==21.9.1 +virtualenv==21.12.1 # via pre-commit wheel==0.48.0 # via pip-tools diff --git a/requirements/lint.txt b/requirements/lint.txt index 7b9fba81d7f..681fd47cd0d 100644 --- a/requirements/lint.txt +++ b/requirements/lint.txt @@ -166,7 +166,7 @@ uvloop==0.22.1 ; platform_system != "Windows" # via -r requirements/lint.in valkey==6.1.1 # via -r requirements/lint.in -virtualenv==21.9.1 +virtualenv==21.12.1 # via pre-commit yarl==1.25.1 # via aiohttp From ced8133ea466a3bbe39d01a42bef79a5d2dbf1b5 Mon Sep 17 00:00:00 2001 From: toolsfox Date: Tue, 29 Sep 2026 09:46:11 +0800 Subject: [PATCH 4/5] Fix read_chunk() on body parts with a zero Content-Length (#13760) --- CHANGES/13758.bugfix.rst | 6 ++++++ CHANGES/13760.bugfix.rst | 1 + CONTRIBUTORS.txt | 1 + aiohttp/multipart.py | 2 +- tests/test_multipart.py | 8 ++++++++ 5 files changed, 17 insertions(+), 1 deletion(-) create mode 100644 CHANGES/13758.bugfix.rst create mode 120000 CHANGES/13760.bugfix.rst diff --git a/CHANGES/13758.bugfix.rst b/CHANGES/13758.bugfix.rst new file mode 100644 index 00000000000..36bb4ffc3e9 --- /dev/null +++ b/CHANGES/13758.bugfix.rst @@ -0,0 +1,6 @@ +Fixed a crash in :meth:`~aiohttp.BodyPartReader.read_chunk` on a body part +with an explicit ``Content-Length: 0``: the part fell through to the +streaming read strategy, whose minimum chunk size assertion then failed for +chunk sizes below the boundary length. Such parts now yield an immediate +empty chunk, like any other part with a known length +-- by :user:`istoolsfox`. diff --git a/CHANGES/13760.bugfix.rst b/CHANGES/13760.bugfix.rst new file mode 120000 index 00000000000..4c97bb5bc7a --- /dev/null +++ b/CHANGES/13760.bugfix.rst @@ -0,0 +1 @@ +13758.bugfix.rst \ No newline at end of file diff --git a/CONTRIBUTORS.txt b/CONTRIBUTORS.txt index e9e72254437..ddbd02c152d 100644 --- a/CONTRIBUTORS.txt +++ b/CONTRIBUTORS.txt @@ -188,6 +188,7 @@ Illia Volochii Ilya Chichak Ilya Gruzinov Ingmar Steen +istoolsfox Ivan Lakovic Ivan Larin J. Nick Koston diff --git a/aiohttp/multipart.py b/aiohttp/multipart.py index 37895666d2d..957b21058d6 100644 --- a/aiohttp/multipart.py +++ b/aiohttp/multipart.py @@ -386,7 +386,7 @@ async def read_chunk(self, size: int = chunk_size) -> bytes: if carry: self._b64_carry = b"" want = max(want, self._boundary_len) - if self._length: + if self._length is not None: fresh = await self._read_chunk_from_length(want) else: fresh = await self._read_chunk_from_stream(want) diff --git a/tests/test_multipart.py b/tests/test_multipart.py index 184b766f5f4..990175d89cd 100644 --- a/tests/test_multipart.py +++ b/tests/test_multipart.py @@ -206,6 +206,14 @@ async def test_read_chunk_without_content_length(self) -> None: assert c1 + c2 == b"Hello, world!" assert c3 == b"" + async def test_read_chunk_with_zero_content_length(self) -> None: + with Stream(b"\r\n--:--\r\n") as stream: + d = HeadersDictProxy(CIMultiDict({"Content-Length": "0"})) + obj = aiohttp.BodyPartReader(BOUNDARY, d, stream) + result = await obj.read_chunk(4) + assert obj.at_eof() + assert b"" == result + async def test_read_incomplete_chunk(self) -> None: with Stream(b"") as stream: From 31b6ebee2249d1cdf19da0f3af0c14ee2bf5d6b1 Mon Sep 17 00:00:00 2001 From: "pre-commit-ci[bot]" <66853113+pre-commit-ci[bot]@users.noreply.github.com> Date: Tue, 29 Sep 2026 04:23:33 +0100 Subject: [PATCH 5/5] [pre-commit.ci] pre-commit autoupdate (#13850) --- .pre-commit-config.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index 3962f573c2e..b98f269a334 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -104,7 +104,7 @@ repos: - id: pyupgrade args: ['--py37-plus'] - repo: https://github.com/PyCQA/flake8 - rev: '7.3.0' + rev: '7.4.1' hooks: - id: flake8 additional_dependencies: