Skip to content

chore(deps): bump python-multipart from 0.0.9 to 0.0.27 in /backend in the pip group across 1 directory - #143

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/pip/backend/pip-14c377a4fb
Closed

chore(deps): bump python-multipart from 0.0.9 to 0.0.27 in /backend in the pip group across 1 directory#143
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/pip/backend/pip-14c377a4fb

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 11, 2026

Copy link
Copy Markdown
Contributor

Bumps the pip group with 1 update in the /backend directory: python-multipart.

Updates python-multipart from 0.0.9 to 0.0.27

Release notes

Sourced from python-multipart's releases.

Version 0.0.27

What's Changed

Full Changelog: Kludex/python-multipart@0.0.26...0.0.27

Version 0.0.26

What's Changed

Full Changelog: Kludex/python-multipart@0.0.25...0.0.26

Version 0.0.25

What's Changed

Full Changelog: Kludex/python-multipart@0.0.24...0.0.25

Version 0.0.24

What's Changed

Full Changelog: Kludex/python-multipart@0.0.23...0.0.24

Version 0.0.23

What's Changed

New Contributors

Full Changelog: Kludex/python-multipart@0.0.22...0.0.23

Version 0.0.22

What's Changed

... (truncated)

Changelog

Sourced from python-multipart's changelog.

0.0.27 (2026-04-27)

  • Add multipart header limits #267.
  • Pass parse offsets via constructors #268.

0.0.26 (2026-04-10)

  • Skip preamble before the first multipart boundary more efficiently #262.
  • Silently discard epilogue data after the closing multipart boundary #259.

0.0.25 (2026-04-10)

  • Add MIME content type info to File #143.
  • Handle CTE values case-insensitively #258.
  • Remove custom FormParser classes #257.
  • Add UPLOAD_DELETE_TMP to FormParser config #254.
  • Emit field_end for trailing bare field names on finalize #230.
  • Handle multipart headers case-insensitively #252.
  • Apply Apache-2.0 properly #247.

0.0.24 (2026-04-05)

  • Validate chunk_size in parse_form() #244.

0.0.23 (2026-04-05)

  • Remove unused trust_x_headers parameter and X-File-Name fallback #196.
  • Return processed length from QuerystringParser._internal_write #229.
  • Cleanup metadata dunders from __init__.py #227.

0.0.22 (2026-01-25)

  • Drop directory path from filename in File 9433f4b.

0.0.21 (2025-12-17)

  • Add support for Python 3.14 and drop EOL 3.8 and 3.9 #216.

0.0.20 (2024-12-16)

  • Handle messages containing only end boundary #142.

0.0.19 (2024-11-30)

  • Don't warn when CRLF is found after last boundary on MultipartParser #193.

0.0.18 (2024-11-28)

  • Hard break if found data after last boundary on MultipartParser #189.

... (truncated)

Commits

Summary by CodeRabbit

  • Chores
    • Updated backend dependencies for improved stability and performance.

Review Change Stack

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels May 11, 2026
@coderabbitai

coderabbitai Bot commented May 11, 2026

Copy link
Copy Markdown
Contributor

Note

.coderabbit.yaml has unrecognized properties

CodeRabbit is using all valid settings from your configuration. Unrecognized properties (listed below) have been ignored and may indicate typos or deprecated fields that can be removed.

⚠️ Parsing warnings (1)
Validation error: Unrecognized key(s) in object: 'version'
⚙️ Configuration instructions
  • Please see the configuration documentation for more information.
  • You can also validate your configuration using the online YAML validator.
  • If your editor has YAML language server enabled, you can add the path at the top of this file to enable auto-completion and validation: # yaml-language-server: $schema=https://coderabbit.ai/integrations/schema.v2.json
📝 Walkthrough

Walkthrough

The backend Python dependency python-multipart is upgraded from version 0.0.9 to 0.0.27 in the requirements file. No other dependencies are changed.

Changes

Backend Dependency Update

Layer / File(s) Summary
Multipart Library Upgrade
backend/requirements.txt
python-multipart dependency is upgraded from version 0.0.9 to 0.0.27.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Poem

🐰 A tiny tweak, so neat and small,
Multipart hops from nine to twenty-seven tall,
Pip files updated, no fuss or fight,
Parsing forms by day and night,
🥕 Silent upgrade, soft and light.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title accurately describes the main change: upgrading python-multipart from 0.0.9 to 0.0.27 in the backend directory.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dependabot/pip/backend/pip-14c377a4fb

Warning

Review ran into problems

🔥 Problems

Git: Failed to clone repository. Please run the @coderabbitai full review command to re-trigger a full review. If the issue persists, set path_filters to include or exclude specific files.


Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions

Copy link
Copy Markdown
Contributor

PR governance metadata gate is not ready for 9e8b5aba3a9c27601d5c9afd89441f57b695220f:

  • 3 required check(s) are not successful on 9e8b5ab.\n- Missing current-head CodeRabbit/coderabbitai evidence for 9e8b5ab.\n

4 similar comments
@github-actions

Copy link
Copy Markdown
Contributor

PR governance metadata gate is not ready for 9e8b5aba3a9c27601d5c9afd89441f57b695220f:

  • 3 required check(s) are not successful on 9e8b5ab.\n- Missing current-head CodeRabbit/coderabbitai evidence for 9e8b5ab.\n

@github-actions

Copy link
Copy Markdown
Contributor

PR governance metadata gate is not ready for 9e8b5aba3a9c27601d5c9afd89441f57b695220f:

  • 3 required check(s) are not successful on 9e8b5ab.\n- Missing current-head CodeRabbit/coderabbitai evidence for 9e8b5ab.\n

@github-actions

Copy link
Copy Markdown
Contributor

PR governance metadata gate is not ready for 9e8b5aba3a9c27601d5c9afd89441f57b695220f:

  • 3 required check(s) are not successful on 9e8b5ab.\n- Missing current-head CodeRabbit/coderabbitai evidence for 9e8b5ab.\n

@github-actions

Copy link
Copy Markdown
Contributor

PR governance metadata gate is not ready for 9e8b5aba3a9c27601d5c9afd89441f57b695220f:

  • 3 required check(s) are not successful on 9e8b5ab.\n- Missing current-head CodeRabbit/coderabbitai evidence for 9e8b5ab.\n

@github-actions

Copy link
Copy Markdown
Contributor

PR governance metadata gate is not ready for 9e8b5aba3a9c27601d5c9afd89441f57b695220f:

  • 2 required check(s) are not successful on 9e8b5ab.\n- Missing current-head CodeRabbit/coderabbitai evidence for 9e8b5ab.\n

1 similar comment
@github-actions

Copy link
Copy Markdown
Contributor

PR governance metadata gate is not ready for 9e8b5aba3a9c27601d5c9afd89441f57b695220f:

  • 2 required check(s) are not successful on 9e8b5ab.\n- Missing current-head CodeRabbit/coderabbitai evidence for 9e8b5ab.\n

@greptile-apps

greptile-apps Bot commented May 11, 2026

Copy link
Copy Markdown

Greptile Summary

  • python-multipart를 0.0.9 → 0.0.27로 업그레이드합니다. 이 범위 내에서 0.0.21(Python 3.8/3.9 지원 종료), 0.0.23(trust_x_headers 파라미터 및 X-File-Name 폴백 제거), 0.0.25(커스텀 FormParser 클래스 제거) 등 여러 주요(breaking) 변경이 포함됩니다.
  • 단일 파일(backend/requirements.txt)만 수정되었으며, 나머지 의존성은 변경되지 않았습니다.

Confidence Score: 4/5

의존성 버전 단독 변경으로 코드 로직 자체는 이상 없으나, 대형 버전 점프에 따른 호환성 검증이 필요합니다.

변경 자체는 단순하지만 18개 버전을 건너뛰는 대형 업그레이드이며, 이전 리뷰에서 지적된 FastAPI 0.111.0과의 호환성 검증이 선행되어야 합니다. 새로운 P0/P1 버그는 발견되지 않았습니다.

backend/requirements.txt — FastAPI 버전과 python-multipart 간 호환성 확인 필요

Important Files Changed

Filename Overview
backend/requirements.txt python-multipart를 0.0.9에서 0.0.27로 버전 업. 18개 버전을 건너뛰는 대형 점프이며 여러 주요 변경 사항 포함.

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
    A["python-multipart 0.0.9"] -->|"업그레이드"| B["python-multipart 0.0.27"]
    B --> C{"호환성 체크"}
    C --> D["fastapi==0.111.0\n멀티파트 감지 로직 확인"]
    C --> E["trust_x_headers 파라미터\n사용 여부 확인"]
    C --> F["커스텀 FormParser 클래스\n사용 여부 확인"]
    C --> G["Python 버전 확인\n(0.0.21부터 3.8/3.9 지원 종료)"]
    D --> H{{"실제 form 엔드포인트\n통합 테스트 필요"}}
    E --> H
    F --> H
    G --> H
Loading

Reviews (2): Last reviewed commit: "chore(deps): bump python-multipart" | Re-trigger Greptile

Comment thread backend/requirements.txt
@github-actions

Copy link
Copy Markdown
Contributor

PR governance metadata gate is not ready for 9e8b5aba3a9c27601d5c9afd89441f57b695220f:

  • Merge state is UNKNOWN; resolve conflicts or refresh mergeability.\n- 1 unresolved current review thread(s) remain.\n- Missing current-head CodeRabbit/coderabbitai evidence for 9e8b5ab.\n

Bumps the pip group with 1 update in the /backend directory: [python-multipart](https://github.com/Kludex/python-multipart).


Updates `python-multipart` from 0.0.9 to 0.0.27
- [Release notes](https://github.com/Kludex/python-multipart/releases)
- [Changelog](https://github.com/Kludex/python-multipart/blob/main/CHANGELOG.md)
- [Commits](Kludex/python-multipart@0.0.9...0.0.27)

---
updated-dependencies:
- dependency-name: python-multipart
  dependency-version: 0.0.27
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/pip/backend/pip-14c377a4fb branch from 9e8b5ab to 3148e13 Compare May 11, 2026 14:20
@github-actions

Copy link
Copy Markdown
Contributor

PR governance metadata gate is not ready for 3148e13066c94c94572a16b42288956321c7b71e:

  • 1 unresolved current review thread(s) remain.\n- 3 required check(s) are not successful on 3148e13.\n- Missing current-head CodeRabbit/coderabbitai evidence for 3148e13.\n

@github-actions

Copy link
Copy Markdown
Contributor

PR governance metadata gate is not ready for 3148e13066c94c94572a16b42288956321c7b71e:

  • 2 required check(s) are not successful on 3148e13.\n- Missing current-head CodeRabbit/coderabbitai evidence for 3148e13.\n

1 similar comment
@github-actions

Copy link
Copy Markdown
Contributor

PR governance metadata gate is not ready for 3148e13066c94c94572a16b42288956321c7b71e:

  • 2 required check(s) are not successful on 3148e13.\n- Missing current-head CodeRabbit/coderabbitai evidence for 3148e13.\n

@github-actions

Copy link
Copy Markdown
Contributor

PR governance metadata gate is not ready for 3148e13066c94c94572a16b42288956321c7b71e:

  • Missing current-head CodeRabbit/coderabbitai evidence for 3148e13.\n

@dependabot @github

dependabot Bot commented on behalf of github May 13, 2026

Copy link
Copy Markdown
Contributor Author

Looks like python-multipart is no longer updatable, so this is no longer needed.

@dependabot dependabot Bot closed this May 13, 2026
@dependabot
dependabot Bot deleted the dependabot/pip/backend/pip-14c377a4fb branch May 13, 2026 04:39
@seonghobae

Copy link
Copy Markdown
Contributor

이 PR은 (보안 잔여 경보 정리)에서 포함·병합되었습니다. 최신 릴리스 기준은 v0.13.0 입니다.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant