aio-libs
aiohttp
Blog
Docs
Changelog
Blog
Docs
Changelog
Overview
Optimizations
Branches
Benchmarks
Runs
Performance History
Latest Results
Add cookie jar and Set-Cookie parsing benchmarks
cookie_benchmarks
14 minutes ago
Load saved non-string attributes and never send a rejected stored cookie
cookie_limits
28 minutes ago
Keep cookie flags with oversized values and round-trip saved names
cookie_limits
1 hour ago
Bump virtualenv from 21.13.0 to 21.14.1 Bumps [virtualenv](https://github.com/pypa/virtualenv) from 21.13.0 to 21.14.1. - [Release notes](https://github.com/pypa/virtualenv/releases) - [Changelog](https://github.com/pypa/virtualenv/blob/main/docs/changelog.rst) - [Commits](https://github.com/pypa/virtualenv/compare/21.13.0...21.14.1) --- updated-dependencies: - dependency-name: virtualenv dependency-version: 21.14.1 dependency-type: indirect update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot/pip/3.15/virtualenv-21.14.1
2 hours ago
Reject HTTP versions other than 1.0/1.1 in both parsers VERSRE accepted any single-digit major.minor (HTTP/0.9, HTTP/2.0, HTTP/9.9, ...) and the C parser's http_version() fell through to an unchecked HttpVersion(major, minor) for anything outside 1.x. Both feed an HttpVersion object straight into keep-alive and Host-header mandation logic. Tighten VERSRE to HTTP/(1).([01]) and add the same major == 1 / minor in (0, 1) guard to http_version(), raising BadStatusLine otherwise. Closes THREAT_MODEL.md section 5.1 threat 1.5.
choudhryfrompak:harden-http-version-regex
3 hours ago
Bump virtualenv from 21.13.0 to 21.14.1 Bumps [virtualenv](https://github.com/pypa/virtualenv) from 21.13.0 to 21.14.1. - [Release notes](https://github.com/pypa/virtualenv/releases) - [Changelog](https://github.com/pypa/virtualenv/blob/main/docs/changelog.rst) - [Commits](https://github.com/pypa/virtualenv/compare/21.13.0...21.14.1) --- updated-dependencies: - dependency-name: virtualenv dependency-version: 21.14.1 dependency-type: indirect update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot/pip/3.15/virtualenv-21.14.1
3 hours ago
Reject HTTP versions other than 1.0/1.1 in both parsers VERSRE accepted any single-digit major.minor (HTTP/0.9, HTTP/2.0, HTTP/9.9, ...) and the C parser's http_version() fell through to an unchecked HttpVersion(major, minor) for anything outside 1.x. Both feed an HttpVersion object straight into keep-alive and Host-header mandation logic. Tighten VERSRE to HTTP/(1).([01]) and add the same major == 1 / minor in (0, 1) guard to http_version(), raising BadStatusLine otherwise. Closes THREAT_MODEL.md section 5.1 threat 1.5.
choudhryfrompak:harden-http-version-regex
3 hours ago
Bump filelock from 4.0.5 to 4.0.7 Bumps [filelock](https://github.com/tox-dev/py-filelock) from 4.0.5 to 4.0.7. - [Release notes](https://github.com/tox-dev/py-filelock/releases) - [Changelog](https://github.com/tox-dev/filelock/blob/main/docs/changelog.rst) - [Commits](https://github.com/tox-dev/py-filelock/compare/4.0.5...4.0.7) --- updated-dependencies: - dependency-name: filelock dependency-version: 4.0.7 dependency-type: indirect update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot/pip/3.15/filelock-4.0.7
3 hours ago
Latest Branches
CodSpeed Performance Gauge
0%
Add cookie jar and Set-Cookie parsing benchmarks
#13931
25 minutes ago
85930b0
cookie_benchmarks
CodSpeed Performance Gauge
0%
Add limits for client cookie handling
#13930
40 minutes ago
82c1834
cookie_limits
CodSpeed Performance Gauge
0%
Bump virtualenv from 21.13.0 to 21.14.1
#13927
3 hours ago
bf7bbc1
dependabot/pip/3.15/virtualenv-21.14.1
© 2026 CodSpeed Technology
Home
Terms
Privacy
Docs