Skip to content

[security] Update security (major) - #1449

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/major-security
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/major-security

Conversation

@renovate

@renovate renovate Bot commented Aug 19, 2026 •

Copy link
Copy Markdown

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
cryptography (changelog) ==49.0.0 → ==50.0.0 age confidence
oauthlib (changelog) ==3.2.2 → ==4.0.0 age confidence
pytest (changelog) ==6.2.5 → ==9.0.3 age confidence

cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing

CVE-2026-69247 / GHSA-g6cj-pr64-35w5

More information

Details

Summary

pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the
outcome of decrypting a RecipientInfo's encryptedKey in several
distinguishable ways, one of which disclosed the exact length recovered from the
RSA operation. The same distinction was also observable by timing. An
application that decrypts attacker-supplied EnvelopedData and reflects the
outcome gives the attacker a Bleichenbacher oracle against the
content-encryption key.

Introduced in 44.0.0. Fixed in 50.0.0.

Details

Decryption ran as: RSA PKCS#1 v1.5 decrypt of encryptedKey → build an AES
cipher from the result → AES-CBC decrypt and PKCS#7 unpad. Each stage failed
differently, with no RFC 3218 mitigation:

  1. invalid RSA padding → Decryption failed
  2. valid padding, bad key length → Invalid key size (N) for AES., disclosing N
  3. correct length, wrong key → Invalid padding bytes.
  4. the real key → plaintext

Case 1 is reachable only where the linked library lacks implicit rejection:
OpenSSL 3.0 and 3.1, LibreSSL, and BoringSSL. On OpenSSL 3.2+, used in our wheels,
invalid padding instead returns a synthetic plaintext of
pseudorandom length, so the error channel does not distinguish conforming
ciphertexts.

Exploitation requires a service that auto-decrypts untrusted EnvelopedData
matching the victim certificate and answers adaptively at high volume, such as
an S/MIME gateway or mail filter.

Fix

Per RFC 3218, the content-encryption algorithm is now resolved before the
private key is used, so the expected key length is known in advance. If the RSA
decryption fails or recovers a key of the wrong length, a random key of the
expected length is substituted and decryption continues down an identical path.
All failures now report identically and perform the same work.

Not addressed by this fix

EnvelopedData does not authenticate its content. Tampering with
encryptedContent alone yields a CBC padding oracle that recovers plaintext at
roughly 256 queries per byte, without recovering any key, on every backend. This
is a property of PKCS#7 rather than of this implementation, cannot be fixed in
the library, and is now documented.

Credit

Reported by @​X1AOxiang.

Severity

  • CVSS Score: 8.2 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)

CVE-2026-49265 / GHSA-xpv3-w29h-x7cv

More information

Details

Summary

A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation
of the Authorization Code Grant flow. The code_challenge_method_plain function
uses Python's standard == operator for string comparison instead of a
constant-time comparison function, potentially allowing timing-based attacks.

Affected Component
  • File: oauthlib/oauth2/rfc6749/grant_types/authorization_code.py
  • Functions: code_challenge_method_plain, code_challenge_method_s256
  • Vulnerability Type: CWE-208 (Observable Timing Discrepancy)
Technical Details

Python's == operator uses short-circuit evaluation when comparing strings:

  1. Returns False immediately if lengths differ
  2. Compares characters left-to-right, stopping at first mismatch

This means comparison time varies linearly with the length of the common prefix
between the attacker-supplied verifier and the stored challenge, creating a
measurable timing oracle.

Proof of Concept

Tested locally against oauthlib source (network jitter eliminated to isolate
pure Python execution time):

Input Result Time (10M iterations)
Wrong first char (B + A*49) Fast reject 0.34106s
49 chars correct (A*49 + B) Deep compare 0.37847s
Difference 0.03741s

The ~37ms delta over 10M iterations corresponds to nanosecond-level differences
per call, which are statistically exploitable under controlled conditions.

Attack Scenario
  1. Attacker intercepts authorization_code via Custom URI Scheme Hijacking
  2. PKCE blocks token request — attacker lacks code_verifier
  3. Attacker sends repeated requests to /token endpoint measuring response times
  4. Using timing oracle, attacker recovers code_verifier character by character
  5. Attacker obtains Access Token → Account Takeover

Note: Practical exploitability is limited due to the single-use nature of
authorization codes and real-world network noise. However, the vulnerable
pattern should be corrected as a defense-in-depth measure.

Recommended Fix

Replace == with hmac.compare_digest() for constant-time comparison:

cr: Elvin Latifli

Severity

  • CVSS Score: 6.8 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Oauthlib : Unsafe JSONP callback injection in RevocationEndpoint allows arbitrary JavaScript response generation

CVE-2026-49264 / GHSA-hj66-6f7g-4r5v

More information

Details

Summary

When enable_jsonp=True, oauthlib's RevocationEndpoint reflects the user-supplied callback parameter directly into JavaScript response bodies on both success and error paths without validating that it is a legal JSONP callback name. This allows arbitrary JavaScript response generation instead of a restricted function call, making the documented JSONP revocation feature unsafe for browser-based JSONP consumption when attackers can influence callback.

Details

The issue is in oauthlib/oauth2/rfc6749/endpoints/revocation.py.

When enable_jsonp=True is passed to the RevocationEndpoint constructor, two code paths wrap the response body using the user-supplied request.callback parameter:

##### Error response path (line 72-73):
if self.enable_jsonp and request.callback:
    response_body = '{}({});'.format(request.callback, response_body)

##### Success response path (line 81-82):
if self.enable_jsonp and request.callback:
    response_body = request.callback + '();'

The request.callback value comes from HTTP request parameters, either the query string or POST body, via the Request class in oauthlib/common.py (lines 394-395), which merges query and body parameters into _params. Any value the client sends as callback is used verbatim.

There is no validation of any kind on the callback parameter:

  • No check that it is a valid JavaScript identifier
  • No whitelist of allowed characters
  • No escaping or sanitization

A safe JSONP implementation must validate that the callback is a legal JavaScript function name (e.g., matching ^[a-zA-Z_$][a-zA-Z0-9_$.]*$). Without this, the attacker controls the JavaScript code returned in the response body. This is the standard mitigation used by jQuery, Express.js, Google APIs, and other major JSONP implementations.

How the injection works:

An attacker sends a revocation request with a crafted callback value:

POST /revoke HTTP/1.1
Content-Type: application/x-www-form-urlencoded

token=anything&callback=alert(document.cookie)//

The server responds with:

alert(document.cookie)//({"error": "invalid_client"});

This is syntactically valid JavaScript. alert(document.cookie) executes as a statement, and // comments out the rest of the line. The attacker has full control over the code that appears before the //.

Execution context and attack surface:

JSONP works by having a browser load a remote script via <script src="...">. The loaded script executes in the origin of the including page, not the remote server. This means a <script src="https://auth.example.com/revoke?token=x&callback=payload"> tag on evil.com would execute the payload in evil.com's context, not the auth server's context.

The impact comes from client-side integrations that consume this endpoint as trusted JSONP. If a legitimate OAuth client includes <script src> pointed at the revocation endpoint and an attacker can influence the callback value (e.g., via query parameter injection, a reflected value, or a man-in-the-middle downgrade), the attacker controls what code runs in the client application's origin. The authorization server becomes a source of attacker-controlled JavaScript that client applications trust and execute.

Note: the enable_jsonp parameter defaults to False, so only deployments that explicitly opt in are affected. However, this is a supported, documented library feature, not a debug flag. The client-side library includes prepare_token_revocation_request() with an explicit callback parameter (oauthlib/oauth2/rfc6749/parameters.py, line 174), and the documentation shows JSONP revocation as a use case (oauthlib/oauth2/rfc6749/clients/base.py, lines 351-358). The existing test suite tests JSONP callback reflection with a benign value (test_revocation_endpoint.py, lines 91-101) but does not test for injection. Deployments that enable JSONP typically do so to support older browsers or cross-origin revocation from JavaScript clients, these are exactly the environments most sensitive to script injection.

PoC

Requirements: Python 3.x with oauthlib installed (pip install oauthlib).

from oauthlib.oauth2.rfc6749.endpoints.revocation import RevocationEndpoint
from oauthlib.oauth2.rfc6749.request_validator import RequestValidator

class FailValidator(RequestValidator):
    """Auth fails -> triggers error response path (lines 72-73)."""
    def client_authentication_required(self, request, *a, **kw): return True
    def authenticate_client(self, request, *a, **kw): return False
    def authenticate_client_id(self, client_id, request, *a, **kw): return False

class PassValidator(RequestValidator):
    """Auth passes -> triggers success response path (lines 81-82)."""
    def client_authentication_required(self, request, *a, **kw): return False
    def authenticate_client_id(self, client_id, request, *a, **kw): return True
    def revoke_token(self, token, token_type_hint, request, *a, **kw): pass

payloads = [
    "alert(document.cookie)//",
    "window.location='https://evil.com/'//",
    "eval('malicious')//",
]

##### --- Error path (401) ---
print("Error path (enable_jsonp=True, auth fails):")
ep_fail = RevocationEndpoint(FailValidator(), enable_jsonp=True)
for p in payloads:
    h, body, status = ep_fail.create_revocation_response(
        "https://auth.example.com/revoke", http_method="POST",
        body=f"token=x&callback={p}")
    assert p in body, "Payload not reflected"
    print(f"  [{status}] Content-Type: {h.get('Content-Type','(none)')}  Body: {body}")

##### --- Success path (200) ---
print("\nSuccess path (enable_jsonp=True, revocation succeeds):")
ep_pass = RevocationEndpoint(PassValidator(), enable_jsonp=True)
for p in payloads:
    h, body, status = ep_pass.create_revocation_response(
        "https://auth.example.com/revoke", http_method="POST",
        body=f"token=x&callback={p}")
    assert p in body, "Payload not reflected"
    print(f"  [{status}] Content-Type: {h.get('Content-Type','(none)')}  Body: {body}")

##### --- Control (default: enable_jsonp=False) ---
print("\nControl (enable_jsonp=False, default):")
ep_safe = RevocationEndpoint(FailValidator(), enable_jsonp=False)
_, body, status = ep_safe.create_revocation_response(
    "https://auth.example.com/revoke", http_method="POST",
    body="token=x&callback=alert(1)//")
assert "alert" not in body, "Payload should not be present"
print(f"  [{status}] {body}")
print("\nAll assertions passed.")

Expected output:

Error path (enable_jsonp=True, auth fails):
  [401] Content-Type: application/json  Body: alert(document.cookie)//({"error": "invalid_client"});
  [401] Content-Type: application/json  Body: window.location='https://evil.com/'//({"error": "invalid_client"});
  [401] Content-Type: application/json  Body: eval('malicious')//({"error": "invalid_client"});

Success path (enable_jsonp=True, revocation succeeds):
  [200] Content-Type: (none)  Body: alert(document.cookie)//();
  [200] Content-Type: (none)  Body: window.location='https://evil.com/'//();
  [200] Content-Type: (none)  Body: eval('malicious')//();

Control (enable_jsonp=False, default):
  [401] {"error": "invalid_client"}

All assertions passed.

Both paths reflect the attacker's payload verbatim into the response body.

Impact

Any oauthlib-based authorization server that enables JSONP on the revocation endpoint (enable_jsonp=True) returns attacker-controlled JavaScript in its response body.

Any page or application that loads this endpoint's response as JSONP and exposes attacker influence over the callback parameter will execute attacker-controlled code in its own origin. If a legitimate OAuth client uses JSONP revocation (as documented by oauthlib's client-side API) and an attacker can influence the callback value, the attacker controls what code runs in the client application, including access to the client page's DOM and any data normally accessible to scripts running in that origin.

The JSONP feature is intended for legacy cross-origin browser support. Deployments that need it are typically JavaScript-heavy clients, exactly the environment most sensitive to script injection.

Affected versions: oauthlib >= 0.6.1 through 3.3.1 (current) and master. The unsanitized callback has been present since the revocation endpoint was first introduced in 2013 (commit da775de). The enable_jsonp gate was added in 2014 (commit b85f89a) but no validation of the callback value was ever added.

Suggested fix

Validate the callback parameter against a strict pattern for legal JavaScript identifiers before using it in the response. Reject or ignore values that do not match:

import re

##### Only allow safe JSONP callback names: valid JS identifiers, optionally dot-separated
JSONP_CALLBACK_PATTERN = re.compile(r'^[a-zA-Z_$][a-zA-Z0-9_$]*(\.[a-zA-Z_$][a-zA-Z0-9_$]*)*$')

##### In create_revocation_response(), before using request.callback:
if self.enable_jsonp and request.callback:
    if not JSONP_CALLBACK_PATTERN.match(request.callback):
        request.callback = None

This is the standard mitigation for JSONP callback injection and is the approach used by jQuery, Express.js, and Google APIs. It ensures only syntactically valid function names like package.hello_world are accepted, while blocking payloads like alert(document.cookie)//.

As a secondary hardening measure, when JSONP is enabled, the response should set Content-Type: application/javascript (not application/json or empty) to ensure correct browser handling. Currently the success path returns no Content-Type at all, and the error path returns application/json.

Alternatively, if JSONP is no longer considered a necessary feature, consider deprecating and removing the enable_jsonp option entirely. CORS is now supported by all modern browsers and is the standard mechanism for cross-origin API access.

Severity

  • CVSS Score: 6.1 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


pytest has vulnerable tmpdir handling

CVE-2025-71176 / GHSA-6w46-j5rx-g56g

More information

Details

pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.

Severity

  • CVSS Score: 6.8 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

pyca/cryptography (cryptography)

v50.0.0

Compare Source

oauthlib/oauthlib (oauthlib)

v4.0.0

Compare Source

OAuth2.0 Provider:

  • Breaking: #​951: Removed JSONP support from token revocation endpoint.
    JSONP has been superseded by CORS for cross-origin requests.
    The enable_jsonp parameter has been removed from RevocationEndpoint
    and the callback parameter has been removed from
    prepare_token_revocation_request.
  • Breaking: #​919, #​920: Fixed DeviceCodeGrant.validate_token_request
    trying to authenticate public clients.
    Client authentication validation has been reorganized and is now shared
    across AuthorizationCodeGrant, DeviceCodeGrant, RefreshTokenGrant
    and ResourceOwnerPasswordCredentialsGrant: the grant_type parameter
    is validated before client authentication, so requests missing
    grant_type now return 400 invalid_request instead of
    401 invalid_client.
  • #​963: Improved PKCE code comparison

Misc:

  • #​904: Stop installing examples into site-packages.
  • #​930: Add devcontainer, Add Python3.14, Python3.14t.
  • #​931: Fix ruff checks about unused variables.
  • #​932: Dropped EOL Python 3.8 from CI.
  • #​934: Pre-commit hooks autoupdate.
  • #​938: Fix typos discovered by typos.
  • Add OAuthLib Maintainer agent for automated issue/PR triage and release
    management.

v3.3.1

Compare Source

OAuth2.0 Client:

  • #​906: fix regression of expires_in parsing when float in string.

v3.3.0

Compare Source

OAuth2.0 Provider:

  • OIDC: #​879 Changed in how ui_locales is parsed
  • RFC8628: Added OAuth2.0 Device Authorization Grant support
  • PKCE: #​876, #​893 Fixed create_code_verifier length
  • OIDC: Pre-configured OIDC server to use Refresh Token by default

OAuth2.0 Common:

  • OAuth2Error: Allow 0 to be a valid state

OAuth2.0 Client:

  • #​745: expires_at is forced to be an int
  • #​899: expires_at clarification

General:

  • Removed Python 3.5, 3.6, 3.7 support
  • #​859, #​883: Added Python 3.12, 3.13 Support
  • Added dependency-review GitHub Action
  • Updated various references of license (SPDX identifier..)
  • Added GitHub Action for lint, replaced bandy with ruff, removed isort...
  • Migrated to GitHub Actions from Travis
  • Added Security Policy
pytest-dev/pytest (pytest)

v9.0.3

Compare Source

pytest 9.0.3 (2026-04-07)

Bug fixes

  • #​12444: Fixed pytest.approx which now correctly takes into account ~collections.abc.Mapping keys order to compare them.

  • #​13634: Blocking a conftest.py file using the -p no: option is now explicitly disallowed.

    Previously this resulted in an internal assertion failure during plugin loading.

    Pytest now raises a clear UsageError explaining that conftest files are not plugins and cannot be disabled via -p.

  • #​13734: Fixed crash when a test raises an exceptiongroup with __tracebackhide__ = True.

  • #​14195: Fixed an issue where non-string messages passed to unittest.TestCase.subTest() were not printed.

  • #​14343: Fixed use of insecure temporary directory (CVE-2025-71176).

Improved documentation

  • #​13388: Clarified documentation for -p vs PYTEST_PLUGINS plugin loading and fixed an incorrect -p example.
  • #​13731: Clarified that capture fixtures (e.g. capsys and capfd) take precedence over the -s / --capture=no command-line options in Accessing captured output from a test function <accessing-captured-output>.
  • #​14088: Clarified that the default pytest_collection hook sets session.items before it calls pytest_collection_finish, not after.
  • #​14255: TOML integer log levels must be quoted: Updating reference documentation.

Contributor-facing changes

  • #​12689: The test reports are now published to Codecov from GitHub Actions.
    The test statistics is visible on the web interface.

    -- by aleguy02

v9.0.2

Compare Source

pytest 9.0.2 (2025-12-06)

Bug fixes

  • #​13896: The terminal progress feature added in pytest 9.0.0 has been disabled by default, except on Windows, due to compatibility issues with some terminal emulators.

    You may enable it again by passing -p terminalprogress. We may enable it by default again once compatibility improves in the future.

    Additionally, when the environment variable TERM is dumb, the escape codes are no longer emitted, even if the plugin is enabled.

  • #​13904: Fixed the TOML type of the tmp_path_retention_count settings in the API reference from number to string.

  • #​13946: The private config.inicfg attribute was changed in a breaking manner in pytest 9.0.0.
    Due to its usage in the ecosystem, it is now restored to working order using a compatibility shim.
    It will be deprecated in pytest 9.1 and removed in pytest 10.

  • #​13965: Fixed quadratic-time behavior when handling unittest subtests in Python 3.10.

Improved documentation

  • #​4492: The API Reference now contains cross-reference-able documentation of pytest's command-line flags <command-line-flags>.

v9.0.1

Compare Source

pytest 9.0.1 (2025-11-12)

Bug fixes

  • #​13895: Restore support for skipping tests via raise unittest.SkipTest.
  • #​13896: The terminal progress plugin added in pytest 9.0 is now automatically disabled when iTerm2 is detected, it generated desktop notifications instead of the desired functionality.
  • #​13904: Fixed the TOML type of the verbosity settings in the API reference from number to string.
  • #​13910: Fixed UserWarning: Do not expect file_or_dir on some earlier Python 3.12 and 3.13 point versions.

Packaging updates and notes for downstreams

  • #​13933: The tox configuration has been adjusted to make sure the desired
    version string can be passed into its package_env through
    the SETUPTOOLS_SCM_PRETEND_VERSION_FOR_PYTEST environment
    variable as a part of the release process -- by webknjaz.

Contributor-facing changes

  • #​13891, #​13942: The CI/CD part of the release automation is now capable of
    creating GitHub Releases without having a Git checkout on
    disk -- by bluetech and webknjaz.
  • #​13933: The tox configuration has been adjusted to make sure the desired
    version string can be passed into its package_env through
    the SETUPTOOLS_SCM_PRETEND_VERSION_FOR_PYTEST environment
    variable as a part of the release process -- by webknjaz.

v9.0.0

Compare Source

pytest 9.0.0 (2025-11-05)

New features

  • #​1367: Support for subtests has been added.

    subtests <subtests> are an alternative to parametrization, useful in situations where the parametrization values are not all known at collection time.

    Example:

    def contains_docstring(p: Path) -> bool:
        """Return True if the given Python file contains a top-level docstring."""
        ...
    
    def test_py_files_contain_docstring(subtests: pytest.Subtests) -> None:
        for path in Path.cwd().glob("*.py"):
            with subtests.test(path=str(path)):
                assert contains_docstring(path)

    Each assert failure or error is caught by the context manager and reported individually, giving a clear picture of all files that are missing a docstring.

    In addition, unittest.TestCase.subTest is now also supported.

    This feature was originally implemented as a separate plugin in pytest-subtests, but since then has been merged into the core.

    [!NOTE]
    This feature is experimental and will likely evolve in future releases. By that we mean that we might change how subtests are reported on failure, but the functionality and how to use it are stable.

  • #​13743: Added support for native TOML configuration files.

    While pytest, since version 6, supports configuration in pyproject.toml files under [tool.pytest.ini_options],
    it does so in an "INI compatibility mode", where all configuration values are treated as strings or list of strings.
    Now, pytest supports the native TOML data model.

    In pyproject.toml, the native TOML configuration is under the [tool.pytest] table.

    # pyproject.toml
    [tool.pytest]
    minversion = "9.0"
    addopts = ["-ra", "-q"]
    testpaths = [
        "tests",
        "integration",
    ]

    The [tool.pytest.ini_options] table remains supported, but both tables cannot be used at the same time.

    If you prefer to use a separate configuration file, or don't use pyproject.toml, you can use pytest.toml or .pytest.toml:

    # pytest.toml or .pytest.toml
    [pytest]
    minversion = "9.0"
    addopts = ["-ra", "-q"]
    testpaths = [
        "tests",
        "integration",
    ]

    The documentation now (sometimes) shows configuration snippets in both TOML and INI formats, in a tabbed interface.

    See config file formats for full details.

  • #​13823: Added a "strict mode" enabled by the strict configuration option.

    When set to true, the strict option currently enables

    • strict_config
    • strict_markers
    • strict_parametrization_ids
    • strict_xfail

    The individual strictness options can be explicitly set to override the global strict setting.

    The previously-deprecated --strict command-line flag now enables strict mode.

    If pytest adds new strictness options in the future, they will also be enabled in strict mode.
    Therefore, you should only enable strict mode if you use a pinned/locked version of pytest,
    or if you want to proactively adopt new strictness options as they are added.

    See strict mode for more details.

  • #​13737: Added the strict_parametrization_ids configuration option.

    When set, pytest emits an error if it detects non-unique parameter set IDs,
    rather than automatically making the IDs unique by adding 0, 1, ... to them.
    This can be particularly useful for catching unintended duplicates.

  • #​13072: Added support for displaying test session progress in the terminal tab using the OSC 9;4; ANSI sequence.
    When pytest runs in a supported terminal emulator like ConEmu, Gnome Terminal, Ptyxis, Windows Terminal, Kitty or Ghostty,
    you'll see the progress in the terminal tab or window,
    allowing you to monitor pytest's progress at a glance.

    This feature is automatically enabled when running in a TTY. It is implemented as an internal plugin. If needed, it can be disabled as follows:

    • On a user level, using -p no:terminalprogress on the command line or via an environment variable PYTEST_ADDOPTS='-p no:terminalprogress'.
    • On a project configuration level, using addopts = "-p no:terminalprogress".
  • #​478: Support PEP420 (implicit namespace packages) as --pyargs target when consider_namespace_packages is true in the config.

    Previously, this option only impacted package imports, now it also impacts tests discovery.

  • #​13678: Added a new faulthandler_exit_on_timeout configuration option set to "false" by default to let faulthandler interrupt the pytest process after a timeout in case of deadlock.

    Previously, a faulthandler timeout would only dump the traceback of all threads to stderr, but would not interrupt the pytest process.

    -- by ogrisel.

  • #​13829: Added support for configuration option aliases via the aliases parameter in Parser.addini() <pytest.Parser.addini>.

    Plugins can now register alternative names for configuration options,
    allowing for more flexibility in configuration naming and supporting backward compatibility when renaming options.
    The canonical name always takes precedence if both the canonical name and an alias are specified in the configuration file.

Improvements in existing functionality

  • #​13330: Having pytest configuration spread over more than one file (for example having both a pytest.ini file and pyproject.toml with a [tool.pytest.ini_options] table) will now print a warning to make it clearer to the user that only one of them is actually used.

    -- by sgaist

  • #​13574: The single argument --version no longer loads the entire plugin infrastructure, making it faster and more reliable when displaying only the pytest version.

    Passing --version twice (e.g., pytest --version --version) retains the original behavior, showing both the pytest version and plugin information.

    [!NOTE]
    Since --version is now processed early, it only takes effect when passed directly via the command line. It will not work if set through other mechanisms, such as PYTEST_ADDOPTS or addopts.

  • #​13823: Added strict_xfail as an alias to the xfail_strict option,
    strict_config as an alias to the --strict-config flag,
    and strict_markers as an alias to the --strict-markers flag.
    This makes all strictness options consistently have configuration options with the prefix strict_.

  • #​13700: --junitxml no longer prints the generated xml file summary at the end of the pytest session when --quiet is given.

  • #​13732: Previously, when filtering warnings, pytest would fail if the filter referenced a class that could not be imported. Now, this only outputs a message indicating the problem.

  • #​13859: Clarify the error message for pytest.raises() when a regex match fails.

  • #​13861: Better sentence structure in a test's expected error message. Previously, the error message would be "expected exception must be <expected>, but got <actual>". Now, it is "Expected <expected>, but got <actual>".

Removals and backward incompatible breaking changes

  • #​12083: Fixed a bug where an invocation such as pytest a/ a/b would cause only tests from a/b to run, and not other tests under a/.

    The fix entails a few breaking changes to how such overlapping arguments and duplicates are handled:

    1. pytest a/b a/ or pytest a/ a/b are equivalent to pytest a; if an argument overlaps another arguments, only the prefix remains.
    2. pytest x.py x.py is equivalent to pytest x.py; previously such an invocation was taken as an explicit request to run the tests from the file twice.

    If you rely on these behaviors, consider using --keep-duplicates <duplicate-paths>, which retains its existing behavior (including the bug).

  • #​13719: Support for Python 3.9 is dropped following its end of life.

  • #​13766: Previously, pytest would assume it was running in a CI/CD environment if either of the environment variables $CI or $BUILD_NUMBER was defined;
    now, CI mode is only activated if at least one of those variables is defined and set to a non-empty value.

  • #​13779: PytestRemovedIn9Warning deprecation warnings are now errors by default.

    Following our plan to remove deprecated features with as little disruption as
    possible, all warnings of type PytestRemovedIn9Warning now generate errors
    instead of warning messages by default.

    The affected features will be effectively removed in pytest 9.1, so please consult the
    deprecations section in the docs for directions on how to update existing code.

    In the pytest 9.0.X series, it is possible to change the errors back into warnings as a
    stopgap measure by adding this to your pytest.ini file:

    [pytest]
    filterwarnings =
        ignore::pytest.PytestRemovedIn9Warning

    But this will stop working when pytest 9.1 is released.

    If you have concerns about the removal of a specific feature, please add a
    comment to 13779.

Deprecations (removal in next major release)

  • #​13807: monkeypatch.syspath_prepend() <pytest.MonkeyPatch.syspath_prepend> now issues a deprecation warning when the prepended path contains legacy namespace packages (those using pkg_resources.declare_namespace()).
    Users should migrate to native namespace packages (420).
    See monkeypatch-fixup-namespace-packages for details.

Bug fixes

  • #​13445: Made the type annotations of pytest.skip and friends more spec-complaint to have them work across more type checkers.

  • #​13537: Fixed a bug in which ExceptionGroup with only Skipped exceptions in teardown was not handled correctly and showed as error.

  • #​13598: Fixed possible collection confusion on Windows when short paths and symlinks are involved.

  • #​13716: Fixed a bug where a nonsensical invocation like pytest x.py[a] (a file cannot be parametrized) was silently treated as pytest x.py. This is now a usage error.

  • #​13722: Fixed a misleading assertion failure message when using pytest.approx on mappings with differing lengths.

  • #​13773: Fixed the static fixture closure calculation to properly consider transitive dependencies requested by overridden fixtures.

  • #​13816: Fixed pytest.approx which now returns a clearer error message when comparing mappings with different keys.

  • #​13849: Hidden .pytest.ini files are now picked up as the config file even if empty.
    This was an inconsistency with non-hidden pytest.ini.

  • #​13865: Fixed --show-capture with --tb=line.

  • #​13522: Fixed pytester in subprocess mode ignored all :attr`pytester.plugins <pytest.Pytester.plugins>` except the first.

    Fixed pytester in subprocess mode silently ignored non-str pytester.plugins <pytest.Pytester.plugins>.
    Now it errors instead.
    If you are affected by this, specify the plugin by name, or switch the affected tests to use pytester.runpytest_inprocess <pytest.Pytester.runpytest_inprocess> explicitly instead.

Packaging updates and notes for downstreams

  • #​13791: Minimum requirements on iniconfig and packaging were bumped to 1.0.1 and 22.0.0, respectively.

Contributor-facing changes

  • #​12244: Fixed self-test failures when TERM=dumb.
  • #​12474: Added scheduled GitHub Action Workflow to run Sphinx linkchecks in repo documentation.
  • #​13621: pytest's own testsuite now handles the lsof command hanging (e.g. due to unreachable network filesystems), with the affected selftests being skipped after 10 seconds.
  • #​13638: Fixed deprecated gh pr new command in scripts/prepare-release-pr.py.
    The script now uses gh pr create which is compatible with GitHub CLI v2.0+.
  • #​13695: Flush stdout and stderr in Pytester.run to avoid truncated outputs in test_faulthandler.py::test_timeout on CI -- by ogrisel.
  • #​13771: Skip test_do_not_collect_symlink_siblings on Windows environments without symlink support to avoid false negatives.
  • #​13841: tox>=4 is now required when contributing to pytest.
  • #​13625: Added missing docstrings to pytest_addoption(), pytest_configure(), and cacheshow() functions in cacheprovider.py.

Miscellaneous internal changes

  • #​13830: Configuration overrides (-o/--override-ini) are now processed during startup rather than during config.getini() <pytest.Config.getini>.

v8.4.2

Compare Source

pytest 8.4.2 (2025-09-03)

Bug fixes

  • #​13478: Fixed a crash when using console_output_style{.interpreted-text role="confval"} with times and a module is skipped.

  • #​13530: Fixed a crash when using pytest.approx{.interpreted-text role="func"} and decimal.Decimal{.interpreted-text role="class"} instances with the decimal.FloatOperation{.interpreted-text role="class"} trap set.

  • #​13549: No longer evaluate type annotations in Python 3.14 when inspecting function signatures.

    This prevents crashes during module collection when modules do not explicitly use from __future__ import annotations and import types for annotations within a if TYPE_CHECKING: block.

  • #​13559: Added missing [int]{.title-ref} and [float]{.title-ref} variants to the [Literal]{.title-ref} type annotation of the [type]{.title-ref} parameter in pytest.Parser.addini{.interpreted-text role="meth"}.

  • #​13563: pytest.approx{.interpreted-text role="func"} now only imports numpy if NumPy is already in sys.modules. This fixes unconditional import behavior introduced in [8.4.0]{.title-ref}.

Improved documentation

  • #​13577: Clarify that pytest_generate_tests is discovered in test modules/classes; other hooks must be in conftest.py or plugins.

Contributor-facing changes

  • #​13480: Self-testing: fixed a few test failures when run with -Wdefault or a similar override.
  • #​13547: Self-testing: corrected expected message for test_doctest_unexpected_exception in Python 3.14.
  • #​13684: Make pytest's own testsuite insensitive to the presence of the CI environment variable -- by ogrisel{.interpreted-text role="user"}.

v8.4.1

Compare Source

pytest 8.4.1 (2025-06-17)

Bug fixes

  • #​13461: Corrected _pytest.terminal.TerminalReporter.isatty to support
    being called as a method. Before it was just a boolean which could
    break correct code when using -o log_cli=true).

  • #​13477: Reintroduced pytest.PytestReturnNotNoneWarning{.interpreted-text role="class"} which was removed by accident in pytest [8.4]{.title-ref}.

    This warning is raised when a test functions returns a value other than None, which is often a mistake made by beginners.

    See return-not-none{.interpreted-text role="ref"} for more information.

  • #​13497: Fixed compatibility with Twisted 25+.

Improved documentation

  • #​13492: Fixed outdated warning about faulthandler not working on Windows.

v8.4.0

Compare Source

pytest 8.4.0 (2025-06-02)

Removals and backward incompatible breaking changes

  • #​11372: Async tests will now fail, instead of warning+skipping, if you don't have any suitable plugin installed.

  • #​12346: Tests will now fail, instead of raising a warning, if they return any value other than None.

  • #​12874: We dropped support for Python 3.8 following its end of life (2024-10-07).

  • #​12960: Test functions containing a yield now cause an explicit error. They have not been run since pytest 4.0, and were previously marked as an expected failure and deprecation warning.

    See the docs <yield tests deprecated>{.interpreted-text role="ref"} for more information.

Deprecations (removal in next major release)

  • #​10839: Requesting an asynchronous fixture without a [pytest_fixture_setup]{.title-ref} hook that resolves it will now give a DeprecationWarning. This most commonly happens if a sync test requests an async fixture. This should have no effect on a majority of users with async tests or fixtures using async pytest plugins, but may affect non-standard hook setups or autouse=True. For guidance on how to work around this warning see sync-test-async-fixture{.interpreted-text role="ref"}.

New features

  • #​11538: Added pytest.RaisesGroup{.interpreted-text role="class"} as an equivalent to pytest.raises{.interpreted-text role="func"} for expecting ExceptionGroup{.interpreted-text role="exc"}. Also adds pytest.RaisesExc{.interpreted-text role="class"} which is now the logic behind pytest.raises{.interpreted-text role="func"} and used as parameter to pytest.RaisesGroup{.interpreted-text role="class"}. RaisesGroup includes the ability to specify multiple different expected exceptions, the structure of nested exception groups, and flags for emulating except* <except_star>{.interpreted-text role="ref"}. See assert-matching-exception-groups{.interpreted-text role="ref"} and docstrings for more information.

  • #​12081: Added capteesys{.interpreted-text role="fixture"} to capture AND pass output to next handler set by --capture=.

  • #​12504: pytest.mark.xfail{.interpreted-text role="func"} now accepts pytest.RaisesGroup{.interpreted-text role="class"} for the raises parameter when you expect an exception group. You can also pass a pytest.RaisesExc{.interpreted-text role="class"} if you e.g. want to make use of the check parameter.

  • #​12713: New [--force-short-summary]{.title-ref} option to force condensed summary output regardless of verbosity level.

    This lets users still see condensed summary output of failures for quick reference in log files from job outputs, being especially useful if non-condensed output is very verbose.

  • #​12749: pytest traditionally collects classes/functions in the test module namespace even if they are imported from another file.

    For example:

contents of src/domain.py

class Testament: ...

contents of tests/test_testament.py

from domain import Testament

def test_testament(): ...
```

In this scenario with the default options, pytest will collect the class [Testament]{.title-ref} from [tests/test_testament.py]{.title-ref} because it starts with [Test]{.title-ref}, even though in this case it is a production class being imported in the test module namespace.

This behavior can now be prevented by setting the new `collect_imported_tests`{.interpreted-text role="confval"} configuration option to `false`, which will make pytest collect classes/functions from test files **only** if they are defined in that file.

\-- by `FreerGit`{.interpreted-text role="user"}
  • #​12765: Thresholds to trigger snippet truncation can now be set with truncation_limit_lines{.interpreted-text role="confval"} and truncation_limit_chars{.interpreted-text role="confval"}.

    See truncation-params{.interpreted-text role="ref"} for more information.

  • #​13125: console_output_style{.interpreted-text role="confval"} now supports times to show execution time of each test.

  • #​13192: pytest.raises{.interpreted-text role="func"} will now raise a warning when passing an empty string to match, as this will match against any value. Use match="^$" if you want to check that an exception has no message.

  • #​13192: pytest.raises{.interpreted-text role="func"} will now print a helpful string diff if matching fails and the match paramet

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added dependencies Pull requests that update a dependency file security labels Aug 19, 2026
@renovate
renovate Bot force-pushed the renovate/major-security branch 2 times, most recently from 92523ec to eaf843e Compare August 26, 2026 15:53
@renovate
renovate Bot force-pushed the renovate/major-security branch 8 times, most recently from 0ef5bda to f89717b Compare September 1, 2026 11:06
@renovate
renovate Bot force-pushed the renovate/major-security branch 6 times, most recently from 641a4e1 to b005c84 Compare September 16, 2026 21:20
@renovate
renovate Bot force-pushed the renovate/major-security branch 10 times, most recently from 7acd4d0 to 51336ef Compare September 29, 2026 14:14
@renovate
renovate Bot force-pushed the renovate/major-security branch from 51336ef to 190a0bc Compare September 29, 2026 14:46
@renovate
renovate Bot force-pushed the renovate/major-security branch from 190a0bc to 265ecbe Compare September 30, 2026 11:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants