Repository navigation
[security] Update security (major) - #1449
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/major-security
branch
2 times, most recently
from
August 26, 2026 15:53
92523ec to
eaf843e
Compare
renovate
Bot
force-pushed
the
renovate/major-security
branch
8 times, most recently
from
September 1, 2026 11:06
0ef5bda to
f89717b
Compare
renovate
Bot
force-pushed
the
renovate/major-security
branch
6 times, most recently
from
September 16, 2026 21:20
641a4e1 to
b005c84
Compare
renovate
Bot
force-pushed
the
renovate/major-security
branch
10 times, most recently
from
September 29, 2026 14:14
7acd4d0 to
51336ef
Compare
renovate
Bot
force-pushed
the
renovate/major-security
branch
from
September 29, 2026 14:46
51336ef to
190a0bc
Compare
renovate
Bot
force-pushed
the
renovate/major-security
branch
from
September 30, 2026 11:46
190a0bc to
265ecbe
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
==49.0.0→==50.0.0==3.2.2→==4.0.0==6.2.5→==9.0.3cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
CVE-2026-69247 / GHSA-g6cj-pr64-35w5
More information
Details
Summary
pkcs7_decrypt_der,pkcs7_decrypt_pem, andpkcs7_decrypt_smimereported theoutcome of decrypting a
RecipientInfo'sencryptedKeyin severaldistinguishable ways, one of which disclosed the exact length recovered from the
RSA operation. The same distinction was also observable by timing. An
application that decrypts attacker-supplied
EnvelopedDataand reflects theoutcome gives the attacker a Bleichenbacher oracle against the
content-encryption key.
Introduced in 44.0.0. Fixed in 50.0.0.
Details
Decryption ran as: RSA PKCS#1 v1.5 decrypt of
encryptedKey→ build an AEScipher from the result → AES-CBC decrypt and PKCS#7 unpad. Each stage failed
differently, with no RFC 3218 mitigation:
Decryption failedInvalid key size (N) for AES., disclosingNInvalid padding bytes.Case 1 is reachable only where the linked library lacks implicit rejection:
OpenSSL 3.0 and 3.1, LibreSSL, and BoringSSL. On OpenSSL 3.2+, used in our wheels,
invalid padding instead returns a synthetic plaintext of
pseudorandom length, so the error channel does not distinguish conforming
ciphertexts.
Exploitation requires a service that auto-decrypts untrusted
EnvelopedDatamatching the victim certificate and answers adaptively at high volume, such as
an S/MIME gateway or mail filter.
Fix
Per RFC 3218, the content-encryption algorithm is now resolved before the
private key is used, so the expected key length is known in advance. If the RSA
decryption fails or recovers a key of the wrong length, a random key of the
expected length is substituted and decryption continues down an identical path.
All failures now report identically and perform the same work.
Not addressed by this fix
EnvelopedDatadoes not authenticate its content. Tampering withencryptedContentalone yields a CBC padding oracle that recovers plaintext atroughly 256 queries per byte, without recovering any key, on every backend. This
is a property of PKCS#7 rather than of this implementation, cannot be fixed in
the library, and is now documented.
Credit
Reported by @X1AOxiang.
Severity
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)
CVE-2026-49265 / GHSA-xpv3-w29h-x7cv
More information
Details
Summary
A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation
of the Authorization Code Grant flow. The
code_challenge_method_plainfunctionuses Python's standard
==operator for string comparison instead of aconstant-time comparison function, potentially allowing timing-based attacks.
Affected Component
oauthlib/oauth2/rfc6749/grant_types/authorization_code.pycode_challenge_method_plain,code_challenge_method_s256Technical Details
Python's
==operator uses short-circuit evaluation when comparing strings:Falseimmediately if lengths differThis means comparison time varies linearly with the length of the common prefix
between the attacker-supplied verifier and the stored challenge, creating a
measurable timing oracle.
Proof of Concept
Tested locally against oauthlib source (network jitter eliminated to isolate
pure Python execution time):
B+A*49)A*49 +B)The ~37ms delta over 10M iterations corresponds to nanosecond-level differences
per call, which are statistically exploitable under controlled conditions.
Attack Scenario
authorization_codevia Custom URI Scheme Hijackingcode_verifier/tokenendpoint measuring response timescode_verifiercharacter by characterRecommended Fix
Replace
==withhmac.compare_digest()for constant-time comparison:cr: Elvin Latifli
Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Oauthlib : Unsafe JSONP callback injection in RevocationEndpoint allows arbitrary JavaScript response generation
CVE-2026-49264 / GHSA-hj66-6f7g-4r5v
More information
Details
Summary
When
enable_jsonp=True, oauthlib'sRevocationEndpointreflects the user-suppliedcallbackparameter directly into JavaScript response bodies on both success and error paths without validating that it is a legal JSONP callback name. This allows arbitrary JavaScript response generation instead of a restricted function call, making the documented JSONP revocation feature unsafe for browser-based JSONP consumption when attackers can influencecallback.Details
The issue is in
oauthlib/oauth2/rfc6749/endpoints/revocation.py.When
enable_jsonp=Trueis passed to theRevocationEndpointconstructor, two code paths wrap the response body using the user-suppliedrequest.callbackparameter:The
request.callbackvalue comes from HTTP request parameters, either the query string or POST body, via theRequestclass inoauthlib/common.py(lines 394-395), which merges query and body parameters into_params. Any value the client sends ascallbackis used verbatim.There is no validation of any kind on the callback parameter:
A safe JSONP implementation must validate that the callback is a legal JavaScript function name (e.g., matching
^[a-zA-Z_$][a-zA-Z0-9_$.]*$). Without this, the attacker controls the JavaScript code returned in the response body. This is the standard mitigation used by jQuery, Express.js, Google APIs, and other major JSONP implementations.How the injection works:
An attacker sends a revocation request with a crafted callback value:
The server responds with:
This is syntactically valid JavaScript.
alert(document.cookie)executes as a statement, and//comments out the rest of the line. The attacker has full control over the code that appears before the//.Execution context and attack surface:
JSONP works by having a browser load a remote script via
<script src="...">. The loaded script executes in the origin of the including page, not the remote server. This means a<script src="https://auth.example.com/revoke?token=x&callback=payload">tag onevil.comwould execute the payload inevil.com's context, not the auth server's context.The impact comes from client-side integrations that consume this endpoint as trusted JSONP. If a legitimate OAuth client includes
<script src>pointed at the revocation endpoint and an attacker can influence the callback value (e.g., via query parameter injection, a reflected value, or a man-in-the-middle downgrade), the attacker controls what code runs in the client application's origin. The authorization server becomes a source of attacker-controlled JavaScript that client applications trust and execute.Note: the
enable_jsonpparameter defaults toFalse, so only deployments that explicitly opt in are affected. However, this is a supported, documented library feature, not a debug flag. The client-side library includesprepare_token_revocation_request()with an explicitcallbackparameter (oauthlib/oauth2/rfc6749/parameters.py, line 174), and the documentation shows JSONP revocation as a use case (oauthlib/oauth2/rfc6749/clients/base.py, lines 351-358). The existing test suite tests JSONP callback reflection with a benign value (test_revocation_endpoint.py, lines 91-101) but does not test for injection. Deployments that enable JSONP typically do so to support older browsers or cross-origin revocation from JavaScript clients, these are exactly the environments most sensitive to script injection.PoC
Requirements: Python 3.x with oauthlib installed (
pip install oauthlib).Expected output:
Both paths reflect the attacker's payload verbatim into the response body.
Impact
Any oauthlib-based authorization server that enables JSONP on the revocation endpoint (
enable_jsonp=True) returns attacker-controlled JavaScript in its response body.Any page or application that loads this endpoint's response as JSONP and exposes attacker influence over the
callbackparameter will execute attacker-controlled code in its own origin. If a legitimate OAuth client uses JSONP revocation (as documented by oauthlib's client-side API) and an attacker can influence the callback value, the attacker controls what code runs in the client application, including access to the client page's DOM and any data normally accessible to scripts running in that origin.The JSONP feature is intended for legacy cross-origin browser support. Deployments that need it are typically JavaScript-heavy clients, exactly the environment most sensitive to script injection.
Affected versions: oauthlib >= 0.6.1 through 3.3.1 (current) and master. The unsanitized callback has been present since the revocation endpoint was first introduced in 2013 (commit
da775de). Theenable_jsonpgate was added in 2014 (commitb85f89a) but no validation of the callback value was ever added.Suggested fix
Validate the
callbackparameter against a strict pattern for legal JavaScript identifiers before using it in the response. Reject or ignore values that do not match:This is the standard mitigation for JSONP callback injection and is the approach used by jQuery, Express.js, and Google APIs. It ensures only syntactically valid function names like
package.hello_worldare accepted, while blocking payloads likealert(document.cookie)//.As a secondary hardening measure, when JSONP is enabled, the response should set
Content-Type: application/javascript(notapplication/jsonor empty) to ensure correct browser handling. Currently the success path returns no Content-Type at all, and the error path returnsapplication/json.Alternatively, if JSONP is no longer considered a necessary feature, consider deprecating and removing the
enable_jsonpoption entirely. CORS is now supported by all modern browsers and is the standard mechanism for cross-origin API access.Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
pytest has vulnerable tmpdir handling
CVE-2025-71176 / GHSA-6w46-j5rx-g56g
More information
Details
pytest through 9.0.2 on UNIX relies on directories with the
/tmp/pytest-of-{user}name pattern, which allows local users to cause a denial of service or possibly gain privileges.Severity
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:LReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
pyca/cryptography (cryptography)
v50.0.0Compare Source
oauthlib/oauthlib (oauthlib)
v4.0.0Compare Source
OAuth2.0 Provider:
JSONP has been superseded by CORS for cross-origin requests.
The
enable_jsonpparameter has been removed fromRevocationEndpointand the
callbackparameter has been removed fromprepare_token_revocation_request.DeviceCodeGrant.validate_token_requesttrying to authenticate public clients.
Client authentication validation has been reorganized and is now shared
across
AuthorizationCodeGrant,DeviceCodeGrant,RefreshTokenGrantand
ResourceOwnerPasswordCredentialsGrant: thegrant_typeparameteris validated before client authentication, so requests missing
grant_typenow return400 invalid_requestinstead of401 invalid_client.Misc:
examplesintosite-packages.management.
v3.3.1Compare Source
OAuth2.0 Client:
v3.3.0Compare Source
OAuth2.0 Provider:
create_code_verifierlengthOAuth2.0 Common:
OAuth2.0 Client:
General:
pytest-dev/pytest (pytest)
v9.0.3Compare Source
pytest 9.0.3 (2026-04-07)
Bug fixes
#12444: Fixed
pytest.approxwhich now correctly takes into account~collections.abc.Mappingkeys order to compare them.#13634: Blocking a
conftest.pyfile using the-p no:option is now explicitly disallowed.Previously this resulted in an internal assertion failure during plugin loading.
Pytest now raises a clear
UsageErrorexplaining that conftest files are not plugins and cannot be disabled via-p.#13734: Fixed crash when a test raises an exceptiongroup with
__tracebackhide__ = True.#14195: Fixed an issue where non-string messages passed to unittest.TestCase.subTest() were not printed.
#14343: Fixed use of insecure temporary directory (CVE-2025-71176).
Improved documentation
-pvsPYTEST_PLUGINSplugin loading and fixed an incorrect-pexample.capsysandcapfd) take precedence over the-s/--capture=nocommand-line options inAccessing captured output from a test function <accessing-captured-output>.pytest_collectionhook setssession.itemsbefore it callspytest_collection_finish, not after.Contributor-facing changes
#12689: The test reports are now published to Codecov from GitHub Actions.
The test statistics is visible on the web interface.
-- by
aleguy02v9.0.2Compare Source
pytest 9.0.2 (2025-12-06)
Bug fixes
#13896: The terminal progress feature added in pytest 9.0.0 has been disabled by default, except on Windows, due to compatibility issues with some terminal emulators.
You may enable it again by passing
-p terminalprogress. We may enable it by default again once compatibility improves in the future.Additionally, when the environment variable
TERMisdumb, the escape codes are no longer emitted, even if the plugin is enabled.#13904: Fixed the TOML type of the
tmp_path_retention_countsettings in the API reference from number to string.#13946: The private
config.inicfgattribute was changed in a breaking manner in pytest 9.0.0.Due to its usage in the ecosystem, it is now restored to working order using a compatibility shim.
It will be deprecated in pytest 9.1 and removed in pytest 10.
#13965: Fixed quadratic-time behavior when handling
unittestsubtests in Python 3.10.Improved documentation
pytest's command-line flags <command-line-flags>.v9.0.1Compare Source
pytest 9.0.1 (2025-11-12)
Bug fixes
raise unittest.SkipTest.Packaging updates and notes for downstreams
version string can be passed into its
package_envthroughthe
SETUPTOOLS_SCM_PRETEND_VERSION_FOR_PYTESTenvironmentvariable as a part of the release process -- by
webknjaz.Contributor-facing changes
creating GitHub Releases without having a Git checkout on
disk -- by
bluetechandwebknjaz.version string can be passed into its
package_envthroughthe
SETUPTOOLS_SCM_PRETEND_VERSION_FOR_PYTESTenvironmentvariable as a part of the release process -- by
webknjaz.v9.0.0Compare Source
pytest 9.0.0 (2025-11-05)
New features
#1367: Support for subtests has been added.
subtests <subtests>are an alternative to parametrization, useful in situations where the parametrization values are not all known at collection time.Example:
Each assert failure or error is caught by the context manager and reported individually, giving a clear picture of all files that are missing a docstring.
In addition,
unittest.TestCase.subTestis now also supported.This feature was originally implemented as a separate plugin in pytest-subtests, but since then has been merged into the core.
#13743: Added support for native TOML configuration files.
While pytest, since version 6, supports configuration in
pyproject.tomlfiles under[tool.pytest.ini_options],it does so in an "INI compatibility mode", where all configuration values are treated as strings or list of strings.
Now, pytest supports the native TOML data model.
In
pyproject.toml, the native TOML configuration is under the[tool.pytest]table.The
[tool.pytest.ini_options]table remains supported, but both tables cannot be used at the same time.If you prefer to use a separate configuration file, or don't use
pyproject.toml, you can usepytest.tomlor.pytest.toml:The documentation now (sometimes) shows configuration snippets in both TOML and INI formats, in a tabbed interface.
See
config file formatsfor full details.#13823: Added a "strict mode" enabled by the
strictconfiguration option.When set to
true, thestrictoption currently enablesstrict_configstrict_markersstrict_parametrization_idsstrict_xfailThe individual strictness options can be explicitly set to override the global
strictsetting.The previously-deprecated
--strictcommand-line flag now enables strict mode.If pytest adds new strictness options in the future, they will also be enabled in strict mode.
Therefore, you should only enable strict mode if you use a pinned/locked version of pytest,
or if you want to proactively adopt new strictness options as they are added.
See
strict modefor more details.#13737: Added the
strict_parametrization_idsconfiguration option.When set, pytest emits an error if it detects non-unique parameter set IDs,
rather than automatically making the IDs unique by adding 0, 1, ... to them.
This can be particularly useful for catching unintended duplicates.
#13072: Added support for displaying test session progress in the terminal tab using the OSC 9;4; ANSI sequence.
When pytest runs in a supported terminal emulator like ConEmu, Gnome Terminal, Ptyxis, Windows Terminal, Kitty or Ghostty,
you'll see the progress in the terminal tab or window,
allowing you to monitor pytest's progress at a glance.
This feature is automatically enabled when running in a TTY. It is implemented as an internal plugin. If needed, it can be disabled as follows:
-p no:terminalprogresson the command line or via an environment variablePYTEST_ADDOPTS='-p no:terminalprogress'.addopts = "-p no:terminalprogress".#478: Support PEP420 (implicit namespace packages) as --pyargs target when
consider_namespace_packagesis true in the config.Previously, this option only impacted package imports, now it also impacts tests discovery.
#13678: Added a new
faulthandler_exit_on_timeoutconfiguration option set to "false" by default to let faulthandler interrupt the pytest process after a timeout in case of deadlock.Previously, a faulthandler timeout would only dump the traceback of all threads to stderr, but would not interrupt the pytest process.
-- by
ogrisel.#13829: Added support for configuration option aliases via the
aliasesparameter inParser.addini() <pytest.Parser.addini>.Plugins can now register alternative names for configuration options,
allowing for more flexibility in configuration naming and supporting backward compatibility when renaming options.
The canonical name always takes precedence if both the canonical name and an alias are specified in the configuration file.
Improvements in existing functionality
#13330: Having pytest configuration spread over more than one file (for example having both a
pytest.inifile andpyproject.tomlwith a[tool.pytest.ini_options]table) will now print a warning to make it clearer to the user that only one of them is actually used.-- by
sgaist#13574: The single argument
--versionno longer loads the entire plugin infrastructure, making it faster and more reliable when displaying only the pytest version.Passing
--versiontwice (e.g.,pytest --version --version) retains the original behavior, showing both the pytest version and plugin information.#13823: Added
strict_xfailas an alias to thexfail_strictoption,strict_configas an alias to the--strict-configflag,and
strict_markersas an alias to the--strict-markersflag.This makes all strictness options consistently have configuration options with the prefix
strict_.#13700: --junitxml no longer prints the generated xml file summary at the end of the pytest session when --quiet is given.
#13732: Previously, when filtering warnings, pytest would fail if the filter referenced a class that could not be imported. Now, this only outputs a message indicating the problem.
#13859: Clarify the error message for pytest.raises() when a regex match fails.
#13861: Better sentence structure in a test's expected error message. Previously, the error message would be "expected exception must be <expected>, but got <actual>". Now, it is "Expected <expected>, but got <actual>".
Removals and backward incompatible breaking changes
#12083: Fixed a bug where an invocation such as pytest a/ a/b would cause only tests from a/b to run, and not other tests under a/.
The fix entails a few breaking changes to how such overlapping arguments and duplicates are handled:
If you rely on these behaviors, consider using
--keep-duplicates <duplicate-paths>, which retains its existing behavior (including the bug).#13719: Support for Python 3.9 is dropped following its end of life.
#13766: Previously, pytest would assume it was running in a CI/CD environment if either of the environment variables $CI or $BUILD_NUMBER was defined;
now, CI mode is only activated if at least one of those variables is defined and set to a non-empty value.
#13779: PytestRemovedIn9Warning deprecation warnings are now errors by default.
Following our plan to remove deprecated features with as little disruption as
possible, all warnings of type
PytestRemovedIn9Warningnow generate errorsinstead of warning messages by default.
The affected features will be effectively removed in pytest 9.1, so please consult the
deprecationssection in the docs for directions on how to update existing code.In the pytest
9.0.Xseries, it is possible to change the errors back into warnings as astopgap measure by adding this to your
pytest.inifile:But this will stop working when pytest
9.1is released.If you have concerns about the removal of a specific feature, please add a
comment to
13779.Deprecations (removal in next major release)
monkeypatch.syspath_prepend() <pytest.MonkeyPatch.syspath_prepend>now issues a deprecation warning when the prepended path contains legacy namespace packages (those usingpkg_resources.declare_namespace()).Users should migrate to native namespace packages (
420).See
monkeypatch-fixup-namespace-packagesfor details.Bug fixes
#13445: Made the type annotations of
pytest.skipand friends more spec-complaint to have them work across more type checkers.#13537: Fixed a bug in which
ExceptionGroupwith onlySkippedexceptions in teardown was not handled correctly and showed as error.#13598: Fixed possible collection confusion on Windows when short paths and symlinks are involved.
#13716: Fixed a bug where a nonsensical invocation like
pytest x.py[a](a file cannot be parametrized) was silently treated aspytest x.py. This is now a usage error.#13722: Fixed a misleading assertion failure message when using
pytest.approxon mappings with differing lengths.#13773: Fixed the static fixture closure calculation to properly consider transitive dependencies requested by overridden fixtures.
#13816: Fixed
pytest.approxwhich now returns a clearer error message when comparing mappings with different keys.#13849: Hidden
.pytest.inifiles are now picked up as the config file even if empty.This was an inconsistency with non-hidden
pytest.ini.#13865: Fixed --show-capture with --tb=line.
#13522: Fixed
pytesterin subprocess mode ignored all :attr`pytester.plugins <pytest.Pytester.plugins>` except the first.Fixed
pytesterin subprocess mode silently ignored non-strpytester.plugins <pytest.Pytester.plugins>.Now it errors instead.
If you are affected by this, specify the plugin by name, or switch the affected tests to use
pytester.runpytest_inprocess <pytest.Pytester.runpytest_inprocess>explicitly instead.Packaging updates and notes for downstreams
iniconfigandpackagingwere bumped to1.0.1and22.0.0, respectively.Contributor-facing changes
lsofcommand hanging (e.g. due to unreachable network filesystems), with the affected selftests being skipped after 10 seconds.gh pr newcommand inscripts/prepare-release-pr.py.The script now uses
gh pr createwhich is compatible with GitHub CLI v2.0+.ogrisel.tox>=4is now required when contributing to pytest.pytest_addoption(),pytest_configure(), andcacheshow()functions incacheprovider.py.Miscellaneous internal changes
-o/--override-ini) are now processed during startup rather than duringconfig.getini() <pytest.Config.getini>.v8.4.2Compare Source
pytest 8.4.2 (2025-09-03)
Bug fixes
#13478: Fixed a crash when using
console_output_style{.interpreted-text role="confval"} withtimesand a module is skipped.#13530: Fixed a crash when using
pytest.approx{.interpreted-text role="func"} anddecimal.Decimal{.interpreted-text role="class"} instances with thedecimal.FloatOperation{.interpreted-text role="class"} trap set.#13549: No longer evaluate type annotations in Python
3.14when inspecting function signatures.This prevents crashes during module collection when modules do not explicitly use
from __future__ import annotationsand import types for annotations within aif TYPE_CHECKING:block.#13559: Added missing [int]{.title-ref} and [float]{.title-ref} variants to the [Literal]{.title-ref} type annotation of the [type]{.title-ref} parameter in
pytest.Parser.addini{.interpreted-text role="meth"}.#13563:
pytest.approx{.interpreted-text role="func"} now only importsnumpyif NumPy is already insys.modules. This fixes unconditional import behavior introduced in [8.4.0]{.title-ref}.Improved documentation
pytest_generate_testsis discovered in test modules/classes; other hooks must be inconftest.pyor plugins.Contributor-facing changes
-Wdefaultor a similar override.test_doctest_unexpected_exceptionin Python3.14.CIenvironment variable -- byogrisel{.interpreted-text role="user"}.v8.4.1Compare Source
pytest 8.4.1 (2025-06-17)
Bug fixes
#13461: Corrected
_pytest.terminal.TerminalReporter.isattyto supportbeing called as a method. Before it was just a boolean which could
break correct code when using
-o log_cli=true).#13477: Reintroduced
pytest.PytestReturnNotNoneWarning{.interpreted-text role="class"} which was removed by accident in pytest [8.4]{.title-ref}.This warning is raised when a test functions returns a value other than
None, which is often a mistake made by beginners.See
return-not-none{.interpreted-text role="ref"} for more information.#13497: Fixed compatibility with
Twisted 25+.Improved documentation
faulthandlernot working on Windows.v8.4.0Compare Source
pytest 8.4.0 (2025-06-02)
Removals and backward incompatible breaking changes
#11372: Async tests will now fail, instead of warning+skipping, if you don't have any suitable plugin installed.
#12346: Tests will now fail, instead of raising a warning, if they return any value other than None.
#12874: We dropped support for Python 3.8 following its end of life (2024-10-07).
#12960: Test functions containing a yield now cause an explicit error. They have not been run since pytest 4.0, and were previously marked as an expected failure and deprecation warning.
See
the docs <yield tests deprecated>{.interpreted-text role="ref"} for more information.Deprecations (removal in next major release)
autouse=True. For guidance on how to work around this warning seesync-test-async-fixture{.interpreted-text role="ref"}.New features
#11538: Added
pytest.RaisesGroup{.interpreted-text role="class"} as an equivalent topytest.raises{.interpreted-text role="func"} for expectingExceptionGroup{.interpreted-text role="exc"}. Also addspytest.RaisesExc{.interpreted-text role="class"} which is now the logic behindpytest.raises{.interpreted-text role="func"} and used as parameter topytest.RaisesGroup{.interpreted-text role="class"}.RaisesGroupincludes the ability to specify multiple different expected exceptions, the structure of nested exception groups, and flags for emulatingexcept* <except_star>{.interpreted-text role="ref"}. Seeassert-matching-exception-groups{.interpreted-text role="ref"} and docstrings for more information.#12081: Added
capteesys{.interpreted-text role="fixture"} to capture AND pass output to next handler set by--capture=.#12504:
pytest.mark.xfail{.interpreted-text role="func"} now acceptspytest.RaisesGroup{.interpreted-text role="class"} for theraisesparameter when you expect an exception group. You can also pass apytest.RaisesExc{.interpreted-text role="class"} if you e.g. want to make use of thecheckparameter.#12713: New [--force-short-summary]{.title-ref} option to force condensed summary output regardless of verbosity level.
This lets users still see condensed summary output of failures for quick reference in log files from job outputs, being especially useful if non-condensed output is very verbose.
#12749: pytest traditionally collects classes/functions in the test module namespace even if they are imported from another file.
For example:
contents of src/domain.py
contents of tests/test_testament.py
#12765: Thresholds to trigger snippet truncation can now be set with
truncation_limit_lines{.interpreted-text role="confval"} andtruncation_limit_chars{.interpreted-text role="confval"}.See
truncation-params{.interpreted-text role="ref"} for more information.#13125:
console_output_style{.interpreted-text role="confval"} now supportstimesto show execution time of each test.#13192:
pytest.raises{.interpreted-text role="func"} will now raise a warning when passing an empty string tomatch, as this will match against any value. Usematch="^$"if you want to check that an exception has no message.#13192:
pytest.raises{.interpreted-text role="func"} will now print a helpful string diff if matching fails and the match parametConfiguration
📅 Schedule: (in timezone America/New_York)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.