Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
106 commits
Select commit Hold shift + click to select a range
68c2a61
⬆ Bump pydantic from 2.12.5 to 2.13.0 (#1687)
dependabot[bot] Apr 14, 2026
f90b3bd
📝 Update release notes
github-actions[bot] Apr 14, 2026
cfe4f42
⬆ Bump rich from 14.3.3 to 15.0.0 (#1688)
dependabot[bot] Apr 14, 2026
70ead14
📝 Update release notes
github-actions[bot] Apr 14, 2026
20646b7
⬆ Bump pygithub from 2.9.0 to 2.9.1 (#1692)
dependabot[bot] Apr 14, 2026
00a02e1
📝 Update release notes
github-actions[bot] Apr 14, 2026
d7e2d89
⬆ Bump prek from 0.3.8 to 0.3.9 (#1691)
dependabot[bot] Apr 14, 2026
0385c88
📝 Update release notes
github-actions[bot] Apr 14, 2026
37c4510
⬆ Bump ty from 0.0.29 to 0.0.30 (#1693)
dependabot[bot] Apr 15, 2026
8d97df3
📝 Update release notes
github-actions[bot] Apr 15, 2026
72d6935
🔒 Pin GitHub actions by commit SHA (#1666)
YuriiMotov Apr 16, 2026
2cc723f
📝 Update release notes
github-actions[bot] Apr 16, 2026
ea6e144
⬆ Bump pydantic from 2.13.0 to 2.13.1 (#1697)
dependabot[bot] Apr 17, 2026
cd4c051
📝 Update release notes
github-actions[bot] Apr 17, 2026
a226003
⬆ Bump ty from 0.0.30 to 0.0.31 (#1696)
dependabot[bot] Apr 17, 2026
5e4975b
📝 Update release notes
github-actions[bot] Apr 17, 2026
d2f72b4
⬆ Bump astral-sh/setup-uv from 7.6.0 to 8.1.0 (#1699)
dependabot[bot] Apr 17, 2026
f436ca1
⬆ Bump ruff from 0.15.10 to 0.15.11 (#1704)
dependabot[bot] Apr 17, 2026
e7d22d3
⬆ Bump cloudflare/wrangler-action from 3.14.1 to 3.15.0 (#1702)
dependabot[bot] Apr 17, 2026
4179e47
📝 Update release notes
github-actions[bot] Apr 17, 2026
217cfe8
📝 Update release notes
github-actions[bot] Apr 17, 2026
42fa75c
📝 Update release notes
github-actions[bot] Apr 17, 2026
6121151
⬆ Bump actions/upload-artifact from 7.0.0 to 7.0.1 (#1701)
dependabot[bot] Apr 17, 2026
2c8a54c
⬆ Bump pydantic from 2.13.1 to 2.13.2 (#1703)
dependabot[bot] Apr 17, 2026
496bb7d
📝 Update release notes
github-actions[bot] Apr 17, 2026
17e291c
📝 Update release notes
github-actions[bot] Apr 17, 2026
5bc1ee1
⬆ Bump actions/cache from 5.0.4 to 5.0.5 (#1700)
dependabot[bot] Apr 17, 2026
6681748
📝 Update release notes
github-actions[bot] Apr 17, 2026
407e125
⬆ Bump pymdown-extensions from 10.20 to 10.21.2 (#1710)
YuriiMotov Apr 21, 2026
59a0f5f
📝 Update release notes
github-actions[bot] Apr 21, 2026
c0b4466
⬆ Bump pygments from 2.19.2 to 2.20.0 (#1667)
dependabot[bot] Apr 21, 2026
04fb72f
📝 Update release notes
github-actions[bot] Apr 21, 2026
9ba0f23
⬆ Bump pydantic from 2.13.2 to 2.13.3 (#1712)
dependabot[bot] Apr 21, 2026
31e614b
⬆ Bump ty from 0.0.31 to 0.0.32 (#1711)
dependabot[bot] Apr 21, 2026
5b1a58e
📝 Update release notes
github-actions[bot] Apr 21, 2026
c93d1c4
📝 Update release notes
github-actions[bot] Apr 21, 2026
22a86d3
⬆ Bump pydantic-settings from 2.13.1 to 2.14.0 (#1713)
dependabot[bot] Apr 21, 2026
9ce8e30
📝 Update release notes
github-actions[bot] Apr 21, 2026
8572894
⬆ Bump prek from 0.3.9 to 0.3.10 (#1716)
dependabot[bot] Apr 22, 2026
6f15177
📝 Update release notes
github-actions[bot] Apr 22, 2026
5382d24
⬆ Bump mypy from 1.20.1 to 1.20.2 (#1715)
dependabot[bot] Apr 22, 2026
f0a6ee8
📝 Update release notes
github-actions[bot] Apr 22, 2026
31b468b
🐛 Ensure that `typer.launch` forwards correctly when launching a file…
svlandeg Apr 22, 2026
98f27ca
📝 Update release notes
github-actions[bot] Apr 22, 2026
c9554ec
🔖 Release version 0.24.2
tiangolo Apr 22, 2026
dfb21ad
🚸 Don't truncate code lines in traceback when formatted with Rich (#1…
YuriiMotov Apr 26, 2026
5e1fcfb
📝 Update release notes
github-actions[bot] Apr 26, 2026
959845e
🔖 Release version 0.25.0
tiangolo Apr 26, 2026
5a5206c
⬆ Bump prek from 0.3.10 to 0.3.11 (#1723)
dependabot[bot] Apr 28, 2026
db4ade6
📝 Update release notes
github-actions[bot] Apr 28, 2026
0f3ead0
⬆ Bump ruff from 0.15.11 to 0.15.12 (#1722)
dependabot[bot] Apr 28, 2026
ba6cc2c
📝 Update release notes
github-actions[bot] Apr 28, 2026
a437469
🔧 Add Typer Library Skill for Agents (#1620)
svlandeg Apr 30, 2026
13846cc
📝 Update release notes
github-actions[bot] Apr 30, 2026
cfcc2ef
🔖 Release version 0.25.1
tiangolo Apr 30, 2026
3f7fb59
⬆ Bump ty from 0.0.32 to 0.0.33 (#1724)
dependabot[bot] May 4, 2026
da88cb5
📝 Update release notes
github-actions[bot] May 4, 2026
a8a1d6c
⬆ Bump ty from 0.0.33 to 0.0.34 (#1729)
dependabot[bot] May 4, 2026
b21f9b4
📝 Update release notes
github-actions[bot] May 4, 2026
612a635
👷 Add pre-commit for typos (#1730)
tiangolo May 5, 2026
250bd77
📝 Update release notes
github-actions[bot] May 5, 2026
fbede2c
⬆ Bump mypy from 1.20.2 to 2.0.0 (#1737)
dependabot[bot] May 10, 2026
fc8dc1d
📝 Update release notes
github-actions[bot] May 10, 2026
5efc373
⬆ Bump prek from 0.3.11 to 0.3.13 (#1735)
dependabot[bot] May 10, 2026
fc353d8
📝 Update release notes
github-actions[bot] May 10, 2026
b69a4e1
⬆ Bump pydantic from 2.13.3 to 2.13.4 (#1736)
dependabot[bot] May 10, 2026
890be06
📝 Update release notes
github-actions[bot] May 10, 2026
552c3cf
⬆ Bump actions/labeler from 6.0.1 to 6.1.0 (#1734)
dependabot[bot] May 10, 2026
ae0301f
📝 Update release notes
github-actions[bot] May 10, 2026
f80c669
⬆ Bump actions/add-to-project from 1.0.2 to 2.0.0 (#1731)
dependabot[bot] May 10, 2026
a020575
📝 Update release notes
github-actions[bot] May 10, 2026
2da8d32
⬆ Bump ty from 0.0.34 to 0.0.35 (#1740)
dependabot[bot] May 12, 2026
b1325b8
📝 Update release notes
github-actions[bot] May 12, 2026
efe1948
⬆ Bump pydantic-settings from 2.14.0 to 2.14.1 (#1739)
dependabot[bot] May 13, 2026
adf2ffb
📝 Update release notes
github-actions[bot] May 13, 2026
38ec705
⬆ Bump mypy from 2.0.0 to 2.1.0 (#1742)
dependabot[bot] May 13, 2026
6209ca0
📝 Update release notes
github-actions[bot] May 13, 2026
54889c9
🔒️ Only allow team members to modify dependencies (#1744)
svlandeg May 14, 2026
f234b1c
📝 Update release notes
github-actions[bot] May 14, 2026
86a96f8
🔒️ Add zizmor and fix audit findings (#1705)
YuriiMotov May 17, 2026
0913db6
📝 Update release notes
github-actions[bot] May 17, 2026
a0c42ab
📌 Pin max version of Click to `>= 8.2.1, < 8.4` temporarily to preven…
tiangolo May 17, 2026
140cf0a
📝 Update release notes
github-actions[bot] May 17, 2026
bdb1ba4
🔧 Remove unnecessary Ruff rule (#1752)
tiangolo May 17, 2026
9c76b63
📝 Update release notes
github-actions[bot] May 17, 2026
d14dc78
⬆ Bump urllib3 from 2.6.3 to 2.7.0 (#1741)
dependabot[bot] May 18, 2026
cc253bb
📝 Update release notes
github-actions[bot] May 18, 2026
f655ef2
⬆️ Migrate to Zensical (#1470)
tiangolo May 18, 2026
c249bea
📝 Update release notes
github-actions[bot] May 18, 2026
56160da
🔧 Fix GitHub link in docs (#1754)
tiangolo May 18, 2026
288865b
📝 Update release notes
github-actions[bot] May 18, 2026
d41c7c5
⬆ Bump actions/github-script from 7.1.0 to 9.0.0 (#1746)
dependabot[bot] May 18, 2026
8c47e39
📝 Update release notes
github-actions[bot] May 18, 2026
e3f56c0
📝 Update and simplify usage of admonitions (#1755)
tiangolo May 18, 2026
d10dff0
📝 Update release notes
github-actions[bot] May 18, 2026
3780a29
📝 Update link syntax to minimal Markdown (#1623)
tiangolo May 18, 2026
4e39eb7
📝 Update release notes
github-actions[bot] May 18, 2026
b712d8e
✅ Extend completion unit tests for zsh, powershell and pwsh (#1767)
ADiTyaRaj8969 May 19, 2026
f81e714
📝 Update release notes
github-actions[bot] May 19, 2026
d20905f
✅ Add Fish shell completion tests for colon options (#1475)
Mohamed-Elwasila May 19, 2026
ad56a62
📝 Update release notes
github-actions[bot] May 19, 2026
c148cfa
📝 Fix categorization of PR 1475 in release notes (#1769)
svlandeg May 19, 2026
1efe72c
📝 Update release notes
github-actions[bot] May 19, 2026
8b5e25a
Merge branch 'master' into drop-click
svlandeg May 20, 2026
d410917
fix
svlandeg May 20, 2026
fcc2a2d
fix uv lock
svlandeg May 20, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 13 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,12 +5,25 @@ updates:
directory: "/"
schedule:
interval: "daily"
cooldown:
default-days: 7
commit-message:
prefix: ⬆
# Python
- package-ecosystem: "uv"
directory: "/"
schedule:
interval: "daily"
cooldown:
default-days: 7
commit-message:
prefix: ⬆
# pre-commit
- package-ecosystem: "pre-commit"
directory: "/"
schedule:
interval: "daily"
cooldown:
default-days: 7
commit-message:
prefix: ⬆
9 changes: 6 additions & 3 deletions .github/workflows/add-to-project.yml
Original file line number Diff line number Diff line change
@@ -1,18 +1,21 @@
name: Add to Project

on:
pull_request_target:
pull_request_target: # zizmor: ignore[dangerous-triggers]
issues:
types:
- opened
- reopened

permissions: {}

jobs:
add-to-project:
name: Add to project
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- uses: actions/add-to-project@v1.0.2
- uses: actions/add-to-project@5afcf98fcd03f1c2f92c3c83f58ae24323cc57fd # v2.0.0
with:
project-url: https://github.com/orgs/fastapi/projects/2
github-token: ${{ secrets.PROJECTS_TOKEN }}
github-token: ${{ secrets.PROJECTS_TOKEN }} # zizmor: ignore[secrets-outside-env]
28 changes: 20 additions & 8 deletions .github/workflows/build-docs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,19 +8,24 @@ on:
- opened
- synchronize

permissions: {}

jobs:
changes:
runs-on: ubuntu-latest
# Required permissions
permissions:
pull-requests: read
timeout-minutes: 5
# Set job outputs to values from filter step
outputs:
docs: ${{ steps.filter.outputs.docs }}
steps:
- uses: actions/checkout@v6
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
# For pull requests it's not necessary to checkout the code but for the main branch it is
- uses: dorny/paths-filter@v4
with:
persist-credentials: false
- uses: dorny/paths-filter@fbd0ab8f3e69293af611ebaee6363fc25e6d187d # v4.0.1
id: filter
with:
filters: |
Expand All @@ -41,32 +46,38 @@ jobs:
- changes
if: ${{ needs.changes.outputs.docs == 'true' }}
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- name: Dump GitHub context
env:
GITHUB_CONTEXT: ${{ toJson(github) }}
run: echo "$GITHUB_CONTEXT"
- uses: actions/checkout@v6
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
persist-credentials: false
- name: Set up Python
uses: actions/setup-python@v6
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
with:
python-version-file: ".python-version"
- name: Setup uv
uses: astral-sh/setup-uv@v7
uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0
with:
# Before upgrading uv version, make sure astral-sh/setup-uv knows its checksum.
# See: https://github.com/astral-sh/setup-uv/issues/851#issuecomment-4282017837
version: "0.11.4"
enable-cache: true
cache-dependency-glob: |
pyproject.toml
uv.lock
- name: Install docs extras
run: uv sync --locked --no-dev --group docs
- uses: actions/cache@v5
- uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
with:
key: mkdocs-cards-${{ github.ref }}-v1
path: .cache
- name: Build Docs
run: uv run ./scripts/docs.py build
- uses: actions/upload-artifact@v7
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: docs-site
path: ./site/**
Expand All @@ -78,9 +89,10 @@ jobs:
needs:
- build-docs
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- name: Decide whether the needed jobs succeeded or failed
uses: re-actors/alls-green@release/v1
uses: re-actors/alls-green@05ac9388f0aebcb5727afa17fcccfecd6f8ec5fe # v1.2.2
with:
jobs: ${{ toJSON(needs) }}
allowed-skips: build-docs
7 changes: 5 additions & 2 deletions .github/workflows/conflict.yml
Original file line number Diff line number Diff line change
@@ -1,18 +1,21 @@
name: "Conflict detector"
on:
push:
pull_request_target:
pull_request_target: # zizmor: ignore[dangerous-triggers]
types: [synchronize]

permissions: {}

jobs:
main:
permissions:
contents: read
pull-requests: write
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- name: Check if PRs have merge conflicts
uses: eps1lon/actions-label-merge-conflict@v3
uses: eps1lon/actions-label-merge-conflict@1df065ebe6e3310545d4f4c4e862e43bdca146f0 # v3.0.3
with:
dirtyLabel: "conflicts"
repoToken: "${{ secrets.GITHUB_TOKEN }}"
Expand Down
38 changes: 21 additions & 17 deletions .github/workflows/deploy-docs.yml
Original file line number Diff line number Diff line change
@@ -1,37 +1,41 @@
name: Deploy Docs
on:
workflow_run:
workflow_run: # zizmor: ignore[dangerous-triggers]
workflows:
- Build Docs
types:
- completed

permissions:
deployments: write
issues: write
pull-requests: write
statuses: write
permissions: {}

jobs:
deploy-docs:
runs-on: ubuntu-latest
permissions:
deployments: write
issues: write
pull-requests: write
statuses: write
timeout-minutes: 5
steps:
- name: Dump GitHub context
env:
GITHUB_CONTEXT: ${{ toJson(github) }}
run: echo "$GITHUB_CONTEXT"
- uses: actions/checkout@v6
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
persist-credentials: false
- name: Set up Python
uses: actions/setup-python@v6
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
with:
python-version-file: ".python-version"
- name: Setup uv
uses: astral-sh/setup-uv@v7
uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0
with:
enable-cache: true
cache-dependency-glob: |
pyproject.toml
uv.lock
# Before upgrading uv version, make sure astral-sh/setup-uv knows its checksum.
# See: https://github.com/astral-sh/setup-uv/issues/851#issuecomment-4282017837
version: "0.11.4"
enable-cache: false
- name: Install GitHub Actions dependencies
run: uv sync --locked --no-dev --group github-actions
- name: Deploy Docs Status Pending
Expand All @@ -45,7 +49,7 @@ jobs:
run: |
rm -rf ./site
mkdir ./site
- uses: actions/download-artifact@v8
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
path: ./site/
pattern: docs-site
Expand All @@ -59,10 +63,10 @@ jobs:
env:
PROJECT_NAME: typertiangolo
BRANCH: ${{ ( github.event.workflow_run.head_repository.full_name == github.repository && github.event.workflow_run.head_branch == 'master' && 'main' ) || ( github.event.workflow_run.head_sha ) }}
uses: cloudflare/wrangler-action@v3
uses: cloudflare/wrangler-action@9acf94ace14e7dc412b076f2c5c20b8ce93c79cd # v3.15.0
with:
apiToken: ${{ secrets.CLOUDFLARE_API_TOKEN }}
accountId: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
apiToken: ${{ secrets.CLOUDFLARE_API_TOKEN }} # zizmor: ignore[secrets-outside-env]
accountId: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }} # zizmor: ignore[secrets-outside-env]
command: pages deploy ./site --project-name=${{ env.PROJECT_NAME }} --branch=${{ env.BRANCH }}
- name: Deploy Docs Status Error
if: failure()
Expand Down
52 changes: 52 additions & 0 deletions .github/workflows/guard-dependencies.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,52 @@
name: Guard Dependencies

on:
pull_request_target: # zizmor: ignore[dangerous-triggers] -- This workflow only reads context.payload metadata, never checks out PR code
branches: [master]
paths:
- pyproject.toml
- uv.lock

permissions:
contents: read
issues: write
pull-requests: write

jobs:
check-author:
runs-on: ubuntu-latest
steps:
- name: Check if author is org member or allowed bot
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
with:
script: |
const pr = context.payload.pull_request;
const author = pr.user.login;
const assoc = pr.author_association;

const botAllowlist = new Set(['dependabot[bot]']);
const orgAuthorAssociations = new Set(['MEMBER', 'OWNER']);

const allowed =
botAllowlist.has(author) ||
(assoc != null && orgAuthorAssociations.has(assoc));

if (!allowed) {
await github.rest.issues.createComment({
owner: context.repo.owner,
repo: context.repo.repo,
issue_number: context.payload.pull_request.number,
body: `This PR modifies dependency files (\`pyproject.toml\` or \`uv.lock\`), which is restricted to members of the **${context.repo.owner}** organization on GitHub.\n\nIf you need a dependency change, please [open a discussion](https://github.com/${context.repo.owner}/${context.repo.repo}/discussions/new) describing what you need and why.\n\nClosing this PR automatically.`
});

await github.rest.pulls.update({
owner: context.repo.owner,
repo: context.repo.repo,
pull_number: context.payload.pull_request.number,
state: 'closed'
});

core.setFailed('Dependency changes are restricted to organization members.');
} else {
console.log(`Author ${author} (author_association=${assoc}) is allowed to make dependency changes.`);
}
12 changes: 7 additions & 5 deletions .github/workflows/issue-manager.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,25 +9,27 @@ on:
issues:
types:
- labeled
pull_request_target:
pull_request_target: # zizmor: ignore[dangerous-triggers]
types:
- labeled
workflow_dispatch:

permissions:
issues: write
pull-requests: write
permissions: {}

jobs:
issue-manager:
if: github.repository_owner == 'fastapi'
runs-on: ubuntu-latest
permissions:
issues: write
pull-requests: write
timeout-minutes: 5
steps:
- name: Dump GitHub context
env:
GITHUB_CONTEXT: ${{ toJson(github) }}
run: echo "$GITHUB_CONTEXT"
- uses: tiangolo/issue-manager@0.6.0
- uses: tiangolo/issue-manager@2fb3484ec9279485df8659e8ec73de262431737d # 0.6.0
with:
token: ${{ secrets.GITHUB_TOKEN }}
config: >
Expand Down
10 changes: 7 additions & 3 deletions .github/workflows/labeler.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
name: Labels
on:
pull_request_target:
pull_request_target: # zizmor: ignore[dangerous-triggers]
types:
- opened
- synchronize
Expand All @@ -9,14 +9,17 @@ on:
- labeled
- unlabeled

permissions: {}

jobs:
labeler:
permissions:
contents: read
pull-requests: write
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- uses: actions/labeler@v6
- uses: actions/labeler@f27b608878404679385c85cfa523b85ccb86e213 # v6.1.0
if: ${{ github.event.action != 'labeled' && github.event.action != 'unlabeled' }}
- run: echo "Done adding labels"
# Run this after labeler applied labels
Expand All @@ -26,8 +29,9 @@ jobs:
permissions:
pull-requests: read
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- uses: docker://agilepathway/pull-request-label-checker:latest
- uses: agilepathway/label-checker@c3d16ad512e7cea5961df85ff2486bb774caf3c5 # v1.6.65
with:
one_of: breaking,security,feature,bug,refactor,upgrade,docs,lang-all,internal
repo_token: ${{ secrets.GITHUB_TOKEN }}
Loading
Loading