Debian Package Tracker
Register | Log in
Subscribe

fastapi

modern, fast, web framework for building APIs, based on type hints

Choose email to subscribe with

general
  • source: fastapi (main)
  • version: 0.92.0-1
  • maintainer: Sandro Tosi (DMD)
  • uploaders: Debian Python Team [DMD]
  • arch: all
  • std-ver: 4.6.2.0
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • stable: 0.63.0-2
  • testing: 0.92.0-1
  • unstable: 0.92.0-1
versioned links
  • 0.63.0-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.92.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • python3-fastapi (1 bugs: 0, 1, 0, 0)
action needed
A new upstream version is available: 0.95.0 high
A new upstream version 0.95.0 is available, you should consider packaging it.
Created: 2023-03-09 Last update: 2023-03-21 09:00
Failed to analyze the VCS repository. Please troubleshoot and fix the issue. high
vcswatch reports that there is an error with this package's VCS, or the debian/changelog file inside it. Please check the error shown below and try to fix it. You might have to update the VCS URL in the debian/control file to point to the correct repository.

fatal: unable to access 'https://salsa.debian.org/python-team/packages/fastapi.git/': Failed to connect to salsa.debian.org port 443: No route to host
Created: 2023-03-16 Last update: 2023-03-16 20:38
lintian reports 4 warnings normal
Lintian reports 4 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2023-02-25 Last update: 2023-02-25 11:02
1 low-priority security issue in bullseye low

There is 1 open security issue in bullseye.

1 issue left for the package maintainer to handle:
  • CVE-2021-32677: (needs triaging) FastAPI is a web framework for building APIs with Python 3.6+ based on standard Python type hints. FastAPI versions lower than 0.65.2 that used cookies for authentication in path operations that received JSON payloads sent by browsers were vulnerable to a Cross-Site Request Forgery (CSRF) attack. In versions lower than 0.65.2, FastAPI would try to read the request payload as JSON even if the content-type header sent was not set to application/json or a compatible JSON media type (e.g. application/geo+json). A request with a content type of text/plain containing JSON data would be accepted and the JSON data would be extracted. Requests with content type text/plain are exempt from CORS preflights, for being considered Simple requests. The browser will execute them right away including cookies, and the text content could be a JSON string that would be parsed and accepted by the FastAPI application. This is fixed in FastAPI 0.65.2. The request data is now parsed as JSON only if the content-type header is application/json or another JSON compatible media type like application/geo+json. It's best to upgrade to the latest FastAPI, but if updating is not possible then a middleware or a dependency that checks the content-type header and aborts the request if it is not application/json or another JSON compatible content type can act as a mitigating workaround.

You can find information about how to handle this issue in the security team's documentation.

Created: 2022-07-04 Last update: 2023-03-07 08:00
news
[rss feed]
  • [2023-03-07] fastapi 0.92.0-1 MIGRATED to testing (Debian testing watch)
  • [2023-03-07] fastapi 0.92.0-1 MIGRATED to testing (Debian testing watch)
  • [2023-02-24] Accepted fastapi 0.92.0-1 (source) into unstable (Sandro Tosi)
  • [2023-02-14] Accepted fastapi 0.91.0-1 (source) into unstable (Sandro Tosi)
  • [2023-01-24] fastapi 0.89.1-1 MIGRATED to testing (Debian testing watch)
  • [2023-01-22] Accepted fastapi 0.89.1-1 (source) into unstable (Sandro Tosi)
  • [2023-01-01] fastapi 0.88.0-1 MIGRATED to testing (Debian testing watch)
  • [2022-12-09] Accepted fastapi 0.88.0-1 (source) into unstable (Sandro Tosi)
  • [2022-10-02] fastapi 0.85.0-2 MIGRATED to testing (Debian testing watch)
  • [2022-10-02] fastapi 0.85.0-2 MIGRATED to testing (Debian testing watch)
  • [2022-09-30] Accepted fastapi 0.85.0-2 (source) into unstable (Sandro Tosi)
  • [2022-09-28] Accepted fastapi 0.85.0-1 (source) into unstable (Sandro Tosi)
  • [2022-03-01] fastapi 0.74.1-1 MIGRATED to testing (Debian testing watch)
  • [2022-02-27] Accepted fastapi 0.74.1-1 (source) into unstable (Sandro Tosi)
  • [2022-01-29] fastapi 0.73.0-1 MIGRATED to testing (Debian testing watch)
  • [2022-01-26] Accepted fastapi 0.73.0-1 (source) into unstable (Sandro Tosi)
  • [2021-12-22] fastapi 0.70.1-1 MIGRATED to testing (Debian testing watch)
  • [2021-12-21] fastapi 0.70.0-2 MIGRATED to testing (Debian testing watch)
  • [2021-12-20] Accepted fastapi 0.70.1-1 (source) into unstable (Sandro Tosi)
  • [2021-12-14] Accepted fastapi 0.70.0-2 (source) into unstable (Sandro Tosi)
  • [2021-10-15] fastapi 0.70.0-1 MIGRATED to testing (Debian testing watch)
  • [2021-10-09] Accepted fastapi 0.70.0-1 (source) into unstable (Sandro Tosi)
  • [2021-02-06] fastapi 0.63.0-2 MIGRATED to testing (Debian testing watch)
  • [2021-01-31] Accepted fastapi 0.63.0-2 (source) into unstable (Sandro Tosi)
  • [2021-01-31] Accepted fastapi 0.63.0-1 (source all) into unstable, unstable (Debian FTP Masters) (signed by: Sandro Tosi)
bugs [bug history graph]
  • all: 1
  • RC: 0
  • I&N: 1
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (0, 4)
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 0.91.0-1
  • 2 bugs

Debian Package Tracker — Copyright 2013-2018 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing