Skip to content

Releases: pallets/jinja

3.1.4

05 May 23:42
3.1.4
dd4a8b5
Compare
Choose a tag to compare

This is the Jinja 3.1.4 security release, which fixes security issues and bugs but does not otherwise change behavior and should not result in breaking changes.

PyPI: https://pypi.org/project/Jinja2/3.1.4/
Changes: https://jinja.palletsprojects.com/en/3.1.x/changes/#version-3-1-4

  • The xmlattr filter does not allow keys with / solidus, > greater-than sign, or = equals sign, in addition to disallowing spaces. Regardless of any validation done by Jinja, user input should never be used as keys to this filter, or must be separately validated first. GHSA-h75v-3vvj-5mfj

3.1.3

10 Jan 23:12
3.1.3
d9de4bb
Compare
Choose a tag to compare

This is a fix release for the 3.1.x feature branch.

3.1.2

28 Apr 17:24
b08cd4b
Compare
Choose a tag to compare

3.1.1

25 Mar 22:36
7f66a58
Compare
Choose a tag to compare

3.1.0

24 Mar 14:24
84c0e2c
Compare
Choose a tag to compare

This is a feature release, which includes new features and removes previously deprecated features. The 3.1.x branch is now the supported bugfix branch, the 3.0.x branch has become a tag marking the end of support for that branch. We encourage everyone to upgrade, and to use a tool such as pip-tools to pin all dependencies and control upgrades. We also encourage upgrading to MarkupSafe 2.1.1, the latest version at this time.

3.0.3

16 Nov 00:34
2a48dd8
Compare
Choose a tag to compare

3.0.2

05 Oct 00:55
b7d12b6
Compare
Choose a tag to compare

3.0.1

18 May 20:41
3b3e16f
Compare
Choose a tag to compare

3.0.0

12 May 00:11
417f822
Compare
Choose a tag to compare

New major versions of all the core Pallets libraries, including Jinja 3.0, have been released! 🎉

This represents a significant amount of work, and there are quite a few changes. Be sure to carefully read the changelog, and use tools such as pip-compile and Dependabot to pin your dependencies and control your updates.

3.0.0rc2

25 Apr 15:16
ac8d8d6
Compare
Choose a tag to compare
3.0.0rc2 Pre-release
Pre-release

Fixes an issue with the deprecated Markup subclass, #1401.