python3-werkzeug: upgrade 3.1.6 -> 3.1.7

Changelog:
==========
- parse_list_header preserves partially quoted items, discards empty items, and
  returns empty for unclosed quoted values.
- WWWAuthenticate.to_header does not produce a trailing space when there are no
  parameters.
- Transfer-Encoding is parsed as a set.
- Request.host, get_host, and host_is_trusted validate the characters of the
  value. An empty value is no longer allowed. A Unix socket server address is
  ignored. The trusted_list argument to host_is_trusted is optional.
- Fix multipart form parser handling of newline at boundary.
- Response.make_conditional sets the Accept-Ranges header even if it is not a
  satisfiable range request.
- merge_slashes merges any number of consecutive slashes.

Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
This commit is contained in:
Wang Mingyu 2026-04-02 10:13:50 +08:00 committed by Khem Raj
parent affabbd410
commit db8bd24b0d
No known key found for this signature in database
GPG Key ID: BB053355919D3314

View File

@ -10,7 +10,7 @@ HOMEPAGE = "https://werkzeug.palletsprojects.com"
LICENSE = "BSD-3-Clause"
LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=5dc88300786f1c214c1e9827a5229462"
SRC_URI[sha256sum] = "210c6bede5a420a913956b4791a7f4d6843a43b6fcee4dfa08a65e93007d0d25"
SRC_URI[sha256sum] = "fb8c01fe6ab13b9b7cdb46892b99b1d66754e1d7ab8e542e865ec13f526b5351"
CVE_PRODUCT = "werkzeug"