NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #5258 most downloaded on PyPI
Object-Oriented HTTP framework
Last release 2 years ago
no release in 18 months
Release timing varies
gaps range from 3 weeks to 1.4 years
Nearly every release is documented
notes for 55 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
21 years old
121 releases · first in 2005
Removed the use of cgi deprecated in Python 3.11 -- by radez.
Removed the use of cgi deprecated in Python 3.11 -- by radez.
Various changes.
* Various changes _.
Various changes.
One column per quarter.
1974: Dangerous characters received in a host header encoded using RFC 2047 are now elided by default. Currently, dangerous characters are defined as
1974: Dangerous characters received in a host header encoded using RFC 2047 are now elided by default. Currently, dangerous characters are defined as CR and LF. The original value is still available as cherrypy.request.headers['Host'].raw if needed.
1923: Drop support for Python 3.5.
1923: Drop support for Python 3.5.
1945: Fixed compatibility on Python 3.11.
1849 via 1879: Fixed XLF flag in gzip header emitted by gzip compression tool per RFC 1952#section-2.3.1 -- by webknjaz.
1849 via 1879: Fixed XLF flag in gzip header emitted by gzip compression tool per 1952#section-2.3.1 -- by webknjaz.
1874: Restricted depending on pywin32 only under CPython so that it won't get pulled-in under PyPy -- by webknjaz.
1920: Bumped minimum version of PyWin32 to 227. Block pywin32 install on Python 3.10 and later.
1776 via 1851: Add support for UTF-8 encoded attachment file names in Content-Disposition header via RFC 6266#appendix-D.
1776 via 1851: Add support for UTF-8 encoded attachment file names in Content-Disposition header via 6266#appendix-D.
1827: Fixed issue where bytes values in a HeaderMap would be converted to strings.
1827: Fixed issue where bytes values in a HeaderMap would be converted to strings.
1826: Rely on jaraco.collections for its case-insensitive dictionary support.
1715: Fixed issue in cpstats where the data/ endpoint would fail with encoding errors on Python 3.
1715: Fixed issue in cpstats where the data/ endpoint would fail with encoding errors on Python 3.
1821: Simplify the passthrough of parameters to CPWebCase.getPage to cheroot. CherryPy now requires cheroot 8.2.1 or later.
1806: Support handling multiple exceptions when processing hooks as reported in 1770.
1806: Support handling multiple exceptions when processing hooks as reported in 1770.
File-based sessions no longer attempt to remove the lock files when releasing locks, instead deferring to the default behavior of zc.lockfile. Fixes 1
File-based sessions no longer attempt to remove the lock files when releasing locks, instead deferring to the default behavior of zc.lockfile. Fixes 1391 and 1779.
1794: Add native support for 308 Permanent Redirect usable via raise cherrypy.HTTPRedirect('/new_uri', 308).
Fixed 1377 via 1785: Restore a native WSGI-less HTTP server support.
Fixed 1377 via 1785: Restore a native WSGI-less HTTP server support.
1769: Reduce log level for non-error events in win32.py
1774 reverts 1759 as new evidence emerged that the original behavior was intentional. Re-opens 1758.
1774 reverts 1759 as new evidence emerged that the original behavior was intentional. Re-opens 1758.
1758 via 1759: In the bus, when awaiting a state change, only publish after the state has changed.
1758 via 1759: In the bus, when awaiting a state change, only publish after the state has changed.
1738 via 1736: Restore support for 'bytes' in response headers.
1738 via 1736: Restore support for 'bytes' in response headers.
Substantial removal of Python 2 compatibility code.
1730: Drop support for Python 2.7. CherryPy 17 will remain an LTS release for bug and security fixes.
1730: Drop support for Python 2.7. CherryPy 17 will remain an LTS release for bug and security fixes.
Drop support for Python 3.4.
Fixed 1377 by backporting 1785 via 1786: Restore a native WSGI-less HTTP server support.
Fixed 1377 by backporting 1785 via 1786: Restore a native WSGI-less HTTP server support.
1738 via 1755: Restore support for 'bytes' in response headers (backport from v18.0.1).
1738 via 1755: Restore support for 'bytes' in response headers (backport from v18.0.1).
a95e619f: When setting Response Body, reject Unicode values, making behavior on Python 2 same as on Python 3.
a95e619f: When setting Response Body, reject Unicode values, making behavior on Python 2 same as on Python 3.
Other inconsequential refactorings.
1193 via 1729: Rely on zc.lockfile for session concurrency support.
1193 via 1729: Rely on zc.lockfile for session concurrency support.
Nothing published for this version
1690 via 1692: Prevent orphaned Event object in cached 304 response.
1690 via 1692: Prevent orphaned Event object in cached 304 response.
1694 via 1695: Add support for accepting uploaded files with non-ascii filenames per RFC 5987.
1694 via 1695: Add support for accepting uploaded files with non-ascii filenames per RFC 5987.
1673: CherryPy now allows namespace packages for its dependencies. Environments that cannot handle namespace packgaes like py2exe will need to add suc
1673: CherryPy now allows namespace packages for its dependencies. Environments that cannot handle namespace packgaes like py2exe will need to add such support or pin to older CherryPy versions.
1722: Pinned the tempora dependency against version 1.13 to avoid pulling in namespace packages.
1722: Pinned the tempora dependency against version 1.13 to avoid pulling in namespace packages.
1716 via 1717: Fixed handling of url-encoded parameters in digest authentication handling, correcting regression in v14.2.0.
1716 via 1717: Fixed handling of url-encoded parameters in digest authentication handling, correcting regression in v14.2.0.
1719 via 1d41828: Digest-auth tool will now return a status code of 401 for when a scheme other than 'digest' is indicated.
1688 via 38ad1da: Removed basic_auth and digest_auth tools and the httpauth module, which have been officially deprecated earlier in v14.0.0.
1688 via 38ad1da: Removed basic_auth and digest_auth tools and the httpauth module, which have been officially deprecated earlier in v14.0.0.
Removed deprecated properties:
cherrypy._cpreqbody.Entity.type deprecated in favor of cherrypy._cpreqbody.Entity.content_type
cherrypy._cprequest.Request.body_params deprecated in favor of cherrypy._cprequest.RequestBody.params
1377: In _cp_native server, set req.status using bytes (fixed in 1712).
1697 via 841f795: Fixed error on Python 3.7 with AutoReloader when __file__ is None.
1713 via 15aa80d: Fix warning emitted during test run.
1370 via 38f199c: Fail with HTTP 400 for invalid headers.
1708: Removed components from webtest that were removed in the refactoring of cheroot.test.webtest for cheroot 6.1.0.
1708: Removed components from webtest that were removed in the refactoring of cheroot.test.webtest for cheroot 6.1.0.
1680 via 1683: Basic Auth and Digest Auth tools now support RFC 7617 UTF-8 charset decoding where possible, using latin-1 as a fallback.
1680 via 1683: Basic Auth and Digest Auth tools now support 7617 UTF-8 charset decoding where possible, using latin-1 as a fallback.
:cr-pr:37: Add support for peercreds lookup over UNIX domain socket. This enables app to automatically identify "who's on the other end of the wire".
37: Add support for peercreds lookup over UNIX domain socket. This enables app to automatically identify "who's on the other end of the wire".
This is how you enable it:
server.peercreds: True server.peercreds_resolve: True
The first option will put remote numeric data to WSGI env vars: app's PID, user's id and group.
Second option will resolve that into user and group names.
To prevent expensive syscalls, data is cached on per connection basis.
1700: Improve windows pywin32 dependency declaration via conditional extras.
1700: Improve windows pywin32 dependency declaration via conditional extras.
1688: Officially deprecated basic_auth and digest_auth tools and the httpauth module, triggering DeprecationWarnings if they're used. Applications sho…
1688: Officially deprecated basic_auth and digest_auth tools and the httpauth module, triggering DeprecationWarnings if they're used. Applications should instead adapt to use the more recent auth_basic and auth_digest tools. This deprecated functionality will be removed in a subsequent release soon.
Removed DeprecatedTool and the long-deprecated and disabled tidy and nsgmls tools. See the rationale for this change.
1231 via 1654: CaseInsensitiveDict now re-uses the generalized functionality from jaraco.collections to provide a more complete interface for a CaseIn
1231 via 1654: CaseInsensitiveDict now re-uses the generalized functionality from jaraco.collections to provide a more complete interface for a CaseInsensitiveDict and HeaderMap.
Users are encouraged to use the implementation from jaraco.collections except when dealing with headers in CherryPy.
1671: Restore support for installing CherryPy into environments hostile to namespace packages, broken since the 11.1.0 release.
1671: Restore support for installing CherryPy into environments hostile to namespace packages, broken since the 11.1.0 release.
1666: Drop support for Python 3.3.
1666: Drop support for Python 3.3.
1665: In request processing, when an invalid cookie is received, render the actual error message reported rather than guessing (sometimes incorrectly)
1665: In request processing, when an invalid cookie is received, render the actual error message reported rather than guessing (sometimes incorrectly) what error occurred.
…mod:cheroot) and added a corresponding class:DeprecationWarning.
Fixed issues importing cherrypy.test.webtest (by creating a module and importing classes from cheroot) and added a corresponding DeprecationWarning.
Drop support for Python 3.1 and 3.2.
Drop support for Python 3.1 and 3.2.
1625: Removed response timeout and timeout monitor and related exceptions, as it not possible to interrupt a request. Servers that wish to exit a request prematurely are recommended to monitor response.time and raise an exception or otherwise act accordingly.
Servers that previously disabled timeouts by invoking cherrypy.engine.timeout_monitor.unsubscribe() will now crash. For forward-compatibility with this release on older versions of CherryPy, disable timeouts using the config option:
'engine.timeout_monitor.on': False,
Or test for the presence of the timeout_monitor attribute:
with contextlib2.suppress(AttributeError):
cherrypy.engine.timeout_monitor.unsubscribe()
Additionally, the TimeoutError exception has been removed, as it's no longer called anywhere. If your application benefits from this Exception, please comment in the linked ticket describing the use case, and we'll help devise a solution or bring the exception back.
cherrypy.engine.subscribe now may be called without a callback, in which case it returns a decorator expecting the callback.
cherrypy.engine.subscribe now may be called without a callback, in which case it returns a decorator expecting the callback.
1656: Images are now compressed using lossless compression and consume less space.
1611: Expose default status logic for a redirect as HTTPRedirect.default_status.
1611: Expose default status logic for a redirect as HTTPRedirect.default_status.
1615: HTTPRedirect.status is now an instance property and derived from the value in args. Although it was previously possible to set the property on an instance, and this change prevents that possibilty, CherryPy never relied on that behavior and we presume no applications depend on that interface.
1627: Fixed issue in proxy tool where more than one port would appear in the request.base and thus in cherrypy.url.
1645: Added new log format markers:
i holds a per-request UUID4
z outputs UTC time in format of RFC 3339
cherrypy._cprequest.Request.unique_id.uuid4 now has lazily invocable UUID4
1646: Improve http status conversion helper.
1638: Always use backslash for path separator when processing paths in staticdir.
1190: Fix gzip, caching, and staticdir tools integration. Makes cache of gzipped content valid.
Requires cheroot 5.8.3 or later.
Also, many improvements around continuous integration and code quality checks.
This release contained an unintentional regression in environments that are hostile to namespace packages, such as Pex, Celery, and py2exe. See 1671 for details.
1607: Dropped support for Python 2.6.
1607: Dropped support for Python 2.6.
1595: Fixed over-eager normalization of paths in cherrypy.url.
1595: Fixed over-eager normalization of paths in cherrypy.url.
Remove unintended dependency on graphviz in Python 2.6.
Remove unintended dependency on graphviz in Python 2.6.
1580: CPWSGIServer.version now reported as CherryPy/x.y.z Cheroot/x.y.z. Bump to cheroot 5.2.0.
1580: CPWSGIServer.version now reported as CherryPy/x.y.z Cheroot/x.y.z. Bump to cheroot 5.2.0.
The codebase is now 8 complaint, flake8 linter is enabled in TravisCI by default.
Max line restriction is now set to 120 for flake8 linter.
257 linter runs as separate allowed failure job in Travis CI.
A few bugs related to undeclared variables have been fixed.
pre-commit testing goes faster due to enabled caching.
1342: Fix AssertionError on shutdown.
1342: Fix AssertionError on shutdown.
794: Prefer setting max-age for session cookie expiration, moving MSIE hack into a function documenting its purpose.
Bump to cheroot 5.1.0.
794: Prefer setting max-age for session cookie expiration, moving MSIE hack into a function documenting its purpose.
1332: CherryPy now uses portend _ for checking and waiting on ports for startup and teardown checks. The following names are no longer present:
1332: CherryPy now uses portend for checking and waiting on ports for startup and teardown checks. The following names are no longer present:
cherrypy._cpserver.client_host
cherrypy._cpserver.check_port
cherrypy._cpserver.wait_for_free_port
cherrypy._cpserver.wait_for_occupied_port
cherrypy.process.servers.check_port
cherrypy.process.servers.wait_for_free_port
cherrypy.process.servers.wait_for_occupied_port
Use this functionality from the portend package directly.
1481: Move functionality from cherrypy.wsgiserver to the cheroot 5.0 _ project.
1481: Move functionality from cherrypy.wsgiserver to the cheroot 5.0 project.
1537: Restore dependency on pywin32 for Python 3.6.
1537: Restore dependency on pywin32 for Python 3.6.
1547: Replaced cherryd distutils script with a setuptools console entry point.
1547: Replaced cherryd distutils script with a setuptools console entry point.
When running CherryPy in daemon mode, the forked process no longer changes directory to /. If that behavior is something on which your application relied and should rely, please file a ticket with the project.
1528: Allow a timeout of 0 to server.
1528: Allow a timeout of 0 to server.
645: Setting a bind port of 0 will bind to an ephemeral port.
645: Setting a bind port of 0 will bind to an ephemeral port.
1538 and 1090: Removed cruft from the setup script and instead rely on include_package_data _ to ensure the relevant files are included in the package
1538 and 1090: Removed cruft from the setup script and instead rely on include_package_data to ensure the relevant files are included in the package. Note, this change does cause LICENSE.md no longer to be included in the installed package.
The pyOpenSSL support is now included on Python 3 builds, removing the last disparity between Python 2 and Python 3 in the CherryPy package. This chan
The pyOpenSSL support is now included on Python 3 builds, removing the last disparity between Python 2 and Python 3 in the CherryPy package. This change is one small step in consideration of 1399. This change also fixes RPM builds, as reported in 1149.
1532: Also release wheels for Python 2, enabling offline installation.
1532: Also release wheels for Python 2, enabling offline installation.
Nothing published for this version
1537: Disable dependency on pypiwin32 on Python 3.6 until a viable build of pypiwin32 can be made on that Python version.
1537: Disable dependency on pypiwin32 on Python 3.6 until a viable build of pypiwin32 can be made on that Python version.
Consolidated some documentation and include the more concise readme in the package long description, as found on PyPI.
Consolidated some documentation and include the more concise readme in the package long description, as found on PyPI.
1463: CherryPy tests are now run under pytest and invoked using tox.
1463: CherryPy tests are now run under pytest and invoked using tox.
1530: Fix the issue with TypeError being swallowed by decorated handlers.
1530: Fix the issue with TypeError being swallowed by decorated handlers.
* 1508
1508
Your coding agent can read these notes before it upgrades. Set up the MCP server →