NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #419 most downloaded on PyPI
Python Git Library
Last release today
03 Oct 2026
Ships fairly regularly
a new release about every 3 weeks
Some releases are documented
notes for 32 of the last 60 stable releases
1 version withdrawn
withdrawn after publishing
13 years old
180 releases · first in 2013
Deprecate importing LOCAL_TAG_PREFIX , SYMREF , check_ref_format , read_packed_refs , read_packed_refs_with_peeled and write_packed_refs from dulwich.…
__all__ in all modules, listing the public names each module defines. (Jelmer Vernooij)LOCAL_TAG_PREFIX, SYMREF, check_ref_format, read_packed_refs, read_packed_refs_with_peeled and write_packed_refs from dulwich.repo; import them from dulwich.refs instead. Likewise BundleList, fetch_bundle_uri and parse_bundle_list should be imported from dulwich.bundle_uri rather than dulwich.client. (Jelmer Vernooij)dulwich.index.SHA1Reader and dulwich.index.SHA1Writer, which were dropped in 1.2.16, as deprecated aliases for the classes in dulwich.pack. (Jelmer Vernooij)Add PackIndex.object_sha_at_position to look up an object by its position in the sorted index, and use it when loading a .bitmap instead of re-scannin
One column per quarter.
PackIndex.object_sha_at_position to look up an object by its position in the sorted index, and use it when loading a .bitmap instead of re-scanning the index for every entry, which made loading quadratic in the pack size, unlike git. (Kartik Kenchi)---/+++ lines and failed with "Patch has no file path". (Jelmer Vernooij)git diff --binary. Their paths are now taken from the diff --git line, literal data is inflated, base85 line lengths are decoded correctly and binary deletions remove the file. (Jelmer Vernooij)delta binary patches, binary changes combined with a rename or copy and reverse application of binary patches in apply_patches. (Jelmer Vernooij)lfs_pull and lfs_migrate, so that a malicious repository can no longer write files outside the work tree via .. entries or symlinks. (Jelmer Vernooij, reported by Choudhry Shehryar)apply_patches. A tracked symlink such as trap -> .git/hooks/pre-commit was followed when writing, so porcelain.am/apply_patch could install a hook. Symlinks are now patched as links, like git does, and a patch whose mode doesn't match the type in the work tree or that adds a file over an existing path is refused. (Jelmer Vernooij, reported by @manus-pi)build_file_from_blob when the content is unchanged. (Jelmer Vernooij)\ No newline at end of file markers when applying patches, which previously made patches to files without a trailing newline fail. (Jelmer Vernooij)multi-pack-index entry whose pack has been removed when answering whether an object is present. After a prune the stale index made sha in repo.object_store disagree with repo.object_store[sha]. (Kartik Kenchi).gitignore or .gitattributes from the work tree. A tree could point either name at a file outside the repository and have its contents drive dulwich. (Kartik Kenchi)GIT_OPTIONAL_LOCKS=0 in dulwich status, skipping the index stat-cache refresh that would otherwise lock the index. (Jelmer Vernooij, #1861)porcelain.merge leaves conflicts, so the working tree matches git's state and git commit can finish the merge. (Jelmer Vernooij)dulwich log <path> on merge commits where the path is unchanged relative to one parent. tree_changes_for_merge reports None for such parents, which the walker and the --name-status and --name-only output wrongly assumed to be a TreeChange. (Jelmer Vernooij, #2412)dulwich log <path> now applies git's default history simplification. Pass --full-history for the old behavior. Walker and get_walker gain a simplify_history flag. (Jelmer Vernooij, #2414)add and commit on a SHA-256 repository wrote SHA-1 identities into the index, trees and refs, leaving a repository neither dulwich nor git could read back. (Jelmer Vernooij, #2416)eol gitattribute. Line ending conversion is now resolved per path from the text/crlf and eol attributes, falling back to core.autocrlf and core.eol only where the attributes are silent, so eol=crlf and eol=lf take precedence over the configuration as they do in git. (Jelmer Vernooij, #2403)\r escape. (Jelmer Vernooij)stripspace in a single pass. The previous pop(0) loop made an all-blank input O(n^2); it is now linear like git. (Kartik Kenchi)Detect delta cycles in Pack.resolve_object : a crafted pack with REF_DELTA objects that name each other sent get_raw into an unbounded loop. Such chai
Pack.resolve_object: a crafted pack with REF_DELTA objects that name each other sent get_raw into an unbounded loop. Such chains now raise DeltaCycle.porcelain.clean when the target directory and the repository path are spelled differently, such as via a relative path or a symlink. (Jelmer Vernooij)show_ref --dereference and the ref advertisement were quadratic. (Jelmer Vernooij, #2406).gitignore in a subdirectory precedence over one closer to the root, matching git. A negation in a deeper file no longer loses to a rule at the root, and a nested negation no longer re-includes a path whose parent directory stays excluded. (Jelmer Vernooij, #2399)tables.list entries that contain a path separator or are absolute, so a hostile repository cannot make a ref lookup open a file outside the reftable directory. (netliomax25-code)dulwich commit -C/--reuse-message and -c/--reedit-message to reuse a commit's message, author and author date, optionally editing the message. The committer and new commit ancestry remain independent. (eunwoo song, #1845)dulwich branch and standalone dulwich branch --list [pattern]. Listing empty repositories or patterns with no matches succeeds without changing refs. (be-student, #1847)dulwich commit --author="Name <email>" to override the author of a new or amended commit. (kudala-bharani, #1845)branch.<name>.remote and branch.<name>.merge for the branch checked out by a clone, so that a subsequent git pull with no arguments has tracking information. (Jelmer Vernooij, #2376)SSHGitClient.get_url, emitting git's ssh://host/~/path form. Cloning from an scp-style URL like user@host:git/repo.git previously stored ssh://user@host/git/repo.git as the remote URL, which points at a different repository. (Jelmer Vernooij, #2375)porcelain.path_to_tree_path, rather than by the path of its target. porcelain.status listed a tracked symlink as untracked whenever the file it pointed at was itself untracked or missing, so a modified symlink was reported twice. (Jerry Xiao)! or /. A bare ! previously re-included a directory that an earlier pattern in the same file had ignored. (Jelmer Vernooij, #2398)PktLineParser.parse, which resliced its remaining buffer once per pkt-line. (Jelmer Vernooij, #2408)Collapse consecutive segments in wildmatch translation, matching git's behavior and avoiding catastrophic regex backtracking on patterns like a////z f
Collapse consecutive ** segments in wildmatch translation, matching git's behavior and avoiding catastrophic regex backtracking on patterns like a/**/**/**/z from untrusted repositories. (netliomax25-code)
Make concurrent Pack.get_raw calls thread-safe by synchronizing PackData 's resolved-object offset cache. (Bojan Zivanovic)
Make concurrent Pack.get_raw calls thread-safe by synchronizing
PackData's resolved-object offset cache.
(Bojan Zivanovic)
Speed up cached PackData.get_object_at lookups by acquiring the
offset-cache lock directly instead of through a with statement.
(Bojan Zivanovic)
Bound fetch negotiation the way C Git's MAX_IN_VAIN does: give up
after 256 unacknowledged "have" lines instead of draining the whole
graph walker into stateless (HTTP) requests. (Bojan Zivanovic, #2343)
Add repo.sanitize_user_identity, which builds an identity from a
name and an email sanitized the way git's fmt_ident does, for
callers who cannot reject invalid input via check_user_identity.
(Bojan Zivanovic, #2342)
Make concurrent PackData reads thread-safe by mmap-ing pack contents
and indexing the mapping at explicit offsets instead of sharing the file
position. New unpack_object_at, read_pack_header_at,
read_zlib_chunks_at, take_msb_bytes_at and compute_buffer_sha
read from a buffer; the existing read-callable variants remain for streams.
(Bojan Zivanovic, Jelmer Vernooij)
Deduplicate the commit walk in find_shallow and get_depth
(dulwich.object_store). Both re-expanded a commit once per path that
reached it, so a merge-heavy history walked in exponential time.
(netliomax25-code)
SECURITY: Don't follow symlinks when writing messages in
porcelain.format_patch, mbox.split_mbox and mbox.split_maildir.
A symlink pre-planted at an output filename was followed, writing the
message outside the output
directory. (Jelmer Vernooij; Reported by wzc)
Only reject reserved Windows device names (aux, nul, con, ...)
when actually running on Windows. C git confines this check to its Windows
compat layer, so repositories carrying such paths could not be cloned
elsewhere. (Jelmer Vernooij, #2351)
Fix ignore and attrs matching for patterns ending in **/. The
trailing slash was dropped when translating the pattern, so foo/**/ also
matched foo/ itself and every file directly inside it. Git only ignores
the directories below foo. (adarshsm)
Catch PackFileDisappeared in the bitmap probe in
get_reachability_provider, which only guarded FileNotFoundError.
(Jelmer Vernooij, #2344)
SECURITY: Widen modes for core.sharedRepository as git does rather than
chmodding to a precomputed one, which left .git/hooks and .git/refs
world-writable for all. (netliomax25-code, Jelmer Vernooij, #2323)
parse_shared_repository now returns a SharedPerm, and
DiskObjectStore, Index and GitFile take a shared_perm
argument in place of file_mode/dir_mode. (Jelmer Vernooij)
Fix commit-graph extra edge indexing: the stored value is a position in a
list of 4-byte entries, not a byte offset, so every octopus merge after
the first got a wrong parent list. (netliomax25-code)
Refresh the mtime of an existing loose object in
DiskObjectStore.add_object(), so that a concurrent git gc cannot
prune an object that was just reported as present.
(Bojan Zivanovic, #2340)
HARDEN: Validate shallow object ids received from the remote.
(netliomax25-code)
SECURITY: Refuse patch targets addressing the .git control directory.
apply_patches (via porcelain.am/apply_patch) previously wrote and
ran .git/hooks/pre-commit. (Jelmer Vernooij, reported by @bhaswanthc)
Extend the verify_leading_dirs symlink guard to
update_working_tree (used by pull, merge and checkout).
The 1.2.12 fix only covered build_index_from_tree, so a tree pairing a
symlink x with a descendant x/config could still write through the
link and overwrite .git/config on pull.
(Jelmer Vernooij, reported by Hugh Lewis)
Translate .gitignore/.gitattributes bracket expressions with Git's
wildmatch() semantics: [^...] negation, POSIX classes, backslash
escapes and malformed-class handling. ignore and attrs now share
one translator, the new public dulwich.wildmatch.
(Vincent Gao, #2326)
Always single-quote the repository path in the SSH command, matching git's
sq_quote(). shlex.quote left paths without shell metacharacters
bare, which broke cloning from servers that parse the command themselves
rather than handing it to a shell, such as Bitbucket Server.
(Jelmer Vernooij, #2319)
SECURITY: Refuse to write a checkout entry whose leading path resolves through a symlink. build_index_from_tree (used by reset_index and thus by clone
SECURITY: Refuse to write a checkout entry whose leading path resolves
through a symlink. `build_index_from_tree` (used by `reset_index` and
thus by `clone`/`checkout`) materialized a tree in sorted order without
checking leading components, so a tree pairing a symlink `link` with a
descendant `link/foo` wrote `foo` through the link to an arbitrary
absolute path. The same `verify_leading_dirs` guard already used by
porcelain and stash is now applied here.
(Jelmer Vernooij, reported by Hugh Lewis)
Fix `Bundle.store_objects()` silently dropping every OFS_DELTA/REF_DELTA
object in the bundle's pack instead of resolving it, leaving the target
object store missing most objects with no error raised. Delta resolution
now goes through `PackInflater`, matching how packs are ingested
elsewhere in the object store code.
(theVinchi, #2312)
Apply core.protectHFS and core.protectNTFS together when selecting the checkout path-element validator. Previously only the NTFS validator ran when pr
Security and hardening
core.protectHFS and core.protectNTFS together when selecting the checkout path-element validator. Previously only the NTFS validator ran when protectNTFS was on (the default), so on macOS an HFS+ spelling of .git using ignorable code points could pass validation and poison .git on checkout.git archive tarballs, so a crafted tree entry can no longer carry setuid/setgid/sticky bits into an extracted file..bitmap index matches the pack it is loaded for, so a stale or swapped-in bitmap can't produce a wrong reachable-object set during fetch negotiation.Features and fixes
core.worktree, so the working tree can live outside the parent of the control directory.env argument, and read GIT_PROTOCOL, GIT_SSH_COMMAND/GIT_SSH when called as a library rather than only from the CLI (fixes a regression since 1.2.1 where porcelain.clone() silently ignored the SSH variables).porcelain.archive() gained a remote argument.core.bare when setting up a submodule's working tree.Security and hardening fixes in this release were contributed by Kartik Kenchi (@netliomax25-code).
Fix regression in 1.2.9 where loose objects whose content inflates to more than 8192 bytes failed to parse with zlib.error: object header exceeds maxi
Reject checkout paths whose leading component is a DOS drive-letter prefix on Windows (e.g. C: ), which os.path.join would otherwise treat as absolute
Highlights of this release:
Security fixes
C:), which os.path.join would otherwise treat as absolute and let a crafted tree write outside the work tree. (reported by Luke Baton)read_zlib_chunks now caps the inflated size at the declared decomp_len, and loose-object parsing accepts max_size defaulting to git's core.bigFileThreshold (512 MiB). (reported by Luke Bento)OFS_DELTA pack entries whose delta_base_offset is zero. Such an entry references itself, so Pack.resolve_object would loop forever growing its delta stack until OOM. (reported by Luke Banto)Transfer-Encoding: chunked request bodies in dulwich.web: strip chunk extensions, reject negative sizes, enforce per-chunk and per-request size limits, and cap requests that omit Content-Length..bitmap index raises ValueError instead of hanging in an unbounded loop that exhausts memory.Other changes
git-upload-pack / git-receive-pack POSTs whose Content-Type is not the exact application/x-<service>-request value, matching git http-backend.dulwich.web: Warn at startup that running python3 -m dulwich.web is not intended as a production web server (no authentication, etc.).See NEWS for the full list.
Deprecate dulwich.objects.filename_to_hex , which is unused.
build_file_from_blob in path-restricted porcelain.checkout(paths=...) instead of a raw os.open. The old path followed a symlink left at the target, so a crafted repository could write attacker content outside the work tree (e.g. into .git/hooks) on checkout.filter-branch --index-filter in memory instead of materializing tree entries into CWD. Persisted entries between commits let a symlink from an ancestor commit redirect a descendant's writes outside the work tree.stash.pop. The old os.path.exists check followed symlinks, so a crafted stash whose parent path was a symlink already present in the worktree (e.g. link -> .git/hooks) let the subsequent write land outside the work tree.porcelain.checkout, restore and reset_file writes whose leading directory is an existing symlink, so a crafted repository can no longer land sub as a link to .git/hooks and have a write to sub/anything traverse it.0o644/0o755 before chmod on checkout and patch apply, matching git. An untrusted tree entry or patch `new file mode` could otherwise set setuid/setgid/sticky or world-writable bits on a materialized file.int(sizestr, 16) accepted a leading -, whose negative length made the following `read(size - 4)` slurp the rest of the stream and caused `PktLineParser` to loop without consuming its buffer. (#2267)TCPGitClient before invoking the core.gitProxy command, matching the SubprocessSSHVendor guard, so a URL like `git://-oProxyCommand=...` can no longer be interpreted as a flag by the proxy program. (#2240).. cannot escape the LFS directory. (#2255)include/includeIf directives when parsing bundle lists served by an untrusted bundle-uri host, matching the handling of `.gitmodules`. (#2243)--status-fd (VALIDSIG) in `GPGCliSignatureVendor.verify` instead of the human-readable stderr text, which could be spoofed by embedding a matching line in the signed payload. (#2245)UntrustedSignature from verify_commit/verify_tag when keyids is set and the object carries no signature, instead of silently accepting it. (#2238)_find_scissors_line so a crafted patch can no longer stall mailinfo/git am --scissors. (#2239)* wildcards to at most ** in .gitattributes, .gitignore and config glob translation to avoid catastrophic backtracking (ReDoS). (#2237)web.ChunkReader.read. (#2262).., .git, etc.) in `diff_working_tree_to_tree` instead of joining them onto the work tree; a working-tree diff against an untrusted commit could otherwise read a file outside the work tree and disclose its contents. (#2261)ShaFile._parse_message. (#2273)git-receive-pack request body starts streaming. `generate_pack_data` previously ran lazily inside the body generator, after the header pkt-lines were already on the wire, so on large repositories the request stalled mid-body while objects were counted and servers such as GitHub aborted the push with a timeout / broken pipe. (#2248)build_file_from_blob instead of writing through it, matching git on checkout. (#2259)GitProtocolError carrying the server's message when the fetch/send-pack tail loop sees a fatal side-band channel (\x03), instead of crashing with `AssertionError: Invalid sideband channel 3` and swallowing the server's error text.ThreadingHTTPServer and advertise HTTP/1.1 in lfs_server so urllib3's keep-alive pool doesn't race a torn-down connection into RemoteDisconnected.http.postBuffer. (#2248)dulwich.objects.filename_to_hex, which is unused.Don't expand config include directives when parsing .gitmodules, so a crafted .gitmodules in a cloned repository can no longer make clone --recurse-su
include directives when parsing .gitmodules, so a crafted .gitmodules in a cloned repository can no longer make clone --recurse-submodules read arbitrary files.../../secret can no longer read a file outside the ref store. Closes a traversal via git-upload-archive's argument and other lookup paths. (#2212)ChecksumMismatch otherwise. (#2223)porcelain.request_pull and a dulwich request-pull command, like git request-pull. (#1823)porcelain.range_diff and a dulwich range-diff command, like git range-diff (requires the dulwich[range_diff] extra). (#1828)apply_patch writing index entries with mode 0, which made native git abort. (#2218)gc/repack fixes on Windows (read-only pack files, leaked temporary packs, files-in-use).pack- names such as loose-<hash> (written by git maintenance). (#2229)See NEWS for the full changelog.
Nothing published for this version
This is a security release. All users are encouraged to upgrade.
This is a security release. All users are encouraged to upgrade.
GHSA-gfhv-vqv2-4544 -- Validate submodule paths in porcelain.submodule_update (and thus porcelain.clone(recurse_submodules=True)). A crafted upstream repository could carry a submodule whose path was .git/hooks (or any other path inside .git or above the work tree), causing the submodule's tree contents to be written there with their executable bits intact. The dulwich analogue of git's CVE-2024-32002 / CVE-2024-32004. (Reported by tonghuaroot)
CVE-2026-42305 -- Harden tree path validation against entry names that are harmless on POSIX but dangerous when checked out on Windows. validate_path_element_ntfs now also rejects Windows path separators, the alternate data stream marker :, NTFS 8.3 short-name aliases of .git, and reserved Windows device names. core.protectNTFS now defaults to true on every platform, and both core.protectNTFS and core.protectHFS are now read under their correct option names. (Reported by Christopher Toth)
CVE-2026-42563 -- Shell-quote values substituted into ProcessMergeDriver commands. A malicious branch could inject shell commands when a merge driver referencing %P was configured. (Reported by Ravishanker Kusuma (hayageek))
CVE-2026-47712 -- Sanitize commit subjects used in porcelain.format_patch filenames so a malicious subject (e.g. x/../../x) cannot direct the generated patch outside outdir. (Reported by Christopher Toth)
receive.maxInputSize -- Honour receive.maxInputSize in ReceivePackHandler. Previously a remote unauthenticated client could send a tiny crafted pack that declared a huge dest_size and trigger hundreds of MB of allocation over git-receive-pack. (Reported by Liyi, Ziyue, Strick, Maurice and Chenchen @ University of Sydney)
refs: reject malformed ref prefixes/suffixes by @jelmer in https://github.com/jelmer/dulwich/pull/2193
Full Changelog: https://github.com/jelmer/dulwich/compare/dulwich-1.2.3...dulwich-1.2.4
Full Changelog: dulwich-1.2.3...dulwich-1.2.4
Nothing published for this version
Nothing published for this version
Derive the LFS endpoint as the remote's on-disk LFS store ( /.git/lfs for worktrees, /lfs for bare repos) when remote.origin.url points at a local fil
Derive the LFS endpoint as the remote's on-disk LFS store
(<remote>/.git/lfs for worktrees, <remote>/lfs for bare repos)
when remote.origin.url points at a local filesystem path or
file:// URL, matching git-lfs behaviour. Previously the built-in
smudge filter constructed an HTTP-style <remote>.git/info/lfs path
that did not exist on disk, leaving LFS-tracked files as pointers
when cloning from a local repo.
Deduplicate objects when writing a multi-pack-index. Objects present
in multiple packs (e.g. after git gc creates a cruft pack) would
otherwise produce an OIDL chunk with repeated SHAs, causing
git multi-pack-index verify to fail with "oid lookup out of order".
(#2152)
Extend ignorecase and precomposeunicode support to index lookups. (#1807)
Add am command and porcelain.am() for applying mailbox-style email patches (git am), with state persistence for --continue, --skip, --abort, and --qui
am command and porcelain.am() for applying mailbox-style email patches (git am), with state persistence for --continue, --skip, --abort, and --quit recovery (#1692).apply command and porcelain.apply_patch() for applying unified diffs, including rename/copy detection, binary patches with Git's base85 encoding, and --3way merge fallback (#1784).log command options: --oneline, --abbrev-commit, --author, --committer, --grep, --since/--after, --until/--before, -n/--max-count, --no-merges, --merges, --stat, -p/--patch, --name-only, and --follow (#1779).-o/--push-option) in push, enabling AGit flow and other server-side push option workflows.--all, --tags, --delete, --dry-run, --prune, --set-upstream, --follow-tags, and --mirror (#1844).--atomic): either all ref updates succeed or none are applied (#1781).extensions.relativeworktrees repository extension, allowing worktrees to use relative paths (#2112).gc.pruneExpire — grace period before unreachable objects are pruned (#1859).core.precomposeunicode — normalize NFD Unicode paths from macOS filesystems to NFC (#1804).core.gitProxy — proxy command for git:// protocol connections (#1850).core.maxStat — limit stat operations when checking for unstaged changes (#1853).core.packedGitLimit — cap memory used for mmapped pack files, closing LRU packs when exceeded (#1848).core.deltaBaseCacheLimit — cap memory used for caching delta base objects; defaults to 96 MiB (#1849).http.userAgent — customize the User-Agent header (global and URL-specific); default is git/dulwich/{version}.BadSignature for all GPG errors, not just BadSignatures; also detect when GPG returns no signatures.unborn argument in Git protocol v2 ls-refs requests to servers that don't advertise ls-refs=unborn, preventing clones from older servers like Gerrit 3.12.2 (#2104).read_info_refs() to show the actual line content when parsing fails (#2103)..gitignore parent re-include handling so a later !dir/ re-include allows a subsequent file-level negation to take effect (#2141, N0zoM1z0).contrib/paramiko_vendor.py by loading known hosts and rejecting unknown SSH host keys by default (#2123, quart27219).contrib/ as part of the distribution. The contrib/ directory has always been documented as unsupported and is now excluded from the installed package (#2122).Add reference to c-git-compatibility doc in README.md by @jelmer in https://github.com/jelmer/dulwich/pull/2069
Full Changelog: https://github.com/jelmer/dulwich/compare/dulwich-1.0.0...dulwich-1.1.0
Remove deprecated functions by @jelmer in https://github.com/jelmer/dulwich/pull/2068
Full Changelog: https://github.com/jelmer/dulwich/compare/dulwich-0.25.2...dulwich-1.0.0
Fix GPG signature test to handle InvalidSigners exception by @jelmer in https://github.com/jelmer/dulwich/pull/2064
Full Changelog: https://github.com/jelmer/dulwich/compare/dulwich-0.25.1...dulwich-0.25.2
Full Changelog: https://github.com/jelmer/dulwich/compare/dulwich-0.25.0...dulwich-0.25.1
Full Changelog: https://github.com/jelmer/dulwich/compare/dulwich-0.25.0...dulwich-0.25.1
ci(deps): bump actions/upload-artifact from 4.6.2 to 5.0.0 by @dependabot[bot] in https://github.com/jelmer/dulwich/pull/1975
porcelain.add check explicit for None by @ejfine in https://github.com/jelmer/dulwich/pull/2027Full Changelog: https://github.com/jelmer/dulwich/compare/dulwich-0.24.10...dulwich-0.25.0
Fix compatibility with python 3.9. (@jelmer, #1991)
Full Changelog: https://github.com/jelmer/dulwich/compare/dulwich-0.24.9...dulwich-0.24.10
Fix passing key_filename and ssh_command parameters to SSHGitClient by @skshetry
Fix passing key_filename and ssh_command parameters to SSHGitClient by @skshetry
Relax check to support subclasses of Urllib3HttpGitClient. Fixes regression from 0.24.2 where subclasses of Urllib3HttpGitClient would not receive the config object. by @skshetry
Fix test_concurrent_ref_operations_compatibility test flakiness by @jelmer
Fix warnings in test suite by @jelmer
Full Changelog: https://github.com/jelmer/dulwich/compare/dulwich-0.24.8...dulwich-0.24.9
Support ref namespaces by @jelmer in https://github.com/jelmer/dulwich/pull/1957
Full Changelog: https://github.com/jelmer/dulwich/compare/dulwich-0.24.7...dulwich-0.24.8
Use make_commit() from test utils in test files by @jelmer in https://github.com/jelmer/dulwich/pull/1943
Full Changelog: https://github.com/jelmer/dulwich/compare/dulwich-0.24.6...dulwich-0.24.7
Restore pool_manager parameter to transport functions by @jelmer in https://github.com/jelmer/dulwich/pull/1929
Full Changelog: https://github.com/jelmer/dulwich/compare/dulwich-0.24.5...dulwich-0.24.6
Fix LFS status tests cleanup issue on Windows Python 3.14 by @jelmer in https://github.com/jelmer/dulwich/pull/1924
Full Changelog: https://github.com/jelmer/dulwich/compare/dulwich-0.24.4...dulwich-0.24.5
Avoid PyObject, deprecated in PyO3 0.26 by @jelmer in https://github.com/jelmer/dulwich/pull/1917
Full Changelog: https://github.com/jelmer/dulwich/compare/dulwich-0.24.2...dulwich-0.24.4
Fix pypi publish action version by @jelmer in https://github.com/jelmer/dulwich/pull/1890
Full Changelog: https://github.com/jelmer/dulwich/compare/dulwich-0.24.2...dulwich-0.24.3
Fix worktree CLI tests to properly change to repository directory by @jelmer in https://github.com/jelmer/dulwich/pull/1739
object_store.iter_commit_contents() by @mathrick in https://github.com/jelmer/dulwich/pull/1761Full Changelog: https://github.com/jelmer/dulwich/compare/dulwich-0.24.1...dulwich-0.24.2
Require typing_extensions on Python 3.10. by @jelmer in https://github.com/jelmer/dulwich/pull/1736
typing_extensions on Python 3.10. by @jelmer in https://github.com/jelmer/dulwich/pull/1736Full Changelog: https://github.com/jelmer/dulwich/compare/dulwich-0.24.0...dulwich-0.24.1
Fix deprecation warnings by @jelmer in https://github.com/jelmer/dulwich/pull/1733
required setting by @jelmer in https://github.com/jelmer/dulwich/pull/1689Full Changelog: https://github.com/jelmer/dulwich/compare/dulwich-0.23.2...dulwich-0.24.0
Emit deprecation warnings on use rather than import by @ncoghlan in https://github.com/jelmer/dulwich/pull/1651
Full Changelog: https://github.com/jelmer/dulwich/compare/dulwich-0.23.1...dulwich-0.23.2
Add basic notes support by @jelmer in https://github.com/jelmer/dulwich/pull/1602
Full Changelog: https://github.com/jelmer/dulwich/compare/dulwich-0.23.0...dulwich-0.23.1
Resolve datetime deprecation warnings by @emmanuel-ferdman in https://github.com/jelmer/dulwich/pull/1528
Full Changelog: https://github.com/jelmer/dulwich/compare/dulwich-0.22.8...dulwich-0.23.0
Bump ruff from 0.8.3 to 0.8.4 by @dependabot in https://github.com/jelmer/dulwich/pull/1469
Full Changelog: https://github.com/jelmer/dulwich/compare/dulwich-0.22.7...dulwich-0.22.8
Fix serializing of commits with empty commit messages. (Castedo Ellerman, #1429)
Various minor rust improvements by @jelmer in https://github.com/jelmer/dulwich/pull/1390
Full Changelog: https://github.com/jelmer/dulwich/compare/v0.22.2...v0.22.6
Drop outdated performance.txt file. Fixes #1411 by @jelmer in https://github.com/jelmer/dulwich/pull/1412
Full Changelog: https://github.com/jelmer/dulwich/compare/dulwich-0.22.4...dulwich-0.22.5
Fix handling of symrefs with protocol v2. (Jelmer Vernooij, #1389)
Fix handling of symrefs with protocol v2. (Jelmer Vernooij, #1389)
Add ObjectStore.iter_prefix. (Jelmer Vernooij)
Revert back to version 3 of Cargo.lock, to allow
building with older Cargo versions.
(Jelmer Vernooij)
Use a default ref-prefix when fetching with git protocol v2 (Stefan Sperling, #1389)
Add ObjectStore.iter_prefix. (Jelmer Vernooij)
Full Changelog: https://github.com/jelmer/dulwich/compare/dulwich-0.22.2...dulwich-0.22.3
Full Changelog: https://github.com/jelmer/dulwich/compare/dulwich-0.22.2...dulwich-0.22.3
Fix pypi deployments by @jelmer in https://github.com/jelmer/dulwich/pull/1284
Full Changelog: https://github.com/jelmer/dulwich/compare/dulwich-0.22.0...dulwich-0.22.1
Start on 0.21.8 by @jelmer in https://github.com/jelmer/dulwich/pull/1240
Full Changelog: https://github.com/jelmer/dulwich/compare/dulwich-0.21.7...dulwich-0.22.0
Fix NameError when encountering errors during HTTP operation. (Jelmer Vernooij, #1208)
Fix NameError when encountering errors during HTTP operation. (Jelmer Vernooij, #1208)
Raise exception when default identity can't be found. (Jelmer Vernooij)
Add a dedicated exception class for unresolved deltas. (Jelmer Vernooij, #1221)
Support credentials in proxy URL. (Jelmer Vernooij, #1227)
Add dulwich.porcelain.for_each_ref. (Daniele Trifirò)
Define a stricter return type for _parse_message by @progval in https://github.com/jelmer/dulwich/pull/1176
git/etc and git/mingw64/etc on windows by @pmrowla in https://github.com/jelmer/dulwich/pull/1194Full Changelog: https://github.com/jelmer/dulwich/compare/dulwich-0.21.5...dulwich-0.21.6
Be more tolerant to non-3-length tuple versions. (Jelmer Vernooij)
Deprecate dulwich.objects.parse_commit.
Support core.symlinks=false. (Jelmer Vernooij, #1169)
Deprecate dulwich.objects.parse_commit.
Fix fetching into MemoryRepo. (Jelmer Vernooij, #1157)
Support init.defaultBranch config.
(Jelmer Vernooij)
Fix ObjectStore.iterobjects_subset() when
hex shas are passed for objects that live in packs.
(Jelmer Vernooij, #1166)
client: Handle absolute path as redirect location in HTTP client. (Antoine Lambert)
Nothing published for this version
Deprecate Commit.extra; the Git project specifically discourages adding custom lines, and the contents of Commit.extra are unpredictable as contents m…
Add support for worktreeconfig extension.
(Jelmer Vernooij)
Deprecate Commit.extra; the Git project specifically
discourages adding custom lines, and the contents of
Commit.extra are unpredictable as contents
may be different between different versions of Dulwich
with support for different headers.
Commit._extra still exists.
(Jelmer Vernooij)
Fix early file close bug in dulwich.pack.extend_pack. (@jelmer)
dulwich.pack.extend_pack.
(@jelmer)Factor out dulwich.pack.extend_pack. (@jelmer)
dulwich.pack.extend_pack.
(@jelmer)Pack internals have been significantly refactored, including significant low-level API changes.
Pack internals have been significantly refactored, including significant low-level API changes.
As a consequence of this, Dulwich now reuses pack deltas when communicating with remote servers, which brings a big boost to network performance. (@jelmer)
Add 'pack-refs' command. (@danchr)
Handle more errors when trying to read a ref (@danchr )
Allow for reuse of existing deltas while creating pack files (@stspdotname )
cli: fix argument parsing for pack-objects --stdout (@stspdotname)
cli: open pack-objects output files in binary mode to avoid write() error (@stspdotname)
Bump minimum python version to 3.7. (@jelmer)
honor no_proxy environment variable (#1098, @afaul )
In HTTP Git Client, allow missing Content-Type. (@jelmer)
Fix --pure builds (@jelmer, #1093)
Allow passing abbrev to describe (#1084, @nanonyme )
Fix Repo.reset_index. Previously, it instead took the union with the given tree. (@sattlerc , #1072)
Fix Repo.reset_index. Previously, it instead took the union with the given tree. (@sattlerc , #1072)
Add -b argument to dulwich clone.
(@jelmer
On Windows, provide a hint about developer mode when creating symlinks fails due to a permission error. (@jelmer, #1005)
Add new ObjectID type in dulwich.objects,
currently just an alias for bytes.
(@jelmer)
Support repository format version 1. (@jelmer, #1056)
Support \r\n line endings with continuations when parsing configuration files. (@jelmer)
Fix handling of SymrefLoop in RefsContainer.setitem. (@domdfcoding, @jelmer)
Nothing published for this version
Nothing published for this version
Nothing published for this version
Move various long-deprecated methods. (@jelmer)
Apply insteadOf to rsync-style location strings (previously it was just applied to URLs). (@jelmer, python-poetry/poetry#6329)
Drop use of certifi, instead relying on urllib3's default code to find system CAs. (@jelmer , #1025)
Implement timezone parsing in porcelain. (@springheeledjack0 , #1026)
Drop support for running without setuptools. (@jelmer )
Ensure configuration is loaded when running "dulwich clone". (@jelmer )
Build 32 bit wheels for Windows. (@bparzella)
tests: Ignore errors when deleting GNUPG home directory. Fixes spurious errors racing gnupg-agent. Thanks, @mcepl . Fixes #1000
config: Support closing brackets in quotes in section names. (@jelmer , #10124)
Various and formatting fixes. (@kianmeng )
Document basic authentication in dulwich.porcelain.clone. (@TuringTux )
Flush before calling fsync, ensuring buffers are filled. (@wernha )
Support GPG commit signing. (@springheeledjack0 )
Add python 3.11 support. (Saugat Pachhai))
Allow missing GPG during tests. (@kulikjak)
status: return posix-style untracked paths instead of nt-style paths on win32 (@dtrifiro)
Honour PATH environment when running C Git for testing. (@stspdotname )
Split out exception for symbolic reference loops. (@jelmer)
Move various long-deprecated methods. (@jelmer)
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →