NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #1658 most downloaded on PyPI
Simple and rapid application development framework, built on top of Flask. includes detailed security, auto CRUD generation for your models, google charts and much more.
Last release 18 days ago
16 Sep 2026
Release timing varies
gaps range from 8 days to 3 months
Nearly every release is documented
notes for 59 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
13 years old
387 releases · first in 2013
Nothing published for this version
New, [deploy] Add release script
New, [deploy] Add release script
New, [i18n] Add italian translation (#1324)
New, [api] Add custom filters to search (#1327)
Fix, [style] Better formatting on jinja template (#1321)
New, [examples] integrate Dash by Plotly in FAB (#1330)
Fix, [api] [mvc] Make like filters case insensitive (#1338)
Nothing published for this version
One column per quarter.
[dependencies] Fix, marshmallow 3 breaks compat
[dependencies] Fix, marshmallow 3 breaks compat (#1333)
Nothing published for this version
New, [i18n] Add korean language
New, [i18n] Add korean language (#1297)
New, [api] support one to many relations (#1307)
Fix, [mvc] reverts select2 to version 3.5.2 (#1308)
Fix, [mvc] Upgrade to Jquery 3 and select2 4
Fix, [api] List filters validation schema (#1303)
Fix, [api] Soften marshmallow version restriction (#1295)
Fix, [mvc] GET delete and action endpoints (#1294)
Fix, [style] impose black code style (#1292)
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Fix, [docs] read the docs requirements
Fix, [docs] read the docs requirements (#1288)
New, [mvc] [security] toggle pvm, perm and vm mvc views config options (#1259)
Fix, [docs] Update actions.rst (#1277)
Fix, [docs] changelog formatting (#1286)
Fix, [mvc] Use os.path.join for downloads (#1281)
Fix, [filemanager] Fix, use a sane mode for directories (#1282)
Fix, [docs] add missing import (#1278)
Fix, [mvc] Use formatters_columns with show_fieldsets (#1280)
Nothing published for this version
Fix, [dependencies] update requirements
Fix, [dependencies] update requirements (#1272)
Fix, [dependencies] Update version of Flask-Babel to support Werkzeug 1.0 (#1266)
Fix, [api] set api jwt user on flask g (#1270)
Fix, [api] make REST API easier to override (#1264)
New, [auth] make CI optional (#1263)
New, [auth] make CI optional (#1263)
Fix, [api] many to many filters (#1256)
New, [api] override merge openapi docs specs (#1252)
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Fix, [mvc] List page's pagination start with 1
Fix, [mvc] List page's pagination start with 1 (#1216)
Fix, AttributeError in manager.py when a permission is null (#1217)
Fix, [api] using default method name when unspecified in method_permission_name (#1235)
New, [api] New, http 403 forbidden on default responses (#1237)
New, [mvc] [api] exclude and include route methods (#1234)
New, [mvc] [security] make userstatschartview optional (#1239)
New, [mvc] Disable old API flag and tests (#1244)
Fix, [mvc] jinja2 crashes with defined actions and removed action routes (#1245)
Nothing published for this version
Nothing published for this version
Nothing published for this version
Fix, [api] OpenAPI method and config exclusions
Fix, [api] OpenAPI method and config exclusions (#1211)
Fix, [mvc] default page size out of sync with jinja macro (#1209)
New, [api] Support for json encoded content on URI parameter (#1205)
Fix, [api] Re-allow filtering by booleans (default generated list) (#1204)
Fix, [api] [menu] openapi spec (#1203)
New, [api] Exclude route methods from ModelRestApi (#1202)
Fix, [api] Don't crash on invalid filters (#1200)
Fix, authentication error when using oracle (#1193)
Fix, [api] openapi spec for the info endpoint (#1197)
Fix, New, Show widget template: Add some basic blocks (#1158)
New, State reason for LDAP login failure (#1164)
Fix, [docs] Get list result (#1196)
Fix, [examples] Update views.py (#1165)
Fix, create filters even when search_columns is empty (#1173)
Fix, jwt refresh endpoint should return new access_token (#1187)
Nothing published for this version
Nothing published for this version
Nothing published for this version
Fix, #1157 Improve API get menu data performance
Fix, #1157 Improve API get menu data performance
Fix, #1143 [mvc] pagination UI bug
Fix, #1147 [babel] crash with empty LANGUAGES config key
New, #1116 Expose menu data as serializable objects
Fix, #1127 MSSQL issue with pagination
Fix, #1132 Add autofocus for login screen (#1132)
Fix, #1125 Support absence of the public role (#1125)
New, #1124 hide tabs when only 'Detail' (no related_views)
Fix, #1119 ldap: safely retrieve error object when loggin exception
Nothing published for this version
Nothing published for this version
Fix, #1105 Has access query fails on MySQL < 8
Fix, #1105 Has access query fails on MySQL < 8
Fix, #1104 Preserve custom property return type on ModelRestApi
Fix, #1104 Preserve custom property return type on ModelRestApi
Fix, #1096 Bootstrap and Bootswatch bump to 3.4.1
Fix, #1097 python version restriction on setup > 3.6 < 4
Fix, #1095 OAuth set fallback when next url in state is empty
Fix, #1092 Has access query fails on MSSQL
Fix, #1092 Has access query fails on MSSQL
Fix, #1079 Make it possible to override register_views when using FAB_ADD_SECURITY_VIEWS
Fix, #1079 Make it possible to override register_views when using FAB_ADD_SECURITY_VIEWS
Fix, #1078 API unlimited page size with unlimited max_page_size issues SQL with negative LIMIT
Fix, #1078 API unlimited page size with unlimited max_page_size issues SQL with negative LIMIT
Fix, #1077 API Info not translating labels and description
Fix, #1077 API Info not translating labels and description
Fix, #1069 API label_columns for get item returning labels for list columns
Fix, #1072 API max_page_size class property override for FAB_API_MAX_SIZE
Fix, #1065 setup version cap on apispec, jsonschema, marshmallow-sqlalchemy, prison
Fix, #1065 setup version cap on apispec, jsonschema, marshmallow-sqlalchemy, prison
Fix, #1050 Catch exceptions on populating forms
Fix, #1050 Catch exceptions on populating forms
Fix, #1046 API include openapi security spec on paths
Fix, #1048 API include refresh token on openapi security specs
Fix, #1045, #1044 Performance improvement on permission checks
New, #1040, #1041 Bump prison to 0.1.2 and remove requests dependency
New, #1040, #1041 Bump prison to 0.1.2 and remove requests dependency
Fix, #1042 is_item_visible confusing behaviour with base_permissions when perm is still on DB
Fix, #1027 API dotted notation joins to same table
Fix, #1027 API dotted notation joins to same table
Fix, #1012 API default resource name must be lower case
Fix, #1013 Use csrf exempt by default when CSRFProtect is registered has a Flask extension
Fix, #1007 API Support for property decorated functions has models fields
Fix, #1002 Permission mapping
New, #1010 Support for UUID sqlalchemy fields has string fields on WTForms
Fix, Index view override on class instantiation is discarded
Fix, Index view override on class instantiation is discarded
Fix, #993 App factory pattern, AppBuilder object can be fully configured using config keys
Fix, #993 App factory pattern, AppBuilder object can be fully configured using config keys
Fix, #994 If builtin role don't check db also, higher permission on DB would allow access
Fix, #991 Make Admin builtin optional, only if declared on config
Fix, #991 Make Admin builtin optional, only if declared on config
Fix, #985 Deprecation warning EOL version was wrong
New, #977 flask-sqlalchemy bump to 2.4.0 (new config options)
New, #986 Builtin roles using regex, Admin role is now one of these
New, #969 Override class and method permission names and procedure to converge/migrate
Fix, #985 Deprecation warning EOL version was wrong
New, #976 pRison version bump
Fix, #966 Change the default email value for auth_remote_user in security manager
BREAKING CHANGES, Python 3.6+ is now required
BREAKING CHANGES, Python 3.6+ is now required
Fix, #951 M-M fields are always required, now they default to not required with optional required flag on col info dict
Fix, #885 list view ordering problem of related model with dotted notation, fixes #884
Fix, #946 Factory app pattern
(DEPRECATION) New, command line integrated with Flask cli, fabmanager is deprecated and will be removed on 1.16.X
New, config key, FAB_SECURITY_MANAGER_CLASS to declare custom SecurityManager classes.
New, sub command 'create-permissions' to create all permissions when update_perms is False.
New, config key, FAB_UPDATE_PERMS to flag FAB to update or not update permissions.
Fix, #955 Find permission view menu superset issue #1944
Fix, new version location, removed deprecated imp package from setup
Nothing published for this version
New, CRUD RESTful API and custom API
New, CRUD RESTful API and custom API
Fix, #928 Copy role modal not showing
Fix, #928 Copy role modal not showing
Fix, #911 fabmanager missing session rollback() when user add fails
Fix, #911 fabmanager missing session rollback() when user add fails
Fix, #910 Next page on OAuth
Fix, #762 Instantiate AdminActions only after DOM finishes loading
Fix, #762 Instantiate AdminActions only after DOM finishes loading
New, #883 Changed templates so that is possible to use Jinja2 StrictUndefined
Fix, #891 Missing import reduce python3 compatibility
Fix, #862 fabmanager appbuilder parameter is now working
Fix, #832 don't install examples as a package with flask-appbuilder
Fix, #832 don't install examples as a package with flask-appbuilder
Fix, #760 Select all checkbox, in related view, selects checkboxes from all related views
New, #833 LDAPS TLS config options
New, #829 Aditional filtering in LDAP search
New, #813 Dependencies unpinned
New, #826 Greek support i18n
New, #813 Dependencies unpinned
Fix, #828 list and form widget rendering html InLine, regression from #797
New, #911 BREAKING CHANGES, bumped Flask-Login dependency to >=0.3,<0.5
Fix, #797 Remove safe filter from template
New, #911 BREAKING CHANGES, bumped Flask-Login dependency to >=0.3,<0.5
Fix, Unlock flask required version, new 0.12.4. does not cause issues anymore
Fix, Unlock flask required version, new 0.12.4. does not cause issues anymore
New, #615 Azure AD as Oauth provider
New, #615 Azure AD as Oauth provider
New, #678 fabmanager create-user command
Fix, #628 Remove double-instantiation of declarative base, problem with flask-migrate
New, #735 Added french translations
Fix, minor typo EMail to Email
Fix, #712 improvement on parsing timezone dates
Fix, #712 improvement on parsing timezone dates
Fix, #701 permission deletion
Fix, #700 Non unique associations on security models
New, #694 Accept SQLAlchemy custom types defined by TypeDecorator
New, #686 Removed support for python 2.6
Fix, #663 Allow remote user to be auto registered.
Fix, #663 Allow remote user to be auto registered.
New, #639 Composite key support for SQLAlchemy.
New, #661 Add feature to allow form to be processed prior to populating model.
New, #655 add feature to allow form prefill.
New, #655 add feature to allow form prefill.
New, #631 add sqlalchemy support for binary types.
New, #626 support for traditional Chinese.
New, #626 possible to disable update permissions on startup.
New, #596 font-awesome from 4.3 to 4.7.
New, #596 font-awesome from 4.3 to 4.7.
Fix, #544 for possible sql injection on order by clauses.
Fix, #544 for possible sql injection on order by clauses.
Fix, #550 check whether session_form_edit_pk still exist in db, on CompactCRUDMixin.
Fix, #553 for AttributeError when edit_columns on a view in related_views does not include relationship.
New, #562 Bump flask-babel version to 0.11.1, and pin.
Fix, #444 Create LDAP user firstname/lastname may return as bytes instead of str.
Fix, Fix divergence on versions between setup and requirements, pinned versions.
Your coding agent can read these notes before it upgrades. Set up the MCP server →