NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #175 most downloaded on PyPI
Safely pass data to untrusted environments and back.
Last release 2 years ago
no release in 18 months
Ships unpredictably
gaps range from 2 weeks to 4.6 years
Nearly every release is documented
notes for 22 of 24 stable releases
Nothing withdrawn
no release was ever pulled
15 years old
27 releases · first in 2011
This is a feature release, which includes new features, removes previously deprecated code, and adds new deprecations. The 2.2.x branch is now the sup…
This is a feature release, which includes new features, removes previously deprecated code, and adds new deprecations. The 2.2.x branch is now the supported fix branch, the 2.1.x branch will become a tag marking the end of support for that branch. We encourage everyone to upgrade, and to use a tool such as pip-tools to pin all dependencies and control upgrades. Test with warnings treated as errors to be able to adapt to deprecation warnings early.
Changes: https://itsdangerous.palletsprojects.com/en/2.2.x/changes/#version-2-2-0
Milestone: https://github.com/pallets/itsdangerous/milestone/8?closed=1
pyproject.toml instead of setup.cfg.flit_core instead of setuptools as build backend.__version__ attribute. Use feature detection, or importlib.metadata.version("itsdangerous"), instead.Serializer and the return type of dumps is generic for type checking. By default it is Serializer[str] and dumps returns a str. If a different serializer argument is given, it will try to infer the return type of its dumps method.hashlib.sha1 may not be available in FIPS builds. Don't access it at import time so the developer has time to change the default.One column per quarter.
Released 2024-04-16
Drop support for Python 3.7. 372
Use modern packaging metadata with pyproject.toml instead of setup.cfg. 326
Use flit_core instead of setuptools as build backend.
Deprecate the __version__ attribute. Use feature detection, or importlib.metadata.version("itsdangerous"), instead. 371
Serializer and the return type of dumps is generic for type checking. By default it is Serializer[str] and dumps returns a str. If a different serializer argument is given, it will try to infer the return type of its dumps method. 347
The default hashlib.sha1 may not be available in FIPS builds. Don't access it at import time so the developer has time to change the default. 375
Changes: https://itsdangerous.palletsprojects.com/en/2.1.x/changes/#version-2-1-2
Released 2022-03-24
Handle date overflow in timed unsign on 32-bit systems. 299
Changes: https://itsdangerous.palletsprojects.com/en/2.1.x/changes/#version-2-1-1
Released 2022-03-09
Handle date overflow in timed unsign. 296
Changes: https://itsdangerous.palletsprojects.com/en/2.1.x/changes/#version-2-1-0
Released 2022-02-17
Drop support for Python 3.6. 272
Remove previously deprecated code. 273
JWS functionality: Use a dedicated library such as Authlib instead.
import itsdangerous.json: Import json from the standard library instead.
Changes: https://itsdangerous.palletsprojects.com/en/2.0.x/changes/#version-2-0-1
Released 2021-05-18
Mark top-level names as exported so type checking understands imports in user projects. 240
The salt argument to Serializer and Signer can be None again. 237
New major versions of all the core Pallets libraries, including ItsDangerous 2.0, have been released! 🎉
New major versions of all the core Pallets libraries, including ItsDangerous 2.0, have been released! 🎉
This represents a significant amount of work, and there are quite a few changes. Be sure to carefully read the changelog, and use tools such as pip-compile and Dependabot to pin your dependencies and control your updates.
Released 2021-05-11
Drop support for Python 2 and 3.5.
JWS support (JSONWebSignatureSerializer, TimedJSONWebSignatureSerializer) is deprecated. Use a dedicated JWS/JWT library such as authlib instead. 129
Importing itsdangerous.json is deprecated. Import Python's json module instead. 152
Simplejson is no longer used if it is installed. To use a different library, pass it as Serializer(serializer=...). 146
datetime values are timezone-aware with timezone.utc. Code using TimestampSigner.unsign(return_timestamp=True) or BadTimeSignature.date_signed may need to change. 150
If a signature has an age less than 0, it will raise SignatureExpired rather than appearing valid. This can happen if the timestamp offset is changed. 126
BadTimeSignature.date_signed is always a datetime object rather than an int in some cases. 124
Added support for key rotation. A list of keys can be passed as secret_key, oldest to newest. The newest key is used for signing, all keys are tried for unsigning. 141
Removed the default SHA-512 fallback signer from default_fallback_signers. 155
Add type information for static typing tools. 186
Changes: https://itsdangerous.palletsprojects.com/en/master/changes/#version-2-0-0
Nothing published for this version
Nothing published for this version
Change default signing algorithm back to SHA-1. 113
Released 2018-10-26
Change default signing algorithm back to SHA-1. 113
Added a default SHA-512 fallback for users who used the yanked 1.0.0 release which defaulted to SHA-512. 114
Add support for fallback algorithms during deserialization to support changing the default in the future without breaking existing signatures. 113
Changed capitalization of packages back to lowercase as the change in capitalization broke some tooling. 113
Added a BadHeader exception that is used for bad headers that replaces the old BadPayload exception that was reused in those cases.
Released 2014-03-28
Added a BadHeader exception that is used for bad headers that replaces the old BadPayload exception that was reused in those cases.
Fixed a packaging mistake that caused the tests and license files to not be included.
Released 2013-08-08
Fixed a packaging mistake that caused the tests and license files to not be included.
Added support for TimedJSONWebSignatureSerializer.
Released 2013-07-03
Added support for TimedJSONWebSignatureSerializer.
Made it possible to override the signature verification function to allow implementing asymmetrical algorithms.
Fixed an issue on Python 3 which caused invalid errors to be generated.
Released 2013-05-26
Fixed an issue on Python 3 which caused invalid errors to be generated.
Fixed an incorrect call into want_bytes that broke some uses of ItsDangerous on Python 2.6.
Released 2013-05-23
Fixed an incorrect call into want_bytes that broke some uses of ItsDangerous on Python 2.6.
Dropped support for 2.5 and added support for 3.3.
Released 2013-05-21
Dropped support for 2.5 and added support for 3.3.
Added support for JSON Web Signatures (JWS).
Released 2013-05-03
Added support for JSON Web Signatures (JWS).
Fixed a name error when overriding the digest method.
Released 2012-08-10
Fixed a name error when overriding the digest method.
Made it possible to pass unicode values to load_payload to make it easier to debug certain things.
Released 2012-07-11
Made it possible to pass unicode values to load_payload to make it easier to debug certain things.
Made standalone load_payload more robust by raising one specific error if something goes wrong.
Released 2012-07-11
Made standalone load_payload more robust by raising one specific error if something goes wrong.
Refactored exceptions to catch more cases individually, added more attributes.
Fixed an issue that caused load_payload not work in some situations with timestamp based serializers
Added an loads_unsafe method.
API refactoring to support different key derivations.
Released 2012-06-29
API refactoring to support different key derivations.
Added attributes to exceptions so that you can inspect the data even if the signature check failed.
Small API change that enables customization of the digest module.
Released 2012-06-10
Small API change that enables customization of the digest module.
Fixed a problem with the local timezone being used for the epoch calculation. This might invalidate some of your signatures if you were not running in
Released 2012-02-22
Fixed a problem with the local timezone being used for the epoch calculation. This might invalidate some of your signatures if you were not running in UTC timezone. You can revert to the old behavior by monkey patching itsdangerous.EPOCH.
Released 2011-07-07 - Fixed an uncaught value error.
Released 2011-07-07
Fixed an uncaught value error.
Refactored interface that the underlying serializers can be swapped by passing in a module instead of having to override the payload loaders and dumpe
Released 2011-06-25
Refactored interface that the underlying serializers can be swapped by passing in a module instead of having to override the payload loaders and dumpers. This makes the interface more compatible with Django's recent changes.
Released 2011-06-25
Refactored interface that the underlying serializers can be swapped by passing in a module instead of having to override the payload loaders and dumpers. This makes the interface more compatible with Django’s recent changes.
Changes
Version 2.2.0
Version 2.1.2
Version 2.1.1
Version 2.1.0
Version 2.0.1
Version 2.0.0
Version 1.1.0
Version 1.0.0
Version 0.24
Version 0.23
Version 0.22
Version 0.21
Version 0.20
Version 0.19
Version 0.18
Version 0.17
Version 0.16
Version 0.15
Version 0.14
Version 0.13
Version 0.12
Version 0.11
Version 0.10
© Copyright 2011 Pallets. Created using Sphinx 8.2.3.
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →