NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #46 most downloaded on PyPI
The little ASGI library that shines.
Last release 6 days ago
23 Sep 2026
Ships fairly regularly
a new release about every 6 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
2 versions withdrawn
withdrawn after publishing
8 years old
203 releases · first in 2018
Add *args to Middleware and improve its type hints #2381.
*args to Middleware and improve its type hints #2381.Iterable instead Iterator on iterate_in_threadpool #2362.root_path to keep compatibility with mounted ASGI applications and WSGI #2400.scope["client"] to None on TestClient #2377.Full Changelog: https://github.com/encode/starlette/compare/0.34.0...0.35.0
Deprecate FileResponse(method=...) parameter #2366.
One column per quarter.
FileResponse(method=...) parameter #2366.Full Changelog: https://github.com/encode/starlette/compare/0.33.0...0.34.0
Add middleware per Route/WebSocketRoute #2349.
Revert mkdocs-material from 9.1.17 to 9.4.7 #2326.
Send reason on WebSocketDisconnect #2309.
Fix import error when exceptiongroup isn't available #2231.
Officially support Python 3.12 #2214.
### Removed * Drop Python 3.7 support #2178.
Add follow_redirects parameter to TestClient #2207.
follow_redirects parameter to TestClient #2207.__str__ to HTTPException and WebSocketException #2181.lifespan together with on_startup/on_shutdown #2193.Host to generate the OpenAPI schema #2183.request argument to TemplateResponse #2191.body_stream in case more_body=False on BaseHTTPMiddleware #2194.Full Changelog: https://github.com/encode/starlette/compare/0.28.0...0.29.0
Add env parameter to Jinja2Templates, and deprecate env_options #2159.
Request's body buffer for call_next in BaseHTTPMiddleware #1692.Route #2026.env parameter to Jinja2Templates, and deprecate **env_options #2159.httpx is not installed #2177.templates url_for() #2127.Full Changelog: https://github.com/encode/starlette/compare/0.27.0...0.28.0
This release fixes a path traversal vulnerability in StaticFiles. You can view the full security advisory: https://github.com/encode/starlette/securit…
This release fixes a path traversal vulnerability in StaticFiles. You can view the full security advisory:
https://github.com/encode/starlette/security/advisories/GHSA-v5gw-mw7f-84px
send_json https://github.com/encode/starlette/pull/2128commonprefix by commonpath on StaticFiles 1797de4.Full Changelog: https://github.com/encode/starlette/compare/0.26.1...0.27.0
Fix typing of Lifespan to allow subclasses of Starlette #2077.
Replace reference from Events to Lifespan on the mkdocs.yml #2072.
Deprecate on_startup and on_shutdown events #2070.
url_for signature to return a URL instance #1385.url_for() and url_path_for() #2050.on_startup and on_shutdown events #2070.Full Changelog: https://github.com/encode/starlette/compare/0.25.0...0.26.0
Limit the number of fields and files when parsing multipart/form-data on the MultipartParser 8c74c2c and #2036.
Allow StaticFiles to follow symlinks #1683.
StaticFiles to follow symlinks #1683.Request.form() as a context manager #1903.size attribute to UploadFile #1405.env_prefix argument to Config #1990.str and datetime on expires parameter on the Response.set_cookie method #1908.file argument required on UploadFile #1413.URL.replace #1965.Only stop receiving stream on body_stream if body is empty on the BaseHTTPMiddleware #1940.
body_stream if body is empty on the BaseHTTPMiddleware #1940.Deprecate Starlette and Router decorators #1897.
Bypass GZipMiddleware when response includes Content-Encoding #1901.
This release replaces the underlying HTTP client used on the TestClient (requests :arrow_right: httpx), and as those clients differ _a bit_ on their A
This release replaces the underlying HTTP client used on the TestClient (requests :arrow_right: httpx), and as those clients differ a bit on their API, your test suite will likely break. To make the migration smoother, you can use the bump-testclient tool.
requests with httpx in TestClient #1376.WebSocketException and support for WebSocket exception handlers #1263.middleware parameter to Mount class #1649.__repr__ for route classes #1864.BackgroundTasks were cancelled when using BaseHTTPMiddleware and client disconnected #1715.Remove converter from path when generating OpenAPI schema #1648.
Revert "Allow StaticFiles to follow symlinks" #1681.
StaticFiles to follow symlinks" #1681.Fix regression on route paths with colons #1675.
Improve detection of async callables #1444.
Drop Python 3.6 support #1357 and #1616.
Deprecate WS_1004_NO_STATUS_RCVD and WS_1005_ABNORMAL_CLOSURE in favor of WS_1005_NO_STATUS_RCVD and WS_1006_ABNORMAL_CLOSURE, as the previous constan…
Route.name when created from methods #1553.TypeError on websocket.disconnect when code is None #1574.WS_1004_NO_STATUS_RCVD and WS_1005_ABNORMAL_CLOSURE in favor of WS_1005_NO_STATUS_RCVD and WS_1006_ABNORMAL_CLOSURE, as the previous constants didn't match the WebSockets specs #1580.Deprecate WSGIMiddleware in favor of a2wsgi #1504.
headers parameter to HTTPException #1435.405 status code insert an Allow header, as described by RFC 7231 #1436.content argument in JSONResponse is now required #1431.FileResponse #1266.raw_path to TestClient scope #1445.MutableHeaders #1240.anyio required version range to >=3.4.0,<5.0 #1421 and #1460.typing-extensions>=3.10 requirement - used only on lower versions than Python 3.10 #1475.BaseHTTPMiddleware from hiding errors of StreamingResponse and mounted applications #1459.SessionMiddleware uses an explicit path=..., instead of defaulting to the ASGI 'root_path' #1512.Request.client is now compliant with the ASGI specifications #1462.KeyError at early stage for missing boundary #1349.Change default chunk size from 4Kb to 64Kb on FileResponse #1345.
FileResponse #1345.functools.partial in WebSocketRoute #1356.StaticFiles packages with directory #1350.Jinja2Templates #1401.HttpEndpoint #1346.websocket.accept message #1361 and #1422.reason to WebSocket close ASGI event #1417.UploadFile #1382.Content-Length header for Content-Length: 0 cases #1395.SessionMiddleware.max_age now accepts None, so cookie can last as long as the browser session #1387.hashlib.md5() function on FileResponses ETag generation. The parameter usedforsecurity flag is set to False, if the flag is available on the system. This fixes an error raised on systems with FIPS enabled #1366 and #1410.path_params type on url_path_for() method i.e. turn str into Any #1341.Host now ignores port on routing #1322.Fix IndexError in authentication requires when wrapped function arguments are distributed between *args and kwargs #1335.
IndexError in authentication requires when wrapped function arguments are distributed between *args and **kwargs #1335.Response.delete_cookie now accepts the same parameters as Response.set_cookie #1228.
Response.delete_cookie now accepts the same parameters as Response.set_cookie #1228.Jinja2Templates constructor to allow PathLike #1292.HTTPConnection.__getitem__ return type from str to typing.Any #1118.ImmutableMultiDict.getlist return type from typing.List[str] to typing.List[typing.Any] #1235.OSError exceptions on StaticFiles #1220.StaticFiles 404.html in HTML mode #1314.Passing an Async Generator Function or a Generator Function to starlette.router.Router(lifespan_context=) is deprecated. You should wrap your lifespan…
starlette.websockets.WebSocket instances are now hashable and compare by identity
#1039starlette.templates.Jinja2Templates.get_env was removed
#1218starlette.testclient.TestClient.async_backend was removed,
the backend is now configured using constructor kwargs
#1211starlette.router.Router(lifespan_context=) is deprecated. You should wrap your lifespan in @contextlib.asynccontextmanager.
#1227
#1110Another significant change with this release is the deprecation of built-in GraphQL support.
This release includes major changes to the low-level asynchronous parts of Starlette. As a result, Starlette now depends on AnyIO and some minor API changes have occurred. Another significant change with this release is the deprecation of built-in GraphQL support.
TestClient.websocket_connect() now must be used as a context manager.GZipMiddleware is now adjustable - #1128.CORSMiddleware. See #1111, #1112, #1113, #1199.RedirectResponse now uses quote instead of quote_plus encoding for the Location header to better match the behaviour in other frameworks such as Django - #1164.BaseHTTPMiddleware when handling large responses - #1012 fixed via #1157GraphQLApp class has been deprecated and will be removed in a future release. Please see #619. GraphQL is not supported on Python 3.10.executor parameter to GraphQLApp was removed. Use executor_class instead.workers parameter to WSGIMiddleware was removed. This hasn't had any effect since Starlette v0.6.3.Fixed ServerErrorMiddleware compatibility with Python 3.9.1/3.8.7 when debug mode is enabled - #1132.
UJSONResponse was removed (this change was intended to be included in 0.14.0). Please see the documentation for how to implement responses using custo
UJSONResponse was removed (this change was intended to be included in 0.14.0). Please see the documentation for how to implement responses using custom JSON serialization - #1074.Starlette now officially supports Python3.9.
StreamingResponse, allow custom async iterator such as objects from classes implementing __aiter__.functools.partial async handlers in Python versions 3.6 and 3.7.asyncio.wait.format_exception instead of format_tb in ServerErrorMiddleware's debug responses.requires decorator.Revert Queue(maxsize=1) fix for BaseHTTPMiddleware middleware classes and streaming responses.
Revert Queue(maxsize=1) fix for BaseHTTPMiddleware middleware classes and streaming responses.
The StaticFiles constructor now allows pathlib.Path in addition to strings for its directory argument.
Fix high memory usage when using BaseHTTPMiddleware middleware classes and streaming responses.
Fix 404 errors with StaticFiles.
StaticFiles.Add support for Starlette(lifespan=...) functions.
Starlette(lifespan=...) functions.More lenient cookie parsing. #900
Nothing published for this version
Nothing published for this version
Nothing published for this version
Switch to promoting application configuration on init style everywhere. This means dropping the decorator style in favour of declarative routing table
Nothing published for this version
Fix request.url_for() for the Mount-within-a-Mount case.
Fix request.url_for() when an ASGI root_path is being used.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Add URL.include_query_params(kwargs)
Add URL.include_query_params(**kwargs)
Add URL.replace_query_params(**kwargs)
Add URL.remove_query_params(param_names)
request.state properly persisting across middleware.
Added request.scope interface.
Add StaticFiles(html=True) support.
Switch to ASGI 3.0.
Fixes to CORS middleware.
Add StaticFiles(html=True) support.
Fix path quoting in redirect responses.
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →