Skip to content

chore(deps): update dependency asgiref to v3.12.1 - #5549

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/asgiref-3.x
Open

chore(deps): update dependency asgiref to v3.12.1#5549
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/asgiref-3.x

Conversation

@renovate

@renovate renovate Bot commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
asgiref (changelog) ==3.7.2==3.12.1 age confidence

Release Notes

django/asgiref (asgiref)

v3.12.1

Compare Source

  • Restored the previous SyncToAsync.call internal code shape, which was
    relied on by some APM services. (#​572)

    Note, this change was available whilst maintaining the underlying fix (from
    #​564). It does not constitute an API stability promise. Ideally APMs are
    not monkey patching internal APIs, and future changes will be made here if
    needed.

v3.12.0

Compare Source

  • AsyncToSync no longer captures the running event loop on
    instantiation. (#​562)

    This resolves a series of deadlocks that users experienced after asgiref 3.9.0,
    particularly with pytest-asyncio. pytest-asyncio stops the event loop between
    tests, and long-running unawaited futures could find themselves trying to
    schedule work onto a stopped loop, and so would never complete. Ideally, code
    should be structured to await long-running futures before returning, but this
    change should help users experiencing issues here.

    The loop is now resolved when the callable is invoked rather than when it is
    created. If async_to_sync is called from within sync_to_async, the
    parent event loop is still used, as before.

    The possibility of deadlock therefore remains in some nested patterns. For
    example, an async function may call a long-running sync_to_async function
    that itself uses async_to_sync; if the outer function returns before the
    sync future completes, the parent event loop may already be stopped, and the
    nested calls cannot be driven to completion.

    This is not a bug in asgiref — the same patterns deadlock in plain asyncio. As
    above, restructure your code to await the sync_to_async future before
    exiting the driving coroutine.

  • Fixed an event loop deadlock when exiting ThreadSensitiveContext
    while its executor thread was still blocked waiting on the event loop.
    (#​535)

  • Dropped support for EOL Python 3.9.

  • Fixed StatelessServer.run() failing on Python 3.14, where
    asyncio.get_event_loop() no longer creates an event loop if none
    exists. It now uses asyncio.run(). (#​559)

  • Fixed Local leaking data between unrelated sync threads when
    sys.flags.thread_inherit_context is enabled (Python 3.14+), so a newly
    started thread inherits a copy of the spawning thread's context. This flag is
    on by default on free-threaded builds and opt-in on the regular GIL build.
    Local storage is now tagged with its owning thread and re-homed only when
    asgiref intentionally moves work across threads (in async_to_sync /
    sync_to_async), restoring the documented thread-local behaviour in sync
    threads.

  • asgiref is now tested against the free-threaded builds of Python 3.13 and
    3.14 in CI.

  • The tests extra no longer installs mypy; a new mypy extra is
    available for type-checking the codebase.

v3.11.1

Compare Source

  • SECURITY FIX CVE-2025-14550: There was a potential DoS vector for users of
    the asgiref.wsgi.WsgiToAsgi adapter. Malicious requests, including an unreasonably
    large number of values for the same header, could lead to resource exhaustion
    when building the WSGI environment.

    To mitigate this, the algorithm is changed to be more efficient, and
    WsgiToAsgi gains a new optional duplicate_header_limit parameter,
    which defaults to 100. This specifies the number of times a single header may
    be repeated before the request is rejected as malformed.

    You may override duplicate_header_limit when configuring your application::

    application = WsgiToAsgi(wsgi_app, duplicate_header_limit=200)
    

    Set duplicate_header_limit=None if you wish to disable this check.

  • Fixed a regression in 3.11.0 in sync_to_async when wrapping a callable
    with an attribute named context. (#​537)

v3.11.0

Compare Source

  • sync_to_async gains a context parameter, similar to those for
    asyncio.create_task, TaskGroup &co, that can be used on Python 3.11+ to
    control the context used by the underlying task.

    The parent context is already propagated by default but the additional
    control is useful if multiple sync_to_async calls need to share the same
    context, e.g. when used with asyncio.gather().

v3.10.0

Compare Source

  • Added AsyncSingleThreadContext context manager to ensure multiple AsyncToSync
    invocations use the same thread. (#​511)

v3.9.2

Compare Source

  • Adds support for Python 3.14.

  • Fixes wsgi.errors file descriptor in WsgiToAsgi adapter.

v3.9.1

Compare Source

  • Fixed deletion of Local values affecting other contexts. (#​523)

  • Skip CPython specific garbage collection test on pypy. (#​521)

v3.9.0

Compare Source

  • Adds support for Python 3.13.

  • Drops support for (end-of-life) Python 3.8.

  • Fixes an error with conflicting kwargs between AsyncToSync and the wrapped
    function. (#​471)

  • Fixes Local isolation between asyncio Tasks. (#​478)

  • Fixes a reference cycle in Local (#​508)

  • Fixes a deadlock in CurrentThreadExecutor with nested async_to_sync →
    sync_to_async → async_to_sync → create_task calls. (#​494)

  • The ApplicationCommunicator testing utility will now return the task result
    if it's already completed on send_input and receive_nothing. You may need to
    catch (e.g.) the asyncio.exceptions.CancelledError if sending messages to
    already finished consumers in your tests. (#​505)

v3.8.1

Compare Source

  • Fixes a regression in 3.8.0 affecting nested task cancellation inside
    sync_to_async.

v3.8.0

Compare Source

  • Adds support for Python 3.12.

  • Drops support for (end-of-life) Python 3.7.

  • Fixes task cancellation propagation to subtasks when using synchronous Django
    middleware.

  • Allows nesting sync_to_async via asyncio.wait_for.

  • Corrects WSGI adapter handling of root path.

  • Handles case where "client" is None in WsgiToAsgi adapter.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "before 8am on Monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added dependencies Pull requests that update a dependency file Skip Changelog PRs that do not require a CHANGELOG.md entry labels Aug 14, 2026
@renovate
renovate Bot requested a review from a team as a code owner August 14, 2026 15:53
@renovate renovate Bot added Skip Changelog PRs that do not require a CHANGELOG.md entry dependencies Pull requests that update a dependency file labels Aug 14, 2026
@opentelemetry-pr-dashboard

opentelemetry-pr-dashboard Bot commented Aug 14, 2026

Copy link
Copy Markdown

Pull request dashboard status

Waiting on reviewers · refreshed 2026-08-21 19:45 UTC

Review the latest changes.

Also blocked by: 1 required status check is failing.

Status above doesn't look right?
  • Just replied or pushed? Anything around or after the refresh time above may not be picked up yet — give it a few minutes.
  • Anything look wrong? Report it with what you expected; it helps us improve the dashboard.

@renovate
renovate Bot force-pushed the renovate/asgiref-3.x branch 10 times, most recently from e8c74fc to 8bed5ed Compare August 21, 2026 14:55
@renovate
renovate Bot force-pushed the renovate/asgiref-3.x branch from 8bed5ed to bafa626 Compare August 21, 2026 19:35
@renovate
renovate Bot force-pushed the renovate/asgiref-3.x branch from bafa626 to f0aa3c8 Compare August 21, 2026 19:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file Skip Changelog PRs that do not require a CHANGELOG.md entry

Projects

Status: No status

Development

Successfully merging this pull request may close these issues.

0 participants