Tags: CodingCossack/openapi-python-client
Tags
Release 0.29.1 (openapi-generators#1460) > [!IMPORTANT] > Merging this pull request will create this release ## 🚨Security ### Arbitrary code generation vulnerability Prior to this release, malicious OpenAPI documents could cause openapi-python-client to generate arbitrary code, which would then be executed by consumers of the generated client. If you generate code from OpenAPI documents you don't control, you should upgrade to this release as **soon as possible** and validate any previously-generated code. See [the GitHub advisory](GHSA-5293-mq8x-g3xj) for more details. ## 🚀 Features - Update `uv_build` to 0.12 when using `--meta=uv` (openapi-generators#1473) ## 🐛 Fixes - Apply PEP 639 for improved license metadata (openapi-generators#1459) - update generated code to use `StrEnum` and `-> Self` (openapi-generators#1474) - Remove trailing spaces in README example code (openapi-generators#1475) - Stopped generating empty docstrings for models with no description ### Fixed invalid Python identifiers when resolving naming conflicts When two property or parameter names conflicted after conversion to `snake_case` (e.g. `foo-bar` and `fooBar`), the conflict-resolution path preserved delimiters like `-`, `.`, and spaces in the generated Python identifiers, producing invalid code which failed generation. Conflicting names now keep their original casing but have any characters which are invalid in Python identifiers stripped (e.g. `foobar` and `fooBar`). ### Improve readability of error messages Errors and warnings which include a snippet of your OpenAPI document now render that snippet as JSON, making them much easier to read. ## 📝Notes ### Breaking changes for all custom templates **ALL** custom templates are expected to break with this version as a result of the security fix. 1. The `utils` global has been renamed to `strings` 2. Most string values can no longer be rendered directly into templates, you must describe how the value is being used so it can be properly escaped using either a Python function or Jinja filter: 1. `strings.snake_case()` / `| snakecase` (existing) 2. `strings.kebab_case()` / `| kebabcase` (existing) 3. `strings.pascal_case()` / `| pascalcase` (existing) 4. `python_identifier()` (existing) 5. `class_name()` (existing) 6. `strings.safe_for_docstring()` / `| safe_for_docstring` for values which get injected into a `"""` docstring 7. `strings.in_f_string_literal()` / `| in_f_string_literal` for values that go into `f""` f-strings 8. `strings.in_double_quote_literal()` / `| in_double_quote_literal` for values that go into **non-f-string** `""` literals 9. `.as_unembedded_code()` / `| as_unembedded_code` ONLY for `PythonCode` values—those that are intended to be Python code which is not embedded into any string/docstring. Examples include usages of `.python_code`, `.get_type_string()`, `.get_instance_type_string()`, `.get_type_strings_in_union()`. You *should not* assume these values are safe to put in docstrings, string literals, or f-string literals. Use the dedicated helpers for those. As always, you can check the diff of the built in templates for examples. You will also want to check generated output for "UntrustedString", which is how any string now requiring one of those functions will appear. ### Many control characters now stripped from string literals Out of an abundance of caution, most Unicode control characters are now stripped from string literals. If your API uses control characters as part of const values, enums, or JSON body property names you may have issues with this new version. Most APIs are not expected to be affected by this change. Co-authored-by: knope-bot[bot] <152252888+knope-bot[bot]@users.noreply.github.com>
Release 0.29.0 (openapi-generators#1439) > [!IMPORTANT] > Merging this pull request will create this release ## Breaking Changes - Drop support for Python 3.10 - Raise minimum httpx version to 0.23.1 ## Features - replace python-dateutil with stdlib datetime.fromisoformat (openapi-generators#1429) ## Fixes - Remove some generated casts that aren't necessary with mypy v2 (openapi-generators#1436) - Explicitly set boundary for multipart/form-data (openapi-generators#1005) Co-authored-by: knope-bot[bot] <152252888+knope-bot[bot]@users.noreply.github.com>
Release 0.28.4 (openapi-generators#1408) > [!IMPORTANT] > Merging this pull request will create this release ## Features - Update `uv_build` to 0.11 when using `--meta=uv` (openapi-generators#1434) ### Add support for x-enum-varnames to string enums openapi-generators#1358 by @mbbush You can now customize the variable names of the generated string enumerations using the x-enum-varnames openapi extension. Previously, this was only possible for integer enumerations. Co-authored-by: knope-bot[bot] <152252888+knope-bot[bot]@users.noreply.github.com>
Release 0.28.3 (openapi-generators#1401) > [!IMPORTANT] > Merging this pull request will create this release ## Fixes - sort remaining lazy imports in model template (openapi-generators#1400) Co-authored-by: knope-bot[bot] <152252888+knope-bot[bot]@users.noreply.github.com>
Release 0.28.2 (openapi-generators#1398) > [!IMPORTANT] > Merging this pull request will create this release ## Features - Update `uv_build` 0.10 when using `--meta=uv` (openapi-generators#1396) Co-authored-by: knope-bot[bot] <152252888+knope-bot[bot]@users.noreply.github.com>
Release 0.28.1 (openapi-generators#1385) > [!IMPORTANT] > Merging this pull request will create this release ## Fixes - Apply required overrides from allOf schemas (openapi-generators#1384) - Sort lazy imports to increase stability of generated code (openapi-generators#1378) Co-authored-by: knope-bot[bot] <152252888+knope-bot[bot]@users.noreply.github.com>
Release 0.28.0 (openapi-generators#1368) > [!IMPORTANT] > Merging this pull request will create this release ## Breaking Changes - URL-encode path parameters in generated endpoints (openapi-generators#1349) ## Fixes ### Fix bad code generation openapi-generators#1360 by @EricAtORS This fixes: - missing parenthesis in to_multipart openapi-generators#1338 openapi-generators#1318 - missing imports in the lazy eval in to_multipart: openapi-generators#931 and openapi-generators#1051 ### Fix optional bodies If a body is not required (the default), it will now: 1. Have `Unset` as part of its type annotation. 2. Default to a value of `UNSET` 3. Not be included in the request if it is `UNSET` Thanks @orelmaliach for the report! Fixes openapi-generators#1354 Co-authored-by: knope-bot[bot] <152252888+knope-bot[bot]@users.noreply.github.com>
Release 0.27.1 (openapi-generators#1345) > [!IMPORTANT] > Merging this pull request will create this release ## Fixes - Remove non-existent CHANGELOG.md references from UV and Poetry templates (openapi-generators#1344) - Initialize optional lists as UNSET, not [] (openapi-generators#1346) - Correct docstring typos in client template (openapi-generators#1347) - Replace bare except blocks with specific exception types (openapi-generators#1348) ### Update `uv_build` to 0.9 openapi-generators#1352 by @johnthagen `uv` has been in the `0.9.x` release cycle for a while, so update templates to use the corresponding `uv_build` range. Co-authored-by: knope-bot[bot] <152252888+knope-bot[bot]@users.noreply.github.com>
Release 0.27.0 (openapi-generators#1330) > [!IMPORTANT] > Merging this pull request will create this release ## Breaking Changes ### Drop support for Python 3.9 Both `openapi-python-client` itself and any generated clients no longer support Python 3.9. ### Generated models now use `from __future__ import annotations` This simplifies using forward references with the newer union syntax. ## Features ### Upgrade generated clients to 3.10 union syntax All generated types now use the `A | B` syntax instead of `Union[A, B]` or `Optional[A]`. ## Fixes - Drop generated `requires-python` upper bounds for uv and PDM (openapi-generators#1329) ### Change default Ruff hook to `--fix-only` This should enable `openapi-python-client` to keep auto-fixing lints (like removing unused imports) but _not_ fail to generate when unfixable lints are violated. Since it's now unlikely for breaking changes to affect our usage (and by popular request), the upper bound of `ruff` has been lifted. Newer versions of `openapi-python-client` should no longer be required to support newer versions of `ruff`. ## Notes - Minimum Typer version is now 0.16 Co-authored-by: knope-bot[bot] <152252888+knope-bot[bot]@users.noreply.github.com>
Release 0.26.2 (openapi-generators#1322) > [!IMPORTANT] > Merging this pull request will create this release ## Fixes - ambigious tilde specifier requires-python with`--meta=uv` (openapi-generators#1321) Co-authored-by: knope-bot[bot] <152252888+knope-bot[bot]@users.noreply.github.com>
PreviousNext