Releases: plotly/dash
Releases · plotly/dash
Release list
Dash Version 4.5.0rc0
Added
- #3947 Make
plotly-clouda default install dependency of Dash instead of an optional extra, so theplotlyCLI and Dash's cloud integration work out of the box. Thedash[cloud]extra is kept for backward compatibility. - #3930 Add shared storage: a backend-agnostic cross-process state manager (key/value with optional TTL, plus ordered replayable pub/sub) on every app via
dash.ctx.shared_storage, started lazily and disabled withshared_storage=None. ShipsLocalSharedStorage(default, in-memory with optional disk persistence),DiskcacheSharedStorage, andRedisSharedStoragefor horizontally-scaled deployments; see.ai/ARCHITECTURE.md. - #3931 Add streaming callbacks: an
async defgenerator callback streams its yields to the browser as they are produced (dash.Patchyields apply incrementally). A browser's streams share one SharedWorker-hosted connection so they do not count against the per-host connection limit; closing a tab cancels its streams. - #3977 Add partial WebSocket prop reads with
get_prop(..., path=...). Closes #3975. - #3765 Add opt-in partial pattern matching for callback
Input,Output, andStateviapartial_pattern=True, so dictionary ID patterns can match component IDs with extra keys and combine withALL/MATCHwildcards. Fixes #3764. - #3646 Add experimental support for React 19 (default stays React 18.3.1); opt in with
REACT_VERSION=19.2.4ordash._dash_renderer._set_react_version("19.2.4"). Dash serves theumd-reactpackage with a compatibility shim so component libraries built against React <=18 keep working; see.ai/ARCHITECTURE.md. - #3925 Add optional callback request payload compression via
compress_payloadandcompress_thresholdcallback parameters (default threshold 5,000 bytes), sending gzip payloads that Dash decompresses on Flask, FastAPI, and Quart. Fixes #3924. - #3961 Added cursor position data (
xPixel,yPixel) todcc.GraphhoverDataandclickDatawhenhoveranywhereorclickanywhereis enabled in the figure. - #3960 Rewrite
dcc.Markdownanddcc.Linkas Typescript components - #3881 Added
dash.remount, a wrapper for a callback-returned component that forces the renderer to remount it (resetting its internal state) instead of reconciling in place: the explicit way to reset a stateful component from a callback without changing itsid.
Removed
- #3646 Remove React 16 support (
16.14.0is no longer an accepted value forREACT_VERSION/_set_react_version).
Changed
- #3986 Adjust
_run_before_hooksin thefastapibackend to honor a response returned by abefore_requestfunction, matching theflaskbackend's behavior.
Fixed
- #3944 Fix
dash.testingrunner backend detection for wrapped FastAPI/Quart servers so threaded Flask-only options are not passed to ASGI runners. - #3955 Unpin
seleniumin the testing requirements (was capped at<=4.2.0from 2022) and require>=4.11.0, so it can drive current stable Chrome via Selenium Manager and stop the widespread CI flakiness. - #3881 Speed up the renderer layout crawl (
crawlLayoutand its callers) by replacing curried-ramdapath/pathOrlookups with direct property access on the hot path: ~16% fasterPatch().append()into a large container, with no behavior change. - #3881 Fix pattern-matching (
MATCH/ALL/ALLSMALLER) callbacks getting quadratically slower as matching components grow; a new O(1) id->path index cuts anALLupdate over 400 components from ~580ms to ~140ms (~4x), with no app changes. - #3941 Fix the FastAPI and Quart backends opening a WebSocket connection on every page load even for apps with no WebSocket callbacks; the socket now opens only when actually needed. Fixes #3939.
- #3916 Fixed a regression where dragging multiple files into
dcc.Uploadwould upload only the first file whenmultiple=True - #3922 Fix
dcc.Input(type="number")stepper behavior when onlyminis set. - #3925 Use the proxied url as the Jupyter server url so
DASH_PROXYis honored by the external url and inline iframe in notebooks. - #3938 Fix
dcc.Patch()re-running the initial callbacks of components already on the page (including everyMATCH/ALLelement) and wiping their user-edited persisted values. Fixes #3681 and #3937 - #3960 Fix
dcc.Markdownnot rendering<dccLink />by using newer dependencies - #3846 Fix callback-returned children being unmounted and remounted on every update instead of reconciled in place, which reset component state and slowed large subtrees 3-4x (regression introduced in 4.2.0 by #3570); use
dash.remountto force a remount. - #3881 Fix components rendered as props (eg.
dcc.Dropdownoption labels,dcc.Tablabels) crashing or failing to update when the host subtree was replaced by a callback; out-of-treeExternalWrappercomponents now re-insert themselves and update in place. - #3929 Fix components that set their own initial state on mount (eg.
dash-bootstrap-componentsTabs) not applying it on first render, because descendant layout hashes were reset on the first fresh render (regression introduced in 4.2.0 by #3570). - #3948 Fix page getting progressively slower as callbacks append children
v4.4.1
Fixed
- #3902 Fix background callbacks trusting the client-supplied
job/oldJob/cancelJobandcacheKeyquery parameters verbatim, which let an unauthenticated client terminate an arbitrary process (withDiskcacheManager, by sending its PID) or read and delete arbitrary result-cache entries. ThecacheKey/jobhandles are now HMAC-signed by the server and bound to a per-page-load token, so forged or replayed values are rejected. Handles stay opaque to the renderer, so no app or callback code changes are required. - 3883 Fix callbacks being registered twice when running the app file as a script with a server that loads it by import string, e.g.
uvicorn.run("app:server", reload=True)withbackend="fastapi". The spawned worker re-executes the main module as__mp_main__and the import string then executed the same file a second time, duplicating every callback in_dash-dependenciesand triggeringDuplicate callback outputserrors in the renderer.Dash()now pre-registers the running main module insys.modulesunder its canonical import name so the second import reuses it instead of re-executing the file. Fixes #3818. - 3885 Fix Flask-WTF
CSRFProtect(and Quart-WTF) exemptions breaking after the backend refactor. The callback dispatch view is now exposed with the fully-qualified namedash.dash.dispatchagain, socsrf._exempt_views.add("dash.dash.dispatch")works as it did in Dash 4.1.0. Fixes #3827. - #3882 Fix
dcc.Graphuser interactions (pan, zoom, edited shapes & annotations, ...) being reverted by a subsequentPatchupdate, by syncing all relayout changes back to thefigureprop instead of only shapes. Fixes #3810. - #3903 Fix missing comm dependency, fix #3657.
- Updated radix-ui to fix #3786
v4.4.0
Added
- #3826 WebSocket callback dispatch no longer lets long-lived callbacks limit the number of concurrent users. Async callbacks (including session-persistent ones) run directly on the connection event loop instead of occupying a worker thread, and synchronous callbacks run on a shared
ThreadPoolExecutorwhose size is configurable via the newwebsocket_max_workersargument toDash(default4). A synchronous persistent (no-output) callback now warns at registration since it would tie up a worker thread.
Fixed
- #3861 Fix synchronous WebSocket callbacks not inheriting
ContextVarvalues bound by ASGI middleware.copy_context()is now captured on the event-loop thread before the callback is submitted to the thread pool, instead of inside the worker thread where only default values were visible. - #3779 Fix
dash.testingBrowser.get_logs()returningNoneon non-Chrome webdrivers, which broke assertions likeassert dash_duo.get_logs() == []. It now returns[], matching the Chrome code path. - #3822 Fix
UnboundLocalErrorforuser_callback_outputin async background callbacks (Celery and Diskcache managers) when the callback raisesPreventUpdateor another exception before the variable is assigned. - #3819 Fix
RuntimeError: No active request in contextwhen a non-Dash path falls through to the FastAPI catch-all route. Fixes #3812. - #3838 Replace
mcpdependency with inline types. - #3824 Fix
dash.testingThreadedRunner.stop()hanging at teardown for Quart apps. Fixes #3823. - #3425 dcc.DatePicker: Fix
updatemode="bothdates"not always respected
Changed
- Drop support for Python 3.8 (end-of-life since October 2024). The minimum supported version is now Python 3.9.
v4.3.0
Added
- #3796 MCP: Add
configure_mcp_server()to toggle which content the MCP server exposes (include_layout,include_callbacks,include_clientside_callbacks,include_pages,expose_callback_docstrings). Only the parameters explicitly passed are updated; omitted parameters retain their current value. - #3710 MCP: Framework utilities, types for interacting with layout
- #3711 MCP:
CallbackAdapterfor representing callback-related data in MCP-friendly format - #3712 MCP:
Resourcesfor exposing app layout, components, and pages - #3731 MCP: Expose callbacks as
Tools - #3747 MCP: Support pattern-matching callbacks in Tools
- #3748 MCP: Format callback results for LLM consumption (rendered graphs, markdown tables)
- #3749 MCP:
get_dash_componentTool and callback execution - #3750 MCP: Server routes,
mcp_enabledfunction decorator, and Streamable HTTP transport - #3766 MCP: Support background callbacks in Tools
Changed
- #3796 MCP: Remove the
mcp_expose_docstringsDash()constructor argument; callback docstring exposure is now controlled viaconfigure_mcp_server(expose_callback_docstrings=...).
Fixed
- #3817 Fix background callback context serialisation for non-dict request args on the FastAPI and Quart backends. Fixes #3816.
- #3805 Fix FastAPI POST routes deadlock caused by middleware consuming request body. Fixes #3801.
- #3813 Fix websockets using incorrect path when deployed behind a proxy
- #3830 MCP: Respond to the Streamable HTTP
GET(SSE) request with an empty event stream instead of405 Method Not Allowed
v4.2.0
[4.2.0] - 2026-06-01 - The Freedom Update
This release marks a major milestone for Dash, bringing unprecedented flexibility to how you build and deploy your applications.
🚀 Multiple Backend Support
Dash is no longer tied to Flask. You can now run your Dash apps on FastAPI or Quart, or even bring your own backend implementation:
# FastAPI backend
app = Dash(__name__, backend="fastapi")
# Quart backend (async-native)
app = Dash(__name__, backend="quart")
# Or use an existing server
from fastapi import FastAPI
server = FastAPI()
app = Dash(__name__, server=server)Install with pip install dash[fastapi] or pip install dash[quart].
⚡ Websocket Callbacks
Real-time, bidirectional communication is here. Websocket callbacks enable persistent connections for live updates without polling:
@callback(
Output("live-output", "children"),
Input("trigger", "n_clicks"),
websocket=True,
persistent=True
)
def live_updates(n_clicks):
ws = ctx.websocket
while True:
data = fetch_live_data()
ws.send(Output("live-output", "children", data))
time.sleep(1)🔓 Relaxed Pattern Matching Rules
MATCH wildcards are now allowed in Input and State even when your Output has no wildcards, making dynamic UIs simpler to build:
@callback(
Output("summary", "children"), # Fixed ID output
Input({"type": "item", "index": MATCH}, "value") # MATCH input - now allowed!
)
def update_summary(value):
return f"Selected: {value}"Added
- #3783 Add batching/debouncing for websocket
set_propsmessages to reduce lag when updating multiple components in a loop. Configurable viawebsocket_batch_delay(default 5ms, set to 0 to disable). - #3669 Selection for DataTable cleared with custom action settings.
- #3680 Added
search_orderprop toDropdownto allow users to preserve original option order during search. - #3745 Added
csrf_token_nameandcsrf_header_nameconfig options to allow configuring the CSRF cookie and header names. Fixes #729. - #3797 Improved websocket callback management with heartbeat configuration and proper reconnection handling.
- #3523 Fall back to background callback function names if source cannot be found.
- #3771 Add persistent callbacks and no inputs/no outputs callback support.
- #3742 Add websocket callbacks to fastapi and quart backends.
- #3737 Add
displayNotifiertodcc.Graphconfig props.
Changed
- #3746 Improve static typing for
dash.callbackby preserving wrapped callback signatures, and add callback typing coverage in compliance plus new callback decorator unit and integration tests. Fixes #3691. - Rename
ctx.get_websockettoctx.websocket. - Add threadpool for running websocket callbacks.
Fixed
- #3690 Fix
dcc.Inputwhen min or max is set to None. - #3723 Fix misaligned
dcc.Slidermarks when some labels are empty strings. - #3738 Add missing
stacklevel=2towarnings.warn()calls so warnings report the caller's location instead of internal Dash source lines. - #3740 Fix cannot tab into dropdowns in Safari.
- #3756 Allow
MATCHinInput/Statewhen the callback'sOutputhas no wildcards (fixed-id Output, no Output, orALL-only wildcard Output).ALLSMALLERstill requires a correspondingMATCHin an Output. Fixes #2462. - #3768 Improved
Dropdownsearch performance for large options lists. - #3759 Fix the issue where
Patchobjects cannot be updated viaset_props()inwebsocketcallback. Fix #3742. - #3789 Fixed extra wrapper in
DatePickerRangeandDatePickerSinglecausing styling and layout issues. - #3799 Fixed dropdown crash when filtering large datasets with component-based labels by using stable item keys for virtualized rows.
- #3785 Fix patch with
dcc.Graphfigure. Fixdcc.Graphnot sending duplicate clicks because it had the same payload by adding a timestamp in the click event object. - #3798 Fix blueprint registering and double init when using
flask runcommand. Fixes #3787. - #3734 Fix websocket used in the same FastAPI server. Fixes #3636.
- #3668 Fix FastAPI url paths order. Fixes #3667.
- #3641 Fix
dcc.Loadingspinner not triggering when callbackOutputuses theALLwildcard. Fixes #3619. - #3570 Fix components not remounting when passed from a parent object. Fixes #3330.
v4.3.0rc0
Added
- #3710 MCP: Framework utilities, types for interacting with layout
- #3711 MCP:
CallbackAdapterfor representing callback-related data in MCP-friendly format - #3712 MCP:
Resourcesfor exposing app layout, components, and pages - #3731 MCP: Expose callbacks as
Tools - #3747 MCP: Support pattern-matching callbacks in Tools
- #3748 MCP: Format callback results for LLM consumption (rendered graphs, markdown tables)
- #3749 MCP:
get_dash_componentTool and callback execution - #3750 MCP: Server routes,
mcp_enabledfunction decorator, and Streamable HTTP transport - #3766 MCP: Support background callbacks in Tools