From 5c8a9a4fa792f8b18bd26bc7a8335e3bbe837852 Mon Sep 17 00:00:00 2001 From: Ben Darnell Date: Thu, 10 Aug 2023 22:38:19 -0400 Subject: [PATCH] Set version to 6.3.3 --- docs/releases.rst | 1 + docs/releases/v6.3.3.rst | 12 ++++++++++++ tornado/__init__.py | 4 ++-- 3 files changed, 15 insertions(+), 2 deletions(-) create mode 100644 docs/releases/v6.3.3.rst diff --git a/docs/releases.rst b/docs/releases.rst index fc7e41654f..076ac86331 100644 --- a/docs/releases.rst +++ b/docs/releases.rst @@ -4,6 +4,7 @@ Release notes .. toctree:: :maxdepth: 2 + releases/v6.3.3 releases/v6.3.2 releases/v6.3.1 releases/v6.3.0 diff --git a/docs/releases/v6.3.3.rst b/docs/releases/v6.3.3.rst new file mode 100644 index 0000000000..7fe0110fda --- /dev/null +++ b/docs/releases/v6.3.3.rst @@ -0,0 +1,12 @@ +What's new in Tornado 6.3.3 +=========================== + +Aug 11, 2023 +------------ + +Security improvements +~~~~~~~~~~~~~~~~~~~~~ + +- The ``Content-Length`` header and ``chunked`` ``Transfer-Encoding`` sizes are now parsed + more strictly (according to the relevant RFCs) to avoid potential request-smuggling + vulnerabilities when deployed behind certain proxies. diff --git a/tornado/__init__.py b/tornado/__init__.py index 475c1f612e..c2a8f25b43 100644 --- a/tornado/__init__.py +++ b/tornado/__init__.py @@ -22,8 +22,8 @@ # is zero for an official release, positive for a development branch, # or negative for a release candidate or beta (after the base version # number has been incremented) -version = "6.3.2" -version_info = (6, 3, 2, 0) +version = "6.3.3" +version_info = (6, 3, 3, 0) import importlib import typing