Skip to content

Bump python-snap7 from 3.1.0 to 3.2.0 - #4

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/python-snap7-3.2.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/python-snap7-3.2.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown

Bumps python-snap7 from 3.1.0 to 3.2.0.

Release notes

Sourced from python-snap7's releases.

3.2.0

python-snap7 3.2.0

Feature and robustness release for the pure-Python classic S7 protocol implementation.

Highlights

  • Add experimental serial PPI support for S7-200 PLCs, including V-memory, system-memory, I/O, counter, and timer access (#824).
  • Add configurable fixed-interval and token-bucket request rate limiting to synchronous and asynchronous clients (#823).
  • Add force/cancel-force APIs, force-table reading, and session password management for synchronous and asynchronous clients (#796, #800, #792, #799).
  • Extend LOGO reconnection, heartbeat, rate-limiting, and connection callback options (#875).
  • Harden classic S7 framing, acknowledgements, element boundaries, server COTP handling, and invalid-range reads (#874, #893, #896).
  • Expand and reorganize documentation for the complete current API.

S7CommPlus support has moved to the standalone s7commplus project. The s7 and snap7 imports in python-snap7 both expose the classic S7 implementation.

Install or upgrade with:

pip install --upgrade python-snap7==3.2.0

See the full changelog and the PyPI package.

3.1.2

python-snap7 3.1.2

Corrective bug-fix and robustness release superseding the yanked 3.1.1 release.

Server and protocol robustness

  • Bound the emulation server to 64 simultaneous clients by default and add a configurable max_clients limit.
  • Validate block-download targets and declared sizes, cap accumulated data at the registered memory area's capacity, and discard abandoned transfer state.
  • Correct block-download parsing so registered DB numbers other than DB1 work.
  • Bound COTP request reassembly to 1 MiB and apply one absolute receive deadline across all request fragments.
  • Apply COTP TPDU-size validation consistently to synchronous and asynchronous clients.

The bundled server is intended for PLC emulation, development, and testing. It is not presented as a production-hardened network service, but robustness and security improvements remain welcome.

Correction to 3.1.1

Version 3.1.1 was yanked because its release notes included vulnerability and CWE characterizations that were not supported by the affected code paths, while some input hardening was incomplete. Use 3.1.2 instead.

Install or upgrade with:

pip install --upgrade python-snap7==3.1.2

Please report bugs and hardening opportunities on the issue tracker.

Changelog

Sourced from python-snap7's changelog.

3.2.0

Feature and robustness release for the classic S7 protocol implementation.

Packaging

  • Move S7CommPlus support to the standalone s7commplus package. The s7 import remains available as an alias for the classic snap7 package.

New features

  • Add configurable request rate limiting to synchronous and asynchronous clients, including fixed-interval and token-bucket modes (#823).
  • Add synchronous and asynchronous APIs for forcing I/O bits, cancelling forces, and reading the PLC force table (#796, #800).
  • Add synchronous and asynchronous session password set/clear APIs for password-protected PLCs (#792, #799).
  • Support LOGO reconnection, heartbeat, rate-limiting, and connection callback options while preserving explicit TSAPs (#875).
  • Add an experimental serial PPI client for S7-200 PLCs, including V-memory, system-memory, I/O, counter, and timer access (#824).

Bug fixes

  • Parse structured and flat SZL 0x0011 records correctly when reading order codes and firmware versions from S7-1500 and classic PLCs (#783, #789).
  • Dispatch server callbacks and queue protocol events for client requests instead of reporting only the server start event (#853, #856).
  • Validate classic S7 TPKT bounds and COTP Class 0 headers in synchronous and asynchronous clients (#874).
  • Reject incomplete reads and mismatched or missing read/write acknowledgements (#874).
  • Size read/write chunks in whole elements and preserve ctypes write datatypes; correct BIT lengths and timer/counter index addressing (#874).
  • Validate write_multi_vars() inputs consistently and preserve each item's declared datatype (#855, #874).
  • Echo the calling and called TSAP values in server connection confirmations, and restart the receive deadline after each complete TPKT header (#893).
  • Return S7 item errors for reads from unregistered server areas or addresses outside registered memory instead of returning fabricated data (#896).

3.1.2

Corrective bug fix and robustness release replacing the yanked 3.1.1 release.

Corrections

... (truncated)

Commits
  • d5cf235 Prepare 3.2.0 release (#900)
  • 35f3b14 feat(ppi): add S7-200 serial transport (#824)
  • 03b4c69 fix(server): return read item errors for invalid ranges (#896)
  • 286a81a fix(server): harden COTP connection framing (#893)
  • fee5ba7 move s7commplus module to its own library
  • 5416e8f chore(deps): bump the all-dependencies group with 4 updates (#895)
  • 4e960e5 fix(s7commplus): correlate request responses (#883)
  • 4984721 fix(server): validate SessionKey handshake emulation (#860)
  • 78c9051 fix(s7commplus): decode CPU operating state (#879)
  • 5e5ec4a fix(s7commplus): restore V1 challenge wire layout (#841)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [python-snap7](https://github.com/gijzelaerr/python-snap7) from 3.1.0 to 3.2.0.
- [Release notes](https://github.com/gijzelaerr/python-snap7/releases)
- [Changelog](https://github.com/gijzelaerr/python-snap7/blob/master/CHANGES.md)
- [Commits](gijzelaerr/python-snap7@3.1.0...3.2.0)

---
updated-dependencies:
- dependency-name: python-snap7
  dependency-version: 3.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot @github

dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Author

Labels

The following labels could not be found: dependencies, python. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants