Starlette End of Life - Dates and Lifecycle
Starlette is a lightweight ASGI framework and toolkit for building async Python web services, serving as the foundation FastAPI is built on.
Last updated 24 July 2026
13
Versions tracked
12
At EOL
1
Supported
All versions
| Version | Released | Security Support | Latest |
|---|---|---|---|
|
1.3.1
|
12 Jun 2026 | — | — |
|
1.3.0
|
11 Jun 2026 |
12 Jun 2026
Ended 1 month, 1 week ago
|
— |
|
1.0.0
|
22 Mar 2026 |
11 Jun 2026
Ended 1 month, 1 week ago
|
— |
|
0.52.1
|
18 Jan 2026 |
22 Mar 2026
Ended 4 months ago
|
— |
|
0.51.0
|
10 Jan 2026 |
18 Jan 2026
Ended 6 months ago
|
— |
|
0.50.0
|
01 Nov 2025 |
10 Jan 2026
Ended 6 months, 2 weeks ago
|
— |
|
0.49.1
|
28 Oct 2025 |
01 Nov 2025
Ended 8 months, 3 weeks ago
|
— |
|
0.48.0
|
13 Sep 2025 |
28 Oct 2025
Ended 8 months, 3 weeks ago
|
— |
About Starlette
Starlette is a lightweight ASGI framework and toolkit for building asynchronous Python web services, providing routing, request and response handling, WebSocket support, and middleware. It's best known as the foundation FastAPI is built on top of, which means most FastAPI users are running Starlette underneath without necessarily tracking it as a separate dependency.
Starlette Lifecycle Explained
Starlette has no formal, scheduled end of life policy, and for most of its life it didn't even have a stable release to build one around. Created in June 2018, it stayed on ZeroVer (0.x) versioning for almost eight years before finally reaching its first stable 1.0.0 release in March 2026. Like other Pallets-adjacent and single-maintainer Python libraries, only the current release is meaningfully supported, once a new version ships, the previous one is effectively retired with no guaranteed backport of fixes, security issues included.
That said, real end of life events do happen, they're just driven by supersession rather than a calendar. New releases have periodically dropped support for older Python versions in step with Python's own lifecycle: 0.20.0 dropped Python 3.6, 0.30.0 dropped Python 3.7, 0.45.0 dropped Python 3.8, and 0.50.0 dropped Python 3.9. An old pinned Starlette version can silently cap which Python release you're able to run.
Security patches have been infrequent but real: a path traversal vulnerability in StaticFiles was fixed in 0.27.0 (2023), a denial-of-service issue in multipart form parsing was fixed in 0.40.0 (2024), and a Range header parsing vulnerability in FileResponse was fixed in 0.49.1 (2025). None of these were backported to older release lines, consistent with Starlette's practice of only patching forward.
Frequently Asked Questions
Do Starlette versions reach end of life?
Yes, in the sense that matters practically, once a new version ships, the previous one no longer receives updates, including security fixes. There's no scheduled or announced end of life date; a version simply stops being current the moment its successor is released.
Is Starlette still on version 0.x?
No, not anymore. Starlette reached its first stable 1.0.0 release in March 2026, after nearly eight years of 0.x versioning since the project's 2018 creation. Versions before 1.0.0 should be treated as pre-stable in terms of API guarantees, even though many were widely used in production for years.
Is Starlette safe to use in production?
Yes, it's the ASGI foundation for FastAPI and is downloaded tens of millions of times daily. Safety depends more on staying current with patch releases than on the framework's overall maturity, since Starlette doesn't guarantee fixes for older versions once superseded.
Does upgrading Starlette affect FastAPI?
It can. FastAPI depends on a compatible range of Starlette versions, and Starlette occasionally removes deprecated features or changes behavior in ways that can affect a FastAPI application. Check FastAPI's required Starlette version range before upgrading Starlette independently of FastAPI itself.