MEDIUM SEVERITYCONFIRMED

required=True option allows empty string and whitespace-only values

Package
click
Version
8.3.1
Verified
2026-03-28

Description

click's `required=True` option flag only checks that the option was provided — it does not validate that the value is non-empty. `--name ""` and `--name " "` both succeed with exit code 0, passing an empty or whitespace-only string to the application.

Reproduction

# @click.option('--name', required=True)
# Running: mycommand --name ""
# exit_code=0, name='' — required but empty accepted
← All bugsScan your code →