Repository navigation
Bump urllib3 from 2.4.0 to 2.8.0 - #471
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [urllib3](https://github.com/urllib3/urllib3) from 2.4.0 to 2.8.0. - [Release notes](https://github.com/urllib3/urllib3/releases) - [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst) - [Commits](urllib3/urllib3@2.4.0...2.8.0) --- updated-dependencies: - dependency-name: urllib3 dependency-version: 2.8.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
Broly Security ScanWarning Latest baseline snapshot is stale. Broly is running in PR-only fallback mode until the next scheduled baseline refreshes. This does not block the PR. Note Summary 13 actionable finding(s) in this PR
Main table: 5 shown, 8 omitted of 13 actionable finding(s) above the reporting threshold. See the repository Security tab for the full set. No finding is at or above
Dismiss false positivesTick a box to dismiss the finding; untick it to bring the finding back. That is the same as replying
Note Re-scan this PR anytime with
|
| @@ -1,4 +1,4 @@ | |||
| # This file is automatically @generated by Poetry 2.2.1 and should not be changed by hand. | |||
| # This file is automatically @generated by Poetry 2.5.1 and should not be changed by hand. | |||
| @@ -1,4 +1,4 @@ | |||
| # This file is automatically @generated by Poetry 2.2.1 and should not be changed by hand. | |||
| # This file is automatically @generated by Poetry 2.5.1 and should not be changed by hand. | |||
| @@ -1,4 +1,4 @@ | |||
| # This file is automatically @generated by Poetry 2.2.1 and should not be changed by hand. | |||
| # This file is automatically @generated by Poetry 2.5.1 and should not be changed by hand. | |||
| @@ -1,4 +1,4 @@ | |||
| # This file is automatically @generated by Poetry 2.2.1 and should not be changed by hand. | |||
| # This file is automatically @generated by Poetry 2.5.1 and should not be changed by hand. | |||
| @@ -1,4 +1,4 @@ | |||
| # This file is automatically @generated by Poetry 2.2.1 and should not be changed by hand. | |||
| # This file is automatically @generated by Poetry 2.5.1 and should not be changed by hand. | |||
| @@ -1,4 +1,4 @@ | |||
| # This file is automatically @generated by Poetry 2.2.1 and should not be changed by hand. | |||
| # This file is automatically @generated by Poetry 2.5.1 and should not be changed by hand. | |||
| @@ -1,4 +1,4 @@ | |||
| # This file is automatically @generated by Poetry 2.2.1 and should not be changed by hand. | |||
| # This file is automatically @generated by Poetry 2.5.1 and should not be changed by hand. | |||
| @@ -1,4 +1,4 @@ | |||
| # This file is automatically @generated by Poetry 2.2.1 and should not be changed by hand. | |||
| # This file is automatically @generated by Poetry 2.5.1 and should not be changed by hand. | |||
| @@ -1,4 +1,4 @@ | |||
| # This file is automatically @generated by Poetry 2.2.1 and should not be changed by hand. | |||
| # This file is automatically @generated by Poetry 2.5.1 and should not be changed by hand. | |||
| @@ -1,4 +1,4 @@ | |||
| # This file is automatically @generated by Poetry 2.2.1 and should not be changed by hand. | |||
| # This file is automatically @generated by Poetry 2.5.1 and should not be changed by hand. | |||
Bumps urllib3 from 2.4.0 to 2.8.0.
Release notes
Sourced from urllib3's releases.
... (truncated)
Changelog
Sourced from urllib3's changelog.
... (truncated)
Commits
b1d30abRelease 2.8.09016d7eSkiptest_read_chunked_with_trailing_data_does_not_hangfor brotlicffi (#5258)9101f58Fixnox -s docswarning (#5256)cd770b0Merge commit from forkea2ad7bMerge commit from fork0716e31Fix loading unencrypted client keys with a password in pyOpenSSL (#5255)43c68c8Test pickling ofInvalidChunkLength(#5247)308b279Share security policy between GitHub and Read the Docs (#5253)53fa073Add policy on duplicate pull requests (#5252)5f2a6a8Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (#5232)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.
Note
Medium Risk
Upgrades a core HTTP stack dependency with high-severity security fixes and a behavior change for HTTPS proxy TLS configuration that could affect proxy setups.
Overview
Updates
poetry.lockto pull in urllib3 2.8.0 (from 2.4.0), including refreshed wheel hashes and urllib3’s stricterpython-versions = ">=3.10"(aligned with this repo’s^3.10constraint).The lockfile was regenerated with Poetry 2.5.1, which also reformats a few transitive dependency markers (e.g. fsspec / pydantic_core version constraints) without changing resolved package versions aside from urllib3. urllib3’s optional brotli and zstd extra metadata in the lockfile updates as well.
urllib3 2.8.0 brings multiple security fixes (HTTPS proxy TLS handling, chunked streaming) and stricter URL/host parsing; deployments using HTTPS forwarding proxies may need to configure
proxy_ssl_context/ proxy assertion options instead of relying on destination TLS settings.Reviewed by Cursor Bugbot for commit 257923f. Bugbot is set up for automated code reviews on this repo. Configure here.