Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Update urllib3 requirement from <2.4.0,>=1.24.2 to >=1.24.2,<2.6.0#2439

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Open
dependabot wants to merge1 commit intomaster
base:master
Choose a base branch
Loading
fromdependabot/pip/urllib3-gte-1.24.2-and-lt-2.6.0

Conversation

@dependabot
Copy link
Contributor

@dependabotdependabotbot commented on behalf ofgithubAug 27, 2025
edited
Loading

Updates the requirements onurllib3 to permit the latest version.

Release notes

Sourced fromurllib3's releases.

2.5.0

🚀 urllib3 is fundraising for HTTP/2 support

urllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project after a sharp decline in financial support. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projectsplease consider contributing financially to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.

Thank you for your support.

Security issues

urllib3 2.5.0 fixes two moderate security issues:

Features

  • Added support for thecompression.zstd module that is new in Python 3.14. SeePEP 784 for more information. (#3610)
  • Added support for version 0.5 ofhatch-vcs (#3612)

Bugfixes

  • Raised exception forHTTPResponse.shutdown on a connection already released to the pool. (#3581)
  • Fixed incorrectCONNECT statement when using an IPv6 proxy withconnection_from_host. Previously would not be wrapped in[]. (#3615)
Changelog

Sourced fromurllib3's changelog.

2.5.0 (2025-06-18)

Features

  • Added support for thecompression.zstd module that is new in Python 3.14.SeePEP 784 <https://peps.python.org/pep-0784/>_ for more information. ([#3610](https://github.com/urllib3/urllib3/issues/3610) <https://github.com/urllib3/urllib3/issues/3610>__)
  • Added support for version 0.5 ofhatch-vcs ([#3612](https://github.com/urllib3/urllib3/issues/3612) <https://github.com/urllib3/urllib3/issues/3612>__)

Bugfixes

  • Fixed a security issue where restricting the maximum number of followedredirects at theurllib3.PoolManager level via theretries parameterdid not work.
  • Made the Node.js runtime respect redirect parameters such asretriesandredirects.
  • Raised exception forHTTPResponse.shutdown on a connection already released to the pool. ([#3581](https://github.com/urllib3/urllib3/issues/3581) <https://github.com/urllib3/urllib3/issues/3581>__)
  • Fixed incorrectCONNECT statement when using an IPv6 proxy withconnection_from_host. Previously would not be wrapped in[]. ([#3615](https://github.com/urllib3/urllib3/issues/3615) <https://github.com/urllib3/urllib3/issues/3615>__)

2.4.0 (2025-04-10)

Features

  • Applied PEP 639 by specifying the license fields in pyproject.toml. ([#3522](https://github.com/urllib3/urllib3/issues/3522) <https://github.com/urllib3/urllib3/issues/3522>__)
  • Updated exceptions to save and restore more properties during the pickle/serialization process. ([#3567](https://github.com/urllib3/urllib3/issues/3567) <https://github.com/urllib3/urllib3/issues/3567>__)
  • Addedverify_flags option tocreate_urllib3_context with a default ofVERIFY_X509_PARTIAL_CHAIN andVERIFY_X509_STRICT for Python 3.13+. ([#3571](https://github.com/urllib3/urllib3/issues/3571) <https://github.com/urllib3/urllib3/issues/3571>__)

Bugfixes

  • Fixed a bug with partial reads of streaming data in Emscripten. ([#3555](https://github.com/urllib3/urllib3/issues/3555) <https://github.com/urllib3/urllib3/issues/3555>__)

Misc

  • Switched to uv for installing development dependecies. ([#3550](https://github.com/urllib3/urllib3/issues/3550) <https://github.com/urllib3/urllib3/issues/3550>__)
  • Removed themultiple.intoto.jsonl asset from GitHub releases. Attestation of release files since v2.3.0 can be found on PyPI. ([#3566](https://github.com/urllib3/urllib3/issues/3566) <https://github.com/urllib3/urllib3/issues/3566>__)

2.3.0 (2024-12-22)

... (truncated)

Commits

You can trigger a rebase of this PR by commenting@dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

sathieu reacted with thumbs up emoji
Updates the requirements on [urllib3](https://github.com/urllib3/urllib3) to permit the latest version.- [Release notes](https://github.com/urllib3/urllib3/releases)- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst)- [Commits](urllib3/urllib3@1.24.2...2.5.0)---updated-dependencies:- dependency-name: urllib3  dependency-version: 2.5.0  dependency-type: direct:production...Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotbot added dependenciesPull requests that update a dependency file pythonPull requests that update Python code labelsAug 27, 2025
@k8s-ci-robot
Copy link
Contributor

Adding the "do-not-merge/release-note-label-needed" label because no release-note block was detected, please follow ourrelease note process to remove it.

Instructions for interacting with me using PR comments are availablehere. If you have questions or suggestions related to my behavior, please file an issue against thekubernetes-sigs/prow repository.

@k8s-ci-robotk8s-ci-robot added the do-not-merge/release-note-label-neededIndicates that a PR should not merge because it's missing one of the release note labels. labelAug 27, 2025
@k8s-ci-robot
Copy link
Contributor

[APPROVALNOTIFIER] This PR isNOT APPROVED

This pull-request has been approved by:dependabot[bot]
Once this PR has been reviewed and has the lgtm label, please assignroycaihw for approval. For more information seethe Code Review Process.

The full list of commands accepted by this bot can be foundhere.

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing/approve in a comment
Approvers can cancel approval by writing/approve cancel in a comment

@k8s-ci-robotk8s-ci-robot added cncf-cla: yesIndicates the PR's author has signed the CNCF CLA. needs-kindIndicates a PR lacks a `kind/foo` label and requires one. size/XSDenotes a PR that changes 0-9 lines, ignoring generated files. labelsAug 27, 2025
@roycaihw
Copy link
Member

/hold

@yliaog I recall we were trying to pin urllib3 version for some issue. We should double check what's our intention here.

@k8s-ci-robotk8s-ci-robot added the do-not-merge/holdIndicates that a PR should not merge because someone has issued a /hold command. labelAug 27, 2025
@roycaihw
Copy link
Member

/assign@yliaog

@yashvardhannanavati
Copy link

@roycaihw#2458 links to#2394 .

However, not merging this PR prevents users from upgrading to a urllib3 version that has CVE fixes like#2458 mentions.

FredPrz, sathieu, chandwanitulsi, and JAVGan reacted with heart emoji

@k8s-ci-robotk8s-ci-robot added the needs-rebaseIndicates a PR cannot be merged because it has merge conflicts with HEAD. labelOct 28, 2025
@k8s-ci-robot
Copy link
Contributor

PR needs rebase.

Instructions for interacting with me using PR comments are availablehere. If you have questions or suggestions related to my behavior, please file an issue against thekubernetes-sigs/prow repository.

Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment

Reviewers

@roycaihwroycaihwAwaiting requested review from roycaihw

@yliaogyliaogAwaiting requested review from yliaog

Assignees

@yliaogyliaog

Labels

cncf-cla: yesIndicates the PR's author has signed the CNCF CLA.dependenciesPull requests that update a dependency filedo-not-merge/holdIndicates that a PR should not merge because someone has issued a /hold command.do-not-merge/release-note-label-neededIndicates that a PR should not merge because it's missing one of the release note labels.needs-kindIndicates a PR lacks a `kind/foo` label and requires one.needs-rebaseIndicates a PR cannot be merged because it has merge conflicts with HEAD.pythonPull requests that update Python codesize/XSDenotes a PR that changes 0-9 lines, ignoring generated files.

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

5 participants

@k8s-ci-robot@roycaihw@yashvardhannanavati@yliaog

[8]ページ先頭

©2009-2025 Movatter.jp