chore(deps): update dependency urllib3 to v2.8.0 #16
No reviewers
Labels
No labels
bug
duplicate
enhancement
help wanted
invalid
question
renovate-bot
renovate-security
security
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
mCaptcha/mcaptcha-api-rs!16
Loading…
Reference in a new issue
No description provided.
Delete branch "renovate/urllib3-2.x"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
==2.2.3->==2.8.0Release Notes
urllib3/urllib3 (urllib3)
v2.8.0Compare Source
==================
Security
Fixed the following security issues:
(High severity,
GHSA-8988-9cw3-xx77 <https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77>__)HTTPResponse.stream()andread_chunked()could buffer a chunk-sizeline of unbounded length in memory. (High severity,
GHSA-vxq7-64xx-v4gw <https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw>__)GHSA-gh4c-6fx4-qh6g <https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g>__).. caution::
Deprecations & Removals
Retryoptionallowed_methodsto retry any verb.(
#​5044 <https://github.com/urllib3/urllib3/issues/5044>__)Features
Url.auth_decodedandUrl.auth_decoded_joinedconvenienceproperties to the result of
parse_url().(
#​4945 <https://github.com/urllib3/urllib3/issues/4945>__)basic_auth_encodingandproxy_basic_auth_encodingparameters tourllib3.util.make_headers().(
#​5092 <https://github.com/urllib3/urllib3/issues/5092>__)Bugfixes
Fixed response header handling to replace obsolete folded header lines
(
obs-fold) with spaces in accordance with RFC 9112, preventing raw CRLFsequences from appearing in header values such as
Set-Cookie.(
#​1362 <https://github.com/urllib3/urllib3/issues/1362>__)Fixed usage of
proxy_ssl_contextwithProxyManagerwhenuse_forwarding_for_https=True. Passingssl_contextinstead ofproxy_ssl_contextfor HTTPS proxies in this configuration now emits aFutureWarningand will raise an error in v3.0.(
#​2577 <https://github.com/urllib3/urllib3/issues/2577>__)Changed behavior of the default
ConnectionPool.poolinitialization.LifoQueueis now resolved from thequeuemodule after theConnectionPoolis instantiated instead of using the default cachedQueueClsclass property. This is done because sometimes thequeue.LifoQueueis monkey-patched late in the program, such as by gevent.(
#​3289 <https://github.com/urllib3/urllib3/issues/3289>__)Raised
UnrewindableBodyErrorinstead ofValueErrorwhen retrying arequest whose body had
tell()but notseek().(
#​3779 <https://github.com/urllib3/urllib3/issues/3779>__)Decoded percent-encoded SOCKS proxy credentials before authenticating with
the proxy server.
(
#​3785 <https://github.com/urllib3/urllib3/issues/3785>__)Fixed
HTTPResponse.drain_conn()to discard unread response data in 64 KiBchunks (same as the default
amtwhen doingHTTPResponse.stream(...)).(
#​5019 <https://github.com/urllib3/urllib3/issues/5019>__)Fixed
is_ipaddress()to detect non-standard IPv4 forms accepted bysocket.connect, such as hex (0x7f000001), octal (0177.0.0.1), anddecimal integers (
2130706433), ensuring SSL certificate verification usesthe correct mode for these addresses.
(
#​5029 <https://github.com/urllib3/urllib3/issues/5029>__)Fixed
HTTPConnectionPool.urlopenraising a misleadingFullPoolErrorinstead of
ValueErrorwhen called with an invalidtimeoutargument ona pool created with
block=True.(
#​5059 <https://github.com/urllib3/urllib3/issues/5059>__)Fixed port-zero handling to preserve explicit
:0values instead ofsubstituting the default ports 80 or 443 in URL parsing, pool selection,
proxy configuration,
connection_from_url(), and HTTP/2 request authority.(
#​5071 <https://github.com/urllib3/urllib3/issues/5071>,#​5101 <https://github.com/urllib3/urllib3/issues/5101>)Fixed a bug where
PoolManagerpassed theassert_hostnameandassert_fingerprintparameters to HTTP connection pools.(
#​5077 <https://github.com/urllib3/urllib3/issues/5077>__)Fixed
HTTPConnectionPool.urlopen()and HTTP proxy forwarding to strip URLfragments from absolute request targets before sending requests.
(
#​5079 <https://github.com/urllib3/urllib3/issues/5079>__)Added safeguards to the proxy tunneling code to prevent potential security
issues when handling invalid characters in the proxy host and HTTP headers.
This change affects users of Python 3.10, Python 3.11, and Python 3.12 when
the standard library does not contain the fix; those on newer Python versions
should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes.
(
#​5091 <https://github.com/urllib3/urllib3/issues/5091>__)Fixed
HTTPSConnection.connect()overridingProxyConfig.ssl_context'scertificate policy and proxy identity checks with the target connection's TLS
settings when forwarding through an HTTPS proxy.
HTTPSConnectionno longer applies target SNI, assertions, or clientcredentials to forwarding proxy handshakes and continues to use its
ssl_contextas a fallback when an HTTPS proxy forwards an HTTP target.(
#​5093 <https://github.com/urllib3/urllib3/issues/5093>__)Fixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting
invalid host input such as raw spaces and control characters, malformed
percent-encodings, and percent-encoded control characters in HTTP(S) hosts
and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host
normalization now also follows RFC 3986 normalization rules for
percent-encoded octets by decoding percent-encoded unreserved characters and
uppercasing the hexadecimal digits of retained percent-encoded octets.
(
#​5095 <https://github.com/urllib3/urllib3/issues/5095>__)Fixed an
AttributeErroron Python built with OpenSSL 4+, wheressl.PROTOCOL_TLSv1no longer exists.(
#​5097 <https://github.com/urllib3/urllib3/issues/5097>__)Fixed
urllib3.contrib.pyopensslto use cryptography APIs when reading acertificate subject and loading encrypted private keys, avoiding
DeprecationWarningraised by pyOpenSSL 26.3.0+.(
#​5103 <https://github.com/urllib3/urllib3/issues/5103>__)Fixed handling of HTTP 303 redirects for requests with chunked or file-like
bodies.
(
#​5161 <https://github.com/urllib3/urllib3/issues/5161>__)Fixed
assert_fingerprint()to raiseSSLErrorinstead ofbinascii.Errorwhen a fingerprint has a supported length but containsnon-hexadecimal characters.
(
#​5211 <https://github.com/urllib3/urllib3/issues/5211>__)Misc
testdependency group containing the minimum dependencies neededto run the test suite, intended for downstream packagers. The
dev-baseand
mypygroups now include this new group viainclude-group,removing duplication.
(
#​3594 <https://github.com/urllib3/urllib3/issues/3594>__)(
#​5094 <https://github.com/urllib3/urllib3/issues/5094>__)(
#​5166 <https://github.com/urllib3/urllib3/issues/5166>__)(
#​5209 <https://github.com/urllib3/urllib3/issues/5209>__)(
#​5232 <https://github.com/urllib3/urllib3/issues/5232>,#​5234 <https://github.com/urllib3/urllib3/issues/5234>,#​5239 <https://github.com/urllib3/urllib3/issues/5239>__)v2.7.0Compare Source
=======================
Security
Addressed high-severity security issues.
Impact was limited to specific use cases detailed in the accompanying
advisories; overall user exposure was estimated to be marginal.
Decompression-bomb safeguards of the streaming API were bypassed:
HTTPResponse.drain_conn()was called after the response had beenread and decompressed partially.
HTTPResponse.read(amt=N)orHTTPResponse.stream(amt=N)call when the response was decompressedusing the official
Brotli <https://pypi.org/project/brotli/>__ library.See
GHSA-mf9v-mfxr-j63j <https://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j>__for details.
HTTP pools created using
ProxyManager.connection_from_urldid not stripsensitive headers specified in
Retry.remove_headers_on_redirectwhenredirecting to a different host.
(
GHSA-qccp-gfcp-xxvc <https://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc>__)Deprecations and Removals
FutureWarninginstead ofDeprecationWarningfor bettervisibility of existing deprecation notices. Rescheduled the removal of
deprecated features to version 3.0.
(
#​3763 <https://github.com/urllib3/urllib3/issues/3763>__)(
#​3720 <https://github.com/urllib3/urllib3/issues/3720>__)(
#​4979 <https://github.com/urllib3/urllib3/issues/4979>__)(
#​3777 <https://github.com/urllib3/urllib3/issues/3777>__)Bugfixes
HTTPResponse.read(amt=None)was ignoring decompresseddata buffered from previous partial reads.
(
#​3636 <https://github.com/urllib3/urllib3/issues/3636>__)HTTPResponse.read()could cache only part of theresponse after a partial read when
cache_content=True.(
#​4967 <https://github.com/urllib3/urllib3/issues/4967>__)HTTPResponse.stream()andHTTPResponse.read_chunked()to handleamt=0.(
#​3793 <https://github.com/urllib3/urllib3/issues/3793>__)_TYPE_BODYtype alias to include missingIterable[str],matching the documented and runtime behavior of chunked request bodies.
(
#​3798 <https://github.com/urllib3/urllib3/issues/3798>__)LocationParseErrorwhen paths resembling schemeless URIs werepassed to
HTTPConnectionPool.urlopen().(
#​3352 <https://github.com/urllib3/urllib3/issues/3352>__)BaseHTTPResponse.readinto()type annotation to acceptmemoryviewin addition tobytearray, matching theio.RawIOBase.readintocontract and enabling use withio.BufferedReaderwithout type errors.(
#​3764 <https://github.com/urllib3/urllib3/issues/3764>__)v2.6.3Compare Source
==================
the streaming API were bypassed when HTTP redirects were followed.
(
GHSA-38jv-5279-wg99 <https://github.com/urllib3/urllib3/security/advisories/GHSA-38jv-5279-wg99>__)Retry-Aftertimes greater than 6 hours as 6 hours bydefault. (
#​3743 <https://github.com/urllib3/urllib3/issues/3743>__)urllib3.connection.VerifiedHTTPSConnectionon Emscripten.(
#​3752 <https://github.com/urllib3/urllib3/issues/3752>__)v2.6.2Compare Source
==================
HTTPResponse.read_chunked()to properly handle leftover data inthe decoder's buffer when reading compressed chunked responses.
(
#​3734 <https://github.com/urllib3/urllib3/issues/3734>__)v2.6.1Compare Source
==================
HTTPResponse.getheaders()andHTTPResponse.getheader()methods.(
#​3731 <https://github.com/urllib3/urllib3/issues/3731>__)v2.6.0Compare Source
==================
Security
compressed HTTP content ("decompression bombs") leading to excessive resource
consumption even when a small amount of data was requested. Reading small
chunks of compressed data is safer and much more efficient now.
(
GHSA-2xpw-w6gg-jr37 <https://github.com/urllib3/urllib3/security/advisories/GHSA-2xpw-w6gg-jr37>__)virtually unlimited links in the
Content-Encodingheader, potentiallyleading to a denial of service (DoS) attack by exhausting system resources
during decoding. The number of allowed chained encodings is now limited to 5.
(
GHSA-gm62-xv2j-4w53 <https://github.com/urllib3/urllib3/security/advisories/GHSA-gm62-xv2j-4w53>__).. caution::
If urllib3 is not installed with the optional
urllib3[brotli]extra, butyour environment contains a Brotli/brotlicffi/brotlipy package anyway, make
sure to upgrade it to at least Brotli 1.2.0 or brotlicffi 1.2.0.0 to
benefit from the security fixes and avoid warnings. Prefer using
urllib3[brotli]to install a compatible Brotli package automatically.If you use custom decompressors, please make sure to update them to
respect the changed API of
urllib3.response.ContentDecoder.Features
HTTPHeaderDictusing bytes keys. (#​3653 <https://github.com/urllib3/urllib3/issues/3653>__)HTTPConnection. (#​3666 <https://github.com/urllib3/urllib3/issues/3666>__)#​3696 <https://github.com/urllib3/urllib3/issues/3696>__)Removals
HTTPResponse.getheaders()method in favor ofHTTPResponse.headers.Removed the
HTTPResponse.getheader(name, default)method in favor ofHTTPResponse.headers.get(name, default). (#​3622 <https://github.com/urllib3/urllib3/issues/3622>__)Bugfixes
urllib3.PoolManagerwhen an integer is passedfor the retries parameter. (
#​3649 <https://github.com/urllib3/urllib3/issues/3649>__)HTTPConnectionPoolwhen used in Emscripten with no explicit port. (#​3664 <https://github.com/urllib3/urllib3/issues/3664>__)SSLKEYLOGFILEwith expandable variables. (#​3700 <https://github.com/urllib3/urllib3/issues/3700>__)Misc
zstdextra to installbackports.zstdinstead ofzstandardon Python 3.13 and before. (#​3693 <https://github.com/urllib3/urllib3/issues/3693>__)BytesQueueBufferclass. (#​3710 <https://github.com/urllib3/urllib3/issues/3710>__)#​3652 <https://github.com/urllib3/urllib3/issues/3652>__)#​3638 <https://github.com/urllib3/urllib3/issues/3638>__)v2.5.0Compare Source
==================
Features
compression.zstdmodule that is new in Python 3.14.See
PEP 784 <https://peps.python.org/pep-0784/>_ for more information. (#​3610 <https://github.com/urllib3/urllib3/issues/3610>__)hatch-vcs(#​3612 <https://github.com/urllib3/urllib3/issues/3612>__)Bugfixes
redirects at the
urllib3.PoolManagerlevel via theretriesparameterdid not work.
retriesand
redirects.HTTPResponse.shutdownon a connection already released to the pool. (#​3581 <https://github.com/urllib3/urllib3/issues/3581>__)CONNECTstatement when using an IPv6 proxy withconnection_from_host. Previously would not be wrapped in[]. (#​3615 <https://github.com/urllib3/urllib3/issues/3615>__)v2.4.0Compare Source
==================
Features
#​3522 <https://github.com/urllib3/urllib3/issues/3522>__)#​3567 <https://github.com/urllib3/urllib3/issues/3567>__)verify_flagsoption tocreate_urllib3_contextwith a default ofVERIFY_X509_PARTIAL_CHAINandVERIFY_X509_STRICTfor Python 3.13+. (#​3571 <https://github.com/urllib3/urllib3/issues/3571>__)Bugfixes
#​3555 <https://github.com/urllib3/urllib3/issues/3555>__)Misc
#​3550 <https://github.com/urllib3/urllib3/issues/3550>__)multiple.intoto.jsonlasset from GitHub releases. Attestation of release files since v2.3.0 can be found on PyPI. (#​3566 <https://github.com/urllib3/urllib3/issues/3566>__)v2.3.0Compare Source
==================
Features
#​3522 <https://github.com/urllib3/urllib3/issues/3522>__)#​3567 <https://github.com/urllib3/urllib3/issues/3567>__)verify_flagsoption tocreate_urllib3_contextwith a default ofVERIFY_X509_PARTIAL_CHAINandVERIFY_X509_STRICTfor Python 3.13+. (#​3571 <https://github.com/urllib3/urllib3/issues/3571>__)Bugfixes
#​3555 <https://github.com/urllib3/urllib3/issues/3555>__)Misc
#​3550 <https://github.com/urllib3/urllib3/issues/3550>__)multiple.intoto.jsonlasset from GitHub releases. Attestation of release files since v2.3.0 can be found on PyPI. (#​3566 <https://github.com/urllib3/urllib3/issues/3566>__)Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.
chore(deps): update dependency urllib3 to v2.3.0to chore(deps): update dependency urllib3 to v2.4.0feeca22ea7toc4ff937604chore(deps): update dependency urllib3 to v2.4.0to chore(deps): update dependency urllib3 to v2.5.0c4ff937604to81fe606448chore(deps): update dependency urllib3 to v2.5.0to chore(deps): update dependency urllib3 to v2.6.081fe606448to21a8f28122chore(deps): update dependency urllib3 to v2.6.0to chore(deps): update dependency urllib3 to v2.6.221a8f28122to6b743a0741chore(deps): update dependency urllib3 to v2.6.2to chore(deps): update dependency urllib3 to v2.6.36b743a0741to499c88d09dchore(deps): update dependency urllib3 to v2.6.3to chore(deps): update dependency urllib3 to v2.7.0499c88d09dtob27e3766deb27e3766deto5ce4ab39aachore(deps): update dependency urllib3 to v2.7.0to chore(deps): update dependency urllib3 to v2.8.05ce4ab39aato2b4d07439eView command line instructions
Checkout
From your project repository, check out a new branch and test the changes.Merge
Merge the changes and update on Forgejo.Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.