Skip to content

chore(deps): update dependency requests to v2.32.4 [security] #1304

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

renovate-bot
Copy link
Contributor

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
Requests (source, changelog) ==2.32.3 -> ==2.32.4 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2024-47081

Impact

Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs.

Workarounds

For older versions of Requests, use of the .netrc file can be disabled with trust_env=False on your Requests Session (docs).

References

https://github.com/psf/requests/pull/6965
https://seclists.org/fulldisclosure/2025/Jun/2


Release Notes

psf/requests (Requests)

v2.32.4

Compare Source

Security

  • CVE-2024-47081 Fixed an issue where a maliciously crafted URL and trusted
    environment will retrieve credentials for the wrong hostname/machine from a
    netrc file.

Improvements

  • Numerous documentation improvements

Deprecations

  • Added support for pypy 3.11 for Linux and macOS.
  • Dropped support for pypy 3.9 following its end of support.

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate-bot renovate-bot requested a review from a team as a code owner June 10, 2025 08:44
@renovate-bot renovate-bot force-pushed the renovate/pypi-requests-vulnerability branch from 373e6d3 to cd224a3 Compare June 10, 2025 17:53
@dpebot
Copy link
Collaborator

dpebot commented Jun 10, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-requests-vulnerability branch from cd224a3 to eb17a5c Compare June 11, 2025 00:09
@dpebot
Copy link
Collaborator

dpebot commented Jun 11, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-requests-vulnerability branch from eb17a5c to 62ec159 Compare June 11, 2025 05:09
@dpebot
Copy link
Collaborator

dpebot commented Jun 11, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-requests-vulnerability branch from 62ec159 to 74146b4 Compare June 11, 2025 14:54
@dpebot
Copy link
Collaborator

dpebot commented Jun 11, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-requests-vulnerability branch from 74146b4 to 7e0043e Compare June 11, 2025 21:10
@dpebot
Copy link
Collaborator

dpebot commented Jun 11, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-requests-vulnerability branch from 7e0043e to 91881f3 Compare June 12, 2025 04:55
@dpebot
Copy link
Collaborator

dpebot commented Jun 12, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-requests-vulnerability branch from 91881f3 to b34d6fc Compare June 12, 2025 14:58
@dpebot
Copy link
Collaborator

dpebot commented Jun 12, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-requests-vulnerability branch from b34d6fc to 3de752c Compare June 12, 2025 21:09
@dpebot
Copy link
Collaborator

dpebot commented Jun 12, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-requests-vulnerability branch from 3de752c to bdd8ac9 Compare June 13, 2025 03:06
@dpebot
Copy link
Collaborator

dpebot commented Jun 13, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-requests-vulnerability branch from bdd8ac9 to 0933da6 Compare June 13, 2025 07:35
@dpebot
Copy link
Collaborator

dpebot commented Jun 13, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-requests-vulnerability branch from 0933da6 to 7486fa6 Compare June 13, 2025 13:31
@dpebot
Copy link
Collaborator

dpebot commented Jun 13, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-requests-vulnerability branch from 7486fa6 to 6dee47a Compare June 13, 2025 19:59
@dpebot
Copy link
Collaborator

dpebot commented Jun 13, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-requests-vulnerability branch from 6dee47a to 36d28ac Compare June 13, 2025 23:11
@dpebot
Copy link
Collaborator

dpebot commented Jun 13, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-requests-vulnerability branch from 36d28ac to 78e9535 Compare June 14, 2025 02:57
@dpebot
Copy link
Collaborator

dpebot commented Jun 14, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-requests-vulnerability branch from 78e9535 to 8881e04 Compare June 14, 2025 07:07
@dpebot
Copy link
Collaborator

dpebot commented Jun 15, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-requests-vulnerability branch from 3db6d55 to 91bb0da Compare June 16, 2025 00:29
@dpebot
Copy link
Collaborator

dpebot commented Jun 16, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-requests-vulnerability branch from 91bb0da to 0a5403c Compare June 16, 2025 09:44
@dpebot
Copy link
Collaborator

dpebot commented Jun 16, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-requests-vulnerability branch from 0a5403c to cc21e46 Compare June 16, 2025 18:43
@dpebot
Copy link
Collaborator

dpebot commented Jun 16, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-requests-vulnerability branch from cc21e46 to 85f61b9 Compare June 17, 2025 00:41
@dpebot
Copy link
Collaborator

dpebot commented Jun 17, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-requests-vulnerability branch from 85f61b9 to 0597d24 Compare June 17, 2025 08:53
@dpebot
Copy link
Collaborator

dpebot commented Jun 17, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-requests-vulnerability branch from 0597d24 to 8c23b2e Compare June 17, 2025 17:57
@dpebot
Copy link
Collaborator

dpebot commented Jun 17, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-requests-vulnerability branch from 8c23b2e to 972d58b Compare June 18, 2025 00:03
@dpebot
Copy link
Collaborator

dpebot commented Jun 18, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-requests-vulnerability branch from 972d58b to face51d Compare June 18, 2025 04:11
@dpebot
Copy link
Collaborator

dpebot commented Jun 18, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-requests-vulnerability branch from face51d to d2ebcdb Compare June 18, 2025 18:37
@dpebot
Copy link
Collaborator

dpebot commented Jun 18, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-requests-vulnerability branch from d2ebcdb to 82879db Compare June 19, 2025 00:40
@dpebot
Copy link
Collaborator

dpebot commented Jun 19, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-requests-vulnerability branch from 82879db to 730e885 Compare June 19, 2025 09:26
@dpebot
Copy link
Collaborator

dpebot commented Jun 19, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-requests-vulnerability branch from 730e885 to f72c2d4 Compare June 19, 2025 17:28
@dpebot
Copy link
Collaborator

dpebot commented Jun 19, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-requests-vulnerability branch from f72c2d4 to 802a329 Compare June 20, 2025 00:26
@dpebot
Copy link
Collaborator

dpebot commented Jun 20, 2025

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/pypi-requests-vulnerability branch from 802a329 to 1808932 Compare June 20, 2025 08:31
@dpebot
Copy link
Collaborator

dpebot commented Jun 20, 2025

/gcbrun

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants