| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
|
We're not really affected by this because setting ssl_verify to False will always skip verification for all requests on the client. But maybe we can bump the minimum just so that automated security scanners are happy and we avoid more user reports. This will need an extra push though. |
Sorry, something went wrong.
Update the minimum versions of the dependencies in the pyproject.toml file. This is related to PR #2878
Update the minimum versions of the dependencies in the pyproject.toml file. This is related to PR #2878
Update the minimum versions of the dependencies in the pyproject.toml file. This is related to PR #2878
Update the minimum versions of the dependencies in the pyproject.toml file. This is related to PR #2878
Update the minimum versions of the dependencies in the pyproject.toml file. This is related to PR #2878
| Back | FazBrowse Home | New Git URL |
This PR contains the following updates:
GitHub Vulnerability Alerts
CVE-2024-35195
When making requests through a Requests Session, if the first request is made with verify=False to disable cert verification, all subsequent requests to the same origin will continue to ignore cert verification regardless of changes to the value of verify. This behavior will continue for the lifecycle of the connection in the connection pool.
Remediation
Any of these options can be used to remediate the current issue, we highly recommend upgrading as the preferred mitigation.
Related Links
Release Notes
psf/requests (requests)v2.32.0
Compare Source
Security
Session will cause subsequent requests to the same origin to also ignore
cert verification, regardless of the value of verify.
(GHSA-9wx4-h78v-vm56)
Improvements
request time variance between first and subsequent requests. It should
also minimize certificate load time on Windows systems when using a Python
version built with OpenSSL 3.x. (#6667)
(chardet or charset_normalizer) when repackaged or vendored.
This enables pip and other projects to minimize their vendoring
surface area. The Response.text() and apparent_encoding APIs
will default to utf-8 if neither library is present. (#6702)
Bugfixes
calculated in the request content-length. (#6589)
urllib3 to unnecessarily reparse the request URI. (#6644)
Deprecations
Documentation
Packaging
The source files for the projects (formerly requests) is now located
in src/requests in the Requests sdist. (#6506)
using hatchling. This should not impact the average user, but extremely old
versions of packaging utilities may have issues with the new packaging format.
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate. View repository job log here.