Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade requests dependency to 2.32.3 #3135

Closed
mbastian opened this issue Sep 16, 2024 · 1 comment
Closed

Upgrade requests dependency to 2.32.3 #3135

mbastian opened this issue Sep 16, 2024 · 1 comment
Labels
duplicate The answer/solution already exists somewhere question Someone is looking for answers requirements workaround exists You can reach your destination if you do this...

Comments

@mbastian
Copy link

Hi, and thank you for maintaining this great library!

Could you please upgrade the requests dependency? The 2.3.1 version is from May 22nd and has a vulnerability (CVE-2024-35195). The 2.32.3 is the latest version.

Thanks in advance!

@mdmintz mdmintz added the duplicate The answer/solution already exists somewhere label Sep 16, 2024
@mdmintz
Copy link
Member

mdmintz commented Sep 16, 2024

Duplicate of #3097 (comment)


There's an issue in requests 2.32.3 leading to "widespread breakage" as mentioned in psf/requests#6730 (comment), and psf/requests#6726. I already talked about this here: #2838 (comment), and here: #2951 (comment).

There's already a PR in place to fix that major issue with requests: psf/requests#6731. Until that fix is in, I'll need to keep requests pinned to 2.31.0. (The versions between 2.31.0 and 2.32.3 had other issues.)

If you absolutely need requests 2.32.3 now (even with that issue), then feel free to force install it.

@mdmintz mdmintz closed this as completed Sep 16, 2024
@mdmintz mdmintz added question Someone is looking for answers requirements workaround exists You can reach your destination if you do this... labels Sep 16, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
duplicate The answer/solution already exists somewhere question Someone is looking for answers requirements workaround exists You can reach your destination if you do this...
Projects
None yet
Development

No branches or pull requests

2 participants