← Back to issue list

build(deps): update dependency requests to v2.32.2 [security] (main)

View original Github issue

Metadata

Project
charmcraft
Number
#1920
Type
pull request
State
closed
Author
renovate[bot]
Labels
Created
Updated
Closed

Current evaluation

The requests security update to v2.32.2 was abandoned and closed without merging. Renovate confirmed the change was intentionally ignored, leaving the dependency at v2.31.0 until a newer version triggers a replacement pull request.

Suggested action:

No scores available.

Issue body

This PR contains the following updates: | Package | Change | Age | Adoption | Passing | Confidence | |---|---|---|---|---|---| | [requests](https://requests.readthedocs.io) ([source](https://redirect.github.com/psf/requests), [changelog](https://redirect.github.com/psf/requests/blob/master/HISTORY.md)) | `==2.31.0` -> `==2.32.2` | [![age](https://developer.mend.io/api/mc/badges/age/pypi/requests/2.32.2?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/pypi/requests/2.32.2?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/pypi/requests/2.31.0/2.32.2?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/pypi/requests/2.31.0/2.32.2?slim=true)](https://docs.renovatebot.com/merge-confidence/) | ### GitHub Vulnerability Alerts #### [CVE-2024-35195](https://redirect.github.com/psf/requests/security/advisories/GHSA-9wx4-h78v-vm56) When making requests through a Requests `Session`, if the first request is made with `verify=False` to disable cert verification, all subsequent requests to the same origin will continue to ignore cert verification regardless of changes to the value of `verify`. This behavior will continue for the lifecycle of the connection in the connection pool. ### Remediation Any of these options can be used to remediate the current issue, we highly recommend upgrading as the preferred mitigation. * Upgrade to `requests>=2.32.0`. * For `requests<2.32.0`, avoid setting `verify=False` for the first request to a host while using a Requests Session. * For `requests<2.32.0`, call `close()` on `Session` objects to clear existing connections if `verify=False` is used. ### Related Links * [https://github.com/psf/requests/pull/6655](https://redirect.github.com/psf/requests/pull/6655) --- ### Release Notes <details> <summary>psf/requests (requests)</summary> ### [`v2.32.2`](https://redirect.github.com/psf/requests/blob/HEAD/HISTORY.md#2322-2024-05-21) [Compare Source](https://redirect.github.com/psf/requests/compare/v2.32.1...v2.32.2) **Deprecations** - To provide a more stable migration for custom HTTPAdapters impacted by the CVE changes in 2.32.0, we've renamed `_get_connection` to a new public API, `get_connection_with_tls_context`. Existing custom HTTPAdapters will need to migrate their code to use this new API. `get_connection` is considered deprecated in all versions of Requests>=2.32.0. A minimal (2-line) example has been provided in the linked PR to ease migration, but we strongly urge users to evaluate if their custom adapter is subject to the same issue described in CVE-2024-35195. ([#&#8203;6710](https://redirect.github.com/psf/requests/issues/6710)) ### [`v2.32.1`](https://redirect.github.com/psf/requests/blob/HEAD/HISTORY.md#2321-2024-05-20) [Compare Source](https://redirect.github.com/psf/requests/compare/v2.32.0...v2.32.1) **Bugfixes** - Add missing test certs to the sdist distributed on PyPI. ### [`v2.32.0`](https://redirect.github.com/psf/requests/blob/HEAD/HISTORY.md#2320-2024-05-20) [Compare Source](https://redirect.github.com/psf/requests/compare/v2.31.0...v2.32.0) **Security** - Fixed an issue where setting `verify=False` on the first request from a Session will cause subsequent requests to the *same origin* to also ignore cert verification, regardless of the value of `verify`. (https://github.com/psf/requests/security/advisories/GHSA-9wx4-h78v-vm56) **Improvements** - `verify=True` now reuses a global SSLContext which should improve request time variance between first and subsequent requests. It should also minimize certificate load time on Windows systems when using a Python version built with OpenSSL 3.x. ([#&#8203;6667](https://redirect.github.com/psf/requests/issues/6667)) - Requests now supports optional use of character detection (`chardet` or `charset_normalizer`) when repackaged or vendored. This enables `pip` and other projects to minimize their vendoring surface area. The `Response.text()` and `apparent_encoding` APIs will default to `utf-8` if neither library is present. ([#&#8203;6702](https://redirect.github.com/psf/requests/issues/6702)) **Bugfixes** - Fixed bug in length detection where emoji length was incorrectly calculated in the request content-length. ([#&#8203;6589](https://redirect.github.com/psf/requests/issues/6589)) - Fixed deserialization bug in JSONDecodeError. ([#&#8203;6629](https://redirect.github.com/psf/requests/issues/6629)) - Fixed bug where an extra leading `/` (path separator) could lead urllib3 to unnecessarily reparse the request URI. ([#&#8203;6644](https://redirect.github.com/psf/requests/issues/6644)) **Deprecations** - Requests has officially added support for CPython 3.12 ([#&#8203;6503](https://redirect.github.com/psf/requests/issues/6503)) - Requests has officially added support for PyPy 3.9 and 3.10 ([#&#8203;6641](https://redirect.github.com/psf/requests/issues/6641)) - Requests has officially dropped support for CPython 3.7 ([#&#8203;6642](https://redirect.github.com/psf/requests/issues/6642)) - Requests has officially dropped support for PyPy 3.7 and 3.8 ([#&#8203;6641](https://redirect.github.com/psf/requests/issues/6641)) **Documentation** - Various typo fixes and doc improvements. **Packaging** - Requests has started adopting some modern packaging practices. The source files for the projects (formerly `requests`) is now located in `src/requests` in the Requests sdist. ([#&#8203;6506](https://redirect.github.com/psf/requests/issues/6506)) - Starting in Requests 2.33.0, Requests will migrate to a PEP 517 build system using `hatchling`. This should not impact the average user, but extremely old versions of packaging utilities may have issues with the new packaging format. </details> --- ### Configuration 📅 **Schedule**: Branch creation - "" in timezone Etc/UTC, Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/canonical/charmcraft). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC45NC4zIiwidXBkYXRlZEluVmVyIjoiMzguOTcuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19-->

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.6-35b-a3b The requests security update to v2.32.2 was abandoned and closed without merging. Renovate confirmed the change was intentionally ignored, leaving the dependency at v2.31.0 until a newer version triggers a replacement pull request.
qwen3.6-35b-a3b-mtp-q6 Abandoned without merging. The security update to requests v2.32.2 was closed, and Renovate will ignore this version, waiting to generate a new PR for a newer release.
qwen3.6-35b-a3b-mtp-q6 Closed without merging. The maintainer rejected the requests security update to v2.32.2, prompting Renovate to ignore this version and await a newer release.

Update history

No update history recorded yet.

Related issues

Issue Project State Summary Similarity
#6125 build(deps): update dependency requests to v2.33.0 [security] (main) - autoclosed snapcraft closed Renovate automatically closed the requests v2.33.0 security update without merging. The PR was abandoned due to inactivity and unresolved CI checks, leaving the dependency outdated.
89%
#5549 build(deps): update dependency requests to v2.32.4 [security] (main) snapcraft closed The PR was closed without merging. The maintainer indicated the security fix for the requests library would be handled via a separate PR (#5557) instead.
88%
#5066 build(deps): update dependency requests to v2.32.2 [security] (hotfix/8.3) snapcraft closed Closed without merging. The requests security update to v2.32.2 was abandoned due to inactivity, with no reviewer comments or CI checks. Likely superseded by a newer dependency update.
88%
#1117 build(deps): update dependency requests to v2.32.4 [security] (main) - autoclosed craft-parts closed Renovate autoclosed the pull request updating requests to v2.32.4 for CVE-2024-47081. The security update was automatically closed and unmerged, likely due to CI failures or being superseded.
87%
#1119 build(deps): update dependency requests to v2.32.4 [security] (hotfix/2.7) - autoclosed craft-parts closed A dependency update to requests v2.32.4 addressing CVE-2024-47081 was autoclosed by the Renovate bot. The security patch was abandoned or superseded without merging.
87%
#1921 build(deps): update dependency requests to v2.32.2 [security] (hotfix/2.7) - autoclosed charmcraft closed Renovate bot pull request updating requests to v2.32.2 to address CVE-2024-35195 was autoclosed. The dependency update was not merged and remains abandoned, likely due to branch deletion or being superseded by another resolution.
86%
#1118 build(deps): update dependency requests to v2.32.4 [security] (hotfix/2.4) - autoclosed craft-parts closed The security update for requests to v2.32.4 was autoclosed by Renovate without merging. The dependency change was not applied to the hotfix/2.4 branch.
86%
#1922 build(deps): update dependency requests to v2.32.2 [security] (hotfix/3.2) - autoclosed charmcraft closed Automated update to requests v2.32.2 for CVE-2024-35195 on the hotfix/3.2 branch. The pull request was autoclosed without review or merge, indicating it was abandoned or superseded.
84%
#5550 build(deps): update dependency requests to v2.32.4 [security] (hotfix/7.5) - autoclosed snapcraft closed Automated dependency update to requests v2.32.4 for CVE-2024-47081 was autoclosed without merging. The security patch was abandoned and not applied to the repository.
84%
#5064 build(deps): update dependency requests to v2.32.2 [security] (main) snapcraft merged Merged to main after approval and CI. Updates requests from v2.31.0 to v2.32.2 to fix CVE-2024-35195, resolving an SSL verification bypass vulnerability in persistent sessions.
83%