build(deps): update dependency requests to v2.33.0 [security] (main)
Metadata
Current evaluation
Merged automated dependency update upgrading requests from 2.32.4 to 2.33.0 to resolve CVE-2026-25645. Approved by reviewers, passed CI checks, and merged into main.
Suggested action: —
No scores available.
Issue body
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [requests](https://redirect.github.com/psf/requests) ([changelog](https://redirect.github.com/psf/requests/blob/master/HISTORY.md)) | `2.32.4` → `2.33.0` |  |  |
### GitHub Vulnerability Alerts
#### [CVE-2026-25645](https://redirect.github.com/psf/requests/security/advisories/GHSA-gc5v-m9x4-r6x2)
### Impact
The `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one.
### Affected usages
**Standard usage of the Requests library is not affected by this vulnerability.** Only applications that call `extract_zipped_paths()` directly are impacted.
### Remediation
Upgrade to at least Requests 2.33.0, where the library now extracts files to a non-deterministic location.
If developers are unable to upgrade, they can set `TMPDIR` in their environment to a directory with restricted write access.
---
### Release Notes
<details>
<summary>psf/requests (requests)</summary>
### [`v2.33.0`](https://redirect.github.com/psf/requests/blob/HEAD/HISTORY.md#2330-2026-03-25)
[Compare Source](https://redirect.github.com/psf/requests/compare/v2.32.5...v2.33.0)
**Announcements**
- 📣 Requests is adding inline types. If you have a typed code base that
uses Requests, please take a look at [#​7271](https://redirect.github.com/psf/requests/issues/7271). Give it a try, and report
any gaps or feedback you may have in the issue. 📣
**Security**
- CVE-2026-25645 `requests.utils.extract_zipped_paths` now extracts
contents to a non-deterministic location to prevent malicious file
replacement. This does not affect default usage of Requests, only
applications calling the utility function directly.
**Improvements**
- Migrated to a PEP 517 build system using setuptools. ([#​7012](https://redirect.github.com/psf/requests/issues/7012))
**Bugfixes**
- Fixed an issue where an empty netrc entry could cause
malformed authentication to be applied to Requests on
Python 3.11+. ([#​7205](https://redirect.github.com/psf/requests/issues/7205))
**Deprecations**
- Dropped support for Python 3.9 following its end of support. ([#​7196](https://redirect.github.com/psf/requests/issues/7196))
**Documentation**
- Various typo fixes and doc improvements.
### [`v2.32.5`](https://redirect.github.com/psf/requests/blob/HEAD/HISTORY.md#2325-2025-08-18)
[Compare Source](https://redirect.github.com/psf/requests/compare/v2.32.4...v2.32.5)
**Bugfixes**
- The SSLContext caching feature originally introduced in 2.32.0 has created
a new class of issues in Requests that have had negative impact across a number
of use cases. The Requests team has decided to revert this feature as long term
maintenance of it is proving to be unsustainable in its current iteration.
**Deprecations**
- Added support for Python 3.14.
- Dropped support for Python 3.8 following its end of support.
</details>
---
### Configuration
📅 **Schedule**: Branch creation - "" in timezone Etc/UTC, Automerge - At any time (no schedule defined).
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/canonical/craft-store).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My45MS41IiwidXBkYXRlZEluVmVyIjoiNDMuOTEuNSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiUFI6IERlcGVuZGVuY2llcyJdfQ==-->
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Merged automated dependency update upgrading requests from 2.32.4 to 2.33.0 to resolve CVE-2026-25645. Approved by reviewers, passed CI checks, and merged into main. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Merged automated dependency update upgrading requests from v2.32.4 to v2.33.0 to patch CVE-2026-25645, a security flaw in extract_zipped_paths. Applied to main by Renovate. |
Update history
No update history recorded yet.
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #1516 build(deps): update dependency requests to v2.33.0 [security] (main) | craft-parts | merged | Merged automated dependency update upgrading requests from 2.32.5 to 2.33.0 to patch CVE-2026-25645. Approved by two reviewers, passed CI validation, and merged into main. | |
| #5064 build(deps): update dependency requests to v2.32.2 [security] (main) | snapcraft | merged | Merged to main after approval and CI. Updates requests from v2.31.0 to v2.32.2 to fix CVE-2024-35195, resolving an SSL verification bypass vulnerability in persistent sessions. | |
| #5065 build(deps): update dependency requests to v2.32.2 [security] (hotfix/7.5) | snapcraft | merged | Merged an automated security update upgrading the requests dependency from v2.28.1 to v2.32.2 to fix CVE-2024-35195. Approved by two reviewers, passed CI, and merged into the hotfix/7.5 branch. | |
| #1519 build(deps): update dependency requests to v2.33.0 [security] (hotfix/2.7) | craft-parts | closed | Updated requests to v2.33.0 to patch CVE-2026-25645. Closed without merging, likely due to failing CI checks or abandonment. No reviewer comments were recorded. | |
| #5067 build(deps): update dependency requests to v2.32.2 [security] (hotfix/8.4) | snapcraft | merged | Merged security hotfix updating requests from v2.31.0 to v2.32.2 to resolve CVE-2024-35195, fixing SSL verification state leakage in HTTP sessions. Approved by two reviewers and passed CI checks. | |
| #122 build(deps): bump requests from 2.32.5 to 2.33.0 | starflow | merged | Merged Dependabot update bumping requests from 2.32.5 to 2.33.0. Includes CVE-2026-25645 security fix and Python 3.9 removal. All CI checks passed and two reviewers approved the change prior to merge. | |
| #1117 build(deps): update dependency requests to v2.32.4 [security] (main) - autoclosed | craft-parts | closed | Renovate autoclosed the pull request updating requests to v2.32.4 for CVE-2024-47081. The security update was automatically closed and unmerged, likely due to CI failures or being superseded. | |
| #5553 build(deps): bump requests to 2.32.4 | snapcraft | merged | Merged a dependency update bumping requests to 2.32.4 to patch a security vulnerability. Approved by two reviewers and passed core CI checks before integration. | |
| #106 build(deps): bump requests from 2.32.5 to 2.33.0 | debcraft | merged | Merged Dependabot update bumping requests from 2.32.5 to 2.33.0. Includes CVE-2026-25645 security fix, PEP 517 migration, and Python 3.9 removal. Approved by two reviewers with all CI checks passing before merge. | |
| #308 build: update requests to 2.33.0 | imagecraft | merged | Merged a dependency update bumping requests to 2.33.0 to resolve an OSV. Approved by two reviewers and passed CI, the single-file change addresses the security vulnerability. |