Update dependency urllib3 to v1.26.5 #122
Open
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
==1.25.8
->==1.26.5
By merging this PR, the below vulnerabilities will be automatically resolved:
Release Notes
urllib3/urllib3
v1.26.5
Compare Source
===================
six
library to 1.16.0.the authority component.
v1.26.4
Compare Source
===================
SSLContext
when connecting to HTTPS proxyduring HTTPS requests. The default
SSLContext
now setscheck_hostname=True
.v1.26.3
Compare Source
===================
Fixed bytes and string comparison issue with headers (Pull #2141)
Changed
ProxySchemeUnknown
error message to bemore actionable if the user supplies a proxy URL without
a scheme. (Pull #2107)
v1.26.2
Compare Source
===================
wrap_socket
andCERT_REQUIRED
wouldn'tbe imported properly on Python 2.7.8 and earlier (Pull #2052)
v1.26.1
Compare Source
===================
User-Agent
headers would be sent if aUser-Agent
header key is passed asbytes
(Pull #2047)v1.26.0
Compare Source
===================
NOTE: urllib3 v2.0 will drop support for Python 2.
Read more in the v2.0 Roadmap <https://urllib3.readthedocs.io/en/latest/v2-roadmap.html>
_.Added support for HTTPS proxies contacting HTTPS servers (Pull #1923, Pull #1806)
Deprecated negotiating TLSv1 and TLSv1.1 by default. Users that
still wish to use TLS earlier than 1.2 without a deprecation warning
should opt-in explicitly by setting
ssl_version=ssl.PROTOCOL_TLSv1_1
(Pull #2002)Starting in urllib3 v2.0: Connections that receive a
DeprecationWarning
will failDeprecated
Retry
optionsRetry.DEFAULT_METHOD_WHITELIST
,Retry.DEFAULT_REDIRECT_HEADERS_BLACKLIST
and
Retry(method_whitelist=...)
in favor ofRetry.DEFAULT_ALLOWED_METHODS
,Retry.DEFAULT_REMOVE_HEADERS_ON_REDIRECT
, andRetry(allowed_methods=...)
(Pull #2000) Starting in urllib3 v2.0: Deprecated options will be removed
Added default
User-Agent
header to every request (Pull #1750)Added
urllib3.util.SKIP_HEADER
for skippingUser-Agent
,Accept-Encoding
,and
Host
headers from being automatically emitted with requests (Pull #2018)Collapse
transfer-encoding: chunked
request data and framing intothe same
socket.send()
call (Pull #1906)Send
http/1.1
ALPN identifier with every TLS handshake by default (Pull #1894)Properly terminate SecureTransport connections when CA verification fails (Pull #1977)
Don't emit an
SNIMissingWarning
when passingserver_hostname=None
to SecureTransport (Pull #1903)
Disabled requesting TLSv1.2 session tickets as they weren't being used by urllib3 (Pull #1970)
Suppress
BrokenPipeError
when writing request body after the serverhas closed the socket (Pull #1524)
Wrap
ssl.SSLError
that can be raised from reading a socket (e.g. "bad MAC")into an
urllib3.exceptions.SSLError
(Pull #1939)v1.25.11
Compare Source
====================
Fix retry backoff time parsed from
Retry-After
header when givenin the HTTP date format. The HTTP date was parsed as the local timezone
rather than accounting for the timezone in the HTTP date (typically
UTC) (Pull #1932, Pull #1935, Pull #1938, Pull #1949)
Fix issue where an error would be raised when the
SSLKEYLOGFILE
environment variable was set to the empty string. Now
SSLContext.keylog_file
is not set in this situation (Pull #2016)
v1.25.10
Compare Source
====================
Added support for
SSLKEYLOGFILE
environment variable forlogging TLS session keys with use with programs like
Wireshark for decrypting captured web traffic (Pull #1867)
Fixed loading of SecureTransport libraries on macOS Big Sur
due to the new dynamic linker cache (Pull #1905)
Collapse chunked request bodies data and framing into one
call to
send()
to reduce the number of TCP packets by 2-4x (Pull #1906)Don't insert
None
intoConnectionPool
if the poolwas empty when requesting a connection (Pull #1866)
Avoid
hasattr
call inBrotliDecoder.decompress()
(Pull #1858)v1.25.9
Compare Source
===================
Added
InvalidProxyConfigurationWarning
which is raised whenerroneously specifying an HTTPS proxy URL. urllib3 doesn't currently
support connecting to HTTPS proxies but will soon be able to
and we would like users to migrate properly without much breakage.
See
this GitHub issue <https://github.com/urllib3/urllib3/issues/1850>
_for more information on how to fix your proxy config. (Pull #1851)
Drain connection after
PoolManager
redirect (Pull #1817)Ensure
load_verify_locations
raisesSSLError
for all backends (Pull #1812)Rename
VerifiedHTTPSConnection
toHTTPSConnection
(Pull #1805)Allow the CA certificate data to be passed as a string (Pull #1804)
Raise
ValueError
if method contains control characters (Pull #1800)Add
__repr__
toTimeout
(Pull #1795)