Opened 11 months ago
Closed 11 months ago
#19821 closed enhancement (fixed)
requests-2.32.2 (Python module)
Reported by: | Bruce Dubbs | Owned by: | Bruce Dubbs |
---|---|---|---|
Priority: | normal | Milestone: | 12.2 |
Component: | BOOK | Version: | git |
Severity: | normal | Keywords: | |
Cc: |
Description ¶
New minor version.
Change History (7)
comment:1 by , 11 months ago
Owner: | changed from | to
---|---|
Status: | new → assigned |
comment:2 by , 11 months ago
Summary: | requests-2.32.1 (Pythin module) → requests-2.32.1 (Python module) |
---|
comment:3 by , 11 months ago
comment:4 by , 11 months ago
Resolution: | → fixed |
---|---|
Status: | assigned → closed |
Fixed at commits
6246e0842a Update to sentry_sdk-2.2.1 (Python module). c6c8877c7e Update to lxml-5.2.2 (Python module). 2996a54605 Mako-1.3.4 (Python module). 421e473976 Update to gi_docgen-2024.1 (Python module). d498165b94 Update to requests-2.32.1 (Python module).
comment:5 by , 11 months ago
Resolution: | fixed |
---|---|
Status: | closed → reopened |
Summary: | requests-2.32.1 (Python module) → requests-2.32.2 (Python module) |
Now version 2.32.2.
comment:6 by , 11 months ago
2.32.2 (2024-05-21)
Deprecations
- To provide a more stable migration for custom HTTPAdapters impacted
by the CVE changes in 2.32.0, we've renamed
_get_connection
to a new public API,get_connection_with_tls_context
. Existing custom HTTPAdapters will need to migrate their code to use this new API.get_connection
is considered deprecated in all versions of Requests>=2.32.0.
A minimal (2-line) example has been provided to ease migration, but we strongly urge users to evaluate if their custom adapter is subject to the same issue described in CVE-2024-35195.
comment:7 by , 11 months ago
Resolution: | → fixed |
---|---|
Status: | reopened → closed |
Note:
See TracTickets
for help on using tickets.
2.32.1 (2024-05-20)
Bugfixes
2.32.0 (2024-05-20)
Security
verify=False
on the first request from a Session will cause subsequent requests to the _same origin_ to also ignore cert verification, regardless of the value ofverify
. (https://github.com/psf/requests/security/advisories/GHSA-9wx4-h78v-vm56)Improvements
verify=True
now reuses a global SSLContext which should improve request time variance between first and subsequent requests. It should also minimize certificate load time on Windows systems when using a Python version built with OpenSSL 3.x.chardet
orcharset_normalizer
) when repackaged or vendored. This enablespip
and other projects to minimize their vendoring surface area. TheResponse.text()
andapparent_encoding
APIs will default toutf-8
if neither library is present.Bugfixes
/
(path separator) could lead urllib3 to unnecessarily reparse the request URI.Deprecations
Documentation
Packaging
requests
) is now located insrc/requests
in the Requests sdist.hatchling
. This should not impact the average user, but extremely old versions of packaging utilities may have issues with the new packaging format.