Opened 8 months ago

Closed 8 months ago

#22799 closed enhancement (fixed)

Python Dependency Updates for BLFS 13.0 - certifi pyproject_metadata urllib3 uv_build

Reported by: Douglas R. Reno Owned by: Douglas R. Reno
Priority: high Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description (last modified by Douglas R. Reno)

We have four new Python dependencies to update. The packages are:

certifi: 2025.11.12 -> 2026.1.4
pyproject_metadata: 0.10.0 -> 0.11.0
urllib3: 2.6.0 -> 2.6.3
uv_build: 0.9.10 -> 0.10.2

Change History (9)

comment:1 by Douglas R. Reno, 8 months ago

Description: modified (diff)

comment:2 by Douglas R. Reno, 8 months ago

Milestone: 13.1 → 13.0

comment:3 by Douglas R. Reno, 8 months ago

Owner: changed from blfs-book to Douglas R. Reno
Status: new → assigned

comment:4 by Douglas R. Reno, 8 months ago

Certifi is just routine certificate and CI updates :)

The git log can be found at ​https://github.com/certifi/python-certifi/compare/2025.11.12...2026.01.04

comment:5 by Douglas R. Reno, 8 months ago

pyproject_metadata

This release refactors a lot of the internals to break up conversion and validation. 
This should not be noticeable except for better error messages in some cases. We also 
now test on some downstream projects; if you are using pyproject-metadata for a backend, 
you can suggest adding a downstream test to our noxfile.

Refactoring:

    Restructured internals around conversion.

Internal and CI:

    Test on some downstream projects.
    Remove some PEP 621 terminology

comment:6 by Douglas R. Reno, 8 months ago

pyproject-metadata needs exceptiongroup or it will skip many of it's tests. I've added instructions in for a virtual environment similar to what we do for other packages.

comment:7 by Douglas R. Reno, 8 months ago

Priority: normal → high

urllib3

2.6.1:

Changes

Restore previously removed HTTPResponse.getheaders() and HTTPResponse.getheader() 
methods. (#3731)

2.6.2:

Changes

Fixed HTTPResponse.read_chunked() to properly handle leftover data in the decoder's 
buffer when reading compressed chunked responses. (#3734)

2.6.3:

Changes

Fixed a security issue where decompression-bomb safeguards of the streaming API were 
bypassed when HTTP redirects were followed. (CVE-2026-21441 reported by @D47A, 8.9 High, 
GHSA-38jv-5279-wg99)

Started treating Retry-After times greater than 6 hours as 6 hours by default. (#3743)

Fixed urllib3.connection.VerifiedHTTPSConnection on Emscripten. (#3752)

There is a high severity vulnerability fixed in this update.

comment:8 by Douglas R. Reno, 8 months ago

Since uv_build is just a small subset of the entire uv package, no specific release notes are available.

comment:9 by Douglas R. Reno, 8 months ago

Resolution: → fixed
Status: assigned → closed

Fixed at 2dbf33632b9e92021eb5e919b516534f6cd2a4a6

SA-12.4-096 issued

Note: See TracTickets for help on using tickets.