Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump requests from 1.0.0 to 2.31.0 #7

Merged
merged 1 commit into from
Feb 5, 2024

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Feb 5, 2024

⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


Bumps requests from 1.0.0 to 2.31.0.

Release notes

Sourced from requests's releases.

v2.31.0

2.31.0 (2023-05-22)

Security

  • Versions of Requests between v2.3.0 and v2.30.0 are vulnerable to potential forwarding of Proxy-Authorization headers to destination servers when following HTTPS redirects.

    When proxies are defined with user info (https://user:pass@proxy:8080), Requests will construct a Proxy-Authorization header that is attached to the request to authenticate with the proxy.

    In cases where Requests receives a redirect response, it previously reattached the Proxy-Authorization header incorrectly, resulting in the value being sent through the tunneled connection to the destination server. Users who rely on defining their proxy credentials in the URL are strongly encouraged to upgrade to Requests 2.31.0+ to prevent unintentional leakage and rotate their proxy credentials once the change has been fully deployed.

    Users who do not use a proxy or do not supply their proxy credentials through the user information portion of their proxy URL are not subject to this vulnerability.

    Full details can be read in our Github Security Advisory and CVE-2023-32681.

v2.30.0

2.30.0 (2023-05-03)

Dependencies

v2.29.0

2.29.0 (2023-04-26)

Improvements

  • Requests now defers chunked requests to the urllib3 implementation to improve standardization. (#6226)
  • Requests relaxes header component requirements to support bytes/str subclasses. (#6356)

... (truncated)

Changelog

Sourced from requests's changelog.

2.31.0 (2023-05-22)

Security

  • Versions of Requests between v2.3.0 and v2.30.0 are vulnerable to potential forwarding of Proxy-Authorization headers to destination servers when following HTTPS redirects.

    When proxies are defined with user info (https://user:pass@proxy:8080), Requests will construct a Proxy-Authorization header that is attached to the request to authenticate with the proxy.

    In cases where Requests receives a redirect response, it previously reattached the Proxy-Authorization header incorrectly, resulting in the value being sent through the tunneled connection to the destination server. Users who rely on defining their proxy credentials in the URL are strongly encouraged to upgrade to Requests 2.31.0+ to prevent unintentional leakage and rotate their proxy credentials once the change has been fully deployed.

    Users who do not use a proxy or do not supply their proxy credentials through the user information portion of their proxy URL are not subject to this vulnerability.

    Full details can be read in our Github Security Advisory and CVE-2023-32681.

2.30.0 (2023-05-03)

Dependencies

2.29.0 (2023-04-26)

Improvements

  • Requests now defers chunked requests to the urllib3 implementation to improve standardization. (#6226)
  • Requests relaxes header component requirements to support bytes/str subclasses. (#6356)

2.28.2 (2023-01-12)

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [requests](https://github.com/psf/requests) from 1.0.0 to 2.31.0.
- [Release notes](https://github.com/psf/requests/releases)
- [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md)
- [Commits](psf/requests@v1.0.0...v2.31.0)

---
updated-dependencies:
- dependency-name: requests
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Feb 5, 2024
@codecov-commenter
Copy link

Codecov Report

All modified and coverable lines are covered by tests ✅

Comparison is base (9593254) 78.58% compared to head (e947651) 78.58%.

❗ Your organization needs to install the Codecov GitHub app to enable full functionality.

Additional details and impacted files
@@           Coverage Diff           @@
##              dev       #7   +/-   ##
=======================================
  Coverage   78.58%   78.58%           
=======================================
  Files           4        4           
  Lines          98       98           
  Branches       12       12           
=======================================
  Hits           77       77           
  Misses         10       10           
  Partials       11       11           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@AHReccese AHReccese merged commit 2b989f0 into dev Feb 5, 2024
36 checks passed
@dependabot dependabot bot deleted the dependabot/pip/dev/requests-2.31.0 branch February 5, 2024 09:42
AHReccese added a commit that referenced this pull request Feb 7, 2024
* add dev-requirements for reserver package

* import uploader object in `__init__`

* add function to check given name existance as a package name

* add function to generate template `setup.py` for the given name

* `Uploader` object initialization

* add `upload_to_pypi` function

* add pypi associated params to `reserver_param.py`

* add docstring for functions in `reserver_func.py`

* update docstring

* add `is_platform_linux` & `get_random_name` utility function

* apply `autopep8.sh`

* add `test.pypi` credentials to test.yml

* add package name to the params

* update test step's name

* reserved name package upload test case

* update .gitignore

* update the exception's description

* update test files

* add requests requirement to `dev-requirements.txt`

* add timeout to `get` request

* add `bandit` config file

* update `test.yml`

* update docstring issues reported by `pydocstyle`

* clean `imports` part

* add return value for `upload_to_pypi` function

* handle invalid PyPI API Key

* split test cases
add `package_exists` test case
add `valid_package_invalid_credentials` test case
add `valid_package_valid_credentials` test case

* enhance docstrings

* remove python 3.6 support for now

* remove assert & dummy pass detection rules in bandit

* add test case to `README.md`

* add placeholder for github stars

* add placeholder for PyPI counter

* update `CHANGELOG.md`

* `dev-requirements.txt` updated

* `requirements.txt` updated

* remove installation of requirements

* temporarily removed `importlib-metadata<5.0`

* remove unused import

* remove `is_platform_linux` function

* move `get_random_name` function from `utils.py` to `reserver_func.py`

* update template `setup.py`

* update docstrings

* remove `util.py` and add inner functionalities to `reserver_func.py`

* update test file import

* update author email

* add logo to readme

* partially update discord badge

* add Logo `.png` file

* fullfil discord badges

* fullfil `pypi` badge in `README.md`

* add References + fix typo

* remove `\n` from packages

* add functionality to create folder with the package name with a __init__.py inside

* make param name shorter

* handle "-" issue in `.eggfile`(replace with "_")

* handle too similiar name

* remove extra print in `reserver_obj.py`

* update test cases

* `README.md` updated

* `CHANGELOG.md` updated

* logo name updated

* fix `requests` requirment to trigger dependent bot

* add `requests` to package main requirments

* remove python 3.6

* correct typo in docstring

* ensure env variables are popped out

* change `>=` to `==` in basic requirments' version to trigger dependent bot

* Bump twine from 4.0.0 to 4.0.2 (#6)

Bumps [twine](https://github.com/pypa/twine) from 4.0.0 to 4.0.2.
- [Release notes](https://github.com/pypa/twine/releases)
- [Changelog](https://github.com/pypa/twine/blob/main/docs/changelog.rst)
- [Commits](pypa/twine@4.0.0...4.0.2)

---
updated-dependencies:
- dependency-name: twine
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Bump requests from 1.0.0 to 2.31.0 (#7)

Bumps [requests](https://github.com/psf/requests) from 1.0.0 to 2.31.0.
- [Release notes](https://github.com/psf/requests/releases)
- [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md)
- [Commits](psf/requests@v1.0.0...v2.31.0)

---
updated-dependencies:
- dependency-name: requests
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Bump wheel from 0.40.0 to 0.42.0 (#8)

Bumps [wheel](https://github.com/pypa/wheel) from 0.40.0 to 0.42.0.
- [Release notes](https://github.com/pypa/wheel/releases)
- [Changelog](https://github.com/pypa/wheel/blob/main/docs/news.rst)
- [Commits](pypa/wheel@0.40.0...0.42.0)

---
updated-dependencies:
- dependency-name: wheel
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Bump setuptools from 40.8.0 to 69.0.3 (#9)

Bumps [setuptools](https://github.com/pypa/setuptools) from 40.8.0 to 69.0.3.
- [Release notes](https://github.com/pypa/setuptools/releases)
- [Changelog](https://github.com/pypa/setuptools/blob/main/NEWS.rst)
- [Commits](pypa/setuptools@v40.8.0...v69.0.3)

---
updated-dependencies:
- dependency-name: setuptools
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* `Disclaimer` section added

* add disclaimer to table of index

* `README.md` updated

---------

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants