Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Jun 10, 2025

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
requests (source, changelog) 2.32.3 -> 2.32.4 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2024-47081

Impact

Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs.

Workarounds

For older versions of Requests, use of the .netrc file can be disabled with trust_env=False on your Requests Session (docs).

References

https://github.com/psf/requests/pull/6965
https://seclists.org/fulldisclosure/2025/Jun/2


Release Notes

psf/requests (requests)

v2.32.4

Compare Source

Security

  • CVE-2024-47081 Fixed an issue where a maliciously crafted URL and trusted
    environment will retrieve credentials for the wrong hostname/machine from a
    netrc file.

Improvements

  • Numerous documentation improvements

Deprecations

  • Added support for pypy 3.11 for Linux and macOS.
  • Dropped support for pypy 3.9 following its end of support.

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

ikheifets-splunk and others added 3 commits June 10, 2025 08:42
* feat: mTLS support for Splunk 10

* docs: fix typo

---------

Co-authored-by: Olga <86965961+omrozowicz-splunk@users.noreply.github.com>
Co-authored-by: ajasnosz <ajasnosz@splunk.com>
# [1.13.0-beta.1](v1.12.3...v1.13.0-beta.1) (2025-06-10)

### Features

* mTLS for Splunk 10 ([#1197](#1197)) ([e8cb2a4](e8cb2a4))
@renovate renovate bot requested a review from omrozowicz-splunk as a code owner June 10, 2025 10:02
@renovate renovate bot added dependencies Pull requests that update a dependency file security labels Jun 10, 2025
@renovate renovate bot requested a review from ajasnosz June 10, 2025 10:02
@ajasnosz ajasnosz closed this Jun 10, 2025
@github-actions github-actions bot locked and limited conversation to collaborators Jun 10, 2025
@renovate renovate bot changed the title chore(deps): update dependency requests to v2.32.4 [security] chore(deps): update dependency requests to v2.32.4 [security] - abandoned Jun 10, 2025
@renovate renovate bot reopened this Jun 10, 2025
Base automatically changed from develop to main September 16, 2025 10:12
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependencies Pull requests that update a dependency file security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants