terraform-google-scheduled-function icon indicating copy to clipboard operation
terraform-google-scheduled-function copied to clipboard

chore(deps): Update dependency requests to v2.32.4 [SECURITY]

Open renovate[bot] opened this issue 5 months ago • 17 comments

This PR contains the following updates:

Package Change Age Confidence
requests (source, changelog) ==2.32.3 -> ==2.32.4 age confidence

GitHub Vulnerability Alerts

CVE-2024-47081

Impact

Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs.

Workarounds

For older versions of Requests, use of the .netrc file can be disabled with trust_env=False on your Requests Session (docs).

References

https://github.com/psf/requests/pull/6965 https://seclists.org/fulldisclosure/2025/Jun/2


Release Notes

psf/requests (requests)

v2.32.4

Compare Source

Security

  • CVE-2024-47081 Fixed an issue where a maliciously crafted URL and trusted environment will retrieve credentials for the wrong hostname/machine from a netrc file.

Improvements

  • Numerous documentation improvements

Deprecations

  • Added support for pypy 3.11 for Linux and macOS.
  • Dropped support for pypy 3.9 following its end of support.

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • [ ] If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

renovate[bot] avatar Jun 10 '25 09:06 renovate[bot]

/gcbrun

dpebot avatar Jun 10 '25 09:06 dpebot

/gcbrun

dpebot avatar Aug 22 '25 17:08 dpebot

/gcbrun

dpebot avatar Aug 22 '25 18:08 dpebot

/gcbrun

dpebot avatar Sep 11 '25 01:09 dpebot

/gcbrun

dpebot avatar Sep 11 '25 04:09 dpebot

/gcbrun

dpebot avatar Sep 11 '25 10:09 dpebot

/gcbrun

dpebot avatar Sep 11 '25 13:09 dpebot

/gcbrun

dpebot avatar Sep 11 '25 20:09 dpebot

/gcbrun

dpebot avatar Sep 11 '25 21:09 dpebot

/gcbrun

dpebot avatar Sep 11 '25 22:09 dpebot

/gcbrun

dpebot avatar Sep 11 '25 22:09 dpebot

/gcbrun

dpebot avatar Sep 12 '25 04:09 dpebot

/gcbrun

dpebot avatar Sep 15 '25 17:09 dpebot

/gcbrun

dpebot avatar Sep 15 '25 20:09 dpebot

/gcbrun

dpebot avatar Sep 16 '25 20:09 dpebot

/gcbrun

dpebot avatar Oct 28 '25 16:10 dpebot

/gcbrun

dpebot avatar Oct 28 '25 18:10 dpebot

/gcbrun

dpebot avatar Nov 12 '25 22:11 dpebot

/gcbrun

dpebot avatar Nov 12 '25 23:11 dpebot

/gcbrun

dpebot avatar Nov 13 '25 05:11 dpebot

/gcbrun

dpebot avatar Nov 13 '25 23:11 dpebot