chore(deps-dev): bump urllib3 from 2.4.0 to 2.5.0
Type: Pull Request
State: Open
![dependabot[bot]](https://github.com/dependabot.png)
Association: Contributor
Comments: 0
(3 months ago)
(3 months ago)
dependencies python
Bumps urllib3 from 2.4.0 to 2.5.0.
Release notes
Sourced from urllib3's releases.
2.5.0
🚀 urllib3 is fundraising for HTTP/2 support
urllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project after a sharp decline in financial support. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects please consider contributing financially to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.
Thank you for your support.
Security issues
urllib3 2.5.0 fixes two moderate security issues:
- Pool managers now properly control redirects when
retries
is passed — CVE-2025-50181 reported by@​sandumjacob
(5.3 Medium, GHSA-pq67-6m6q-mj2v)- Redirects are now controlled by urllib3 in the Node.js runtime — CVE-2025-50182 (5.3 Medium, GHSA-48p4-8xcf-vxj5)
Features
- Added support for the
compression.zstd
module that is new in Python 3.14. See PEP 784 for more information. (#3610)- Added support for version 0.5 of
hatch-vcs
(#3612)Bugfixes
Changelog
Sourced from urllib3's changelog.
2.5.0 (2025-06-18)
Features
- Added support for the
compression.zstd
module that is new in Python 3.14. SeePEP 784 <https://peps.python.org/pep-0784/>
_ for more information. ([#3610](https://github.com/urllib3/urllib3/issues/3610) <https://github.com/urllib3/urllib3/issues/3610>
__)- Added support for version 0.5 of
hatch-vcs
([#3612](https://github.com/urllib3/urllib3/issues/3612) <https://github.com/urllib3/urllib3/issues/3612>
__)Bugfixes
- Fixed a security issue where restricting the maximum number of followed redirects at the
urllib3.PoolManager
level via theretries
parameter did not work.- Made the Node.js runtime respect redirect parameters such as
retries
andredirects
.- Raised exception for
HTTPResponse.shutdown
on a connection already released to the pool. ([#3581](https://github.com/urllib3/urllib3/issues/3581) <https://github.com/urllib3/urllib3/issues/3581>
__)- Fixed incorrect
CONNECT
statement when using an IPv6 proxy withconnection_from_host
. Previously would not be wrapped in[]
. ([#3615](https://github.com/urllib3/urllib3/issues/3615) <https://github.com/urllib3/urllib3/issues/3615>
__)
Commits
aaab4ec
Release 2.5.07eb4a2a
Merge commit from forkf05b132
Merge commit from forkd03fe32
Fix HTTP tunneling with IPv6 in older Python versions11661e9
Bump github/codeql-action from 3.28.0 to 3.29.0 (#3624)6a0ecc6
Update v2 migration guide to 2.4.0 (#3621)8e32e60
Raise exception for shutdown on a connection already released to the pool (#3...9996e0f
Fix emscripten CI for Chrome 137+ (#3599)4fd1a99
Bump RECENT_DATE (#3617)c4b5917
Add support for the newcompression.zstd
module in Python 3.14 (#3611)- Additional commits viewable in compare view
Most Recent Ignore Conditions Applied to This Pull Request
Dependency Name | Ignore Conditions |
---|---|
urllib3 | [>= 2.3.dev0, < 2.4] |
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Pull Request Statistics
1
1
+1
-1
Package Dependencies
Security Advisories
urllib3 does not control redirects in browsers and Node.js
urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation
Technical Details
ID: | 1902875 |
UUID: | 2603533693 |
Node ID: | PR_kwDODnmQMs6bLsV9 |
Host: | GitHub |
Repository: | microsoftgraph/msgraph-sdk-python-core |
Merge State: | Unknown |