Skip to content

[Snyk] Security upgrade urllib3 from 2.0.7 to 2.8.0 - #91

Open
HeyItsGilbert wants to merge 1 commit into
mainfrom
snyk-fix-5aeb22aba9e7c85c7a5275f1160ef3e9
Open

HeyItsGilbert wants to merge 1 commit into
mainfrom
snyk-fix-5aeb22aba9e7c85c7a5275f1160ef3e9

Conversation

@HeyItsGilbert

Copy link
Copy Markdown
Owner

snyk-top-banner

Snyk has created this PR to fix 1 vulnerabilities in the pip dependencies of this project.

Snyk changed the following file(s):

  • docs/requirements.txt
⚠️ Warning
mkdocs-material 9.2.8 requires pymdown-extensions, which is not installed.

Breaking Change Risk

Merge Risk: High

Notice: This assessment is enhanced by AI.


Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Some vulnerabilities couldn't be fully fixed and so Snyk will still find them when the project is tested again. This may be because the vulnerability existed within more than one direct dependency, but not all of the affected dependencies could be upgraded.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Allocation of Resources Without Limits or Throttling

The following vulnerabilities are fixed by pinning transitive dependencies:
- https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-20302846
@HeyItsGilbert

Copy link
Copy Markdown
Owner Author

Merge Risk: High

This upgrade of urllib3 from version 2.0.7 to 2.8.0 contains significant breaking changes and important security fixes.

Breaking Changes:

  • API Removals: As of v2.1.0, the deprecated methods HTTPResponse.getheaders() and HTTPResponse.getheader() have been removed. Code must be updated to use the HTTPResponse.headers attribute instead (e.g., response.headers.get('Content-Type')). [3]
  • HTTPS Proxy Behavior: Version 2.8.0 includes a security fix that changes how TLS is configured for HTTPS proxies. Proxy-specific TLS settings (proxy_ssl_context, proxy_assert_hostname) are now strictly enforced and are no longer overridden by the destination server's settings. Configurations that relied on the previous behavior will likely break. [2]

Other Notable Changes:

  • Redirect Behavior: Version 2.0.7 changed how HTTP 303 "See Other" redirects are handled, now stripping the request body and changing the method to GET, which aligns with RFC standards but may alter existing application logic. [3]

Recommendation:

  • Review API Usage: Search your codebase for usages of .getheaders() and .getheader() and refactor them to use the .headers dictionary.
  • Verify Proxy Configurations: If you use HTTPS proxies, you must review your connection settings to ensure they are correctly configured using proxy_ssl_context and related parameters, as they will no longer inherit from the destination's context. [2]

Notice 🤖: This content was augmented using artificial intelligence. AI-generated content may contain errors and should be reviewed for accuracy before use.

Copilot AI balanced review requested due to automatic review settings September 30, 2026 11:00

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

Version 2.8.0 exists and is compatible with the documentation workflow’s Python 3.11 runtime.

Review effort: Balanced
Findings: None

What changed in this PR

Upgrades the indirect urllib3 dependency to remediate the identified vulnerability.

Changes:

  • Raises the minimum urllib3 version from 2.6.3 to 2.8.0.
File Description
docs/​requirements.txt Updates the documentation dependency constraint.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@github-actions

Copy link
Copy Markdown

Test Results

370 tests   359 ✅  6s ⏱️
111 suites   11 💤
  1 files      0 ❌

Results for commit 929e79b.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants