Update requests requirement from >=2.33.1 to >=2.34.2 in /src #31
No reviewers
Labels
No labels
app
bug
ci
compliance
dependencies
docs
documentation
duplicate
enhancement
good first issue
help wanted
infra
invalid
javascript
python
question
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/exec-aide#31
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "dependabot/pip/src/requests-gte-2.34.2"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Updates the requirements on requests to permit the latest version.
Release notes
Sourced from requests's releases.
Changelog
Sourced from requests's changelog.
... (truncated)
Commits
6e83187v2.34.284d10f0Move Request.headers back to Mapping (#7441)b7b549bv2.34.1e511bc7Fix mutability issues with headers input types (#7431)5691f59Update JsonType containers to read-based collections (#7436)2144213Constrain Response.reason to str (#7437)6404f34Fixprepare_bodystream detection for__getattr__-based file wrappers (#7...0b401c7v2.34.086b378dAlign Session.get parameters with requests.get (#7429)a4f9a59Port bpo-39057 to Requests (#7427)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)LGTM, straightforward Dependabot minor version bump for requests.
Extended reasoning...
Overview
This PR updates a single line in
src/requirements.txtto bump the minimum allowed version ofrequestsfrom>=2.33.1to>=2.34.2. It is a Dependabot-generated dependency floor bump with no code changes.Security risks
None apparent. The release notes describe typing refinements (headers/json input types), a no_proxy matching fix (CPython bpo-39057 port), prevention of self-referential
Response.history, and addingusedforsecurity=Falseto Digest Auth hashing. These are bugfixes/improvements with no known security regressions.Level of scrutiny
Low. This is a minor version floor bump in a requirements file — the kind of mechanical Dependabot change that does not warrant human review. The only potential consumer-side impact is the headers/json typing tightening, but since this only raises the minimum (no upper bound was added or removed), behavior at runtime is unchanged for code that already worked.
Other factors
No prior reviews or unresolved comments on this PR. Bug hunting system found no issues.