Closed dependabot[bot] closed 1 year ago
@dependabot merge
Best, Flo
On October 18, 2023, Github @.***> wrote:
This automated pull request fixes a security vulnerability https://github.com/HelloThisIsFlo/Appdaemon-Test- Framework/security/dependabot/51 (moderate severity). Learn more about Dependabot security updates https://docs.github.com/github/managing-security- vulnerabilities/configuring-dependabot-security-updates.
Bumps urllib3 https://github.com/urllib3/urllib3 from 1.26.16 to 1.26.18.
Release notes Sourced from urllib3's releases https://github.com/urllib3/urllib3/releases.
1.26.18
- Made body stripped from HTTP requests changing the request method to GET after HTTP 303 "See Other" redirect responses. (GHSA-g4mx-q9vg-27p4 https://github.com/advisories/GHSA-g4mx- q9vg-27p4)
1.26.17
- Added the Cookie header to the list of headers to strip from requests when redirecting to a different host. As before, different headers can be set via Retry.remove_headers_on_redirect. (GHSA-v845-jxx5-vc9f https://github.com/advisories/GHSA-v845-jxx5-vc9f)
Changelog Sourced from urllib3's changelog https://github.com/urllib3/urllib3/blob/main/CHANGES.rst.
1.26.18 (2023-10-17)
- Made body stripped from HTTP requests changing the request method to GET after HTTP 303 "See Other" redirect responses.
1.26.17 (2023-10-02)
- Added the Cookie header to the list of headers to strip from requests when redirecting to a different host. As before, different headers can be set via Retry.remove_headers_onredirect. (#3139 https://github.com/urllib3/urllib3/pull/3139)
Commits
- 9c2c230 https://github.com/urllib3/urllib3/commit/9c2c2307dd1d6af504e09aac0326d86ee3597a0b Release 1.26.18 (#3159 https://redirect.github.com/urllib3/urllib3/issues/3159)
- b594c5c https://github.com/urllib3/urllib3/commit/b594c5ceaca38e1ac215f916538fb128e3526a36 Merge pull request from GHSA-g4mx-q9vg-27p4 https://github.com/advisories/GHSA- g4mx-q9vg-27p4
- 944f0eb https://github.com/urllib3/urllib3/commit/944f0eb134485f41bc531be52de12ba5a37bca73 [1.26] Use vendored six in urllib3.contrib.securetransport
- c9016bf https://github.com/urllib3/urllib3/commit/c9016bf464751a02b7e46f8b86504f47d4238784 Release 1.26.17
- 0122035 https://github.com/urllib3/urllib3/commit/01220354d389cd05474713f8c982d05c9b17aafb Backport GHSA-v845-jxx5-vc9f https://github.com/advisories/GHSA-v845-jxx5-vc9f (#3139 https://redirect.github.com/urllib3/urllib3/issues/3139)
- e63989f https://github.com/urllib3/urllib3/commit/e63989f97d206e839ab9170c8a76e3e097cc60e8 Fix installing brotli extra on Python 2.7
- 2e7a24d https://github.com/urllib3/urllib3/commit/2e7a24d08713a0131f0b3c7197889466d645cc49 [1.26] Configure OS for RTD to fix building docs
- 57181d6 https://github.com/urllib3/urllib3/commit/57181d6ea910ac7cb2ff83345d9e5e0eb816a0d0 [1.26] Improve error message when calling urllib3.request() (#3058 https://redirect.github.com/urllib3/urllib3/issues/3058)
- 3c01480 https://github.com/urllib3/urllib3/commit/3c0148048a523325819377b23fc67f8d46afc3aa [1.26] Run coverage even with failed jobs
- See full diff in compare view https://github.com/urllib3/urllib3/compare/1.26.16...1.26.18
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- @dependabot rebase will rebase this PR
- @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
- @dependabot merge will merge this PR after your CI passes on it
- @dependabot squash and merge will squash and merge this PR after your CI passes on it
- @dependabot cancel merge will cancel a previously requested merge and block automerging
- @dependabot reopen will reopen this PR if it is closed
- @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- @dependabot show
ignore conditions will show all of the ignore conditions of the specified dependency - @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page https://github.com/HelloThisIsFlo/Appdaemon- Test-Framework/network/alerts.
You can view, comment on, or merge this pull request online at: https://github.com/HelloThisIsFlo/Appdaemon-Test-Framework/pull/85
Commit Summary
- b7c7f53 https://github.com/HelloThisIsFlo/Appdaemon-Test- Framework/pull/85/commits/b7c7f533ae6241c34adff29e862da5930fff9d4c Bump urllib3 from 1.26.16 to 1.26.18
File Changes
(1 file https://github.com/HelloThisIsFlo/Appdaemon-Test- Framework/pull/85/files)
- M Pipfile.lock https://github.com/HelloThisIsFlo/Appdaemon-Test- Framework/pull/85/files#diff- a86c67a0a29ed0e95909b9b7c420140f302d17399ee6dcce4e1a51a14d27fd51 (484)
Patch Links:
- https://github.com/HelloThisIsFlo/Appdaemon-Test-Framework/pull/85.patch
- https://github.com/HelloThisIsFlo/Appdaemon-Test-Framework/pull/85.diff — Reply to this email directly, view it on GitHub https://github.com/HelloThisIsFlo/Appdaemon-Test- Framework/pull/85, or unsubscribe https://github.com/notifications/unsubscribe- auth/ACSUOIPBOV4WPB4VDJQP7PTX74RCRAVCNFSM6AAAAAA6EVK5QOVHI2DSMVQWIX3LMV43ASLTON2WKOZRHE2DQNJSG4ZTENY. You are receiving this because you are subscribed to this thread.Message ID: @.***>
Bumps urllib3 from 1.26.16 to 1.26.18.
Release notes
Sourced from urllib3's releases.
Changelog
Sourced from urllib3's changelog.
Commits
9c2c230
Release 1.26.18 (#3159)b594c5c
Merge pull request from GHSA-g4mx-q9vg-27p4944f0eb
[1.26] Use vendored six in urllib3.contrib.securetransportc9016bf
Release 1.26.170122035
Backport GHSA-v845-jxx5-vc9f (#3139)e63989f
Fix installingbrotli
extra on Python 2.72e7a24d
[1.26] Configure OS for RTD to fix building docs57181d6
[1.26] Improve error message when calling urllib3.request() (#3058)3c01480
[1.26] Run coverage even with failed jobsDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show