Closed dependabot[bot] closed 1 year ago
@dependabot merge
On Tue, Oct 17, 2023 at 5:04 PM dependabot[bot] @.***> wrote:
This automated pull request fixes a security vulnerability https://github.com/beaufour/flickr-download/security/dependabot/6 (moderate severity).
Learn more about Dependabot security updates https://docs.github.com/github/managing-security-vulnerabilities/configuring-dependabot-security-updates.
Bumps urllib3 https://github.com/urllib3/urllib3 from 2.0.6 to 2.0.7. Release notes
Sourced from urllib3's releases https://github.com/urllib3/urllib3/releases.
2.0.7
- Made body stripped from HTTP requests changing the request method to GET after HTTP 303 "See Other" redirect responses. (GHSA-g4mx-q9vg-27p4 https://github.com/advisories/GHSA-g4mx-q9vg-27p4)
Changelog
Sourced from urllib3's changelog https://github.com/urllib3/urllib3/blob/main/CHANGES.rst.
2.0.7 (2023-10-17)
- Made body stripped from HTTP requests changing the request method to GET after HTTP 303 "See Other" redirect responses.
Commits
- 56f01e0 https://github.com/urllib3/urllib3/commit/56f01e088dc006c03d4ee6ea9da4ab810f1ed700 Release 2.0.7
- 4e50fbc https://github.com/urllib3/urllib3/commit/4e50fbc5db74e32cabd5ccc1ab81fc103adfe0b3 Merge pull request from GHSA-g4mx-q9vg-27p4 https://github.com/advisories/GHSA-g4mx-q9vg-27p4
- 80808b0 https://github.com/urllib3/urllib3/commit/80808b04bfa68fbd099828848c96ee25df185f1d Fix docs build on Python 3.12 (#3144 https://redirect.github.com/urllib3/urllib3/issues/3144)
- f28deff https://github.com/urllib3/urllib3/commit/f28deff1cf162c673b50d88d3552e91bda6d68a8 Add 1.26.17 to the current changelog
- See full diff in compare view https://github.com/urllib3/urllib3/compare/2.0.6...2.0.7
[image: Dependabot compatibility score] https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- @dependabot rebase will rebase this PR
- @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
- @dependabot merge will merge this PR after your CI passes on it
- @dependabot squash and merge will squash and merge this PR after your CI passes on it
- @dependabot cancel merge will cancel a previously requested merge and block automerging
- @dependabot reopen will reopen this PR if it is closed
- @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- @dependabot show
ignore conditions will show all of the ignore conditions of the specified dependency - @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page https://github.com/beaufour/flickr-download/network/alerts.
You can view, comment on, or merge this pull request online at:
https://github.com/beaufour/flickr-download/pull/83 Commit Summary
- 45894e8 https://github.com/beaufour/flickr-download/pull/83/commits/45894e8291d9f3c1cf833e7d1eb91f4281aed3e6 Bump urllib3 from 2.0.6 to 2.0.7
File Changes
(1 file https://github.com/beaufour/flickr-download/pull/83/files)
- M poetry.lock https://github.com/beaufour/flickr-download/pull/83/files#diff-f53a023eedfa3fbf2925ec7dc76eecdc954ea94b7e47065393dbad519613dc89 (6)
Patch Links:
- https://github.com/beaufour/flickr-download/pull/83.patch
- https://github.com/beaufour/flickr-download/pull/83.diff
— Reply to this email directly, view it on GitHub https://github.com/beaufour/flickr-download/pull/83, or unsubscribe https://github.com/notifications/unsubscribe-auth/AAB2POLD6RGKSK77DU3QXA3X73XHHAVCNFSM6AAAAAA6EOZTFSVHI2DSMVQWIX3LMV43ASLTON2WKOZRHE2DQMRWGQ2DANQ . You are receiving this because you are subscribed to this thread.Message ID: @.***>
Bumps urllib3 from 2.0.6 to 2.0.7.
Release notes
Sourced from urllib3's releases.
Changelog
Sourced from urllib3's changelog.
Commits
56f01e0
Release 2.0.74e50fbc
Merge pull request from GHSA-g4mx-q9vg-27p480808b0
Fix docs build on Python 3.12 (#3144)f28deff
Add 1.26.17 to the current changelogDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show