Requests now supports Brotli compression, if either the brotli or
brotlicffi package is installed. (#5783)
Session.send now correctly resolves proxy configurations from both
the Session and Request. Behavior now matches Session.request. (#5681)
Bugfixes
Fixed a race condition in zip extraction when using Requests in parallel
from zip archive. (#5707)
Dependencies
Instead of chardet, use the MIT-licensed charset_normalizer for Python3
to remove license ambiguity for projects bundling requests. If chardet
is already installed on your machine it will be used instead of charset_normalizer
to keep backwards compatibility. (#5797)
You can also install chardet while installing requests by
specifying [use_chardet_on_py3] extra as follows:
pip install "requests[use_chardet_on_py3]"
Python2 still depends upon the chardet module.
Requests now supports idna 3.x on Python 3. idna 2.x will continue to
be used on Python 2 installations. (#5711)
Deprecations
The requests[security] extra has been converted to a no-op install.
PyOpenSSL is no longer the recommended secure option for Requests. (#5867)
Requests has officially dropped support for Python 3.5. (#5867)
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Bumps requests from 2.25.1 to 2.26.0.
Changelog
Sourced from requests's changelog.
Commits
a1a6a54
v2.26.0e253eba
Stop abusing pytest-httpbin to test commonName supportf6c0619
Disable requests[security] and remove 3.5 support references33cf965
Allow idna 3.x to be installed on Python 3.x5351469
Add support for brotli decoding (#5783)2463074
Avoid zip extract racing condition by using read+write instead extract (#5707)2ed84f5
Switch LGPL'd chardet for MIT licensed charset_normalizer (#5797)33d448e
Pin Flask to <2.0 to fix the test suite1466ad7
Fix GitHub links (#5835)f6d43b0
Updated to new be-cordial-or-be-on-your-way URL and CoC now references Python...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)