Skip to content

Bump urllib3 from 1.26.4 to 2.7.0 in /blueprints/gap-wave2-20260923/grype-known-cve-fixture - #105

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/blueprints/gap-wave2-20260923/grype-known-cve-fixture/urllib3-2.7.0
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/blueprints/gap-wave2-20260923/grype-known-cve-fixture/urllib3-2.7.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 23, 2026

Copy link
Copy Markdown
Contributor

Bumps urllib3 from 1.26.4 to 2.7.0.

Release notes

Sourced from urllib3's releases.

2.7.0

🚀 urllib3 is fundraising for HTTP/2 support

urllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project after a sharp decline in financial support. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects please consider contributing financially to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.

Thank you for your support.

Security

Addressed high-severity security issues. Impact was limited to specific use cases detailed in the accompanying advisories; overall user exposure was estimated to be marginal.

  • Decompression-bomb safeguards of the streaming API were bypassed:

    1. When HTTPResponse.drain_conn() was called after the response had been read and decompressed partially. (Reported by @​Cycloctane)
    2. During the second HTTPResponse.read(amt=N) or HTTPResponse.stream(amt=N) call when the response was decompressed using the official Brotli library. (Reported by @​kimkou2024)

    See GHSA-mf9v-mfxr-j63j for details.

  • HTTP pools created using ProxyManager.connection_from_url did not strip sensitive headers specified in Retry.remove_headers_on_redirect when redirecting to a different host. (GHSA-qccp-gfcp-xxvc reported by @​christos-spearbit)

Deprecations and Removals

  • Used FutureWarning instead of DeprecationWarning for better visibility of existing deprecation notices. Rescheduled the removal of deprecated features to version 3.0. (urllib3/urllib3#3763)
  • Removed support for end-of-life Python 3.9. (urllib3/urllib3#3720)
  • Removed support for end-of-life PyPy3.10. (urllib3/urllib3#4979)
  • Bumped the minimum supported pyOpenSSL version to 19.0.0. (urllib3/urllib3#3777)

Bugfixes

  • Fixed a bug where HTTPResponse.read(amt=None) was ignoring decompressed data buffered from previous partial reads. (urllib3/urllib3#3636)
  • Fixed a bug where HTTPResponse.read() could cache only part of the response after a partial read when cache_content=True. (urllib3/urllib3#4967)
  • Fixed HTTPResponse.stream() and HTTPResponse.read_chunked() to handle amt=0. (urllib3/urllib3#3793)
  • Updated _TYPE_BODY type alias to include missing Iterable[str], matching the documented and runtime behavior of chunked request bodies. (urllib3/urllib3#3798)
  • Fixed LocationParseError when paths resembling schemeless URIs were passed to HTTPConnectionPool.urlopen(). (urllib3/urllib3#3352)
  • Fixed BaseHTTPResponse.readinto() type annotation to accept memoryview in addition to bytearray, matching the io.RawIOBase.readinto contract and enabling use with io.BufferedReader without type errors. (urllib3/urllib3#3764)

2.6.3

🚀 urllib3 is fundraising for HTTP/2 support

urllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project after a sharp decline in financial support. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects please consider contributing financially to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.

Thank you for your support.

Changes

2.6.2

... (truncated)

Changelog

Sourced from urllib3's changelog.

2.7.0 (2026-05-07)

Security

Addressed high-severity security issues. Impact was limited to specific use cases detailed in the accompanying advisories; overall user exposure was estimated to be marginal.

  • Decompression-bomb safeguards of the streaming API were bypassed:

    1. When HTTPResponse.drain_conn() was called after the response had been read and decompressed partially.
    2. During the second HTTPResponse.read(amt=N) or HTTPResponse.stream(amt=N) call when the response was decompressed using the official Brotli <https://pypi.org/project/brotli/>__ library.

    See GHSA-mf9v-mfxr-j63j <https://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j>__ for details.

  • HTTP pools created using ProxyManager.connection_from_url did not strip sensitive headers specified in Retry.remove_headers_on_redirect when redirecting to a different host. (GHSA-qccp-gfcp-xxvc <https://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc>__)

Deprecations and Removals

  • Used FutureWarning instead of DeprecationWarning for better visibility of existing deprecation notices. Rescheduled the removal of deprecated features to version 3.0. ([#3763](https://github.com/urllib3/urllib3/issues/3763) <https://github.com/urllib3/urllib3/issues/3763>__)
  • Removed support for end-of-life Python 3.9. ([#3720](https://github.com/urllib3/urllib3/issues/3720) <https://github.com/urllib3/urllib3/issues/3720>__)
  • Removed support for end-of-life PyPy3.10. ([#4979](https://github.com/urllib3/urllib3/issues/4979) <https://github.com/urllib3/urllib3/issues/4979>__)
  • Bumped the minimum supported pyOpenSSL version to 19.0.0. ([#3777](https://github.com/urllib3/urllib3/issues/3777) <https://github.com/urllib3/urllib3/issues/3777>__)

Bugfixes

  • Fixed a bug where HTTPResponse.read(amt=None) was ignoring decompressed data buffered from previous partial reads. ([#3636](https://github.com/urllib3/urllib3/issues/3636) <https://github.com/urllib3/urllib3/issues/3636>__)
  • Fixed a bug where HTTPResponse.read() could cache only part of the response after a partial read when cache_content=True.

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [urllib3](https://github.com/urllib3/urllib3) from 1.26.4 to 2.7.0.
- [Release notes](https://github.com/urllib3/urllib3/releases)
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst)
- [Commits](urllib3/urllib3@1.26.4...2.7.0)

---
updated-dependencies:
- dependency-name: urllib3
  dependency-version: 2.7.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 23, 2026
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedpypi/​urllib3@​1.26.4 ⏵ 2.7.097 +2100 +61100100100

View full report

@seathatflowsinourveins

Copy link
Copy Markdown
Owner

Closing: this manifest is a deliberately vulnerable positive-control fixture for the grype known-CVE detection test (gap ci-supply-chain[13], #101). Bumping urllib3 would break the control. The alerts are dismissed as not_used.

@dependabot @github

dependabot Bot commented on behalf of github Sep 23, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/pip/blueprints/gap-wave2-20260923/grype-known-cve-fixture/urllib3-2.7.0 branch September 23, 2026 04:41
seathatflowsinourveins added a commit that referenced this pull request Sep 23, 2026
…immutable releases, target ruleset (#108)

* Close the catalog's GitHub automation: OSV/zizmor-online scans, gates, immutable releases, target ruleset

Add security-scan.yml: an osv-scanner job (OSV-Scanner 2.6.0, checksum-verified)
over every tracked lockfile in .github/osv-scanner-lockfiles.json with
--no-resolve, failing on unignored vulnerabilities and uploading SARIF off PRs,
plus a zizmor-online SARIF job. A unittest fails when a tracked lockfile is
missing from the inventory or an ignore lacks a <=90-day expiry.

Gate dependency review at high (warn-only removed) and grype at --fail-on high
with a reviewed, empty .grype.yaml; upload Scorecard SARIF with a job-scoped
security-events write; add a 7-day Dependabot cooldown. publish-catalog.yml
gains a tag-only release job (contents: write only) that re-checks the attested
digests and creates the immutable release with both files attached at creation.

.github/main-ruleset.json becomes the target (dependency-review and osv-scanner
required, strict checks, signatures, CodeQL code_scanning, squash only); the
tag rulesets match live 23829417 and 23859358. Record the evidence, the
CodeQL-vs-zizmor comparison on 168a3a8 and the superseded decisions in
docs/decisions/2026-09-22-github-automation-closure.md; update SECURITY.md,
automation.json, the docs, the regenerated verdicts/explorer and evidence hashes.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Drop required_signatures from the target ruleset; gate .grype.yaml changes; fix stale gate docs

A measured agent-lab run (2026-09-23) blocked PRs with unsigned branch
commits under required_signatures even though GitHub signs the squash merge,
so the target main ruleset leaves the rule out as keep-but-compare until every
writer signs. supply-chain.yml now runs its grype gate when .grype.yaml
changes, with a test. Scorecard, dependency-review and grype docs no longer
call the new gates report-only, and the CodeQL default-setup row cites the
re-read settings GET.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Resolve the catalog-automation review findings after rebasing on main

- Rebase onto origin/main 8faca90 (#96, #99-#104, #106): take main's removal of
  docs/ecosystem/index.html, merge main's explorer build/attest/upload steps
  with the release job's digest outputs, and re-register manifest hashes
  with host_receipts.register_file.
- OSV inventory: add a reasoned "excluded" list for the #101 grype
  positive-control fixture; the coverage test accepts only listed,
  fixture-scoped exclusions with an evidence path and still fails on any
  unlisted tracked lockfile. osv-scanner 2.6.0 exits 0 on the 37 listed files.
- Target main ruleset: strict_required_status_checks_policy false (auto-merge
  without a merge queue would stall every open PR when main moves);
  required_signatures stays out; regression tests assert both.
- automation.json: gating lanes move to security_gate_lanes with boolean
  required_check/target_required_check; fresh CodeQL default-setup GET cited.
- foundation.json: restore ci-supply-chain lane gap text, replace stale
  automation.json line citations with JSON-path anchors at 92bb279;
  regenerate verdicts and the handbook section with build_verdicts.
- Handbook automation summary and closure record updated (mlx branch dropped
  after #99, fixture alerts 7-15 dismissed and #105 closed, security updates
  kept on, strict decision, gap-ledger mapping).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Align merge-queue and osv-scanner catalog text with the strict-off target; record #104 CodeQL triage

- automation.json merge-queue non-adoption no longer cites strict checks;
  it points at the strict-off decision (closure record section 10) with its
  overturn condition.
- osv-scanner selection says "required in the target ruleset once applied"
  and names the 37 listed lockfiles, 2 covered manifests and 1 fixture
  exclusion.
- Closure record section 2: the 10 first-analysis CodeQL alerts were
  resolved in #104, not left for owners.
- Hashes re-registered in manifests/evidence.json.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Keep Dependabot security PRs off the grype positive-control fixture

ignore: urllib3 on a pip entry scoped to the fixture directory (ignore applies to
security updates; exclude-paths does not). Clarify that osv-scanner becomes a
required check only after the target ruleset is applied.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Refresh evidence hashes after rebasing onto #95

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Fix the OSV SARIF path under bash -e; keep the zizmor write token away from the analyzer

shell: bash implies -e, so a findings exit ended the OSV step before the SARIF run
(reproduced; found by an independent-implementation comparison and the Codex
cross-family review). zizmor now runs read-only and a tool-free upload job holds
security-events: write. Tests cover both, plus OSV PackageOverrides and grype
review-by dates.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: seathatflowsinourveins <234074349+seathatflowsinourveins@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant