diff mbox series

[AUH] python3-urllib3: upgrading to 2.8.0 SUCCEEDED

Message ID 010101a0a8bf2485-7fcc913b-46eb-4433-90e8-9347981ba858-000000@us-west-2.amazonses.com
State New
Headers show
Series [AUH] python3-urllib3: upgrading to 2.8.0 SUCCEEDED | expand

Commit Message

auh@yoctoproject.org Sept. 16, 2026, 5:44 a.m. UTC
Hello,

this email is a notification from the Auto Upgrade Helper
that the automatic attempt to upgrade the recipe(s) *python3-urllib3* to *2.8.0* has Succeeded.

Next steps:
    - apply the patch: git am 0001-python3-urllib3-upgrade-2.7.0-2.8.0.patch
    - check the changes to upstream patches and summarize them in the commit message,
    - compile an image that contains the package
    - perform some basic sanity tests
    - amend the patch and sign it off: git commit -s --reset-author --amend
    - send it to the appropriate mailing list

Alternatively, if you believe the recipe should not be upgraded at this time,
you can fill RECIPE_NO_UPDATE_REASON in respective recipe file so that
automatic upgrades would no longer be attempted.

Please review the attached files for further information and build/update failures.
Any problem please file a bug at https://bugzilla.yoctoproject.org/enter_bug.cgi?product=Automated%20Update%20Handler

Regards,
The Upgrade Helper

-- >8 --
From 4048ca87d1bb1dbd0e37e15ff770cda24c87322c Mon Sep 17 00:00:00 2001
From: Upgrade Helper <auh@yoctoproject.org>
Date: Wed, 16 Sep 2026 05:39:03 +0000
Subject: [PATCH] python3-urllib3: upgrade 2.7.0 -> 2.8.0

Source: CHANGES.rst

2.8.0 (2026-09-15)
==================

Security
--------

Fixed the following security issues:

- The TLS configuration for HTTPS proxies could be ignored or overridden.
  (High severity, `GHSA-8988-9cw3-xx77 <https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77>`__)
- ``HTTPResponse.stream()`` and ``read_chunked()`` could buffer a chunk-size
  line of unbounded length in memory. (High severity,
  `GHSA-vxq7-64xx-v4gw <https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw>`__)
- Chunked Deflate streaming could enter an infinite loop. (Medium severity,
  `GHSA-gh4c-6fx4-qh6g <https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g>`__)

.. caution::

    urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or
    overridden by destination settings. Configurations relying on that
    behavior may require changes.

    Configure proxy CA certificates and client certificates in
    ``proxy_ssl_context``, and proxy identity checks with
    ``proxy_assert_hostname`` or ``proxy_assert_fingerprint``.
    Destination client certificates and identity overrides no longer
    apply to HTTPS forwarding proxy connections.

Deprecations & Removals
-----------------------

- Deprecated using an empty collection as the ``Retry`` option
  ``allowed_methods`` to retry any verb.
  (`#5044 <https://github.com/urllib3/urllib3/issues/5044>`__)

Features
--------

- Added ``Url.auth_decoded`` and ``Url.auth_decoded_joined`` convenience
  properties to the result of ``parse_url()``.
  (`#4945 <https://github.com/urllib3/urllib3/issues/4945>`__)
- Added ``basic_auth_encoding`` and ``proxy_basic_auth_encoding`` parameters to
  ``urllib3.util.make_headers()``.
  (`#5092 <https://github.com/urllib3/urllib3/issues/5092>`__)

Bugfixes
--------

- Fixed response header handling to replace obsolete folded header lines
  (`obs-fold`) with spaces in accordance with RFC 9112, preventing raw CRLF
  sequences from appearing in header values such as ``Set-Cookie``.
  (`#1362 <https://github.com/urllib3/urllib3/issues/1362>`__)
- Fixed usage of ``proxy_ssl_context`` with ``ProxyManager`` when
  ``use_forwarding_for_https=True``. Passing ``ssl_context`` instead of
  ``proxy_ssl_context`` for HTTPS proxies in this configuration now emits a
  ``FutureWarning`` and will raise an error in v3.0.
  (`#2577 <https://github.com/urllib3/urllib3/issues/2577>`__)
- Changed behavior of the default ``ConnectionPool.pool`` initialization.
  ``LifoQueue`` is now resolved from the ``queue`` module after the
  ``ConnectionPool`` is instantiated instead of using the default cached
  ``QueueCls`` class property. This is done because sometimes the
  ``queue.LifoQueue`` is monkey-patched late in the program, such as by gevent.
  (`#3289 <https://github.com/urllib3/urllib3/issues/3289>`__)
- Raised ``UnrewindableBodyError`` instead of ``ValueError`` when retrying a
  request whose body had ``tell()`` but not ``seek(

[Changelog truncated as it exceeds 3000 characters;
the full changelog can be found in an attachment to the AUH email]
---
 .../{python3-urllib3_2.7.0.bb => python3-urllib3_2.8.0.bb}      | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
 rename meta/recipes-devtools/python/{python3-urllib3_2.7.0.bb => python3-urllib3_2.8.0.bb} (91%)
diff mbox series

Patch

diff --git a/meta/recipes-devtools/python/python3-urllib3_2.7.0.bb b/meta/recipes-devtools/python/python3-urllib3_2.8.0.bb
similarity index 91%
rename from meta/recipes-devtools/python/python3-urllib3_2.7.0.bb
rename to meta/recipes-devtools/python/python3-urllib3_2.8.0.bb
index 9e73a49bca..4aafe2d63d 100644
--- a/meta/recipes-devtools/python/python3-urllib3_2.7.0.bb
+++ b/meta/recipes-devtools/python/python3-urllib3_2.8.0.bb
@@ -3,7 +3,7 @@  HOMEPAGE = "https://github.com/urllib3/urllib3"
 LICENSE = "MIT"
 LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=52d273a3054ced561275d4d15260ecda"
 
-SRC_URI[sha256sum] = "231e0ec3b63ceb14667c67be60f2f2c40a518cb38b03af60abc813da26505f4c"
+SRC_URI[sha256sum] = "63bf2ead4c879426ebf22ef2a781eeb4aa3b4ae798a0435506f8687fd5bb9b63"
 
 inherit pypi python_hatchling