Skip to content

Bump requests from 2.32.5 to 2.33.1#581

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/pip/master/requests-2.33.1
Closed

Bump requests from 2.32.5 to 2.33.1#581
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/pip/master/requests-2.33.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Mar 31, 2026

Copy link
Copy Markdown
Contributor

Bumps requests from 2.32.5 to 2.33.1.

Release notes

Sourced from requests's releases.

v2.33.1

2.33.1 (2026-03-30)

Bugfixes

  • Fixed test cleanup for CVE-2026-25645 to avoid leaving unnecessary files in the tmp directory. (#7305)
  • Fixed Content-Type header parsing for malformed values. (#7309)
  • Improved error consistency for malformed header values. (#7308)

New Contributors

Full Changelog: https://github.com/psf/requests/blob/main/HISTORY.md#2331-2026-03-30

v2.33.0

2.33.0 (2026-03-25)

Announcements

  • 📣 Requests is adding inline types. If you have a typed code base that uses Requests, please take a look at #7271. Give it a try, and report any gaps or feedback you may have in the issue. 📣

Security

  • CVE-2026-25645 requests.utils.extract_zipped_paths now extracts contents to a non-deterministic location to prevent malicious file replacement. This does not affect default usage of Requests, only applications calling the utility function directly.

Improvements

  • Migrated to a PEP 517 build system using setuptools. (#7012)

Bugfixes

  • Fixed an issue where an empty netrc entry could cause malformed authentication to be applied to Requests on Python 3.11+. (#7205)

Deprecations

  • Dropped support for Python 3.9 following its end of support. (#7196)

Documentation

  • Various typo fixes and doc improvements.

New Contributors

Full Changelog: https://github.com/psf/requests/blob/main/HISTORY.md#2330-2026-03-25

Changelog

Sourced from requests's changelog.

2.33.1 (2026-03-30)

Bugfixes

  • Fixed test cleanup for CVE-2026-25645 to avoid leaving unnecessary files in the tmp directory. (#7305)
  • Fixed Content-Type header parsing for malformed values. (#7309)
  • Improved error consistency for malformed header values. (#7308)

2.33.0 (2026-03-25)

Announcements

  • 📣 Requests is adding inline types. If you have a typed code base that uses Requests, please take a look at #7271. Give it a try, and report any gaps or feedback you may have in the issue. 📣

Security

  • CVE-2026-25645 requests.utils.extract_zipped_paths now extracts contents to a non-deterministic location to prevent malicious file replacement. This does not affect default usage of Requests, only applications calling the utility function directly.

Improvements

  • Migrated to a PEP 517 build system using setuptools. (#7012)

Bugfixes

  • Fixed an issue where an empty netrc entry could cause malformed authentication to be applied to Requests on Python 3.11+. (#7205)

Deprecations

  • Dropped support for Python 3.9 following its end of support. (#7196)

Documentation

  • Various typo fixes and doc improvements.
Commits

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Mar 31, 2026
@dependabot @github

dependabot Bot commented on behalf of github Mar 31, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: poetry. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the python Pull requests that update python code label Mar 31, 2026
@dependabot dependabot Bot force-pushed the dependabot/pip/master/requests-2.33.1 branch from 4abc198 to 869f086 Compare March 31, 2026 09:43
github-actions[bot]
github-actions Bot previously approved these changes Mar 31, 2026
@dependabot dependabot Bot force-pushed the dependabot/pip/master/requests-2.33.1 branch from 869f086 to 25963f5 Compare April 6, 2026 05:03
github-actions[bot]
github-actions Bot previously approved these changes Apr 6, 2026
@dependabot dependabot Bot force-pushed the dependabot/pip/master/requests-2.33.1 branch from 25963f5 to 6f6f69e Compare April 8, 2026 04:55
github-actions[bot]
github-actions Bot previously approved these changes Apr 8, 2026
@dependabot dependabot Bot force-pushed the dependabot/pip/master/requests-2.33.1 branch from 6f6f69e to dcf5107 Compare April 9, 2026 04:55
github-actions[bot]
github-actions Bot previously approved these changes Apr 9, 2026
@dependabot dependabot Bot force-pushed the dependabot/pip/master/requests-2.33.1 branch from dcf5107 to e7266ca Compare April 21, 2026 04:55
@dependabot dependabot Bot force-pushed the dependabot/pip/master/requests-2.33.1 branch from e7266ca to d0e626c Compare April 22, 2026 04:55
Bumps [requests](https://github.com/psf/requests) from 2.32.5 to 2.33.1.
- [Release notes](https://github.com/psf/requests/releases)
- [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md)
- [Commits](psf/requests@v2.32.5...v2.33.1)

---
updated-dependencies:
- dependency-name: requests
  dependency-version: 2.33.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/pip/master/requests-2.33.1 branch from d0e626c to 2c65499 Compare April 23, 2026 04:56
@sonarqubecloud

Copy link
Copy Markdown

@dependabot @github

dependabot Bot commented on behalf of github May 14, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #601.

@dependabot dependabot Bot closed this May 14, 2026
@dependabot dependabot Bot deleted the dependabot/pip/master/requests-2.33.1 branch May 14, 2026 04:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants