Skip to content

chore(deps): update dependency requests to v2.32.4#5

Open
mend-for-github-com[bot] wants to merge 1 commit intomainfrom
whitesource-remediate/requests-2.x
Open

chore(deps): update dependency requests to v2.32.4#5
mend-for-github-com[bot] wants to merge 1 commit intomainfrom
whitesource-remediate/requests-2.x

Conversation

@mend-for-github-com
Copy link
Copy Markdown

@mend-for-github-com mend-for-github-com bot commented Oct 26, 2025

This PR contains the following updates:

Package Update Change
requests (changelog) patch ==2.32.3==2.32.4

By merging this PR, the below vulnerabilities will be automatically resolved:

Severity CVSS Score Vulnerability Reachability
Medium Medium 5.3 CVE-2024-47081
Medium Medium 4.4 CVE-2026-25645

Release Notes

psf/requests (requests)

v2.32.4

Compare Source

Security

  • CVE-2024-47081 Fixed an issue where a maliciously crafted URL and trusted
    environment will retrieve credentials for the wrong hostname/machine from a
    netrc file.

Improvements

  • Numerous documentation improvements

Deprecations

  • Added support for pypy 3.11 for Linux and macOS.
  • Dropped support for pypy 3.9 following its end of support.

  • If you want to rebase/retry this PR, check this box

@mend-for-github-com mend-for-github-com bot added the security fix Security fix generated by Mend label Oct 26, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fix Security fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants