Skip to content

Conversation

@alarthast
Copy link
Contributor

urllib3 <v2.6.3 has a security vulnerability reported in GHSA-38jv-5279-wg99, so we are bumping the version to 2.6.3 without waiting for a 7-day cooldown period.

The exclude-newer-package timestamp should be removed once it is 7 days old, as per the guidelines in DEVELOPERS.md.

`urllib3 <v2.6.3` has a security vulnerability reported in
GHSA-38jv-5279-wg99, so we are bumping
the version to `2.6.3` without waiting for a 7-day cooldown period.

The `exclude-newer-package` timestamp should be removed once it is 7
days old, as per the guidelines in `DEVELOPERS.md`.
@alarthast alarthast marked this pull request as ready for review January 8, 2026 16:02
@alarthast alarthast enabled auto-merge January 8, 2026 16:02
@alarthast alarthast merged commit ff9de5b into main Jan 8, 2026
5 checks passed
@alarthast alarthast deleted the aw/bump-urllib3 branch January 8, 2026 16:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants