Skip to content

[Snyk] Security upgrade urllib3 from 2.0.7 to 2.8.0 - #43

Open
caniszczyk wants to merge 1 commit into
masterfrom
snyk-fix-8c65b0dce584188efaa6d019680e0e32
Open

caniszczyk wants to merge 1 commit into
masterfrom
snyk-fix-8c65b0dce584188efaa6d019680e0e32

Conversation

@caniszczyk

Copy link
Copy Markdown

snyk-top-banner

Snyk has created this PR to fix 1 vulnerabilities in the pip dependencies of this project.

Snyk changed the following file(s):

  • examples/cloud_run_cloud_events/requirements.txt
⚠️ Warning
equests 2.31.0 requires urllib3, which is not installed.

Breaking Change Risk

Merge Risk: High

Notice: This assessment is enhanced by AI.


Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Some vulnerabilities couldn't be fully fixed and so Snyk will still find them when the project is tested again. This may be because the vulnerability existed within more than one direct dependency, but not all of the affected dependencies could be upgraded.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Allocation of Resources Without Limits or Throttling

…rabilities

The following vulnerabilities are fixed by pinning transitive dependencies:
- https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-20302846
@caniszczyk

Copy link
Copy Markdown
Author

Merge Risk: High

This upgrade of urllib3 from version 2.0.7 to 2.8.0 contains significant breaking changes and important security fixes.

Breaking Changes:

  • API Removals: As of v2.1.0, the deprecated methods HTTPResponse.getheaders() and HTTPResponse.getheader() have been removed. Code must be updated to use the HTTPResponse.headers attribute instead (e.g., response.headers.get('Content-Type')). [3]
  • HTTPS Proxy Behavior: Version 2.8.0 includes a security fix that changes how TLS is configured for HTTPS proxies. Proxy-specific TLS settings (proxy_ssl_context, proxy_assert_hostname) are now strictly enforced and are no longer overridden by the destination server's settings. Configurations that relied on the previous behavior will likely break. [2]

Other Notable Changes:

  • Redirect Behavior: Version 2.0.7 changed how HTTP 303 "See Other" redirects are handled, now stripping the request body and changing the method to GET, which aligns with RFC standards but may alter existing application logic. [3]

Recommendation:

  • Review API Usage: Search your codebase for usages of .getheaders() and .getheader() and refactor them to use the .headers dictionary.
  • Verify Proxy Configurations: If you use HTTPS proxies, you must review your connection settings to ensure they are correctly configured using proxy_ssl_context and related parameters, as they will no longer inherit from the destination's context. [2]

Notice 🤖: This content was augmented using artificial intelligence. AI-generated content may contain errors and should be reviewed for accuracy before use.

@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants