From 278949fd7a1752820a57386478bdf7ec936e86d4d4ecc8916dd24e68e15dc9ac Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Adrian=20Schr=C3=B6ter?= Date: Fri, 13 Sep 2024 16:24:54 +0200 Subject: [PATCH] Sync from SUSE:SLFO:Main python-requests revision fd68f60913a6803685813840ff84a640 --- python-requests.changes | 24 ++++++++++++++++++++++++ python-requests.spec | 9 +++------ requests-2.31.0.tar.gz | 3 --- requests-2.32.2.tar.gz | 3 +++ 4 files changed, 30 insertions(+), 9 deletions(-) delete mode 100644 requests-2.31.0.tar.gz create mode 100644 requests-2.32.2.tar.gz diff --git a/python-requests.changes b/python-requests.changes index ed5faa3..e9d3cb7 100644 --- a/python-requests.changes +++ b/python-requests.changes @@ -1,3 +1,27 @@ +------------------------------------------------------------------- +Wed May 22 14:00:50 UTC 2024 - Markéta Machová + +- Update to 2.32.2 + * To provide a more stable migration for custom HTTPAdapters impacted by the CVE changes in 2.32.0, + we've renamed _get_connection to a new public API, get_connection_with_tls_context. Existing + custom HTTPAdapters will need to migrate their code to use this new API. get_connection is + considered deprecated in all versions of Requests>=2.32.0. + +------------------------------------------------------------------- +Tue May 21 12:33:41 UTC 2024 - Markéta Machová + +- Update to 2.32.1 + * Fixed an issue where setting verify=False on the first request from a Session + will cause subsequent requests to the same origin to also ignore cert verification, + regardless of the value of verify. (bsc#1224788, CVE-2024-35195) + * verify=True now reuses a global SSLContext which should improve request time + variance between first and subsequent requests. + * Requests now supports optional use of character detection (chardet or charset_normalizer) + when repackaged or vendored. This enables pip and other projects to minimize their + vendoring surface area. + * Requests has officially added support for CPython 3.12 and dropped support for CPython 3.7. + * Starting in Requests 2.33.0, Requests will migrate to a PEP 517 build system using hatchling. + ------------------------------------------------------------------- Mon Sep 11 20:41:40 UTC 2023 - Dirk Müller diff --git a/python-requests.spec b/python-requests.spec index 15a42a6..90d1061 100644 --- a/python-requests.spec +++ b/python-requests.spec @@ -1,7 +1,7 @@ # -# spec file +# spec file for package python-requests # -# Copyright (c) 2023 SUSE LLC +# Copyright (c) 2024 SUSE LLC # # All modifications and additions to the file contributed by third parties # remain the property of their copyright owners, unless otherwise agreed @@ -26,7 +26,7 @@ %endif %{?sle15_python_module_pythons} Name: python-requests%{psuffix} -Version: 2.31.0 +Version: 2.32.2 Release: 0 Summary: Python HTTP Library License: Apache-2.0 @@ -89,9 +89,6 @@ Features of Requests: %prep %autosetup -p1 -n requests-%{version} -# drop shebang from certs.py -sed -i '1s/^#!.*$//' requests/certs.py - # remove 'never' default parameter from digest-auth check # requires httpbin 0.6.0 sed -i "s#\(httpbin.*\), 'never'#\1#" tests/test_requests.py diff --git a/requests-2.31.0.tar.gz b/requests-2.31.0.tar.gz deleted file mode 100644 index 74eeead..0000000 --- a/requests-2.31.0.tar.gz +++ /dev/null @@ -1,3 +0,0 @@ -version https://git-lfs.github.com/spec/v1 -oid sha256:942c5a758f98d790eaed1a29cb6eefc7ffb0d1cf7af05c3d2791656dbd6ad1e1 -size 110794 diff --git a/requests-2.32.2.tar.gz b/requests-2.32.2.tar.gz new file mode 100644 index 0000000..47f4b74 --- /dev/null +++ b/requests-2.32.2.tar.gz @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:dd951ff5ecf3e3b3aa26b40703ba77495dab41da839ae72ef3c8e5d8e2433289 +size 130327