Skip to content

Bump requests from 2.32.4 to 2.33.0 - #6898

Merged
AmitPhulera merged 1 commit into
masterfrom
dependabot/uv/requests-2.33.0
Jun 30, 2026
Merged

Bump requests from 2.32.4 to 2.33.0#6898
AmitPhulera merged 1 commit into
masterfrom
dependabot/uv/requests-2.33.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 29, 2026

Copy link
Copy Markdown
Contributor

Bumps requests from 2.32.4 to 2.33.0.

Release notes

Sourced from requests's releases.

v2.33.0

2.33.0 (2026-03-25)

Announcements

  • 📣 Requests is adding inline types. If you have a typed code base that uses Requests, please take a look at #7271. Give it a try, and report any gaps or feedback you may have in the issue. 📣

Security

  • CVE-2026-25645 requests.utils.extract_zipped_paths now extracts contents to a non-deterministic location to prevent malicious file replacement. This does not affect default usage of Requests, only applications calling the utility function directly.

Improvements

  • Migrated to a PEP 517 build system using setuptools. (#7012)

Bugfixes

  • Fixed an issue where an empty netrc entry could cause malformed authentication to be applied to Requests on Python 3.11+. (#7205)

Deprecations

  • Dropped support for Python 3.9 following its end of support. (#7196)

Documentation

  • Various typo fixes and doc improvements.

New Contributors

Full Changelog: https://github.com/psf/requests/blob/main/HISTORY.md#2330-2026-03-25

v2.32.5

2.32.5 (2025-08-18)

Bugfixes

  • The SSLContext caching feature originally introduced in 2.32.0 has created a new class of issues in Requests that have had negative impact across a number of use cases. The Requests team has decided to revert this feature as long term maintenance of it is proving to be unsustainable in its current iteration.

Deprecations

  • Added support for Python 3.14.
  • Dropped support for Python 3.8 following its end of support.
Changelog

Sourced from requests's changelog.

2.33.0 (2026-03-25)

Announcements

  • 📣 Requests is adding inline types. If you have a typed code base that uses Requests, please take a look at #7271. Give it a try, and report any gaps or feedback you may have in the issue. 📣

Security

  • CVE-2026-25645 requests.utils.extract_zipped_paths now extracts contents to a non-deterministic location to prevent malicious file replacement. This does not affect default usage of Requests, only applications calling the utility function directly.

Improvements

  • Migrated to a PEP 517 build system using setuptools. (#7012)

Bugfixes

  • Fixed an issue where an empty netrc entry could cause malformed authentication to be applied to Requests on Python 3.11+. (#7205)

Deprecations

  • Dropped support for Python 3.9 following its end of support. (#7196)

Documentation

  • Various typo fixes and doc improvements.

2.32.5 (2025-08-18)

Bugfixes

  • The SSLContext caching feature originally introduced in 2.32.0 has created a new class of issues in Requests that have had negative impact across a number of use cases. The Requests team has decided to revert this feature as long term maintenance of it is proving to be unsustainable in its current iteration.

Deprecations

  • Added support for Python 3.14.
  • Dropped support for Python 3.8 following its end of support.
Commits
  • bc04dfd v2.33.0
  • 66d21cb Merge commit from fork
  • 8b9bc8f Move badges to top of README (#7293)
  • e331a28 Remove unused extraction call (#7292)
  • 753fd08 docs: fix FAQ grammar in httplib2 example
  • 774a0b8 docs(socks): same block as other sections
  • 9c72a41 Bump github/codeql-action from 4.33.0 to 4.34.1
  • ebf7190 Bump github/codeql-action from 4.32.0 to 4.33.0
  • 0e4ae38 docs: exclude Response.is_permanent_redirect from API docs (#7244)
  • d568f47 docs: clarify Quickstart POST example (#6960)
  • Additional commits viewable in compare view

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels May 29, 2026
@dependabot
dependabot Bot force-pushed the dependabot/uv/requests-2.33.0 branch from 6db9504 to a60b9e2 Compare June 3, 2026 17:37
Bumps [requests](https://github.com/psf/requests) from 2.32.4 to 2.33.0.
- [Release notes](https://github.com/psf/requests/releases)
- [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md)
- [Commits](psf/requests@v2.32.4...v2.33.0)

---
updated-dependencies:
- dependency-name: requests
  dependency-version: 2.33.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/uv/requests-2.33.0 branch from a60b9e2 to 0560b0a Compare June 8, 2026 20:10
@claude

claude Bot commented Jun 30, 2026

Copy link
Copy Markdown

🔍 Dependency Analysis Summary

This PR bumps requests by a single minor version. It is largely a maintenance release: a Python version-support drop, a build-system migration, and a small auth-handling bug fix. commcare-cloud only uses the stable, high-level requests API (get/post/put, RequestException, requests.exceptions.*), none of which are affected.

  • Overall risk assessment: LOW

📋 Detailed Changelog Review

requests (2.32.4 → 2.33.0)

  • Changes:
    • Dropped support for Python 3.9 (following its end of life).
    • Migrated to a PEP 517 build system using setuptools (Migrate build system to PEP 517 psf/requests#7012).
    • Fixed a bug where an empty netrc entry could cause malformed authentication to be applied on Python 3.11+ (Fix empty netrc entry usage psf/requests#7205).
    • Hardening change to the requests.utils.extract_zipped_paths utility (only relevant if you call that function directly).
    • Inline type hints are previewed as landing in the next release (2.34.0), not this one.
  • Breaking Changes: None for the runtime API. The only removal is Python 3.9 support.
  • Migration Notes: None — commcare-cloud already requires python ~=3.10.0 (see pyproject.toml:10), so the 3.9 drop has no effect.

⚠️ Impact Assessment

  • Breaking Changes Found: No.
  • Affected Files: None require changes. requests is imported in src/commcare_cloud/events.py, src/commcare_cloud/commands/sentry.py, src/commcare_cloud/commands/deploy/sentry.py, src/commcare_cloud/commands/deploy/formplayer.py, src/commcare_cloud/commands/deploy/slack.py, and src/commcare_cloud/commands/terraform/aws.py. All usages are standard request calls and exception handling. No use of requests.utils / extract_zipped_paths, and no reliance on netrc-based auth in these paths.
  • Test Impact: None expected.
  • Configuration Changes: None.

🛠️ Recommendations

  • Action Required: None beyond a normal merge once CI passes.
  • Testing Focus: A quick smoke check of the HTTP-using commands (Sentry release creation, Slack deploy notifications, formplayer /info health check, AWS instance-identity lookup in terraform/aws.py) is sufficient, though no behavioral change is expected.
  • Follow-up Tasks: None. Be aware the next release (2.34.0) introduces inline type hints, which could matter if/when type-checking is enabled.
  • Merge Recommendation: APPROVE

📚 Useful Links

@AmitPhulera AmitPhulera left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed changelog. No breaking changes. Safe to merge.

@AmitPhulera
AmitPhulera merged commit 3b6fb0d into master Jun 30, 2026
7 checks passed
@AmitPhulera
AmitPhulera deleted the dependabot/uv/requests-2.33.0 branch June 30, 2026 16:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

1 participant