Releases: psf/requests
v2.32.3
v2.32.2
2.32.2 (2024-05-21)
Deprecations
-
To provide a more stable migration for custom HTTPAdapters impacted
by the CVE changes in 2.32.0, we've renamed_get_connection
to
a new public API,get_connection_with_tls_context
. Existing custom
HTTPAdapters will need to migrate their code to use this new API.
get_connection
is considered deprecated in all versions of Requests>=2.32.0.A minimal (2-line) example has been provided in the linked PR to ease
migration, but we strongly urge users to evaluate if their custom adapter
is subject to the same issue described in CVE-2024-35195. (#6710)
v2.32.1
2.32.1 (2024-05-20)
Bugfixes
- Add missing test certs to the sdist distributed on PyPI.
v2.32.0
2.32.0 (2024-05-20)
🐍 PYCON US 2024 EDITION 🐍
Security
- Fixed an issue where setting
verify=False
on the first request from a
Session will cause subsequent requests to the same origin to also ignore
cert verification, regardless of the value ofverify
.
(GHSA-9wx4-h78v-vm56)
Improvements
verify=True
now reuses a global SSLContext which should improve
request time variance between first and subsequent requests. It should
also minimize certificate load time on Windows systems when using a Python
version built with OpenSSL 3.x. (#6667)- Requests now supports optional use of character detection
(chardet
orcharset_normalizer
) when repackaged or vendored.
This enablespip
and other projects to minimize their vendoring
surface area. TheResponse.text()
andapparent_encoding
APIs
will default toutf-8
if neither library is present. (#6702)
Bugfixes
- Fixed bug in length detection where emoji length was incorrectly
calculated in the request content-length. (#6589) - Fixed deserialization bug in JSONDecodeError. (#6629)
- Fixed bug where an extra leading
/
(path separator) could lead
urllib3 to unnecessarily reparse the request URI. (#6644)
Deprecations
- Requests has officially added support for CPython 3.12 (#6503)
- Requests has officially added support for PyPy 3.9 and 3.10 (#6641)
- Requests has officially dropped support for CPython 3.7 (#6642)
- Requests has officially dropped support for PyPy 3.7 and 3.8 (#6641)
Documentation
- Various typo fixes and doc improvements.
Packaging
- Requests has started adopting some modern packaging practices.
The source files for the projects (formerlyrequests
) is now located
insrc/requests
in the Requests sdist. (#6506) - Starting in Requests 2.33.0, Requests will migrate to a PEP 517 build system
usinghatchling
. This should not impact the average user, but extremely old
versions of packaging utilities may have issues with the new packaging format.
New Contributors
- @matthewarmand made their first contribution in #6258
- @cpzt made their first contribution in #6456
- @ittner made their first contribution in #6214
- @ZetaTwo made their first contribution in #6465
- @joren485 made their first contribution in #6475
- @elprimato made their first contribution in #6266
- @dependabot made their first contribution in #6499
- @Ocupe made their first contribution in #6507
- @13steinj made their first contribution in #6508
- @jnhyperion made their first contribution in #6517
- @swims-hjkl made their first contribution in #6552
- @msea1 made their first contribution in #6574
- @EFord36 made their first contribution in #6581
- @MestreLion made their first contribution in #6600
- @atatuzuner61 made their first contribution in #6592
- @jaikishpai made their first contribution in #6605
- @miketheman made their first contribution in #6613
- @Tarty made their first contribution in #6629
- @bruceadams made their first contribution in #6589
- @amkarn258 made their first contribution in #6562
- @flysee made their first contribution in #6302
- @mbeijen made their first contribution in #6680
- @franekmagiera made their first contribution in #6700
- @agubelu made their first contribution in #6667
Full Changelog: https://github.com/psf/requests/blob/main/HISTORY.md#2320-2024-05-20
v2.31.0
2.31.0 (2023-05-22)
Security
-
Versions of Requests between v2.3.0 and v2.30.0 are vulnerable to potential
forwarding ofProxy-Authorization
headers to destination servers when
following HTTPS redirects.When proxies are defined with user info (https://user:pass@proxy:8080), Requests
will construct aProxy-Authorization
header that is attached to the request to
authenticate with the proxy.In cases where Requests receives a redirect response, it previously reattached
theProxy-Authorization
header incorrectly, resulting in the value being
sent through the tunneled connection to the destination server. Users who rely on
defining their proxy credentials in the URL are strongly encouraged to upgrade
to Requests 2.31.0+ to prevent unintentional leakage and rotate their proxy
credentials once the change has been fully deployed.Users who do not use a proxy or do not supply their proxy credentials through
the user information portion of their proxy URL are not subject to this
vulnerability.Full details can be read in our Github Security Advisory
and CVE-2023-32681.
v2.30.0
2.30.0 (2023-05-03)
Dependencies
-
⚠️ Added support for urllib3 2.0.⚠️ This may contain minor breaking changes so we advise careful testing and
reviewing https://urllib3.readthedocs.io/en/latest/v2-migration-guide.html
prior to upgrading.Users who wish to stay on urllib3 1.x can pin to
urllib3<2
.
v2.29.0
v2.28.2
2.28.2 (2023-01-12)
Dependencies
- Requests now supports charset_normalizer 3.x. (#6261)
Bugfixes
- Updated MissingSchema exception to suggest https scheme rather than http. (#6188)
New Contributors
- @slyapustin made their first contribution in #6188
- @mila made their first contribution in #6200
- @DavidCain made their first contribution in #6204
- @jaap3 made their first contribution in #6234
- @deedy5 made their first contribution in #6261
- @winmorre made their first contribution in #6262
- @oliviacrain made their first contribution in #6291
- @ch-iv made their first contribution in #6317
- @boahc077 made their first contribution in #6236
Full Changelog: v2.28.1...v2.28.2
v2.28.1
2.28.1 (2022-06-29)
Improvements
- Speed optimization in
iter_content
with transition toyield from
. (#6170)
Dependencies
New Contributors
- @hswong3i made their first contribution in #6179
- @frenzymadness made their first contribution in #6169
Full Changelog: https://github.com/psf/requests/blob/main/HISTORY.md#2281-2022-06-29
v2.28.0
2.28.0 (2022-06-09)
Deprecations
⚠️ Requests has officially dropped support for Python 2.7.⚠️ (#6091)- Requests has officially dropped support for Python 3.6 (including pypy3). (#6091)
Improvements
- Wrap JSON parsing issues in Request's JSONDecodeError for payloads without
an encoding to makejson()
API consistent. (#6097) - Parse header components consistently, raising an InvalidHeader error in
all invalid cases. (#6154) - Added provisional 3.11 support with current beta build. (#6155)
- Requests got a makeover and we decided to paint it black. (#6095)
Bugfixes
- Fixed bug where setting
CURL_CA_BUNDLE
to an empty string would disable
cert verification. All Requests 2.x versions before 2.28.0 are affected. (#6074) - Fixed urllib3 exception leak, wrapping
urllib3.exceptions.SSLError
with
requests.exceptions.SSLError
forcontent
anditer_content
. (#6057) - Fixed issue where invalid Windows registry entires caused proxy resolution
to raise an exception rather than ignoring the entry. (#6149) - Fixed issue where entire payload could be included in the error message for
JSONDecodeError. (#6079)
New Contributors
- @marwanpro made their first contribution in #6035
- @chyzzqo2 made their first contribution in #6036
- @Chavithra made their first contribution in #6044
- @sha016 made their first contribution in #5978
- @BoboTiG made their first contribution in #4766
- @davidshivaji made their first contribution in #6133
- @ogayot made their first contribution in #6136
Full Changelog: https://github.com/psf/requests/blob/main/HISTORY.md#2280-2022-06-09