build(deps): bump requests from 2.33.0 to 2.34.2 - #24
Conversation
Bumps [requests](https://github.com/psf/requests) from 2.33.0 to 2.34.2. - [Release notes](https://github.com/psf/requests/releases) - [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md) - [Commits](psf/requests@v2.33.0...v2.34.2) --- updated-dependencies: - dependency-name: requests dependency-version: 2.34.2 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
nishantmodak
left a comment
There was a problem hiding this comment.
Reviewed the complete requests 2.33.0 → 2.34.2 dependency change and all three production consumers at e8c2fec6d48b3455aa27e6d6d1451d8ba17a21b5. No actionable regression found.
Local validation: 50 tests pass on both base and head, including 18 added tests importing the actual webhook, Prometheus scraper and instance-metadata consumers. These exercise real Requests preparation, JSON/Unicode payloads, authentication, timeouts, HTTP/transport errors, cross-origin redirects and the IMDS token sequence, with only the HTTP transport replaced. All 13 CI checks are green.
Validation limit: the hashed development lock is already unsatisfiable on both versions (cryptography requires cffi>=2 while the lock pins 1.17.1). The comparison used identical resolved environments with only Requests changed. No real network/TLS/proxy or hardware integration was run locally.
Bumps requests from 2.33.0 to 2.34.2.
Release notes
Sourced from requests's releases.
... (truncated)
Changelog
Sourced from requests's changelog.
... (truncated)
Commits
6e83187v2.34.284d10f0Move Request.headers back to Mapping (#7441)b7b549bv2.34.1e511bc7Fix mutability issues with headers input types (#7431)5691f59Update JsonType containers to read-based collections (#7436)2144213Constrain Response.reason to str (#7437)6404f34Fixprepare_bodystream detection for__getattr__-based file wrappers (#7...0b401c7v2.34.086b378dAlign Session.get parameters with requests.get (#7429)a4f9a59Port bpo-39057 to Requests (#7427)You can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)