[Security] Bump urllib3 from 1.25.3 to 1.26.4#41
[Security] Bump urllib3 from 1.25.3 to 1.26.4#41dependabot-preview[bot] wants to merge 1 commit intomasterfrom
Conversation
Bumps [urllib3](https://github.com/urllib3/urllib3) from 1.25.3 to 1.26.4. - [Release notes](https://github.com/urllib3/urllib3/releases) - [Changelog](https://github.com/urllib3/urllib3/blob/1.26.4/CHANGES.rst) - [Commits](urllib3/urllib3@1.25.3...1.26.4) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
|
We've just been alerted that this update fixes a security vulnerability: Sourced from The GitHub Security Advisory Database.
|
|
Superseded by #54. |
Bumps urllib3 from 1.25.3 to 1.26.4.
Release notes
Sourced from urllib3's releases.
... (truncated)
Changelog
Sourced from urllib3's changelog.
... (truncated)
Commits
a891304Release 1.26.48d65ea1Merge pull request from GHSA-5phf-pp7p-vc2r5e34326Add proper stacklevel to method_allowlist warning361f1e2Release 1.26.33179dfdAllow using deprecated OpenSSL with CRYPTOGRAPHY_ALLOW_OPENSSL_102d97e5d4Use Python 3.5 compatible get-pipcb5e2fc[1.26] Don't compare bytes and str in putheader()b89158f[1.26] Update RECENT_DATE to 2020-07-01a800c74[1.26] Recommend GitHub Sponsors instead of Open Collective947284e[1.26] Improve message for ProxySchemeUnknown exceptionDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)@dependabot use these labelswill set the current labels as the default for future PRs for this repo and language@dependabot use these reviewerswill set the current reviewers as the default for future PRs for this repo and language@dependabot use these assigneeswill set the current assignees as the default for future PRs for this repo and language@dependabot use this milestonewill set the current milestone as the default for future PRs for this repo and language@dependabot badge mewill comment on this PR with code to add a "Dependabot enabled" badge to your readmeAdditionally, you can set the following in your Dependabot dashboard: