Skip to content

chore(deps-dev): bump requests from 2.32.5 to 2.33.0#1059

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/requests-2.33.0
Closed

chore(deps-dev): bump requests from 2.32.5 to 2.33.0#1059
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/requests-2.33.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 19, 2026

Copy link
Copy Markdown
Contributor

Bumps requests from 2.32.5 to 2.33.0.

Release notes

Sourced from requests's releases.

v2.33.0

2.33.0 (2026-03-25)

Announcements

  • 📣 Requests is adding inline types. If you have a typed code base that uses Requests, please take a look at #7271. Give it a try, and report any gaps or feedback you may have in the issue. 📣

Security

  • CVE-2026-25645 requests.utils.extract_zipped_paths now extracts contents to a non-deterministic location to prevent malicious file replacement. This does not affect default usage of Requests, only applications calling the utility function directly.

Improvements

  • Migrated to a PEP 517 build system using setuptools. (#7012)

Bugfixes

  • Fixed an issue where an empty netrc entry could cause malformed authentication to be applied to Requests on Python 3.11+. (#7205)

Deprecations

  • Dropped support for Python 3.9 following its end of support. (#7196)

Documentation

  • Various typo fixes and doc improvements.

New Contributors

Full Changelog: https://github.com/psf/requests/blob/main/HISTORY.md#2330-2026-03-25

Changelog

Sourced from requests's changelog.

2.33.0 (2026-03-25)

Announcements

  • 📣 Requests is adding inline types. If you have a typed code base that uses Requests, please take a look at #7271. Give it a try, and report any gaps or feedback you may have in the issue. 📣

Security

  • CVE-2026-25645 requests.utils.extract_zipped_paths now extracts contents to a non-deterministic location to prevent malicious file replacement. This does not affect default usage of Requests, only applications calling the utility function directly.

Improvements

  • Migrated to a PEP 517 build system using setuptools. (#7012)

Bugfixes

  • Fixed an issue where an empty netrc entry could cause malformed authentication to be applied to Requests on Python 3.11+. (#7205)

Deprecations

  • Dropped support for Python 3.9 following its end of support. (#7196)

Documentation

  • Various typo fixes and doc improvements.
Commits
  • bc04dfd v2.33.0
  • 66d21cb Merge commit from fork
  • 8b9bc8f Move badges to top of README (#7293)
  • e331a28 Remove unused extraction call (#7292)
  • 753fd08 docs: fix FAQ grammar in httplib2 example
  • 774a0b8 docs(socks): same block as other sections
  • 9c72a41 Bump github/codeql-action from 4.33.0 to 4.34.1
  • ebf7190 Bump github/codeql-action from 4.32.0 to 4.33.0
  • 0e4ae38 docs: exclude Response.is_permanent_redirect from API docs (#7244)
  • d568f47 docs: clarify Quickstart POST example (#6960)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels May 19, 2026
@dependabot dependabot Bot requested a review from a team as a code owner May 19, 2026 20:49
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels May 19, 2026
@github-actions github-actions Bot enabled auto-merge May 19, 2026 21:00
@dependabot dependabot Bot force-pushed the dependabot/pip/requests-2.33.0 branch from 7800f03 to 66129c8 Compare May 20, 2026 01:18
Bumps [requests](https://github.com/psf/requests) from 2.32.5 to 2.33.0.
- [Release notes](https://github.com/psf/requests/releases)
- [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md)
- [Commits](psf/requests@v2.32.5...v2.33.0)

---
updated-dependencies:
- dependency-name: requests
  dependency-version: 2.33.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/pip/requests-2.33.0 branch from 66129c8 to 45adcfb Compare May 21, 2026 01:39
gavinbarron added a commit that referenced this pull request May 21, 2026
* chore(deps-dev): consolidate dependabot dependency updates

Bump the following dev dependencies:
- aiohttp: 3.12.15 → 3.13.5
- anyio: 4.10.0 → 4.13.0
- attrs: 25.3.0 → 26.1.0
- cryptography: 46.0.5 → 48.0.0
- dill: 0.4.0 → 0.4.1
- idna: 3.10 → 3.15
- opentelemetry-api: 1.38.0 → 1.42.0
- opentelemetry-sdk: 1.38.0 → 1.42.0
- opentelemetry-semantic-conventions: 0.59b0 → 0.63b0
- requests: 2.32.5 → 2.33.0
- tomlkit: 0.13.3 → 0.15.0
- tzdata: 2025.2 → 2026.2

Consolidates PRs #1047, #1050, #1051, #1052, #1053, #1054, #1055, #1056, #1057, #1059

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* chore: group remaining dependabot updates with catch-all pattern

Add an 'other-dependencies' group with a wildcard pattern to catch
all packages not already matched by a specific group. This reduces
individual PRs for ungrouped packages like requests, idna, attrs,
cryptography, etc. into a single grouped PR.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@dependabot @github

dependabot Bot commented on behalf of github May 22, 2026

Copy link
Copy Markdown
Contributor Author

Looks like requests is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this May 22, 2026
auto-merge was automatically disabled May 22, 2026 00:01

Pull request was closed

@dependabot dependabot Bot deleted the dependabot/pip/requests-2.33.0 branch May 22, 2026 00:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants