fix(deps): vuln minor upgrades — 15 packages (minor: 7 · patch: 8) [src/loadgenerator]#73
Conversation
Release Notesurllib3 (2.0.7 → 2.6.3) — GitHub Release2.6.3🚀 urllib3 is fundraising for HTTP/2 supporturllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project after a sharp decline in financial support. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects please consider contributing financially to ensure HTTP/2 support is developed sustainably and maintained for the long-haul. Thank you for your support. Changes
2.6.2🚀 urllib3 is fundraising for HTTP/2 supporturllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project after a sharp decline in financial support. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects please consider contributing financially to ensure HTTP/2 support is developed sustainably and maintained for the long-haul. Thank you for your support. Changes
2.6.1🚀 urllib3 is fundraising for HTTP/2 supporturllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project after a sharp decline in financial support. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects please consider contributing financially to ensure HTTP/2 support is developed sustainably and maintained for the long-haul. Thank you for your support. Changes
2.6.0🚀 urllib3 is fundraising for HTTP/2 supporturllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project after a sharp decline in financial support. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects please consider contributing financially to ensure HTTP/2 support is developed sustainably and maintained for the long-haul. Thank you for your support. Security
(truncated — see source for full notes) flask-cors (4.0.0 → 4.0.2) — GitHub Release4.0.2What's Changed
New Contributors
Full Changelog: corydolphin/flask-cors@4.0.1...4.0.2 4.0.1What's Changed
New Contributors
Full Changelog: corydolphin/flask-cors@4.0.0...4.0.1 werkzeug (3.0.1 → 3.0.6) — GitHub Release3.0.6This is the Werkzeug 3.0.6 security fix release, which fixes security issues but does not otherwise change behavior and should not result in breaking changes. PyPI: https://pypi.org/project/Werkzeug/3.0.6/
3.0.5This is the Werkzeug 3.0.5 fix release, which fixes bugs but does not otherwise change behavior and should not result in breaking changes. PyPI: https://pypi.org/project/Werkzeug/3.0.5/
3.0.4This is the Werkzeug 3.0.4 fix release, which fixes bugs but does not otherwise change behavior and should not result in breaking changes. PyPI: https://pypi.org/project/Werkzeug/3.0.4/
3.0.3This is the Werkzeug 3.0.3 security release, which fixes security issues and bugs but does not otherwise change behavior and should not result in breaking changes. PyPI: https://pypi.org/project/Werkzeug/3.0.3/
3.0.2(truncated — see source for full notes) idna (3.4 → 3.11) — GitHub Releasev3.8What's Changed
Thanks to Hugo van Kemenade for contributions to this release. Full Changelog: kjd/idna@v3.7...v3.8 v3.7What's Changed
Thanks to Guido Vranken for reporting the issue. Full Changelog: kjd/idna@v3.6...v3.7 (and 3 more releases — view all) brotli (1.1.0 → 1.2.0) — GitHub Releasev1.2.0SECURITY
Added
Removed
Fixed
Improved
Changed
jinja2 (3.1.2 → 3.1.6) — GitHub Release3.1.6This is the Jinja 3.1.6 security release, which fixes security issues but does not otherwise change behavior and should not result in breaking changes compared to the latest feature release. PyPI: https://pypi.org/project/Jinja2/3.1.6/
3.1.5This is the Jinja 3.1.5 security fix release, which fixes security issues and bugs but does not otherwise change behavior and should not result in breaking changes compared to the latest feature release. PyPI: https://pypi.org/project/Jinja2/3.1.5/
(truncated) 3.1.4This is the Jinja 3.1.4 security release, which fixes security issues and bugs but does not otherwise change behavior and should not result in breaking changes. PyPI: https://pypi.org/project/Jinja2/3.1.4/
3.1.3This is a fix release for the 3.1.x feature branch.
(truncated — see source for full notes) requests (2.31.0 → 2.33.1) — GitHub Releasev2.33.12.33.1 (2026-03-30)Bugfixes
New Contributors
Full Changelog: https://github.com/psf/requests/blob/main/HISTORY.md#2331-2026-03-30 v2.33.02.33.0 (2026-03-25)Announcements
Security
Improvements
Bugfixes
Deprecations
Documentation
New Contributors
Full Changelog: https://github.com/psf/requests/blob/main/HISTORY.md#2330-2026-03-25 v2.32.52.32.5 (2025-08-18)Bugfixes
Deprecations
v2.32.42.32.4 (2025-06-10)Security
Improvements
Deprecations
v2.32.32.32.3 (2024-05-29)Bugfixes
v2.32.22.32.2 (2024-05-21)Deprecations
(truncated — see source for full notes) googleapis-common-protos (1.61.0 → 1.74.0) — Changeloghttps://github.com/googleapis/google-cloud-python/blob/main/CHANGELOG.md six (1.16.0 → 1.17.0) — Commit comparison
... and 1 more commits typing-extensions (4.8.0 → 4.15.0) — GitHub Release4.15.0No user-facing changes since 4.15.0rc1. New features since 4.14.1:
4.14.1Release 4.14.1 (July 4, 2025)
4.14.0This release adds several new features, including experimental support for inline typed dictionaries (PEP 764) and sentinels (PEP 661), and support for changes in Python 3.14. In addition, Python 3.8 is no longer supported. Changes since 4.14.0rc1:
Changes included in 4.14.0rc1:
New features:
4.13.2
4.13.1This is a bugfix release fixing two edge cases that appear on old bugfix releases of CPython. Bugfixes:
4.13.0New features:
(truncated — see source for full notes) click (8.1.7 → 8.1.8) — GitHub ReleaseThis is the Click 8.1.8 fix release, which fixes bugs but does not otherwise change behavior and should not result in breaking changes compared to the latest feature release. PyPI: https://pypi.org/project/click/8.1.8/
configargparse (1.7 → 1.7.5) — GitHub ReleaseSlightly simplified PyPI deployment workflow via setuptools-scm deprecated (1.2.14 → 1.2.18) — GitHub Releasev1.2.18What's ChangedFull Changelog: laurent-laporte-pro/deprecated@v1.2.17...v1.2.18 v1.2.17What's Changed
Full Changelog: laurent-laporte-pro/deprecated@v1.2.16...v1.2.17 v1.2.16What's Changed
New Contributors
Full Changelog: laurent-laporte-pro/deprecated@v1.2.15...v1.2.16 v1.2.15What's Changed
New Contributors
Full Changelog: laurent-laporte-pro/deprecated@v1.2.14...v1.2.15 flask (3.0.0 → 3.0.3) — GitHub Release3.0.3This is a fix release for the 3.0.x feature branch. PyPI: https://pypi.org/project/Flask/3.0.3/
3.0.2This is a fix release for the 3.0.x feature release branch. It fixes bugs but does not otherwise change behavior and should not result in breaking changes.
3.0.1This is a fix release for the 3.0.x feature release branch. Fixes an issue where using other JSON providers, such as markupsafe (2.1.3 → 2.1.5) — GitHub Release2.1.5This is a fix release for the 2.1.x feature release branch. It fixes bugs but does not otherwise change behavior and should not result in breaking changes. Fixes a regression in
2.1.4This is a fix release for the 2.1.x feature release branch. It fixes bugs but does not otherwise change behavior and should not result in breaking changes.
Generated by ADMS Sources: 13 GitHub Releases, 1 Changelog, 1 Commit comparison. |
Please could you fix your bot not to mention me in your automated updates? Thank you! |
|
@hugovk Changelogs feature is tagging people which is not expected. The feature flag is off now should not be the case anymore |
|
Hey, sorry for the noise. This was caused by a bug in our automated dependency update system that incorrectly included upstream changelog content in PR comments, triggering notifications to external contributors. The feature flag has been turned off and we're working on a fix. Sorry about that again. |
|
Thanks, appreciated :) |
Summary: High-severity security update — 15 packages upgraded (MINOR changes included)
Manifests changed:
src/loadgenerator(pip)✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.
Updates
Packages marked with "-" are updated due to dependency constraints.
Security Details
🚨 Critical & High Severity (14 fixed)
Access-Control-Allow-Private-NetworkCORS header to be set to true by defaultℹ️ Other Vulnerabilities (40)
Sessionobject does not verify requests after making first request with verify=FalseSessionobject does not verify requests after making first request with verify=FalseVary: Cookieheader when accessed in some waysVary: Cookieheader when accessed in some ways8.1.78.1.8src/loadgenerator/requirements.txt1.71.7.5src/loadgenerator/requirements.txt1.61.01.74.0src/loadgenerator/requirements.txt3.43.11src/loadgenerator/requirements.txt2.1.32.1.5src/loadgenerator/requirements.txt2.31.02.33.1src/loadgenerator/requirements.txt4.8.04.15.0src/loadgenerator/requirements.txt📅 Dependencies Nearing EOL (1)
1.16.01.17.0src/loadgenerator/requirements.txtReview Checklist
Standard review:
Update Mode: Vulnerability Remediation (High)
🤖 Generated by DataDog Automated Dependency Management System