Re: [PR] chore(deps): Bump urllib3 from 2.6.3 to 2.7.0 in /.github/actions/check-container-upgrade [camel]

2026-05-11 Thread via GitHub


apupier merged PR #23128:
URL: https://github.com/apache/camel/pull/23128


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]



Re: [PR] chore(deps): Bump urllib3 from 2.6.3 to 2.7.0 in /.github/actions/check-container-upgrade [camel]

2026-05-11 Thread via GitHub


github-actions[bot] commented on PR #23128:
URL: https://github.com/apache/camel/pull/23128#issuecomment-4424987489

   :star2: Thank you for your contribution to the Apache Camel project! :star2:
 :robot: CI automation will test this PR automatically.
   
 :camel: Apache Camel Committers, please review the following items:
   
 * First-time contributors **require MANUAL approval** for the GitHub 
Actions to run
 * You can use the command `/component-test (camel-)component-name1 
(camel-)component-name2..` to request a test from the test bot although they 
are normally detected and executed by CI.
 * You can label PRs using `skip-tests` and `test-dependents` to fine-tune 
the checks executed by this PR.
 * Build and test logs are available in the summary page. **Only** [Apache 
Camel committers](https://camel.apache.org/community/team/#committers) have 
access to the summary.
 
 :warning: Be careful when sharing logs. Review their contents before 
sharing them publicly.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]



[PR] chore(deps): Bump urllib3 from 2.6.3 to 2.7.0 in /.github/actions/check-container-upgrade [camel]

2026-05-11 Thread via GitHub


dependabot[bot] opened a new pull request, #23128:
URL: https://github.com/apache/camel/pull/23128

   Bumps [urllib3](https://github.com/urllib3/urllib3) from 2.6.3 to 2.7.0.
   
   Release notes
   Sourced from https://github.com/urllib3/urllib3/releases";>urllib3's 
releases.
   
   2.7.0
   🚀 urllib3 is fundraising for HTTP/2 support
   https://sethmlarson.dev/urllib3-is-fundraising-for-http2-support";>urllib3 
is raising ~$40,000 USD to release HTTP/2 support and ensure long-term 
sustainable maintenance of the project after a sharp decline in financial 
support. If your company or organization uses Python and would benefit from 
HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects https://opencollective.com/urllib3";>please consider contributing 
financially to ensure HTTP/2 support is developed sustainably and 
maintained for the long-haul.
   Thank you for your support.
   Security
   Addressed high-severity security issues. Impact was limited to specific 
use cases detailed in the accompanying advisories; overall user exposure was 
estimated to be marginal.
   
   
   Decompression-bomb safeguards of the streaming API were bypassed:
   
   When HTTPResponse.drain_conn() was called after the 
response had been read and decompressed partially. (Reported by https://github.com/Cycloctane";>@​Cycloctane)
   During the second HTTPResponse.read(amt=N) or 
HTTPResponse.stream(amt=N) call when the response was decompressed 
using the official https://pypi.org/project/brotli/";>Brotli 
library. (Reported by https://github.com/kimkou2024";>@​kimkou2024)
   
   See GHSA-mf9v-mfxr-j63j for details.
   
   
   HTTP pools created using ProxyManager.connection_from_url 
did not strip sensitive headers specified in 
Retry.remove_headers_on_redirect when redirecting to a different 
host. (GHSA-qccp-gfcp-xxvc reported by https://github.com/christos-spearbit";>@​christos-spearbit)
   
   
   Deprecations and Removals
   
   Used FutureWarning instead of 
DeprecationWarning for better visibility of existing deprecation 
notices. Rescheduled the removal of deprecated features to version 3.0. (https://redirect.github.com/urllib3/urllib3/issues/3763";>urllib3/urllib3#3763)
   Removed support for end-of-life Python 3.9. (https://redirect.github.com/urllib3/urllib3/issues/3720";>urllib3/urllib3#3720)
   Removed support for end-of-life PyPy3.10. (https://redirect.github.com/urllib3/urllib3/issues/4979";>urllib3/urllib3#4979)
   Bumped the minimum supported pyOpenSSL version to 19.0.0. (https://redirect.github.com/urllib3/urllib3/issues/3777";>urllib3/urllib3#3777)
   
   Bugfixes
   
   Fixed a bug where HTTPResponse.read(amt=None) was ignoring 
decompressed data buffered from previous partial reads. (https://redirect.github.com/urllib3/urllib3/issues/3636";>urllib3/urllib3#3636)
   Fixed a bug where HTTPResponse.read() could cache only part 
of the response after a partial read when cache_content=True. (https://redirect.github.com/urllib3/urllib3/issues/4967";>urllib3/urllib3#4967)
   Fixed HTTPResponse.stream() and 
HTTPResponse.read_chunked() to handle amt=0. (https://redirect.github.com/urllib3/urllib3/issues/3793";>urllib3/urllib3#3793)
   Updated _TYPE_BODY type alias to include missing 
Iterable[str], matching the documented and runtime behavior of 
chunked request bodies. (https://redirect.github.com/urllib3/urllib3/issues/3798";>urllib3/urllib3#3798)
   Fixed LocationParseError when paths resembling schemeless 
URIs were passed to HTTPConnectionPool.urlopen(). (https://redirect.github.com/urllib3/urllib3/issues/3352";>urllib3/urllib3#3352)
   Fixed BaseHTTPResponse.readinto() type annotation to accept 
memoryview in addition to bytearray, matching the 
io.RawIOBase.readinto contract and enabling use with 
io.BufferedReader without type errors. (https://redirect.github.com/urllib3/urllib3/issues/3764";>urllib3/urllib3#3764)
   
   
   
   
   Changelog
   Sourced from https://github.com/urllib3/urllib3/blob/main/CHANGES.rst";>urllib3's 
changelog.
   
   2.7.0 (2026-05-07)
   Security
   Addressed high-severity security issues.
   Impact was limited to specific use cases detailed in the accompanying
   advisories; overall user exposure was estimated to be marginal.
   
   
   Decompression-bomb safeguards of the streaming API were bypassed:
   
   When HTTPResponse.drain_conn() was called after the 
response had been
   read and decompressed partially.
   During the second HTTPResponse.read(amt=N) or
   HTTPResponse.stream(amt=N) call when the response was 
decompressed
   using the official Brotli 
;__ library.
   
   See GHSA-mf9v-mfxr-j63j 
;__
   for details.
   
   
   HTTP pools created using ProxyManager.connection_from_url 
did not strip
   sensitive headers specified in Retry.remove_headers_on_redirect 
when
   redirecting to a different host.
   (GHSA-qccp-gfcp-xxvc