Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package python-urllib3 for openSUSE:Factory 
checked in at 2026-10-03 20:12:18
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/python-urllib3 (Old)
 and      /work/SRC/openSUSE:Factory/.python-urllib3.new.1631729 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "python-urllib3"

Sat Oct  3 20:12:18 2026 rev:77 rq:1382029 version:2.8.0

Changes:
--------
--- /work/SRC/openSUSE:Factory/python-urllib3/python-urllib3.changes    
2026-06-16 18:29:18.701299398 +0200
+++ 
/work/SRC/openSUSE:Factory/.python-urllib3.new.1631729/python-urllib3.changes   
    2026-10-03 20:12:19.663574278 +0200
@@ -1,0 +2,120 @@
+Fri Oct  2 06:38:18 UTC 2026 - Daniel Garcia <[email protected]>
+
+- Update to 2.8.0:
+  # Security
+  - The TLS configuration for HTTPS proxies could be ignored or
+    overridden.
+    (bsc#1283908, CVE-2026-97687)
+  - ``HTTPResponse.stream()`` and ``read_chunked()`` could buffer a
+    chunk-size line of unbounded length in memory.
+    (bsc#1283910, CVE-2026-97689)
+  - Chunked Deflate streaming could enter an infinite loop.
+    (bsc#1283909, CVE-2026-97688)
+
+  ## caution
+    urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or
+    overridden by destination settings. Configurations relying on that
+    behavior may require changes.
+
+    Configure proxy CA certificates and client certificates in
+    ``proxy_ssl_context``, and proxy identity checks with
+    ``proxy_assert_hostname`` or ``proxy_assert_fingerprint``.
+    Destination client certificates and identity overrides no longer
+    apply to HTTPS forwarding proxy connections.
+
+  # Deprecations & Removals
+  - Deprecated using an empty collection as the ``Retry`` option
+    ``allowed_methods`` to retry any verb.
+
+  # Features
+  - Added ``Url.auth_decoded`` and ``Url.auth_decoded_joined``
+    convenience properties to the result of ``parse_url()``.
+  - Added ``basic_auth_encoding`` and ``proxy_basic_auth_encoding``
+    parameters to ``urllib3.util.make_headers()``.
+
+  # Bugfixes
+  - Fixed response header handling to replace obsolete folded header
+    lines (`obs-fold`) with spaces in accordance with RFC 9112,
+    preventing raw CRLF sequences from appearing in header values such
+    as ``Set-Cookie``.
+  - Fixed usage of ``proxy_ssl_context`` with ``ProxyManager`` when
+    ``use_forwarding_for_https=True``. Passing ``ssl_context`` instead
+    of ``proxy_ssl_context`` for HTTPS proxies in this configuration
+    now emits a ``FutureWarning`` and will raise an error in v3.0.
+  - Changed behavior of the default ``ConnectionPool.pool``
+    initialization.  ``LifoQueue`` is now resolved from the ``queue``
+    module after the ``ConnectionPool`` is instantiated instead of
+    using the default cached ``QueueCls`` class property. This is done
+    because sometimes the ``queue.LifoQueue`` is monkey-patched late
+    in the program, such as by gevent.
+  - Raised ``UnrewindableBodyError`` instead of ``ValueError`` when
+    retrying a request whose body had ``tell()`` but not ``seek()``.
+  - Decoded percent-encoded SOCKS proxy credentials before
+    authenticating with the proxy server.
+  - Fixed ``HTTPResponse.drain_conn()`` to discard unread response
+    data in 64 KiB chunks (same as the default ``amt`` when doing
+    ``HTTPResponse.stream(...)``).
+  - Fixed ``is_ipaddress()`` to detect non-standard IPv4 forms
+    accepted by ``socket.connect``, such as hex (``0x7f000001``),
+    octal (``0177.0.0.1``), and decimal integers (``2130706433``),
+    ensuring SSL certificate verification uses the correct mode for
+    these addresses.
+  - Fixed ``HTTPConnectionPool.urlopen`` raising a misleading
+    ``FullPoolError`` instead of ``ValueError`` when called with an
+    invalid ``timeout`` argument on a pool created with
+    ``block=True``.
+  - Fixed port-zero handling to preserve explicit ``:0`` values
+    instead of substituting the default ports 80 or 443 in URL
+    parsing, pool selection, proxy configuration,
+    ``connection_from_url()``, and HTTP/2 request authority.
+  - Fixed a bug where ``PoolManager`` passed the ``assert_hostname``
+    and ``assert_fingerprint`` parameters to HTTP connection pools.
+  - Fixed ``HTTPConnectionPool.urlopen()`` and HTTP proxy forwarding
+    to strip URL fragments from absolute request targets before
+    sending requests.
+  - Added safeguards to the proxy tunneling code to prevent potential
+    security issues when handling invalid characters in the proxy host
+    and HTTP headers.  This change affects users of Python 3.10,
+    Python 3.11, and Python 3.12 when the standard library does not
+    contain the fix; those on newer Python versions should upgrade to
+    3.13.14+ or 3.14.5+ to get the same security fixes.
+  - Fixed ``HTTPSConnection.connect()`` overriding
+    ``ProxyConfig.ssl_context``'s certificate policy and proxy
+    identity checks with the target connection's TLS settings when
+    forwarding through an HTTPS proxy.
+  
+    ``HTTPSConnection`` no longer applies target SNI, assertions, or
+    client credentials to forwarding proxy handshakes and continues to
+    use its ``ssl_context`` as a fallback when an HTTPS proxy forwards
+    an HTTP target.
+  - Fixed URL parsing to more strictly enforce RFC 3986 host syntax,
+    rejecting invalid host input such as raw spaces and control
+    characters, malformed percent-encodings, and percent-encoded
+    control characters in HTTP(S) hosts and IPv6 zone identifiers,
+    including proxy CONNECT tunnel targets. Host normalization now
+    also follows RFC 3986 normalization rules for percent-encoded
+    octets by decoding percent-encoded unreserved characters and
+    uppercasing the hexadecimal digits of retained percent-encoded
+    octets.
+  - Fixed an ``AttributeError`` on Python built with OpenSSL 4+, where
+    ``ssl.PROTOCOL_TLSv1`` no longer exists.
+  - Fixed ``urllib3.contrib.pyopenssl`` to use cryptography APIs when
+    reading a certificate subject and loading encrypted private keys,
+    avoiding ``DeprecationWarning`` raised by pyOpenSSL 26.3.0+.
+  - Fixed handling of HTTP 303 redirects for requests with chunked or
+    file-like bodies.
+  - Fixed ``assert_fingerprint()`` to raise ``SSLError`` instead of
+    ``binascii.Error`` when a fingerprint has a supported length but
+    contains non-hexadecimal characters.
+
+  # Misc
+  - Added a ``test`` dependency group containing the minimum
+    dependencies needed to run the test suite, intended for downstream
+    packagers. The ``dev-base`` and ``mypy`` groups now include this
+    new group via ``include-group``, removing duplication.
+  - Fixed test failures with pytest >= 9.1.
+  - Enabled JSPI tests with Firefox in the Emscripten test suite.
+  - Improved streamed response decoding performance.
+  - Fixed flaky tests.
+
+-------------------------------------------------------------------

Old:
----
  urllib3-2.7.0.tar.gz

New:
----
  urllib3-2.8.0.tar.gz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ python-urllib3.spec ++++++
--- /var/tmp/diff_new_pack.LSXMNQ/_old  2026-10-03 20:12:20.716618328 +0200
+++ /var/tmp/diff_new_pack.LSXMNQ/_new  2026-10-03 20:12:20.718618412 +0200
@@ -26,7 +26,7 @@
 %endif
 %{?sle15_python_module_pythons}
 Name:           python-urllib3%{psuffix}
-Version:        2.7.0
+Version:        2.8.0
 Release:        0
 Summary:        HTTP library with thread-safe connection pooling, file post, 
and more
 License:        MIT

++++++ urllib3-2.7.0.tar.gz -> urllib3-2.8.0.tar.gz ++++++
++++ 5419 lines of diff (skipped)

Reply via email to