dependabot[bot] opened a new pull request, #2516:
URL: https://github.com/apache/datafusion-ballista/pull/2516

   Bumps [urllib3](https://github.com/urllib3/urllib3) from 2.7.0 to 2.8.0.
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/urllib3/urllib3/releases";>urllib3's 
releases</a>.</em></p>
   <blockquote>
   <h2>2.8.0</h2>
   <h2>🚀 urllib3 is fundraising for HTTP/2 support</h2>
   <p><a 
href="https://sethmlarson.dev/urllib3-is-fundraising-for-http2-support";>urllib3 
is raising ~$40,000 USD</a> to release HTTP/2 support and ensure long-term 
sustainable maintenance of the project. If your company or organization uses 
Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and 
thousands of other projects <a href="https://opencollective.com/urllib3";>please 
consider contributing financially</a> to ensure HTTP/2 support is developed 
sustainably and maintained for the long-haul.</p>
   <p>Thank you for your support.</p>
   <h2>Security</h2>
   <p>Fixed the following security issues:</p>
   <ul>
   <li>The TLS configuration for HTTPS proxies could be ignored or overridden. 
(High severity, GHSA-8988-9cw3-xx77)</li>
   <li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code> could 
buffer a chunk-size line of unbounded length in memory. (High severity, 
GHSA-vxq7-64xx-v4gw)</li>
   <li>Chunked Deflate streaming could enter an infinite loop. (Medium 
severity, GHSA-gh4c-6fx4-qh6g)</li>
   </ul>
   <blockquote>
   <p>[!IMPORTANT]
   urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or 
overridden by destination settings. Configurations relying on that behavior may 
require changes.</p>
   <p>Configure proxy CA certificates and client certificates in 
<code>proxy_ssl_context</code>, and proxy identity checks with 
<code>proxy_assert_hostname</code> or <code>proxy_assert_fingerprint</code>. 
Destination client certificates and identity overrides no longer apply to HTTPS 
forwarding proxy connections.</p>
   </blockquote>
   <blockquote>
   <p>[!NOTE]
   CVE IDs had not yet been assigned to these advisories at the time of release 
due to a backlog at GitHub's CNA.</p>
   </blockquote>
   <h2>Deprecations &amp; Removals</h2>
   <ul>
   <li>Deprecated using an empty collection as the <code>Retry</code> option 
<code>allowed_methods</code> to retry any verb. (<a 
href="https://redirect.github.com/urllib3/urllib3/issues/5044";>#5044</a>)</li>
   </ul>
   <h2>Features</h2>
   <ul>
   <li>Added <code>Url.auth_decoded</code> and 
<code>Url.auth_decoded_joined</code> convenience properties to the result of 
<code>parse_url()</code>. (<a 
href="https://redirect.github.com/urllib3/urllib3/issues/4945";>#4945</a>)</li>
   <li>Added <code>basic_auth_encoding</code> and 
<code>proxy_basic_auth_encoding</code> parameters to 
<code>urllib3.util.make_headers()</code>. (<a 
href="https://redirect.github.com/urllib3/urllib3/issues/5092";>#5092</a>)</li>
   </ul>
   <h2>Bugfixes</h2>
   <ul>
   <li>
   <p>Fixed response header handling to replace obsolete folded header lines 
(<code>obs-fold</code>) with spaces in accordance with RFC 9112, preventing raw 
CRLF sequences from appearing in header values such as <code>Set-Cookie</code>. 
(<a 
href="https://redirect.github.com/urllib3/urllib3/issues/1362";>#1362</a>)</p>
   </li>
   <li>
   <p>Fixed usage of <code>proxy_ssl_context</code> with 
<code>ProxyManager</code> when <code>use_forwarding_for_https=True</code>. 
Passing <code>ssl_context</code> instead of <code>proxy_ssl_context</code> for 
HTTPS proxies in this configuration now emits a <code>FutureWarning</code> and 
will raise an error in v3.0. (<a 
href="https://redirect.github.com/urllib3/urllib3/issues/2577";>#2577</a>)</p>
   </li>
   <li>
   <p>Changed behavior of the default <code>ConnectionPool.pool</code> 
initialization. <code>LifoQueue</code> is now resolved from the 
<code>queue</code> module after the <code>ConnectionPool</code> is instantiated 
instead of using the default cached <code>QueueCls</code> class property. This 
is done because sometimes the <code>queue.LifoQueue</code> is monkey-patched 
late in the program, such as by gevent. (<a 
href="https://redirect.github.com/urllib3/urllib3/issues/3289";>#3289</a>)</p>
   </li>
   <li>
   <p>Raised <code>UnrewindableBodyError</code> instead of 
<code>ValueError</code> when retrying a request whose body had 
<code>tell()</code> but not <code>seek()</code>. (<a 
href="https://redirect.github.com/urllib3/urllib3/issues/3779";>#3779</a>)</p>
   </li>
   <li>
   <p>Decoded percent-encoded SOCKS proxy credentials before authenticating 
with the proxy server. (<a 
href="https://redirect.github.com/urllib3/urllib3/issues/3785";>#3785</a>)</p>
   </li>
   <li>
   <p>Fixed <code>HTTPResponse.drain_conn()</code> to discard unread response 
data in 64 KiB chunks (same as the default <code>amt</code> when doing 
<code>HTTPResponse.stream(...)</code>). (<a 
href="https://redirect.github.com/urllib3/urllib3/issues/5019";>#5019</a>)</p>
   </li>
   <li>
   <p>Fixed <code>is_ipaddress()</code> to detect non-standard IPv4 forms 
accepted by <code>socket.connect</code>, such as hex (<code>0x7f000001</code>), 
octal (<code>0177.0.0.1</code>), and decimal integers 
(<code>2130706433</code>), ensuring SSL certificate verification uses the 
correct mode for these addresses. (<a 
href="https://redirect.github.com/urllib3/urllib3/issues/5029";>#5029</a>)</p>
   </li>
   <li>
   <p>Fixed <code>HTTPConnectionPool.urlopen</code> raising a misleading 
<code>FullPoolError</code> instead of <code>ValueError</code> when called with 
an invalid <code>timeout</code> argument on a pool created with 
<code>block=True</code>. (<a 
href="https://redirect.github.com/urllib3/urllib3/issues/5059";>#5059</a>)</p>
   </li>
   <li>
   <p>Fixed port-zero handling to preserve explicit <code>:0</code> values 
instead of substituting the default ports 80 or 443 in URL parsing, pool 
selection, proxy configuration, <code>connection_from_url()</code>, and HTTP/2 
request authority. (<a 
href="https://redirect.github.com/urllib3/urllib3/issues/5071";>#5071</a>, <a 
href="https://redirect.github.com/urllib3/urllib3/issues/5101";>#5101</a>)</p>
   </li>
   <li>
   <p>Fixed a bug where <code>PoolManager</code> passed the 
<code>assert_hostname</code> and <code>assert_fingerprint</code> parameters to 
HTTP connection pools. (<a 
href="https://redirect.github.com/urllib3/urllib3/issues/5077";>#5077</a>)</p>
   </li>
   <li>
   <p>Fixed <code>HTTPConnectionPool.urlopen()</code> and HTTP proxy forwarding 
to strip URL fragments from absolute request targets before sending requests. 
(<a 
href="https://redirect.github.com/urllib3/urllib3/issues/5079";>#5079</a>)</p>
   </li>
   <li>
   <p>Added safeguards to the proxy tunneling code to prevent potential 
security issues when handling invalid characters in the proxy host and HTTP 
headers. This change affects users of Python 3.10, Python 3.11, and Python 3.12 
when the standard library does not contain the fix; those on newer Python 
versions should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes. 
(<a 
href="https://redirect.github.com/urllib3/urllib3/issues/5091";>#5091</a>)</p>
   </li>
   <li>
   <p>Fixed <code>HTTPSConnection.connect()</code> overriding 
<code>ProxyConfig.ssl_context</code>'s certificate policy and proxy identity 
checks with the target connection's TLS settings when forwarding through an 
HTTPS proxy.</p>
   <p><code>HTTPSConnection</code> no longer applies target SNI, assertions, or 
client credentials to forwarding proxy handshakes and continues to use its 
<code>ssl_context</code> as a fallback when an HTTPS proxy forwards an HTTP 
target. (<a 
href="https://redirect.github.com/urllib3/urllib3/issues/5093";>#5093</a>)</p>
   </li>
   <li>
   <p>Fixed URL parsing to more strictly enforce RFC 3986 host syntax, 
rejecting invalid host input such as raw spaces and control characters, 
malformed percent-encodings, and percent-encoded control characters in HTTP(S) 
hosts and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host 
normalization now also follows RFC 3986 normalization rules for percent-encoded 
octets by decoding percent-encoded unreserved characters and uppercasing the 
hexadecimal digits of retained percent-encoded octets. (<a 
href="https://redirect.github.com/urllib3/urllib3/issues/5095";>#5095</a>)</p>
   </li>
   </ul>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Changelog</summary>
   <p><em>Sourced from <a 
href="https://github.com/urllib3/urllib3/blob/main/CHANGES.rst";>urllib3's 
changelog</a>.</em></p>
   <blockquote>
   <h1>2.8.0 (2026-09-15)</h1>
   <h2>Security</h2>
   <p>Fixed the following security issues:</p>
   <ul>
   <li>The TLS configuration for HTTPS proxies could be ignored or overridden.
   (High severity, <code>GHSA-8988-9cw3-xx77 
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77&gt;</code>__)</li>
   <li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code> could 
buffer a chunk-size
   line of unbounded length in memory. (High severity,
   <code>GHSA-vxq7-64xx-v4gw 
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw&gt;</code>__)</li>
   <li>Chunked Deflate streaming could enter an infinite loop. (Medium severity,
   <code>GHSA-gh4c-6fx4-qh6g 
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g&gt;</code>__)</li>
   </ul>
   <p>.. caution::</p>
   <pre><code>urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or
   overridden by destination settings. Configurations relying on that
   behavior may require changes.
   <p>Configure proxy CA certificates and client certificates in
   <code>proxy_ssl_context</code>, and proxy identity checks with
   <code>proxy_assert_hostname</code> or <code>proxy_assert_fingerprint</code>.
   Destination client certificates and identity overrides no longer
   apply to HTTPS forwarding proxy connections.
   </code></pre></p>
   <h2>Deprecations &amp; Removals</h2>
   <ul>
   <li>Deprecated using an empty collection as the <code>Retry</code> option
   <code>allowed_methods</code> to retry any verb.
   (<code>[#5044](https://github.com/urllib3/urllib3/issues/5044) 
&lt;https://github.com/urllib3/urllib3/issues/5044&gt;</code>__)</li>
   </ul>
   <h2>Features</h2>
   <ul>
   <li>Added <code>Url.auth_decoded</code> and 
<code>Url.auth_decoded_joined</code> convenience
   properties to the result of <code>parse_url()</code>.
   (<code>[#4945](https://github.com/urllib3/urllib3/issues/4945) 
&lt;https://github.com/urllib3/urllib3/issues/4945&gt;</code>__)</li>
   <li>Added <code>basic_auth_encoding</code> and 
<code>proxy_basic_auth_encoding</code> parameters to
   <code>urllib3.util.make_headers()</code>.
   (<code>[#5092](https://github.com/urllib3/urllib3/issues/5092) 
&lt;https://github.com/urllib3/urllib3/issues/5092&gt;</code>__)</li>
   </ul>
   <h2>Bugfixes</h2>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/urllib3/urllib3/commit/b1d30ab61fe0db8f11092805e8c5ac43e091064a";><code>b1d30ab</code></a>
 Release 2.8.0</li>
   <li><a 
href="https://github.com/urllib3/urllib3/commit/9016d7e8afc68185496ef07f3c3a4a743d04922e";><code>9016d7e</code></a>
 Skip <code>test_read_chunked_with_trailing_data_does_not_hang</code> for 
brotlicffi (<a 
href="https://redirect.github.com/urllib3/urllib3/issues/5258";>#5258</a>)</li>
   <li><a 
href="https://github.com/urllib3/urllib3/commit/9101f581a8b3659af23b6ff335ae77200ca33533";><code>9101f58</code></a>
 Fix <code>nox -s docs</code> warning (<a 
href="https://redirect.github.com/urllib3/urllib3/issues/5256";>#5256</a>)</li>
   <li><a 
href="https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed";><code>cd770b0</code></a>
 Merge commit from fork</li>
   <li><a 
href="https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f";><code>ea2ad7b</code></a>
 Merge commit from fork</li>
   <li><a 
href="https://github.com/urllib3/urllib3/commit/0716e31534345dc1599ea95d903c79f276239bd8";><code>0716e31</code></a>
 Fix loading unencrypted client keys with a password in pyOpenSSL (<a 
href="https://redirect.github.com/urllib3/urllib3/issues/5255";>#5255</a>)</li>
   <li><a 
href="https://github.com/urllib3/urllib3/commit/43c68c8b43a9dcb44ed2cf4ec91384ca0d46b37d";><code>43c68c8</code></a>
 Test pickling of <code>InvalidChunkLength</code> (<a 
href="https://redirect.github.com/urllib3/urllib3/issues/5247";>#5247</a>)</li>
   <li><a 
href="https://github.com/urllib3/urllib3/commit/308b279b3fb28e7bee952e152ec5baeb5bfd0817";><code>308b279</code></a>
 Share security policy between GitHub and Read the Docs (<a 
href="https://redirect.github.com/urllib3/urllib3/issues/5253";>#5253</a>)</li>
   <li><a 
href="https://github.com/urllib3/urllib3/commit/53fa0731b27d4b71ab0755ea5b896422d005d706";><code>53fa073</code></a>
 Add policy on duplicate pull requests (<a 
href="https://redirect.github.com/urllib3/urllib3/issues/5252";>#5252</a>)</li>
   <li><a 
href="https://github.com/urllib3/urllib3/commit/5f2a6a843d0100d1351c3f94d58581ca98d17267";><code>5f2a6a8</code></a>
 Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (<a 
href="https://redirect.github.com/urllib3/urllib3/issues/5232";>#5232</a>)</li>
   <li>Additional commits viewable in <a 
href="https://github.com/urllib3/urllib3/compare/2.7.0...2.8.0";>compare 
view</a></li>
   </ul>
   </details>
   <br />
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=urllib3&package-manager=uv&previous-version=2.7.0&new-version=2.8.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot show <dependency name> ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   You can disable automated security fix PRs for this repo from the [Security 
Alerts page](https://github.com/apache/datafusion-ballista/network/alerts).
   
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to