[py] Bump urllib3 in packaging and dev dependencies#16690
[py] Bump urllib3 in packaging and dev dependencies#16690cgoldberg merged 1 commit intoSeleniumHQ:trunkfrom
Conversation
PR Compliance Guide 🔍Below is a summary of compliance checks for this PR:
Compliance status legend🟢 - Fully Compliant🟡 - Partial Compliant 🔴 - Not Compliant ⚪ - Requires Further Human Verification 🏷️ - Compliance label |
||||||||||||||||||||||||
PR Code Suggestions ✨No code suggestions found for the PR. |
User description
💥 What does this PR do?
This PR bumps urllib3 minimum version to 2.6.0 in packaging because of a vulnerability in 2.5.0. It also includes an updated
requirements.txtand lock file for dependencies in dev/CI.https://github.com/SeleniumHQ/selenium/security/dependabot/226
https://github.com/SeleniumHQ/selenium/security/dependabot/224
🔄 Types of changes
PR Type
Enhancement
Description
Bump urllib3 minimum version to 2.6.0
Addresses security vulnerability in urllib3 2.5.0
Updates lock file with new urllib3 hashes
Diagram Walkthrough
File Walkthrough
pyproject.toml
Update urllib3 minimum version constraintpy/pyproject.toml
requirements.txt
Pin urllib3 to 2.6.0 versionpy/requirements.txt
requirements_lock.txt
Update urllib3 lock file with new hashespy/requirements_lock.txt