Bump urllib3 from 2.7.0 to 2.8.0 - #1072
Conversation
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Repository: NVIDIA/cloudai/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
|
@dependabot rebase |
Bumps [urllib3](https://github.com/urllib3/urllib3) from 2.7.0 to 2.8.0. - [Release notes](https://github.com/urllib3/urllib3/releases) - [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst) - [Commits](urllib3/urllib3@2.7.0...2.8.0) --- updated-dependencies: - dependency-name: urllib3 dependency-version: 2.8.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
e07d112 to
094833b
Compare
podkidyshev
left a comment
There was a problem hiding this comment.
Reviewed actual CloudAI usage and verified compatibility of urllib3 2.8.0, revising the initial conservative hold based on upstream release notes.
Usage: no direct urllib3 imports in CloudAI. The only direct parents in uv.lock are Requests 2.33.0 (RunAI REST, Slurm REST, NeMo HttpDataRepository) and Kubernetes SDK 35.0.0. Hugging Face downloads use HTTPX, which does not use urllib3. Both parent requirements accept 2.8.0.
The clients use default CONNECT tunneling for HTTPS destinations; neither Requests nor the Kubernetes SDK enables use_forwarding_for_https. CloudAI does not configure proxy_ssl_context, proxy hostname/fingerprint overrides, custom HTTPAdapters, urllib3 Retry allowed_methods, gevent queue monkey patches, or unseekable retry bodies. The HTTPS-forwarding proxy migration warning therefore does not imply a CloudAI regression. Invalid-host rejection is security hardening; no such hostnames are constructed by CloudAI.
Validation on the rebased tree: 235 focused tests passed on Python 3.14 and again on Python 3.10. Actual CloudAI clients were exercised against local HTTP/HTTPS endpoints, HTTP/HTTPS proxies, and Kubernetes mutual-TLS endpoints: 27 client/scenario combinations passed with each of urllib3 2.7.0 and 2.8.0 on both Python 3.10 and 3.14 (108 successful calls/combinations). Pre-commit checks for uv.lock passed. The published Dependabot tree matches the tested tree; fresh CI will be checked before merging.
Provenance: release artifact URLs and SHA-256 hashes match PyPI; the release is not yanked and PyPI reports no advisories affecting this version. PyPI publisher provenance identifies urllib3/urllib3 publish.yml. All 35 non-generated wheel Python files match the official release tag; the sole generated version module contains only version metadata. No evidence of compromise found. The version also fixes three upstream security advisories. This validation covers CloudAI's own clients and ordinary configurations, not arbitrary external custom adapters or integrations.
Bumps urllib3 from 2.7.0 to 2.8.0.
Release notes
Sourced from urllib3's releases.
... (truncated)
Changelog
Sourced from urllib3's changelog.
... (truncated)
Commits
b1d30abRelease 2.8.09016d7eSkiptest_read_chunked_with_trailing_data_does_not_hangfor brotlicffi (#5258)9101f58Fixnox -s docswarning (#5256)cd770b0Merge commit from forkea2ad7bMerge commit from fork0716e31Fix loading unencrypted client keys with a password in pyOpenSSL (#5255)43c68c8Test pickling ofInvalidChunkLength(#5247)308b279Share security policy between GitHub and Read the Docs (#5253)53fa073Add policy on duplicate pull requests (#5252)5f2a6a8Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (#5232)