Skip to content

Bump requests from 2.32.5 to 2.33.0#210

Merged
gwharris7 merged 4 commits into
mainfrom
dependabot/uv/requests-2.33.0
May 14, 2026
Merged

Bump requests from 2.32.5 to 2.33.0#210
gwharris7 merged 4 commits into
mainfrom
dependabot/uv/requests-2.33.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Mar 26, 2026

Copy link
Copy Markdown
Contributor

Bumps requests from 2.32.5 to 2.33.0.

Release notes

Sourced from requests's releases.

v2.33.0

2.33.0 (2026-03-25)

Announcements

  • 📣 Requests is adding inline types. If you have a typed code base that uses Requests, please take a look at #7271. Give it a try, and report any gaps or feedback you may have in the issue. 📣

Security

  • CVE-2026-25645 requests.utils.extract_zipped_paths now extracts contents to a non-deterministic location to prevent malicious file replacement. This does not affect default usage of Requests, only applications calling the utility function directly.

Improvements

  • Migrated to a PEP 517 build system using setuptools. (#7012)

Bugfixes

  • Fixed an issue where an empty netrc entry could cause malformed authentication to be applied to Requests on Python 3.11+. (#7205)

Deprecations

  • Dropped support for Python 3.9 following its end of support. (#7196)

Documentation

  • Various typo fixes and doc improvements.

New Contributors

Full Changelog: https://github.com/psf/requests/blob/main/HISTORY.md#2330-2026-03-25

Changelog

Sourced from requests's changelog.

2.33.0 (2026-03-25)

Announcements

  • 📣 Requests is adding inline types. If you have a typed code base that uses Requests, please take a look at #7271. Give it a try, and report any gaps or feedback you may have in the issue. 📣

Security

  • CVE-2026-25645 requests.utils.extract_zipped_paths now extracts contents to a non-deterministic location to prevent malicious file replacement. This does not affect default usage of Requests, only applications calling the utility function directly.

Improvements

  • Migrated to a PEP 517 build system using setuptools. (#7012)

Bugfixes

  • Fixed an issue where an empty netrc entry could cause malformed authentication to be applied to Requests on Python 3.11+. (#7205)

Deprecations

  • Dropped support for Python 3.9 following its end of support. (#7196)

Documentation

  • Various typo fixes and doc improvements.
Commits
  • bc04dfd v2.33.0
  • 66d21cb Merge commit from fork
  • 8b9bc8f Move badges to top of README (#7293)
  • e331a28 Remove unused extraction call (#7292)
  • 753fd08 docs: fix FAQ grammar in httplib2 example
  • 774a0b8 docs(socks): same block as other sections
  • 9c72a41 Bump github/codeql-action from 4.33.0 to 4.34.1
  • ebf7190 Bump github/codeql-action from 4.32.0 to 4.33.0
  • 0e4ae38 docs: exclude Response.is_permanent_redirect from API docs (#7244)
  • d568f47 docs: clarify Quickstart POST example (#6960)
  • Additional commits viewable in compare view

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Mar 26, 2026
@dependabot dependabot Bot requested a review from a team as a code owner March 26, 2026 17:03
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Mar 26, 2026
@github-actions

github-actions Bot commented Mar 26, 2026

Copy link
Copy Markdown

⚠️ Deprecation Warning: The deny-licenses option is deprecated for possible removal in the next major release. For more information, see issue 997.

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
pip/requests 2.33.0 UnknownUnknown

Scanned Files

  • uv.lock

@dependabot dependabot Bot force-pushed the dependabot/uv/requests-2.33.0 branch 2 times, most recently from cb26e81 to c8bc7b0 Compare March 30, 2026 18:23
Bumps [requests](https://github.com/psf/requests) from 2.32.5 to 2.33.0.
- [Release notes](https://github.com/psf/requests/releases)
- [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md)
- [Commits](psf/requests@v2.32.5...v2.33.0)

---
updated-dependencies:
- dependency-name: requests
  dependency-version: 2.33.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/uv/requests-2.33.0 branch from c8bc7b0 to 16d496c Compare April 1, 2026 20:37
@gwharris7 gwharris7 enabled auto-merge (squash) April 13, 2026 18:57
gwharris7 pushed a commit that referenced this pull request Apr 13, 2026
* Initial plan

* Add BaggageMiddleware, OutputLoggingMiddleware, and ObservabilityHostingManager

Implement Python equivalents of the Node.js PR #210 middleware:
- BaggageMiddleware: propagates OpenTelemetry baggage from TurnContext
- OutputLoggingMiddleware: creates OutputScope spans for outgoing messages
- ObservabilityHostingManager: singleton to configure hosting middleware
- 19 unit tests covering all three middleware components

Co-authored-by: nikhilNava <211831449+nikhilNava@users.noreply.github.com>

* Update ObservabilityHostingManager.configure to use ChannelAdapter type and require non-None params

- Replace _AdapterLike protocol with actual ChannelAdapter from microsoft_agents.hosting.core
- Make adapter and options required (non-optional) parameters
- Raise TypeError if either is None
- Update tests to match new contract

Co-authored-by: nikhilNava <211831449+nikhilNava@users.noreply.github.com>

* Use MiddlewareSet type for adapter and Activity helper methods instead of direct attribute access

- Change adapter param type from ChannelAdapter to MiddlewareSet (the actual
  middleware registration object)
- Use activity.get_agentic_instance_id() instead of recipient.agentic_app_id
- Use activity.get_agentic_user() instead of recipient.agentic_user_id
- Update test to use agentic role for proper helper method behavior

Co-authored-by: nikhilNava <211831449+nikhilNava@users.noreply.github.com>

* Fix ObservabilityHostingManager.configure to accept MiddlewareSet instead of ChannelAdapter

ChannelAdapter is an ABC (CloudAdapter extends ChannelServiceAdapter extends
ChannelAdapter). The adapter HAS-A MiddlewareSet (composition) — it is not one.
The configure() method only needs the middleware registration object, so accept
MiddlewareSet directly. Users pass adapter.middleware_set.

Rename parameter from 'adapter' to 'middleware_set' for clarity.

Co-authored-by: nikhilNava <211831449+nikhilNava@users.noreply.github.com>

* Address review comments: fix logic callback type, gate on is_agentic_request

- Fix `logic` type annotation from `Callable[[TurnContext], Awaitable]` to
  `Callable[[], Awaitable]` in both BaggageMiddleware and
  OutputLoggingMiddleware. At runtime, MiddlewareSet passes a zero-arg
  `call_next_middleware` closure, so the annotation now matches the callsite.

- Gate `_derive_agent_details` on `activity.is_agentic_request()` to avoid
  emitting spans with empty agent_id for non-agentic requests.

- Remove unused `logging`/`logger` from baggage_middleware.py.

- Update test recipient role from "assistant" to "agenticAppInstance" to
  exercise the intended agentic code path.

Co-authored-by: nikhilNava <211831449+nikhilNava@users.noreply.github.com>

* Revert logic type to Callable[[TurnContext], Awaitable] to match Middleware Protocol; consolidate tests

Co-authored-by: nikhilNava <211831449+nikhilNava@users.noreply.github.com>

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: nikhilNava <211831449+nikhilNava@users.noreply.github.com>
Co-authored-by: Nikhil Navakiran <nikhil.navakiran@gmail.com>
Copilot AI review requested due to automatic review settings May 14, 2026 22:19

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.

@gwharris7 gwharris7 merged commit 42e1670 into main May 14, 2026
9 checks passed
@gwharris7 gwharris7 deleted the dependabot/uv/requests-2.33.0 branch May 14, 2026 22:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants