Files
Martin Vogel 3f99b2ddd3 build(pypi): bump urllib3 to 2.8.0 in the publish toolchain pins
urllib3 2.7.0, pinned in pkg/pypi/requirements-publish.txt for the
PyPI publish step, is affected by three advisories published on
2026-09-30, all fixed in 2.8.0:
- GHSA-8988-9cw3-xx77 (high): HTTPS proxy TLS configuration may be
  ignored or overridden
- GHSA-vxq7-64xx-v4gw (high): unbounded chunk-size line buffering in
  HTTPResponse.stream() / read_chunked()
- GHSA-gh4c-6fx4-qh6g (medium): chunked deflate streaming can loop
  forever

OSSF Scorecard reports them as code-scanning alert #33
(VulnerabilitiesID), which the CodeQL gate counts as an open alert,
so every PR's gate is blocked until the pin moves.

Only urllib3 changes. The file was regenerated with the documented
recipe (pip-compile 7.5.1 on a linux/amd64 python:3.12 image) in
upgrade-only mode (--upgrade-package urllib3==2.8.0), so every other
pin and hash is byte-identical. Both new hashes match PyPI's published
digests for urllib3-2.8.0-py3-none-any.whl and urllib3-2.8.0.tar.gz.

Proof: `pip install --require-hashes --no-deps -r
requirements-publish.txt` on linux/amd64 python:3.12 installs the full
set with every hash verified, imports urllib3 2.8.0, twine and build,
and `pip check` reports no broken requirements.

Signed-off-by: Martin Vogel <martin.vogel.tech@gmail.com>
2026-09-30 22:55:43 +02:00
..