Skip to content

Conversation

@mend-for-github-com
Copy link
Contributor

This PR contains the following updates:

Package Update Change
httpcore major ==0.18.0 -> ==1.0.0

By merging this PR, the issue #58 will be automatically resolved and closed:

Severity CVSS Score Vulnerability
Critical Critical 9.1 CVE-2025-43859

Release Notes

encode/httpcore (httpcore)

v1.0.0

Compare Source

From version 1.0 our async support is now optional, as the package has minimal dependencies by default.

For async support use either pip install 'httpcore[asyncio]' or pip install 'httpcore[trio]'.

The project versioning policy is now explicitly governed by SEMVER. See https://semver.org/.

  • Async support becomes fully optional. (#​809)
  • Add support for Python 3.12. (#​807)

  • If you want to rebase/retry this PR, check this box

@mend-for-github-com mend-for-github-com bot added the security fix Security fix generated by Mend label Oct 9, 2025
@mend-for-github-com mend-for-github-com bot changed the title chore(deps): update dependency httpcore to v1 chore(deps): update dependency httpcore to v1 - autoclosed Oct 9, 2025
@mend-for-github-com mend-for-github-com bot deleted the whitesource-remediate/httpcore-1.x branch October 9, 2025 07:03
@mend-for-github-com mend-for-github-com bot changed the title chore(deps): update dependency httpcore to v1 - autoclosed chore(deps): update dependency httpcore to v1 Oct 9, 2025
@mend-for-github-com mend-for-github-com bot reopened this Oct 9, 2025
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/httpcore-1.x branch from bbfbaa6 to c9c3ad5 Compare October 9, 2025 07:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fix Security fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant