Skip to content

Commit e604ea1

Browse files
authored
Update urllib3 to 2.6.3+ (#136)
This dependency update adds decompression-bomb safeguards to HTTP redirects. See CVE-2026-21441. https://nvd.nist.gov/vuln/detail/CVE-2026-21441
1 parent 1de06de commit e604ea1

2 files changed

Lines changed: 4 additions & 2 deletions

File tree

.github/workflows/pr_checks.yml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -29,6 +29,7 @@ jobs:
2929
run-spelling-check: true,
3030
run-complexity: false,
3131
run-doxygen: false,
32+
exclude-urls: 'https://www.microchip.com, https://www.microchip.com/support',
3233
},
3334
{
3435
repository: FreeRTOS-Plus-TCP,
@@ -39,6 +40,7 @@ jobs:
3940
run-complexity: false,
4041
run-doxygen: false,
4142
exclude-dirs: 'source/portable/NetworkInterface/STM32'
43+
exclude-urls: 'https://www.microchip.com/en-us/support/design-help, http://www.atmel.com/design-support'
4244
},
4345
{
4446
repository: FreeRTOS,
@@ -209,7 +211,7 @@ jobs:
209211
with:
210212
path: repo/${{ matrix.inputs.repository }}
211213
exclude-dirs: complexity, formatting
212-
exclude-urls: https://dummy-url.com/ota.bin, https://s3.region.amazonaws.com/joe-ota, https://www.gnu.org/software/complexity/manual/complexity.html, https://www.u-blox.com/en/product/sara-r4-series
214+
exclude-urls: https://dummy-url.com/ota.bin, https://s3.region.amazonaws.com/joe-ota, https://www.gnu.org/software/complexity/manual/complexity.html, https://www.u-blox.com/en/product/sara-r4-series${{ matrix.inputs.exclude-urls && format(',{0}', matrix.inputs.exclude-urls) || '' }}
213215

214216
- name: "Complexity Check: ${{ matrix.inputs.repository }}"
215217
if: matrix.inputs.run-complexity && ( success() || failure() )

link-verifier/requirements.txt

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,4 +6,4 @@ idna==3.7
66
requests==2.32.4
77
soupsieve==2.1
88
termcolor==1.1.0
9-
urllib3>=2.6.0
9+
urllib3>=2.6.3

0 commit comments

Comments
 (0)