Skip to content

[feature] Allow newer versions of urllib #18767

@marlamb

Description

@marlamb

What is your suggestion?

Hi,
in order to use conan in environments that are strict with regard to security concerns it would be great to have a less restrictive bound on the urllib, which is currently bound to < 2.1, but CVE-2024-37891 exists for versions smaller than 2.2.2.
I will create a pull request expanding the allowed range of versions a little, but I don't know how you evaluate that all versions within that range work as expected and would appreciate your help to allow for newer versions.
Thanks in advance!

Have you read the CONTRIBUTING guide?

  • I've read the CONTRIBUTING guide

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions