Skip to content

Conversation

@danielfcollier
Copy link

@danielfcollier danielfcollier commented Oct 14, 2025

Summary

The httpcore subdependency h11 has a security fix for the critical security issue that requires the minimum version 1.0.9.

References:

Checklist

  • I understand that this PR may be closed in case there was no previous discussion. (This doesn't apply to typos!)
  • I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change.
  • I've updated the documentation accordingly.

@davidrogger
Copy link

Nice work!

@lovelydinosaur
Copy link
Contributor

Duplicate of #3560

@BryceLohr
Copy link

Duplicate of #3560

I'm trying to understand what this means: are you saying that httpx will not update its dependency to resolve this security issue? Or am I misunderstanding this?

@zanieb
Copy link
Contributor

zanieb commented Oct 16, 2025

Yes there's no need to change the minimum required version for users to receive the security fix as was discussed at length in #3564 (comment)

@zanieb zanieb closed this Oct 16, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants