Update dependency urllib3 to v2.8.0 [SECURITY] (#64995)
This PR contains the following updates:
| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [urllib3](https://redirect.github.com/urllib3/urllib3)
([changelog](https://redirect.github.com/urllib3/urllib3/blob/main/CHANGES.rst))
| `2.7.0` → `2.8.0` |

|

|
---
> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/15138) for more information.
---
### urllib3: HTTPS proxy TLS configuration may be ignored or overridden
[CVE-2026-97687](https://nvd.nist.gov/vuln/detail/CVE-2026-97687) /
[GHSA-8988-9cw3-xx77](https://redirect.github.com/advisories/GHSA-8988-9cw3-xx77)
<details>
<summary>More information</summary>
#### Details
##### Impact
urllib3 supports configuring TLS independently for an HTTPS proxy and
the target server.
`proxy_ssl_context`, `proxy_assert_hostname`, and
`proxy_assert_fingerprint` configure the TLS connection to the proxy.
`ssl_context` and the other target-specific TLS parameters configure the
connection to the target server.
In urllib3 versions 1.26.0 through 2.7.0, these configurations were not
consistently separated. Depending on the proxy mode, urllib3 could:
1. Ignore `proxy_ssl_context` and use the target server's SSL context
for the TLS connection to an HTTPS forwarding proxy.
2. Override the HTTPS proxy's certificate-verification policy with the
target server's certificate-verification policy.
3. Apply target-specific SNI, hostname assertions, certificate
fingerprint assertions, or TLS client credentials to the TLS connection
to an HTTPS forwarding proxy.
In particular, configuring `cert_reqs="CERT_NONE"` for a target server
could overwrite the `verify_mode` of the SSL context configured for the
HTTPS proxy. This modification occurred in place and persisted on the
context object, potentially disabling proxy certificate verification for
later connections that reused the same context.
An attacker able to intercept the connection to an HTTPS proxy may be
able to impersonate the proxy when the effective proxy TLS configuration
disables certificate verification or otherwise accepts the attacker's
certificate. This may occur, for example, when the target server's trust
or identity policy is incorrectly applied to the proxy connection.
When HTTPS forwarding is enabled, an impersonated proxy can observe or
modify forwarded requests and responses, potentially exposing
credentials, authentication tokens, request bodies, response data, and
other sensitive information.
A TLS client certificate intended for the target server may also be
presented to the proxy or to an attacker impersonating it. This can
disclose the client's identity and provide proof of possession of the
corresponding private key. The private key itself is not transmitted
during the TLS handshake.
In CONNECT tunneling mode, impersonating the HTTPS proxy does not by
itself defeat the separate end-to-end TLS connection between the client
and the target server.
##### Affected Usages
Code using urllib3 versions 1.26.0 through 2.7.0 may be affected in any
of the following cases.
##### 1. The target SSL context is used for an HTTPS forwarding proxy
HTTPS requests are forwarded through an HTTPS proxy with
`use_forwarding_for_https=True`, and `proxy_ssl_context` is configured
for the proxy.
urllib3 may ignore `proxy_ssl_context` and use the target server's
`ssl_context` for the proxy TLS handshake. The proxy may therefore be
verified using the target server's trust and certificate policy instead
of the policy explicitly configured for the proxy.
##### 2. The target verification policy overrides the proxy policy
An HTTPS proxy is configured with `proxy_ssl_context`, while the target
server uses a different certificate-verification policy.
urllib3 may apply the target server's `cert_reqs` value to the proxy SSL
context. For example, setting `cert_reqs="CERT_NONE"` for the target
server may also disable certificate verification for the HTTPS proxy,
even when `proxy_ssl_context` was configured to require verification.
This issue can affect the TLS connection to an HTTPS proxy in both
forwarding and CONNECT tunneling configurations.
##### 3. A mutated proxy SSL context is reused
The same SSL context is reused as `proxy_ssl_context` across multiple
connections, and certificate verification is disabled for one target
server.
urllib3 may modify the proxy SSL context's `verify_mode` in place. Later
connections that reuse the same context may therefore connect to the
HTTPS proxy without certificate verification.
##### 4. Target-specific TLS identity or credentials are applied to the
proxy
HTTPS requests are forwarded through an HTTPS proxy with
`use_forwarding_for_https=True`, and target-specific SNI, hostname
assertions, certificate fingerprint assertions, or TLS client
credentials are configured.
urllib3 may apply these target-specific settings to the proxy TLS
handshake. This may cause urllib3 to:
- send SNI intended for the target server to the proxy;
- verify the proxy using a hostname or certificate fingerprint intended
for the target server; or
- present a TLS client certificate intended for the target server to the
proxy.
Code connecting through a plain HTTP proxy does not establish a TLS
connection to the proxy and is not affected by this issue.
##### Remediation
Upgrade to urllib3 2.8.0 or later.
urllib3 2.8.0 independently applies the explicitly configured
`proxy_ssl_context` and proxy-specific certificate assertions to the
HTTPS proxy connection. Target-specific SNI, certificate assertions, and
TLS client certificate parameters are no longer applied to the HTTPS
proxy handshake.
For backward compatibility, when an HTTPS proxy is used with
`use_forwarding_for_https=True` and `proxy_ssl_context` is not provided,
urllib3 2.8.0 continues to use `ssl_context` for the TLS connection to
the proxy. This configuration emits a `FutureWarning`. In urllib3 3.0,
passing `ssl_context` with `use_forwarding_for_https=True` for an HTTPS
proxy will raise an error. Applications should use `proxy_ssl_context`
to configure TLS for an HTTPS forwarding proxy.
The fixes were implemented in commits
b6447295fff7b38fdffc67e0df9712d60cef3cc3 and
07408cec79d1856d81bb42c74a904a24fdb9e465.
#### Severity
- CVSS Score: 7.6 / 10 (High)
- Vector String:
`CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N`
#### References
-
[https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77](https://redirect.github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77)
-
[https://nvd.nist.gov/vuln/detail/CVE-2026-97687](https://nvd.nist.gov/vuln/detail/CVE-2026-97687)
-
[https://github.com/urllib3/urllib3/pull/5093](https://redirect.github.com/urllib3/urllib3/pull/5093)
-
[https://github.com/urllib3/urllib3/commit/07408cec79d1856d81bb42c74a904a24fdb9e465](https://redirect.github.com/urllib3/urllib3/commit/07408cec79d1856d81bb42c74a904a24fdb9e465)
-
[https://github.com/urllib3/urllib3/commit/b6447295fff7b38fdffc67e0df9712d60cef3cc3](https://redirect.github.com/urllib3/urllib3/commit/b6447295fff7b38fdffc67e0df9712d60cef3cc3)
-
[https://github.com/urllib3/urllib3/releases/tag/2.8.0](https://redirect.github.com/urllib3/urllib3/releases/tag/2.8.0)
-
[https://github.com/advisories/GHSA-8988-9cw3-xx77](https://redirect.github.com/advisories/GHSA-8988-9cw3-xx77)
This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-8988-9cw3-xx77)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>
---
### urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded
chunk-size line into memory
[CVE-2026-97689](https://nvd.nist.gov/vuln/detail/CVE-2026-97689) /
[GHSA-vxq7-64xx-v4gw](https://redirect.github.com/advisories/GHSA-vxq7-64xx-v4gw)
<details>
<summary>More information</summary>
#### Details
##### Impact
urllib3's [streaming
API](https://urllib3.readthedocs.io/en/2.7.0/advanced-usage.html#streaming-and-i-o)
is designed for efficiently handling large HTTP responses by reading the
content in chunks, rather than loading the entire response body into
memory at once. When decoding a [chunked-transfer-encoded
response](https://httpwg.org/specs/rfc9112.html#chunked.encoding), this
API reads each chunk's size field by buffering until it sees `\n` or
EOF.
A malicious HTTP server can return `Transfer-Encoding: chunked` and then
send a very long run of bytes without any newline, causing the streaming
client to buffer that entire run before urllib3 can reject the chunk
size as invalid and allocate more memory than intended.
To fix the issue, we'll reject chunk-size fields larger than 65536
bytes, as already done in the non-streaming case, which is currently
handled by the Python standard library. Note that this only applies to
reading the chunk-size field, not the chunk data, which is already
handled correctly. Thus, there shouldn't be any impact for non-malicious
servers.
##### Affected usages
Applications and libraries using urllib3 versions earlier than 2.8.0 may
be affected when streaming a chunked response from untrusted sources.
Specifically, this affects the
[read_chunked()](https://urllib3.readthedocs.io/en/stable/reference/urllib3.response.html#urllib3.response.BaseHTTPResponse.read_chunked)
and
[stream()](https://urllib3.readthedocs.io/en/stable/reference/urllib3.response.html#urllib3.response.BaseHTTPResponse.stream)
methods of the HTTPResponse object.
This also affects requests streaming API, which uses urllib3 under the
hood.
##### Remediation
Upgrade to urllib3 version 2.8.0 or later, where chunk-size fields
larger than 65536 will be rejected. If upgrading is not immediately
possible, consider reading the response at once using the
[read()](https://urllib3.readthedocs.io/en/stable/reference/urllib3.response.html#urllib3.response.BaseHTTPResponse.read)
method.
#### Severity
- CVSS Score: 8.9 / 10 (High)
- Vector String:
`CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H`
#### References
-
[https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw](https://redirect.github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw)
-
[https://nvd.nist.gov/vuln/detail/CVE-2026-97689](https://nvd.nist.gov/vuln/detail/CVE-2026-97689)
-
[https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed](https://redirect.github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed)
-
[https://github.com/urllib3/urllib3/releases/tag/2.8.0](https://redirect.github.com/urllib3/urllib3/releases/tag/2.8.0)
-
[https://github.com/advisories/GHSA-vxq7-64xx-v4gw](https://redirect.github.com/advisories/GHSA-vxq7-64xx-v4gw)
This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-vxq7-64xx-v4gw)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>
---
### urllib3: Chunked Deflate streaming can enter an infinite loop
[CVE-2026-97688](https://nvd.nist.gov/vuln/detail/CVE-2026-97688) /
[GHSA-gh4c-6fx4-qh6g](https://redirect.github.com/advisories/GHSA-gh4c-6fx4-qh6g)
<details>
<summary>More information</summary>
#### Details
##### Impact
urllib3's streaming API is designed for the efficient handling of large
HTTP responses by reading content in chunks instead of loading the
entire response body into memory at once.
urllib3 can decompress response bodies according to the HTTP
`Content-Encoding` header. When streaming a compressed, chunked
response, urllib3 first consumes data already buffered by the decoder
before reading the next HTTP chunk.
However, urllib3 versions from 2.6.2 through 2.7.0 could enter an
infinite loop when a chunked response contained bytes after the end of
the Deflate stream. If the decompressed body exceeded the requested
streaming chunk size, Python's zlib implementation could retain the
trailing bytes as unconsumed input after reaching the end of the
compressed stream. urllib3 would repeatedly attempt to decode those same
bytes without making progress or reading more data from the network.
A malicious server could exploit this behavior to cause excessive CPU
usage and prevent the affected request from completing on the client.
Network read timeouts would not interrupt the loop because no further
socket operation was required.
##### Affected usages
Applications and libraries using urllib3 versions 2.6.2 through 2.7.0
may be affected when all of the following conditions are met:
1. Compressed responses from an untrusted source are streamed using
`HTTPResponse.stream(amt=N)` or `HTTPResponse.read_chunked(amt=N)` with
a positive, finite chunk size.
2. Content decoding is enabled.
3. The response uses both `Transfer-Encoding: chunked` and
`Content-Encoding: deflate`.
4. The decoded body exceeds the requested chunk size and the encoded
body contains bytes after the end of the Deflate stream.
`HTTPResponse.stream()` uses a finite chunk size by default and is
therefore affected when the other conditions are met.
##### Remediation
Upgrade to urllib3 2.8.0, in which the Deflate decoder stops accepting
input after reaching the end of the compressed stream and no longer
reports trailing bytes as data that can produce more decoded output.
If upgrading is not immediately possible, disable automatic content
decoding for responses from untrusted sources by setting
`decode_content=False`, or reject streamed responses using the Deflate
content encoding. Applications that disable automatic decoding must
handle the compressed response safely at another layer.
#### Severity
- CVSS Score: 6.9 / 10 (Medium)
- Vector String:
`CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N`
#### References
-
[https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g](https://redirect.github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g)
-
[https://nvd.nist.gov/vuln/detail/CVE-2026-97688](https://nvd.nist.gov/vuln/detail/CVE-2026-97688)
-
[https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f](https://redirect.github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f)
-
[https://github.com/urllib3/urllib3/releases/tag/2.8.0](https://redirect.github.com/urllib3/urllib3/releases/tag/2.8.0)
-
[https://github.com/advisories/GHSA-gh4c-6fx4-qh6g](https://redirect.github.com/advisories/GHSA-gh4c-6fx4-qh6g)
This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-gh4c-6fx4-qh6g)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>
---
### Release Notes
<details>
<summary>urllib3/urllib3 (urllib3)</summary>
###
[`v2.8.0`](https://redirect.github.com/urllib3/urllib3/blob/HEAD/CHANGES.rst#280-2026-09-15)
[Compare
Source](https://redirect.github.com/urllib3/urllib3/compare/2.7.0...2.8.0)
\==================
## Security
Fixed the following security issues:
- The TLS configuration for HTTPS proxies could be ignored or
overridden.
(High severity, `GHSA-8988-9cw3-xx77
<https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77>`\_\_)
- `HTTPResponse.stream()` and `read_chunked()` could buffer a chunk-size
line of unbounded length in memory. (High severity,
`GHSA-vxq7-64xx-v4gw
<https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw>`\_\_)
- Chunked Deflate streaming could enter an infinite loop. (Medium
severity,
`GHSA-gh4c-6fx4-qh6g
<https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g>`\_\_)
.. caution::
```
urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.
Configure proxy CA certificates and client certificates in
``proxy_ssl_context``, and proxy identity checks with
``proxy_assert_hostname`` or ``proxy_assert_fingerprint``.
Destination client certificates and identity overrides no longer
apply to HTTPS forwarding proxy connections.
```
## Deprecations & Removals
- Deprecated using an empty collection as the `Retry` option
`allowed_methods` to retry any verb.
(`#​5044 <https://github.com/urllib3/urllib3/issues/5044>`\_\_)
## Features
- Added `Url.auth_decoded` and `Url.auth_decoded_joined` convenience
properties to the result of `parse_url()`.
(`#​4945 <https://github.com/urllib3/urllib3/issues/4945>`\_\_)
- Added `basic_auth_encoding` and `proxy_basic_auth_encoding` parameters
to
`urllib3.util.make_headers()`.
(`#​5092 <https://github.com/urllib3/urllib3/issues/5092>`\_\_)
## Bugfixes
- Fixed response header handling to replace obsolete folded header lines
(`obs-fold`) with spaces in accordance with RFC 9112, preventing raw
CRLF
sequences from appearing in header values such as `Set-Cookie`.
(`#​1362 <https://github.com/urllib3/urllib3/issues/1362>`\_\_)
- Fixed usage of `proxy_ssl_context` with `ProxyManager` when
`use_forwarding_for_https=True`. Passing `ssl_context` instead of
`proxy_ssl_context` for HTTPS proxies in this configuration now emits a
`FutureWarning` and will raise an error in v3.0.
(`#​2577 <https://github.com/urllib3/urllib3/issues/2577>`\_\_)
- Changed behavior of the default `ConnectionPool.pool` initialization.
`LifoQueue` is now resolved from the `queue` module after the
`ConnectionPool` is instantiated instead of using the default cached
`QueueCls` class property. This is done because sometimes the
`queue.LifoQueue` is monkey-patched late in the program, such as by
gevent.
(`#​3289 <https://github.com/urllib3/urllib3/issues/3289>`\_\_)
- Raised `UnrewindableBodyError` instead of `ValueError` when retrying a
request whose body had `tell()` but not `seek()`.
(`#​3779 <https://github.com/urllib3/urllib3/issues/3779>`\_\_)
- Decoded percent-encoded SOCKS proxy credentials before authenticating
with
the proxy server.
(`#​3785 <https://github.com/urllib3/urllib3/issues/3785>`\_\_)
- Fixed `HTTPResponse.drain_conn()` to discard unread response data in
64 KiB
chunks (same as the default `amt` when doing
`HTTPResponse.stream(...)`).
(`#​5019 <https://github.com/urllib3/urllib3/issues/5019>`\_\_)
- Fixed `is_ipaddress()` to detect non-standard IPv4 forms accepted by
`socket.connect`, such as hex (`0x7f000001`), octal (`0177.0.0.1`), and
decimal integers (`2130706433`), ensuring SSL certificate verification
uses
the correct mode for these addresses.
(`#​5029 <https://github.com/urllib3/urllib3/issues/5029>`\_\_)
- Fixed `HTTPConnectionPool.urlopen` raising a misleading
`FullPoolError`
instead of `ValueError` when called with an invalid `timeout` argument
on
a pool created with `block=True`.
(`#​5059 <https://github.com/urllib3/urllib3/issues/5059>`\_\_)
- Fixed port-zero handling to preserve explicit `:0` values instead of
substituting the default ports 80 or 443 in URL parsing, pool selection,
proxy configuration, `connection_from_url()`, and HTTP/2 request
authority.
(`#​5071 <https://github.com/urllib3/urllib3/issues/5071>`**,
`#​5101 <https://github.com/urllib3/urllib3/issues/5101>`**)
- Fixed a bug where `PoolManager` passed the `assert_hostname` and
`assert_fingerprint` parameters to HTTP connection pools.
(`#​5077 <https://github.com/urllib3/urllib3/issues/5077>`\_\_)
- Fixed `HTTPConnectionPool.urlopen()` and HTTP proxy forwarding to
strip URL
fragments from absolute request targets before sending requests.
(`#​5079 <https://github.com/urllib3/urllib3/issues/5079>`\_\_)
- Added safeguards to the proxy tunneling code to prevent potential
security
issues when handling invalid characters in the proxy host and HTTP
headers.
This change affects users of Python 3.10, Python 3.11, and Python 3.12
when
the standard library does not contain the fix; those on newer Python
versions
should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes.
(`#​5091 <https://github.com/urllib3/urllib3/issues/5091>`\_\_)
- Fixed `HTTPSConnection.connect()` overriding
`ProxyConfig.ssl_context`'s
certificate policy and proxy identity checks with the target
connection's TLS
settings when forwarding through an HTTPS proxy.
`HTTPSConnection` no longer applies target SNI, assertions, or client
credentials to forwarding proxy handshakes and continues to use its
`ssl_context` as a fallback when an HTTPS proxy forwards an HTTP target.
(`#​5093 <https://github.com/urllib3/urllib3/issues/5093>`\_\_)
- Fixed URL parsing to more strictly enforce RFC 3986 host syntax,
rejecting
invalid host input such as raw spaces and control characters, malformed
percent-encodings, and percent-encoded control characters in HTTP(S)
hosts
and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host
normalization now also follows RFC 3986 normalization rules for
percent-encoded octets by decoding percent-encoded unreserved characters
and
uppercasing the hexadecimal digits of retained percent-encoded octets.
(`#​5095 <https://github.com/urllib3/urllib3/issues/5095>`\_\_)
- Fixed an `AttributeError` on Python built with OpenSSL 4+, where
`ssl.PROTOCOL_TLSv1` no longer exists.
(`#​5097 <https://github.com/urllib3/urllib3/issues/5097>`\_\_)
- Fixed `urllib3.contrib.pyopenssl` to use cryptography APIs when
reading a
certificate subject and loading encrypted private keys, avoiding
`DeprecationWarning` raised by pyOpenSSL 26.3.0+.
(`#​5103 <https://github.com/urllib3/urllib3/issues/5103>`\_\_)
- Fixed handling of HTTP 303 redirects for requests with chunked or
file-like
bodies.
(`#​5161 <https://github.com/urllib3/urllib3/issues/5161>`\_\_)
- Fixed `assert_fingerprint()` to raise `SSLError` instead of
`binascii.Error` when a fingerprint has a supported length but contains
non-hexadecimal characters.
(`#​5211 <https://github.com/urllib3/urllib3/issues/5211>`\_\_)
## Misc
- Added a `test` dependency group containing the minimum dependencies
needed
to run the test suite, intended for downstream packagers. The `dev-base`
and `mypy` groups now include this new group via `include-group`,
removing duplication.
(`#​3594 <https://github.com/urllib3/urllib3/issues/3594>`\_\_)
- Fixed test failures with pytest >= 9.1.
(`#​5094 <https://github.com/urllib3/urllib3/issues/5094>`\_\_)
- Enabled JSPI tests with Firefox in the Emscripten test suite.
(`#​5166 <https://github.com/urllib3/urllib3/issues/5166>`\_\_)
- Improved streamed response decoding performance.
(`#​5209 <https://github.com/urllib3/urllib3/issues/5209>`\_\_)
- Fixed flaky tests.
(`#​5232 <https://github.com/urllib3/urllib3/issues/5232>`**,
`#​5234 <https://github.com/urllib3/urllib3/issues/5234>`**,
`#​5239 <https://github.com/urllib3/urllib3/issues/5239>`\_\_)
</details>
---
### Configuration
📅 **Schedule**: (in timezone America/New_York)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box
---
Release Notes:
- N/A
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMjUuMSIsInVwZGF0ZWRJblZlciI6IjQ0LjEyNS4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
ba2b48461drenovate[bot] committed on 10/2/2026, 7:57:16 AM· committed by GitHubparent35bba8e