From 6305f317cad5c436ccf6143e45b1768af62c3c0f Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 13 Apr 2026 09:39:43 +0000 Subject: [PATCH] Bump urllib3 from 1.24.0 to 2.6.3 Bumps [urllib3](https://github.com/urllib3/urllib3) from 1.24.0 to 2.6.3. - [Release notes](https://github.com/urllib3/urllib3/releases) - [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst) - [Commits](https://github.com/urllib3/urllib3/compare/1.24...2.6.3) --- updated-dependencies: - dependency-name: urllib3 dependency-version: 2.6.3 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] --- requirements.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/requirements.txt b/requirements.txt index 6f52ae3..82cdb91 100644 --- a/requirements.txt +++ b/requirements.txt @@ -1,7 +1,7 @@ # INTENTIONALLY VULNERABLE PYTHON PACKAGES Django==2.2.0 requests==2.20.0 -urllib3==1.24.0 +urllib3==2.6.3 Pillow==6.0.0 cryptography==2.8 PyYAML==5.1