Skip to content

Bump the pip group across 5 directories with 3 updates - #531

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/dot-aitk/requirements/pip-e108685de4
Open

Bump the pip group across 5 directories with 3 updates#531
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/dot-aitk/requirements/pip-e108685de4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 8, 2026

Copy link
Copy Markdown
Contributor

Bumps the pip group with 2 updates in the /.aitk/requirements directory: aiohttp and tornado.
Bumps the pip group with 1 update in the /.aitk/requirements/AMD directory: aiohttp.
Bumps the pip group with 1 update in the /.aitk/requirements/General directory: aiohttp.
Bumps the pip group with 2 updates in the /.aitk/requirements/Intel directory: aiohttp and tornado.
Bumps the pip group with 3 updates in the /meta-llama-Llama-3.1-8B-Instruct/QAIRT directory: aiohttp, tornado and bleach.

Updates aiohttp from 3.14.0 to 3.14.1

Changelog

Sourced from aiohttp's changelog.

3.14.1 (2026-06-07)

Bug fixes

  • Fixed a race condition in :py:class:~aiohttp.TCPConnector where closing the connector while a DNS resolution was in-flight could raise :py:exc:AttributeError instead of :py:exc:~aiohttp.ClientConnectionError -- by :user:goingforstudying-ctrl.

    Related issues and pull requests on GitHub: :issue:12497.

  • Fixed CancelledError not closing a connection -- by :user:aiolibsbot.

    Related issues and pull requests on GitHub: :issue:12795.

  • Tightened up some websocket parser checks -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub: :issue:12817.

  • Fixed :class:~aiohttp.CookieJar dropping the host-only flag of cookies when persisted with :meth:~aiohttp.CookieJar.save and reloaded with :meth:~aiohttp.CookieJar.load, so a cookie set without a Domain attribute is again scoped to the exact host that set it after a reload; the absolute expiration deadline is now persisted as well, so a reloaded cookie keeps its original lifetime instead of being rescheduled from the load time. :meth:~aiohttp.CookieJar.load now replaces the jar contents rather than merging onto prior state, and loaded cookies pass through the same acceptance rules as :meth:~aiohttp.CookieJar.update_cookies, so a cookie for an IP-address host is dropped when loaded into a jar created without unsafe=True -- by :user:bdraco.

    Related issues and pull requests on GitHub: :issue:12824.

  • Scoped :class:~aiohttp.DigestAuthMiddleware credentials to the origin of the first request it handles, so a redirect to a different origin no longer triggers a digest response computed from the configured credentials; a challenge from another origin is only answered when that origin falls within a protection space advertised by the anchor origin through the RFC 7616 domain directive -- by :user:bdraco.

    Related issues and pull requests on GitHub: :issue:12825.

  • Fixed the C HTTP parser not enforcing max_line_size on a request target or response reason phrase that is split across multiple reads; each fragment was checked on its own, so an accumulated line could exceed the limit without raising LineTooLong. The accumulated length is now checked, matching the pure-Python parser -- by :user:bdraco.

    Related issues and pull requests on GitHub:

... (truncated)

Commits
  • 9c35d03 Release v3.14.1 (#12864)
  • 38b956c [PR #12861/59684b5c backport][3.14] Revert "Drop list compression (#12857)" (...
  • 8f31009 [PR #12857/69dff14d backport][3.14] Drop list compression (#12858)
  • dfdfa9d [PR #12830/93a2b1c3 backport][3.14] Bound pipelined request queue per connect...
  • 0e9cedd [PR #12827/ccf218ab backport][3.14] Numeric ipv4 resolver bypass (#12849)
  • a762eda [PR #12831/1ac92dae backport][3.14] Payload close on disconnect (#12843)
  • a329a7a [PR #12824/60b85e98 backport][3.14] Preserve host-only cookie scope across Co...
  • 4f7480e [PR #12828/13b635d7 backport][3.14] Bounded unread compressed drain (#12845)
  • 5ab61bb [PR #12826/36df6c13 backport][3.14] Enforce max_line_size on fragmented reque...
  • 3912667 [3.14] Add test that env proxy auth is scoped to the redirect-selected proxy ...
  • Additional commits viewable in compare view

Updates tornado from 6.5.5 to 6.5.7

Changelog

Sourced from tornado's changelog.

Release notes

.. toctree:: :maxdepth: 2

releases/v6.5.7 releases/v6.5.6 releases/v6.5.5 releases/v6.5.4 releases/v6.5.3 releases/v6.5.2 releases/v6.5.1 releases/v6.5.0 releases/v6.4.2 releases/v6.4.1 releases/v6.4.0 releases/v6.3.3 releases/v6.3.2 releases/v6.3.1 releases/v6.3.0 releases/v6.2.0 releases/v6.1.0 releases/v6.0.4 releases/v6.0.3 releases/v6.0.2 releases/v6.0.1 releases/v6.0.0 releases/v5.1.1 releases/v5.1.0 releases/v5.0.2 releases/v5.0.1 releases/v5.0.0 releases/v4.5.3 releases/v4.5.2 releases/v4.5.1 releases/v4.5.0 releases/v4.4.3 releases/v4.4.2 releases/v4.4.1 releases/v4.4.0 releases/v4.3.0 releases/v4.2.1 releases/v4.2.0 releases/v4.1.0 releases/v4.0.2 releases/v4.0.1 releases/v4.0.0 releases/v3.2.2 releases/v3.2.1

... (truncated)

Commits
  • 48fc2d4 Merge pull request #3633 from bdarnell/curl-reset-65
  • 4ae1ddd Release notes and version bump for 6.5.7
  • 3154caa curl_httpclient: Reset the curl object before putting it on the freelist
  • 7d869c0 Merge pull request #3631 from bdarnell/cve-links
  • 288241f docs: Use the correct link syntax
  • 8da981c docs: Add CVE links to 6.5.6 release notes
  • aba2569 Merge pull request #3626 from bdarnell/fixes-656
  • a24b260 httpclient_test: Accept an additional error message variant
  • a74240a Release notes and version bump for 6.5.6.
  • e8fc7ed simple_httpclient: Strip auth headers on cross-origin redirects
  • Additional commits viewable in compare view

Updates aiohttp from 3.14.0 to 3.14.1

Changelog

Sourced from aiohttp's changelog.

3.14.1 (2026-06-07)

Bug fixes

  • Fixed a race condition in :py:class:~aiohttp.TCPConnector where closing the connector while a DNS resolution was in-flight could raise :py:exc:AttributeError instead of :py:exc:~aiohttp.ClientConnectionError -- by :user:goingforstudying-ctrl.

    Related issues and pull requests on GitHub: :issue:12497.

  • Fixed CancelledError not closing a connection -- by :user:aiolibsbot.

    Related issues and pull requests on GitHub: :issue:12795.

  • Tightened up some websocket parser checks -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub: :issue:12817.

  • Fixed :class:~aiohttp.CookieJar dropping the host-only flag of cookies when persisted with :meth:~aiohttp.CookieJar.save and reloaded with :meth:~aiohttp.CookieJar.load, so a cookie set without a Domain attribute is again scoped to the exact host that set it after a reload; the absolute expiration deadline is now persisted as well, so a reloaded cookie keeps its original lifetime instead of being rescheduled from the load time. :meth:~aiohttp.CookieJar.load now replaces the jar contents rather than merging onto prior state, and loaded cookies pass through the same acceptance rules as :meth:~aiohttp.CookieJar.update_cookies, so a cookie for an IP-address host is dropped when loaded into a jar created without unsafe=True -- by :user:bdraco.

    Related issues and pull requests on GitHub: :issue:12824.

  • Scoped :class:~aiohttp.DigestAuthMiddleware credentials to the origin of the first request it handles, so a redirect to a different origin no longer triggers a digest response computed from the configured credentials; a challenge from another origin is only answered when that origin falls within a protection space advertised by the anchor origin through the RFC 7616 domain directive -- by :user:bdraco.

    Related issues and pull requests on GitHub: :issue:12825.

  • Fixed the C HTTP parser not enforcing max_line_size on a request target or response reason phrase that is split across multiple reads; each fragment was checked on its own, so an accumulated line could exceed the limit without raising LineTooLong. The accumulated length is now checked, matching the pure-Python parser -- by :user:bdraco.

    Related issues and pull requests on GitHub:

... (truncated)

Commits
  • 9c35d03 Release v3.14.1 (#12864)
  • 38b956c [PR #12861/59684b5c backport][3.14] Revert "Drop list compression (#12857)" (...
  • 8f31009 [PR #12857/69dff14d backport][3.14] Drop list compression (#12858)
  • dfdfa9d [PR #12830/93a2b1c3 backport][3.14] Bound pipelined request queue per connect...
  • 0e9cedd [PR #12827/ccf218ab backport][3.14] Numeric ipv4 resolver bypass (#12849)
  • a762eda [PR #12831/1ac92dae backport][3.14] Payload close on disconnect (#12843)
  • a329a7a [PR #12824/60b85e98 backport][3.14] Preserve host-only cookie scope across Co...
  • 4f7480e [PR #12828/13b635d7 backport][3.14] Bounded unread compressed drain (#12845)
  • 5ab61bb [PR #12826/36df6c13 backport][3.14] Enforce max_line_size on fragmented reque...
  • 3912667 [3.14] Add test that env proxy auth is scoped to the redirect-selected proxy ...
  • Additional commits viewable in compare view

Updates aiohttp from 3.14.0 to 3.14.1

Changelog

Sourced from aiohttp's changelog.

3.14.1 (2026-06-07)

Bug fixes

  • Fixed a race condition in :py:class:~aiohttp.TCPConnector where closing the connector while a DNS resolution was in-flight could raise :py:exc:AttributeError instead of :py:exc:~aiohttp.ClientConnectionError -- by :user:goingforstudying-ctrl.

    Related issues and pull requests on GitHub: :issue:12497.

  • Fixed CancelledError not closing a connection -- by :user:aiolibsbot.

    Related issues and pull requests on GitHub: :issue:12795.

  • Tightened up some websocket parser checks -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub: :issue:12817.

  • Fixed :class:~aiohttp.CookieJar dropping the host-only flag of cookies when persisted with :meth:~aiohttp.CookieJar.save and reloaded with :meth:~aiohttp.CookieJar.load, so a cookie set without a Domain attribute is again scoped to the exact host that set it after a reload; the absolute expiration deadline is now persisted as well, so a reloaded cookie keeps its original lifetime instead of being rescheduled from the load time. :meth:~aiohttp.CookieJar.load now replaces the jar contents rather than merging onto prior state, and loaded cookies pass through the same acceptance rules as :meth:~aiohttp.CookieJar.update_cookies, so a cookie for an IP-address host is dropped when loaded into a jar created without unsafe=True -- by :user:bdraco.

    Related issues and pull requests on GitHub: :issue:12824.

  • Scoped :class:~aiohttp.DigestAuthMiddleware credentials to the origin of the first request it handles, so a redirect to a different origin no longer triggers a digest response computed from the configured credentials; a challenge from another origin is only answered when that origin falls within a protection space advertised by the anchor origin through the RFC 7616 domain directive -- by :user:bdraco.

    Related issues and pull requests on GitHub: :issue:12825.

  • Fixed the C HTTP parser not enforcing max_line_size on a request target or response reason phrase that is split across multiple reads; each fragment was checked on its own, so an accumulated line could exceed the limit without raising LineTooLong. The accumulated length is now checked, matching the pure-Python parser -- by :user:bdraco.

    Related issues and pull requests on GitHub:

... (truncated)

Commits
  • 9c35d03 Release v3.14.1 (#12864)
  • 38b956c [PR #12861/59684b5c backport][3.14] Revert "Drop list compression (#12857)" (...
  • 8f31009 [PR #12857/69dff14d backport][3.14] Drop list compression (#12858)
  • dfdfa9d [PR #12830/93a2b1c3 backport][3.14] Bound pipelined request queue per connect...
  • 0e9cedd [PR #12827/ccf218ab backport][3.14] Numeric ipv4 resolver bypass (#12849)
  • a762eda [PR #12831/1ac92dae backport][3.14] Payload close on disconnect (#12843)
  • a329a7a [PR #12824/60b85e98 backport][3.14] Preserve host-only cookie scope across Co...
  • 4f7480e [PR #12828/13b635d7 backport][3.14] Bounded unread compressed drain (#12845)
  • 5ab61bb [PR #12826/36df6c13 backport][3.14] Enforce max_line_size on fragmented reque...
  • 3912667 [3.14] Add test that env proxy auth is scoped to the redirect-selected proxy ...
  • Additional commits viewable in compare view

Updates aiohttp from 3.14.0 to 3.14.1

Changelog

Sourced from aiohttp's changelog.

3.14.1 (2026-06-07)

Bug fixes

  • Fixed a race condition in :py:class:~aiohttp.TCPConnector where closing the connector while a DNS resolution was in-flight could raise :py:exc:AttributeError instead of :py:exc:~aiohttp.ClientConnectionError -- by :user:goingforstudying-ctrl.

    Related issues and pull requests on GitHub: :issue:12497.

  • Fixed CancelledError not closing a connection -- by :user:aiolibsbot.

    Related issues and pull requests on GitHub: :issue:12795.

  • Tightened up some websocket parser checks -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub: :issue:12817.

  • Fixed :class:~aiohttp.CookieJar dropping the host-only flag of cookies when persisted with :meth:~aiohttp.CookieJar.save and reloaded with :meth:~aiohttp.CookieJar.load, so a cookie set without a Domain attribute is again scoped to the exact host that set it after a reload; the absolute expiration deadline is now persisted as well, so a reloaded cookie keeps its original lifetime instead of being rescheduled from the load time. :meth:~aiohttp.CookieJar.load now replaces the jar contents rather than merging onto prior state, and loaded cookies pass through the same acceptance rules as :meth:~aiohttp.CookieJar.update_cookies, so a cookie for an IP-address host is dropped when loaded into a jar created without unsafe=True -- by :user:bdraco.

    Related issues and pull requests on GitHub: :issue:12824.

  • Scoped :class:~aiohttp.DigestAuthMiddleware credentials to the origin of the first request it handles, so a redirect to a different origin no longer triggers a digest response computed from the configured credentials; a challenge from another origin is only answered when that origin falls within a protection space advertised by the anchor origin through the RFC 7616 domain directive -- by :user:bdraco.

    Related issues and pull requests on GitHub: :issue:12825.

  • Fixed the C HTTP parser not enforcing max_line_size on a request target or response reason phrase that is split across multiple reads; each fragment was checked on its own, so an accumulated line could exceed the limit without raising LineTooLong. The accumulated length is now checked, matching the pure-Python parser -- by :user:bdraco.

    Related issues and pull requests on GitHub:

... (truncated)

Commits
  • 9c35d03 Release v3.14.1 (#12864)
  • 38b956c [PR #12861/59684b5c backport][3.14] Revert "Drop list compression (#12857)" (...
  • 8f31009 [PR #12857/69dff14d backport][3.14] Drop list compression (#12858)
  • dfdfa9d [PR #12830/93a2b1c3 backport][3.14] Bound pipelined request queue per connect...
  • 0e9cedd [PR #12827/ccf218ab backport][3.14] Numeric ipv4 resolver bypass (#12849)
  • a762eda [PR #12831/1ac92dae backport][3.14] Payload close on disconnect (#12843)
  • a329a7a [PR #12824/60b85e98 backport][3.14] Preserve host-only cookie scope across Co...
  • 4f7480e [PR #12828/13b635d7 backport][3.14] Bounded unread compressed drain (#12845)
  • 5ab61bb [PR #12826/36df6c13 backport][3.14] Enforce max_line_size on fragmented reque...
  • 3912667 [3.14] Add test that env proxy auth is scoped to the redirect-selected proxy ...
  • Additional commits viewable in compare view

Updates tornado from 6.5.5 to 6.5.7

Changelog

Sourced from tornado's changelog.

Release notes

.. toctree:: :maxdepth: 2

releases/v6.5.7 releases/v6.5.6 releases/v6.5.5 releases/v6.5.4 releases/v6.5.3 releases/v6.5.2 releases/v6.5.1 releases/v6.5.0 releases/v6.4.2 releases/v6.4.1 releases/v6.4.0 releases/v6.3.3 releases/v6.3.2 releases/v6.3.1 releases/v6.3.0 releases/v6.2.0 releases/v6.1.0 releases/v6.0.4 releases/v6.0.3 releases/v6.0.2 releases/v6.0.1 releases/v6.0.0 releases/v5.1.1 releases/v5.1.0 releases/v5.0.2 releases/v5.0.1 releases/v5.0.0 releases/v4.5.3 releases/v4.5.2 releases/v4.5.1 releases/v4.5.0 releases/v4.4.3 releases/v4.4.2 releases/v4.4.1 releases/v4.4.0 releases/v4.3.0 releases/v4.2.1 releases/v4.2.0 releases/v4.1.0 releases/v4.0.2 releases/v4.0.1 releases/v4.0.0 releases/v3.2.2 releases/v3.2.1

... (truncated)

Commits
  • 48fc2d4 Merge pull request #3633 from bdarnell/curl-reset-65
  • 4ae1ddd Release notes and version bump for 6.5.7
  • 3154caa curl_httpclient: Reset the curl object before putting it on the freelist
  • 7d869c0 Merge pull request #3631 from bdarnell/cve-links
  • 288241f docs: Use the correct link syntax
  • 8da981c docs: Add CVE links to 6.5.6 release notes
  • aba2569 Merge pull request #3626 from bdarnell/fixes-656
  • a24b260 httpclient_test: Accept an additional error message variant
  • a74240a Release notes and version bump for 6.5.6.
  • e8fc7ed simple_httpclient: Strip auth headers on cross-origin redirects
  • Additional commits viewable in compare view

Updates aiohttp from 3.14.0 to 3.14.1

Changelog

Sourced from aiohttp's changelog.

3.14.1 (2026-06-07)

Bug fixes

  • Fixed a race condition in :py:class:~aiohttp.TCPConnector where closing the connector while a DNS resolution was in-flight could raise :py:exc:AttributeError instead of :py:exc:~aiohttp.ClientConnectionError -- by :user:goingforstudying-ctrl.

    Related issues and pull requests on GitHub: :issue:12497.

  • Fixed CancelledError not closing a connection -- by :user:aiolibsbot.

    Related issues and pull requests on GitHub: :issue:12795.

  • Tightened up some websocket parser checks -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub: :issue:12817.

  • Fixed :class:~aiohttp.CookieJar dropping the host-only flag of cookies when persisted with :meth:~aiohttp.CookieJar.save and reloaded with :meth:~aiohttp.CookieJar.load, so a cookie set without a Domain attribute is again scoped to the exact host that set it after a reload; the absolute expiration deadline is now persisted as well, so a reloaded cookie keeps its original lifetime instead of being rescheduled from the load time. :meth:~aiohttp.CookieJar.load now replaces the jar contents rather than merging onto prior state, and loaded cookies pass through the same acceptance rules as :meth:~aiohttp.CookieJar.update_cookies, so a cookie for an IP-address host is dropped when loaded into a jar created without unsafe=True -- by :user:bdraco.

    Related issues and pull requests on GitHub: :issue:12824.

  • Scoped :class:~aiohttp.DigestAuthMiddleware credentials to the origin of the first request it handles, so a redirect to a different origin no longer triggers a digest response computed from the configured credentials; a challenge from another origin is only answered when that origin falls within a protection space advertised by the anchor origin through the RFC 7616 domain directive -- by :user:bdraco.

    Related issues and pull requests on GitHub: :issue:12825.

  • Fixed the C HTTP parser not enforcing max_line_size on a request target or response reason phrase that is split across multiple reads; each fragment was checked on its own, so an accumulated line could exceed the limit without raising LineTooLong. The accumulated length is now checked, matching the pure-Python parser -- by :user:bdraco.

    Related issues and pull requests on GitHub:

... (truncated)

Commits
  • 9c35d03 Release v3.14.1 (#12864)
  • 38b956c [PR #12861/59684b5c backport][3.14] Revert "Drop list compression (#12857)" (...
  • 8f31009 [PR #12857/69dff14d backport][3.14] Drop list compression (#12858)
  • dfdfa9d [PR #12830/93a2b1c3 backport][3.14] Bound pipelined request queue per connect...
  • 0e9cedd [PR #12827/ccf218ab backport][3.14] Numeric ipv4 resolver bypass (#12849)
  • a762eda [PR #12831/1ac92dae backport][3.14] Payload close on disconnect (#12843)
  • a329a7a [PR #12824/60b85e98 backport][3.14] Preserve host-only cookie scope across Co...
  • 4f7480e [PR #12828/13b635d7 backport][3.14] Bounded unread compressed drain (#12845)
  • 5ab61bb [PR #12826/36df6c13 backport][3.14] Enforce max_line_size on fragmented reque...
  • 3912667 [3.14] Add test that env proxy auth is scoped to the redirect-selected proxy ...
  • Additional commits viewable in compare view

Updates tornado from 6.5.5 to 6.5.7

Changelog

Sourced from tornado's changelog.

Release notes

.. toctree:: :maxdepth: 2

releases/v6.5.7 releases/v6.5.6 releases/v6.5.5 releases/v6.5.4 releases/v6.5.3 releases/v6.5.2 releases/v6.5.1 releases/v6.5.0 releases/v6.4.2 releases/v6.4.1 releases/v6.4.0 releases/v6.3.3 releases/v6.3.2 releases/v6.3.1 releases/v6.3.0 releases/v6.2.0 releases/v6.1.0 releases/v6.0.4 releases/v6.0.3 releases/v6.0.2 releases/v6.0.1 releases/v6.0.0 releases/v5.1.1 releases/v5.1.0 releases/v5.0.2 releases/v5.0.1 releases/v5.0.0 releases/v4.5.3 releases/v4.5.2 releases/v4.5.1 releases/v4.5.0 releases/v4.4.3 releases/v4.4.2 releases/v4.4.1 releases/v4.4.0 releases/v4.3.0 releases/v4.2.1 releases/v4.2.0 releases/v4.1.0 releases/v4.0.2 releases/v4.0.1 releases/v4.0.0 releases/v3.2.2 releases/v3.2.1

... (truncated)

Commits
  • 48fc2d4 Merge pull request #3633 from bdarnell/curl-reset-65
  • 4ae1ddd Release notes and version bump for 6.5.7
  • 3154caa curl_httpclient: Reset the curl object before putting it on the freelist
  • 7d869c0 Merge pull request #3631 from bdarnell/cve-links
  • 288241f docs: Use the correct link syntax
  • 8da981c docs: Add CVE links to 6.5.6 release notes
  • aba2569 Merge pull request #3626 from bdarnell/fixes-656
  • a24b260 httpclient_test: Accept an additional error message variant
  • a74240a Release notes and version bump for 6.5.6.
  • e8fc7ed simple_httpclient: Strip auth headers on cross-origin redirects
  • Additional commits viewable in compare view

Updates aiohttp from 3.14.0 to 3.14.1

Changelog

Sourced from aiohttp's changelog.

3.14.1 (2026-06-07)

Bug fixes

  • Fixed a race condition in :py:class:~aiohttp.TCPConnector where closing the connector while a DNS resolution was in-flight could raise :py:exc:AttributeError instead of :py:exc:~aiohttp.ClientConnectionError -- by :user:goingforstudying-ctrl.

    Related issues and pull requests on GitHub: :issue:12497.

  • Fixed CancelledError not closing a connection -- by :user:aiolibsbot.

    Related issues and pull requests on GitHub: :issue:12795.

  • Tightened up some websocket parser checks -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub: :issue:12817.

  • Fixed :class:~aiohttp.CookieJar dropping the host-only flag of cookies when persisted with :meth:~aiohttp.CookieJar.save and reloaded with :meth:~aiohttp.CookieJar.load, so a cookie set without a Domain attribute is again scoped to the exact host that set it after a reload; the absolute expiration deadline is now persisted as well, so a reloaded cookie keeps its original lifetime instead of being rescheduled from the load time. :meth:~aiohttp.CookieJar.load now replaces the jar contents rather than merging onto prior state, and loaded cookies pass through the same acceptance rules as :meth:~aiohttp.CookieJar.update_cookies, so a cookie for an IP-address host is dropped when loaded into a jar created without unsafe=True -- by :user:bdraco.

    Related issues and pull requests on GitHub: :issue:12824.

  • Scoped :class:~aiohttp.DigestAuthMiddleware credentials to the origin of the first request it handles, so a redirect to a different origin no longer triggers a digest response computed from the configured credentials; a challenge from another origin is only answered when that origin falls within a protection space advertised by the anchor origin through the RFC 7616 domain directive -- by :user:bdraco.

    Related issues and pull requests on GitHub: :issue:12825.

  • Fixed the C HTTP parser not enforcing max_line_size on a request target or response reason phrase that is split across multiple reads; each fragment was checked on its own, so an accumulated line could exceed the limit without raising LineTooLong. The accumulated length is now checked, matching the pure-Python parser -- by :user:bdraco.

    Related issues and pull requests on GitHub:

... (truncated)

Commits
  • 9c35d03 Release v3.14.1 (#12864)
  • 38b956c [PR #12861/59684b5c backport][3.14] Revert "Drop list compression (#12857)" (...
  • 8f31009 [PR #12857/69dff14d backport][3.14] Drop list compression (#12858)
  • dfdfa9d [PR #12830/93a2b1c3 backport][3.14] Bound pipelined request queue per connect...
  • 0e9cedd [PR #12827/ccf218ab backport][3.14] Numeric ipv4 resolver bypass (#12849)
  • a762eda [PR #12831/1ac92dae backport][3.14] Payload close on disconnect (#12843)
  • a329a7a [PR #12824/60b85e98 backport][3.14] Preserve host-only cookie scope across Co...
  • 4f7480e [PR #12828/13b635d7 backport][3.14] Bounded unread compressed drain (#12845)
  • 5ab61bb [PR #12826/36df6c13 backport][3.14] Enforce max_line_size on fragmented reque...
  • 3912667 [3.14] Add test that env proxy auth is scoped to the redirect-selected proxy ...
  • Additional commits viewable in compare view

Updates aiohttp from 3.14.0 to 3.14.1

Changelog

Sourced from aiohttp's changelog.

3.14.1 (2026-06-07)

Bug fixes

  • Fixed a race condition in :py:class:~aiohttp.TCPConnector where closing the connector while a DNS resolution was in-flight could raise :py:exc:AttributeError instead of :py:exc:~aiohttp.ClientConnectionError -- by :user:goingforstudying-ctrl.

    Related issues and pull requests on GitHub: :issue:12497.

  • Fixed CancelledError not closing a connection -- by :user:aiolibsbot.

    Related issues and pull requests on GitHub: :issue:12795.

  • Tightened up some websocket parser checks -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub: :issue:12817.

  • Fixed :class:~aiohttp.CookieJar dropping the host-only flag of cookies when persisted with :meth:~aiohttp.CookieJar.save and reloaded with :meth:~aiohttp.CookieJar.load, so a cookie set without a Domain attribute is again scoped to the exact host that set it after a reload; the absolute expiration deadline is now persisted as well, so a reloaded cookie keeps its original lifetime instead of being rescheduled from the load time. :meth:~aiohttp.CookieJar.load now replaces the jar contents rather than merging onto prior state, and loaded cookies pass through the same acceptance rules as :meth:~aiohttp.CookieJar.update_cookies, so a cookie for an IP-address host is dropped when loaded into a jar created without unsafe=True -- by :user:bdraco.

    Related issues and pull requests on GitHub: :issue:12824.

  • Scoped :class:~aiohttp.DigestAuthMiddleware credentials to the origin of the first request it handles, so a redirect to a different origin no longer triggers a digest response computed from the configured credentials; a challenge from another origin is only answered when that origin falls within a protection space advertised by the anchor origin through the RFC 7616 domain directive -- by :user:bdraco.

    Related issues and pull requests on GitHub: :issue:12825.

  • Fixed the C HTTP parser not enforcing max_line_size on a request target or response reason phrase that is split across multiple reads; each fragment was checked on its own, so an accumulated line could exceed the limit without raising LineTooLong. The accumulated length is now checked, matching the pure-Python parser -- by :user:bdraco.

    Related issues and pull requests on GitHub:

... (truncated)

Commits
  • 9c35d03 Release v3.14.1 (#12864)
  • 38b956c [PR #12861/59684b5c backport][3.14] Revert "Drop list compression (#12857)" (...
  • 8f31009 [PR #12857/69dff14d backport][3.14] Drop list compression (#12858)
  • dfdfa9d [PR #12830/93a2b1c3 backport][3.14] Bound pipelined request queue per connect...
  • 0e9cedd [PR #12827/ccf218ab backport][3.14] Numeric ipv4 resolver bypass (#12849)
  • a762eda [PR #12831/1ac92dae backport][3.14] Payload close on disconnect (#12843)
  • a329a7a [PR #12824/60b85e98 backport][3.14] Preserve host-only cookie scope across Co...
  • 4f7480e [PR #12828/13b635d7 backport][3.14] Bounded unread compressed drain (#12845)
  • 5ab61bb [PR #12826/36df6c13 backport][3.14] Enforce max_line_size on fragmented reque...
  • 3912667 [3.14] Add test that env proxy auth is scoped to the redirect-selected proxy ...
  • Additional commits viewable in compare view

Updates aiohttp from 3.14.0 to 3.14.1

Changelog

Sourced from aiohttp's changelog.

3.14.1 (2026-06-07)

Bug fixes

  • Fixed a race condition in :py:class:~aiohttp.TCPConnector where closing the connector while a DNS resolution was in-flight could raise :py:exc:AttributeError instead of :py:exc:~aiohttp.ClientConnectionError -- by :user:goingforstudying-ctrl.

    Related issues and pull requests on GitHub: :issue:12497.

  • Fixed CancelledError not closing a connection -- by :user:aiolibsbot.

    Related issues and pull requests on GitHub: :issue:12795.

  • Tightened up some websocket parser checks -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub: :issue:12817.

  • Fixed :class:~aiohttp.CookieJar dropping the host-only flag of cookies when persisted with :meth:~aiohttp.CookieJar.save and reloaded with :meth:~aiohttp.CookieJar.load, so a cookie set without a Domain attribute is again scoped to the exact host that set it after a reload; the absolute expiration deadline is now persisted as well, so a reloaded cookie keeps its original lifetime instead of being rescheduled from the load time. :meth:~aiohttp.CookieJar.load now replaces the jar contents rather than merging onto prior state, and loaded cookies pass through the same acceptance rules as :meth:~aiohttp.CookieJar.update_cookies, so a cookie for an IP-address host is dropped when loaded into a jar created without unsafe=True -- by :user:bdraco.

    Related issues and pull requests on GitHub: :issue:12824.

  • Scoped :class:~aiohttp.DigestAuthMiddleware credentials to the origin of the first request it handles, so a redirect to a different origin no longer triggers a digest response computed from the configured credentials; a challenge from another origin is only answered when that origin falls within a protection space advertised by the anchor origin through the RFC 7616 domain directive -- by :user:bdraco.

    Related issues and pull requests on GitHub: :issue:12825.

  • Fixed the C HTTP parser not enforcing max_line_size on a request target or response reason phrase that is split across multiple reads; each fragment was checked on its own, so an accumulated line could exceed the limit without raising LineTooLong. The accumulated length is now checked, matching the pure-Python parser -- by :user:bdraco.

    Related issues and pull requests on GitHub:

... (truncated)

Commits
  • 9c35d03 Release v3.14.1 (#12864)
  • 38b956c [PR #12861/59684b5c backport][3.14] Revert "Drop list compression (#12857)" (...
  • 8f31009 [PR #12857/69dff14d backport][3.14] Drop list compression (#12858)
  • dfdfa9d [PR #12830/93a2b1c3 backport][3.14] Bound pipelined request queue per connect...
  • 0e9cedd [PR #12827/ccf218ab backport][3.14] Numeric ipv4 resolver bypass (#12849)
  • a762eda [PR #12831/1ac92dae backport][3.14] Payload close on disconnect (#12843)
  • a329a7a [PR #12824/60b85e98 backport][3.14] Preserve host-only cookie scope across Co...
  • 4f7480e [PR #12828/13b635d7 backport][3.14] Bounded unread compressed drain (#12845)
  • 5ab61bb [PR #12826/36df6c13 backport][3.14] Enforce max_line_size on fragmented reque...
  • 3912667 [3.14] Add test that env proxy auth is scoped to the redirect-selected proxy ...
  • Additional commits viewable in compare view

Updates aiohttp from 3.14.0 to 3.14.1

Changelog

Sourced from aiohttp's changelog.

3.14.1 (2026-06-07)

Bug fixes

  • Fixed a race condition in :py:class:~aiohttp.TCPConnector where closing the connector while a DNS resolution was in-flight could raise :py:exc:AttributeError instead of :py:exc:~aiohttp.ClientConnectionError -- by :user:goingforstudying-ctrl.

    Related issues and pull requests on GitHub: :issue:12497.

  • Fixed CancelledError not closing a connection -- by :user:aiolibsbot.

    Related issues and pull requests on GitHub: :issue:12795.

  • Tightened up some websocket parser checks -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub: :issue:12817.

  • Fixed :class:~aiohttp.CookieJar dropping the host-only flag of cookies when persisted with :meth:~aiohttp.CookieJar.save and reloaded with :meth:~aiohttp.CookieJar.load, so a cookie set without a Domain attribute is again scoped to the exact host that set it after a reload; the absolute expiration deadline is now persisted as well, so a reloaded cookie keeps its original lifetime instead of being rescheduled from the load time. :meth:~aiohttp.CookieJar.load now replaces the jar contents rather than merging onto prior state, and loaded cookies pass through the same acceptance rules as :meth:~aiohttp.CookieJar.update_cookies, so a cookie for an IP-address host is dropped when loaded into a jar created without unsafe=True -- by :user:bdraco.

    Related issues and pull requests on GitHub: :issue:12824.

  • Scoped :class:~aiohttp.DigestAuthMiddleware credentials to the origin of the first request it handles, so a redirect to a different origin no longer triggers a digest response computed from the configured credentials; a challenge from another origin is only answered when that origin falls within a protection space advertised by the anchor origin through the RFC 7616 domain directive -- by :user:bdraco.

    Related issues and pull requests on GitHub: :issue:12825.

  • Fixed the C HTTP parser not enforcing max_line_size on a request target or response reason phrase that is split across multiple reads; each fragment was checked on its own, so an accumulated line could exceed the limit without raising LineTooLong. The accumulated length is now checked, matching the pure-Python parser -- by :user:bdraco.

    Related issues and pull requests on GitHub:

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Jul 8, 2026
Copilot AI review requested due to automatic review settings July 8, 2026 02:01
@dependabot
dependabot Bot requested a review from a team as a code owner July 8, 2026 02:01
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Jul 8, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner July 8, 2026 02:01
@dependabot dependabot Bot added the python Pull requests that update python code label Jul 8, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot can't review bot-authored pull requests automatically. A user with Copilot access can request a review manually.

Bumps the pip group with 2 updates in the /.aitk/requirements directory: [aiohttp](https://github.com/aio-libs/aiohttp) and [tornado](https://github.com/tornadoweb/tornado).
Bumps the pip group with 1 update in the /.aitk/requirements/AMD directory: [aiohttp](https://github.com/aio-libs/aiohttp).
Bumps the pip group with 1 update in the /.aitk/requirements/General directory: [aiohttp](https://github.com/aio-libs/aiohttp).
Bumps the pip group with 2 updates in the /.aitk/requirements/Intel directory: [aiohttp](https://github.com/aio-libs/aiohttp) and [tornado](https://github.com/tornadoweb/tornado).
Bumps the pip group with 3 updates in the /meta-llama-Llama-3.1-8B-Instruct/QAIRT directory: [aiohttp](https://github.com/aio-libs/aiohttp), [tornado](https://github.com/tornadoweb/tornado) and [bleach](https://github.com/mozilla/bleach).


Updates `aiohttp` from 3.14.0 to 3.14.1
- [Changelog](https://github.com/aio-libs/aiohttp/blob/master/CHANGES.rst)
- [Commits](aio-libs/aiohttp@v3.14.0...v3.14.1)

Updates `tornado` from 6.5.5 to 6.5.7
- [Changelog](https://github.com/tornadoweb/tornado/blob/master/docs/releases.rst)
- [Commits](tornadoweb/tornado@v6.5.5...v6.5.7)

Updates `aiohttp` from 3.14.0 to 3.14.1
- [Changelog](https://github.com/aio-libs/aiohttp/blob/master/CHANGES.rst)
- [Commits](aio-libs/aiohttp@v3.14.0...v3.14.1)

Updates `aiohttp` from 3.14.0 to 3.14.1
- [Changelog](https://github.com/aio-libs/aiohttp/blob/master/CHANGES.rst)
- [Commits](aio-libs/aiohttp@v3.14.0...v3.14.1)

Updates `aiohttp` from 3.14.0 to 3.14.1
- [Changelog](https://github.com/aio-libs/aiohttp/blob/master/CHANGES.rst)
- [Commits](aio-libs/aiohttp@v3.14.0...v3.14.1)

Updates `tornado` from 6.5.5 to 6.5.7
- [Changelog](https://github.com/tornadoweb/tornado/blob/master/docs/releases.rst)
- [Commits](tornadoweb/tornado@v6.5.5...v6.5.7)

Updates `aiohttp` from 3.14.0 to 3.14.1
- [Changelog](https://github.com/aio-libs/aiohttp/blob/master/CHANGES.rst)
- [Commits](aio-libs/aiohttp@v3.14.0...v3.14.1)

Updates `tornado` from 6.5.5 to 6.5.7
- [Changelog](https://github.com/tornadoweb/tornado/blob/master/docs/releases.rst)
- [Commits](tornadoweb/tornado@v6.5.5...v6.5.7)

Updates `aiohttp` from 3.14.0 to 3.14.1
- [Changelog](https://github.com/aio-libs/aiohttp/blob/master/CHANGES.rst)
- [Commits](aio-libs/aiohttp@v3.14.0...v3.14.1)

Updates `aiohttp` from 3.14.0 to 3.14.1
- [Changelog](https://github.com/aio-libs/aiohttp/blob/master/CHANGES.rst)
- [Commits](aio-libs/aiohttp@v3.14.0...v3.14.1)

Updates `aiohttp` from 3.14.0 to 3.14.1
- [Changelog](https://github.com/aio-libs/aiohttp/blob/master/CHANGES.rst)
- [Commits](aio-libs/aiohttp@v3.14.0...v3.14.1)

Updates `aiohttp` from 3.14.0 to 3.14.1
- [Changelog](https://github.com/aio-libs/aiohttp/blob/master/CHANGES.rst)
- [Commits](aio-libs/aiohttp@v3.14.0...v3.14.1)

Updates `aiohttp` from 3.14.0 to 3.14.1
- [Changelog](https://github.com/aio-libs/aiohttp/blob/master/CHANGES.rst)
- [Commits](aio-libs/aiohttp@v3.14.0...v3.14.1)

Updates `aiohttp` from 3.14.0 to 3.14.1
- [Changelog](https://github.com/aio-libs/aiohttp/blob/master/CHANGES.rst)
- [Commits](aio-libs/aiohttp@v3.14.0...v3.14.1)

Updates `aiohttp` from 3.14.0 to 3.14.1
- [Changelog](https://github.com/aio-libs/aiohttp/blob/master/CHANGES.rst)
- [Commits](aio-libs/aiohttp@v3.14.0...v3.14.1)

Updates `aiohttp` from 3.14.0 to 3.14.1
- [Changelog](https://github.com/aio-libs/aiohttp/blob/master/CHANGES.rst)
- [Commits](aio-libs/aiohttp@v3.14.0...v3.14.1)

Updates `aiohttp` from 3.14.0 to 3.14.1
- [Changelog](https://github.com/aio-libs/aiohttp/blob/master/CHANGES.rst)
- [Commits](aio-libs/aiohttp@v3.14.0...v3.14.1)

Updates `aiohttp` from 3.14.0 to 3.14.1
- [Changelog](https://github.com/aio-libs/aiohttp/blob/master/CHANGES.rst)
- [Commits](aio-libs/aiohttp@v3.14.0...v3.14.1)

Updates `aiohttp` from 3.14.0 to 3.14.1
- [Changelog](https://github.com/aio-libs/aiohttp/blob/master/CHANGES.rst)
- [Commits](aio-libs/aiohttp@v3.14.0...v3.14.1)

Updates `tornado` from 6.5.5 to 6.5.7
- [Changelog](https://github.com/tornadoweb/tornado/blob/master/docs/releases.rst)
- [Commits](tornadoweb/tornado@v6.5.5...v6.5.7)

Updates `aiohttp` from 3.14.0 to 3.14.1
- [Changelog](https://github.com/aio-libs/aiohttp/blob/master/CHANGES.rst)
- [Commits](aio-libs/aiohttp@v3.14.0...v3.14.1)

Updates `aiohttp` from 3.14.0 to 3.14.1
- [Changelog](https://github.com/aio-libs/aiohttp/blob/master/CHANGES.rst)
- [Commits](aio-libs/aiohttp@v3.14.0...v3.14.1)

Updates `aiohttp` from 3.14.0 to 3.14.1
- [Changelog](https://github.com/aio-libs/aiohttp/blob/master/CHANGES.rst)
- [Commits](aio-libs/aiohttp@v3.14.0...v3.14.1)

Updates `tornado` from 6.5.5 to 6.5.7
- [Changelog](https://github.com/tornadoweb/tornado/blob/master/docs/releases.rst)
- [Commits](tornadoweb/tornado@v6.5.5...v6.5.7)

Updates `aiohttp` from 3.14.0 to 3.14.1
- [Changelog](https://github.com/aio-libs/aiohttp/blob/master/CHANGES.rst)
- [Commits](aio-libs/aiohttp@v3.14.0...v3.14.1)

Updates `tornado` from 6.5.5 to 6.5.7
- [Changelog](https://github.com/tornadoweb/tornado/blob/master/docs/releases.rst)
- [Commits](tornadoweb/tornado@v6.5.5...v6.5.7)

Updates `aiohttp` from 3.14.0 to 3.14.1
- [Changelog](https://github.com/aio-libs/aiohttp/blob/master/CHANGES.rst)
- [Commits](aio-libs/aiohttp@v3.14.0...v3.14.1)

Updates `tornado` from 6.5.5 to 6.5.7
- [Changelog](https://github.com/tornadoweb/tornado/blob/master/docs/releases.rst)
- [Commits](tornadoweb/tornado@v6.5.5...v6.5.7)

Updates `aiohttp` from 3.14.0 to 3.14.1
- [Changelog](https://github.com/aio-libs/aiohttp/blob/master/CHANGES.rst)
- [Commits](aio-libs/aiohttp@v3.14.0...v3.14.1)

Updates `aiohttp` from 3.14.0 to 3.14.1
- [Changelog](https://github.com/aio-libs/aiohttp/blob/master/CHANGES.rst)
- [Commits](aio-libs/aiohttp@v3.14.0...v3.14.1)

Updates `aiohttp` from 3.14.0 to 3.14.1
- [Changelog](https://github.com/aio-libs/aiohttp/blob/master/CHANGES.rst)
- [Commits](aio-libs/aiohttp@v3.14.0...v3.14.1)

Updates `tornado` from 6.5.5 to 6.5.7
- [Changelog](https://github.com/tornadoweb/tornado/blob/master/docs/releases.rst)
- [Commits](tornadoweb/tornado@v6.5.5...v6.5.7)

Updates `aiohttp` from 3.14.0 to 3.14.1
- [Changelog](https://github.com/aio-libs/aiohttp/blob/master/CHANGES.rst)
- [Commits](aio-libs/aiohttp@v3.14.0...v3.14.1)

Updates `bleach` from 6.3.0 to 6.4.0
- [Changelog](https://github.com/mozilla/bleach/blob/main/CHANGES)
- [Commits](mozilla/bleach@v6.3.0...v6.4.0)

Updates `tornado` from 6.5.5 to 6.5.7
- [Changelog](https://github.com/tornadoweb/tornado/blob/master/docs/releases.rst)
- [Commits](tornadoweb/tornado@v6.5.5...v6.5.7)

---
updated-dependencies:
- dependency-name: aiohttp
  dependency-version: 3.14.1
  dependency-type: direct:production
- dependency-name: aiohttp
  dependency-version: 3.14.1
  dependency-type: direct:production
- dependency-name: aiohttp
  dependency-version: 3.14.1
  dependency-type: direct:production
- dependency-name: aiohttp
  dependency-version: 3.14.1
  dependency-type: direct:production
- dependency-name: aiohttp
  dependency-version: 3.14.1
  dependency-type: direct:production
- dependency-name: aiohttp
  dependency-version: 3.14.1
  dependency-type: direct:production
- dependency-name: aiohttp
  dependency-version: 3.14.1
  dependency-type: direct:production
- dependency-name: aiohttp
  dependency-version: 3.14.1
  dependency-type: direct:production
- dependency-name: aiohttp
  dependency-version: 3.14.1
  dependency-type: direct:production
- dependency-name: aiohttp
  dependency-version: 3.14.1
  dependency-type: direct:production
- dependency-name: aiohttp
  dependency-version: 3.14.1
  dependency-type: direct:production
- dependency-name: aiohttp
  dependency-version: 3.14.1
  dependency-type: direct:production
- dependency-name: aiohttp
  dependency-version: 3.14.1
  dependency-type: direct:production
- dependency-name: aiohttp
  dependency-version: 3.14.1
  dependency-type: direct:production
- dependency-name: aiohttp
  dependency-version: 3.14.1
  dependency-type: direct:production
- dependency-name: aiohttp
  dependency-version: 3.14.1
  dependency-type: direct:production
- dependency-name: aiohttp
  dependency-version: 3.14.1
  dependency-type: direct:production
- dependency-name: aiohttp
  dependency-version: 3.14.1
  dependency-type: direct:production
- dependency-name: aiohttp
  dependency-version: 3.14.1
  dependency-type: direct:production
- dependency-name: aiohttp
  dependency-version: 3.14.1
  dependency-type: direct:production
- dependency-name: aiohttp
  dependency-version: 3.14.1
  dependency-type: direct:production
- dependency-name: aiohttp
  dependency-version: 3.14.1
  dependency-type: direct:production
- dependency-name: aiohttp
  dependency-version: 3.14.1
  dependency-type: direct:production
- dependency-name: aiohttp
  dependency-version: 3.14.1
  dependency-type: direct:production
- dependency-name: aiohttp
  dependency-version: 3.14.1
  dependency-type: direct:production
- dependency-name: bleach
  dependency-version: 6.4.0
  dependency-type: direct:production
- dependency-name: tornado
  dependency-version: 6.5.7
  dependency-type: direct:production
- dependency-name: tornado
  dependency-version: 6.5.7
  dependency-type: direct:production
- dependency-name: tornado
  dependency-version: 6.5.7
  dependency-type: direct:production
- dependency-name: tornado
  dependency-version: 6.5.7
  dependency-type: direct:production
- dependency-name: tornado
  dependency-version: 6.5.7
  dependency-type: direct:production
- dependency-name: tornado
  dependency-version: 6.5.7
  dependency-type: direct:production
- dependency-name: tornado
  dependency-version: 6.5.7
  dependency-type: direct:production
- dependency-name: tornado
  dependency-version: 6.5.7
  dependency-type: direct:production
- dependency-name: tornado
  dependency-version: 6.5.7
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/pip/dot-aitk/requirements/pip-e108685de4 branch from e3e833c to b4de30c Compare July 20, 2026 06:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant