From 63133097e4b6e1d29eaa4c293ff76f9c781cabc2 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 18 Aug 2026 22:22:06 -0400 Subject: [PATCH] build(deps): update httpx[http2] requirement from >=0.27 to >=0.28.1 (#1227) Updates the requirements on [httpx[http2]](https://github.com/encode/httpx) to permit the latest version.
Release notes

Sourced from httpx[http2]'s releases.

Version 0.28.1

0.28.1 (6th December, 2024)

Changelog

Sourced from httpx[http2]'s changelog.

0.28.1 (6th December, 2024)

0.28.0 (28th November, 2024)

Be aware that the default JSON request bodies now use a more compact representation. This is generally considered a prefered style, tho may require updates to test suites.

The 0.28 release includes a limited set of deprecations...

Deprecations:

We are working towards a simplified SSL configuration API.

For users of the standard verify=True or verify=False cases, or verify=<ssl_context> case this should require no changes. The following cases have been deprecated...

Our revised SSL documentation covers how to implement the same behaviour with a more constrained API.

The following changes are also included:

0.27.2 (27th August, 2024)

Fixed

0.27.1 (27th August, 2024)

Added

Fixed

0.27.0 (21st February, 2024)

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) ---
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- pyproject.toml | 2 +- uv.lock | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/pyproject.toml b/pyproject.toml index 44b9b4e5..6426c986 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -25,7 +25,7 @@ dependencies = [ "apprise>=1.12.0", # HTTP/2 client for RFC 8484 DoH: quad9 rejects HTTP/1.1 outright (505), which # requests cannot speak. See shelfmark/download/doh_wireformat.py. - "httpx[http2]>=0.27", + "httpx[http2]>=0.28.1", ] [project.optional-dependencies] diff --git a/uv.lock b/uv.lock index bf29ffc3..362f77c7 100644 --- a/uv.lock +++ b/uv.lock @@ -1510,7 +1510,7 @@ requires-dist = [ { name = "gevent" }, { name = "gevent-websocket" }, { name = "gunicorn" }, - { name = "httpx", extras = ["http2"], specifier = ">=0.27" }, + { name = "httpx", extras = ["http2"], specifier = ">=0.28.1" }, { name = "psutil" }, { name = "pyautogui", marker = "extra == 'browser'" }, { name = "python-socketio" },