Skip to content

urllib3 pinned to <2.4.0 breaks packaging #2458

Description

@jmontleon

Is there a more permanent solution to the issues with python 2.4.0+ pending?
https://github.com/kubernetes-client/python/blob/master/requirements.txt#L10
https://bodhi.fedoraproject.org/updates/FEDORA-2025-34e5603fe3

Fedora 43+ has moved to urllib3 2.5.0 so in order to continue packaging the python kubernetes-client will mean carrying a patch to revert this change.

Activity

  1. added
    kind/bugCategorizes issue or PR as related to a bug.
    on Sep 30, 2025
  2. RyanBDB commented on Oct 1, 2025

    @RyanBDB

    urllib3 versions < 2.5.0 have the following known CVEs:

    Pinning urllib3 to < 2.4.0 also prevents users taking a version which addresses these CVEs.

  3. YevheniiSemendiak commented on Oct 1, 2025

    @YevheniiSemendiak

    Is urllib3 >= 2.5.0 support planned?

  4. lukehsiao commented on Oct 1, 2025

    @lukehsiao

    For reference, these are some of the issues that motivated the original constraint: #2394

  5. roycaihw commented on Oct 9, 2025

    @roycaihw
    Member

    The <2.4.0 pin was from #2417.

    cc @Tenzer

  6. roycaihw commented on Oct 9, 2025

    @roycaihw
    Member

    @Tenzer Based on the description in #2417, could you check if there is a good urllib3 version that is greater than 2.4.0?

    /help

  7. k8s-ci-robot commented on Oct 9, 2025

    @k8s-ci-robot
    Contributor

    @roycaihw:
    This request has been marked as needing help from a contributor.

    Guidelines

    Please ensure that the issue body includes answers to the following questions:

    • Why are we solving this issue?
    • To address this issue, are there any code changes? If there are code changes, what needs to be done in the code and what places can the assignee treat as reference points?
    • How can the assignee reach out to you for help?

    For more details on the requirements of such an issue, please see here and ensure that they are met.

    If this request no longer meets these requirements, the label can be removed
    by commenting with the /remove-help command.

    Details

    In response to this:

    @Tenzer Based on the description in #2417, could you check if there is a good urllib3 version that is greater than 2.4.0?

    /help

    Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

  8. added
    help wantedDenotes an issue that needs help from a contributor. Must meet "help wanted" guidelines.
    on Oct 9, 2025
  9. Tenzer commented on Oct 10, 2025

    @Tenzer
    Contributor

    @Tenzer Based on the description in #2417, could you check if there is a good urllib3 version that is greater than 2.4.0?

    The only more recent urllib3 release, v2.5.0, does not back down on the increased security stance, and I don't imagine it's something they would want to do, since they specifically made the change in v2.4.0 to align with what Python 3.13 does.

    In the original discussion about the urllib3 v2.4.0 issue, I suggested that an alternative way to address this could be to add an option to easily disable the extra strictness in urllib3: #2394 (comment). Perhaps that's an option worth investigating, so the maximum urllib3 version can be removed?

  10. ikalnytskyi commented on Oct 13, 2025

    @ikalnytskyi

    As far as I understand, urllib3 2.4 and above only breaks an edge-case scenario. Could we maybe remove the upper version constraint and instead let those affected pin urllib3 on their side?

  11. Tenzer commented on Oct 13, 2025

    @Tenzer
    Contributor

    Sounds good to me. There's also the workaround mentioned in #2394 (comment) for disabling the SSL verification for people who are affected.

  12. hoerup commented on Oct 30, 2025

    @hoerup

    Solved in #2461

  13. lukehsiao commented on Nov 10, 2025

    @lukehsiao

    We still need a release to get the solution. When is the next anticipated release?

  14. acornett21 commented on Dec 4, 2025

    @acornett21

    Just bumping this to see when a release might happen, since this is blocking work/releases for other projects. Thanks.

  15. gpupuck commented on Dec 10, 2025

    @gpupuck

    Just another bumping this to see when a release might happen, since this is blocking work/releases for other projects. Thanks.

  16. 3 remaining items

  17. bonastreyair commented on Dec 17, 2025

    @bonastreyair

    I wonder when it will be released...

  18. gpupuck commented on Dec 19, 2025

    @gpupuck

    Hi! When could we expect a new release? Thanks.

    /help

  19. lukehsiao commented on Dec 22, 2025

    @lukehsiao
  20. gpupuck commented on Jan 5, 2026

    @gpupuck

    Hi! When could we expect a new release? @yliaog @sathieu Many of our projects are blocked by this issue.

  21. sathieu commented on Jan 5, 2026

    @sathieu
    Contributor

    @gpupuck I don't have more info than: #2482 (comment)

  22. added a commit that references this issue on Jan 14, 2026
  23. yurnov commented on Aug 16, 2026

    @yurnov
    Contributor

    This looks resolved. master now has urllib3>=2.7.0,<3.0.0 in requirements.txt (and urllib3>=2.7.0 in requirements-asyncio.txt), and the released 36.0.3 on PyPI requires urllib3!=2.6.0,>=1.24.2 — the <2.4.0 cap is gone both in the tree and in a release.

    @jmontleon does that cover the packaging problem on your side?

    @yliaog I think this one can be closed.

  24. yliaog commented on Aug 16, 2026

    @yliaog
    Contributor

    thanks @yurnov

    /close

  25. kubernetes-prow commented on Aug 16, 2026

    @kubernetes-prow
    Contributor

    @yliaog: Closing this issue.

    Details

    In response to this:

    thanks @yurnov

    /close

    Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    help wantedDenotes an issue that needs help from a contributor. Must meet "help wanted" guidelines.kind/bugCategorizes issue or PR as related to a bug.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions