Moved headers input type back to Mapping to avoid invariance issues
with MutableMapping and inferred dict types. Users calling Request.headers.update() may need to narrow typing in their code. (#7441)
Requests 2.34.0 introduces inline types, replacing those provided by
typeshed. Public API types should be fully compatible with mypy, pyright,
and ty. We believe types are comprehensive but if you find issues, please
report them to the pinned tracking issue.
Response.history no longer contains a reference to itself, preventing
accidental looping when traversing the history list. (#7328)
Requests no longer performs greedy matching on no_proxy domains. The
proxy_bypass implementation has been updated with CPython's fix from
bpo-39057. (#7427)
Requests no longer incorrectly strips duplicate leading slashes in
URI paths. This should address user issues with specific presigned
URLs. Note the full fix requires urllib3 2.7.0+. (#7315)
This PR contains the following updates:
| Package | Update | Change |
|---|---|---|
| [requests](https://github.com/psf/requests) ([changelog](https://github.com/psf/requests/blob/master/HISTORY.md)) | minor | `==2.33.0` → `==2.34.2` |
---
### Release Notes
<details>
<summary>psf/requests (requests)</summary>
### [`v2.34.2`](https://github.com/psf/requests/blob/HEAD/HISTORY.md#2342-2026-05-14)
[Compare Source](https://github.com/psf/requests/compare/v2.34.1...v2.34.2)
- Moved `headers` input type back to `Mapping` to avoid invariance issues
with `MutableMapping` and inferred dict types. Users calling
`Request.headers.update()` may need to narrow typing in their code. ([#​7441](https://github.com/psf/requests/issues/7441))
### [`v2.34.1`](https://github.com/psf/requests/blob/HEAD/HISTORY.md#2341-2026-05-13)
[Compare Source](https://github.com/psf/requests/compare/v2.34.0...v2.34.1)
**Bugfixes**
- Widened `json` input type from `dict` and `list` to `Mapping`
and `Sequence`. ([#​7436](https://github.com/psf/requests/issues/7436))
- Changed `headers` input type to MutableMapping and removed `None` from
`Request.headers` typing to improve handling for users. ([#​7431](https://github.com/psf/requests/issues/7431))
- `Response.reason` moved from `str | None` to `str` to improve handling
for users. ([#​7437](https://github.com/psf/requests/issues/7437))
- Fixed a bug where some bodies with custom `__getattr__` implementations
weren't being properly detected as Iterables. ([#​7433](https://github.com/psf/requests/issues/7433))
### [`v2.34.0`](https://github.com/psf/requests/blob/HEAD/HISTORY.md#2340-2026-05-11)
[Compare Source](https://github.com/psf/requests/compare/v2.33.1...v2.34.0)
**Announcements**
- Requests 2.34.0 introduces inline types, replacing those provided by
typeshed. Public API types should be fully compatible with mypy, pyright,
and ty. We believe types are comprehensive but if you find issues, please
report them to the pinned tracking issue.
Special thanks to [@​bastimeyer](https://github.com/bastimeyer), [@​cthoyt](https://github.com/cthoyt), [@​edgarrmondragon](https://github.com/edgarrmondragon), and [@​srittau](https://github.com/srittau) for
helping review and test the types ahead of the release. ([#​7272](https://github.com/psf/requests/issues/7272))
**Improvements**
- Digest Auth hashing algorithms have added `usedforsecurity=False` to clarify
security considerations. ([#​7310](https://github.com/psf/requests/issues/7310))
- Requests added support for Python 3.15 based on beta1. Downstream projects
should be able to start testing prior to its release in October. ([#​7422](https://github.com/psf/requests/issues/7422))
- Requests added support for Python 3.14t. ([#​7419](https://github.com/psf/requests/issues/7419))
**Bugfixes**
- `Response.history` no longer contains a reference to itself, preventing
accidental looping when traversing the history list. ([#​7328](https://github.com/psf/requests/issues/7328))
- Requests no longer performs greedy matching on no\_proxy domains. The
proxy\_bypass implementation has been updated with CPython's fix from
bpo-39057. ([#​7427](https://github.com/psf/requests/issues/7427))
- Requests no longer incorrectly strips duplicate leading slashes in
URI paths. This should address user issues with specific presigned
URLs. Note the full fix requires urllib3 2.7.0+. ([#​7315](https://github.com/psf/requests/issues/7315))
### [`v2.33.1`](https://github.com/psf/requests/blob/HEAD/HISTORY.md#2331-2026-03-30)
[Compare Source](https://github.com/psf/requests/compare/v2.33.0...v2.33.1)
**Bugfixes**
- Fixed test cleanup for CVE-2026-25645 to avoid leaving unnecessary
files in the tmp directory. ([#​7305](https://github.com/psf/requests/issues/7305))
- Fixed Content-Type header parsing for malformed values. ([#​7309](https://github.com/psf/requests/issues/7309))
- Improved error consistency for malformed header values. ([#​7308](https://github.com/psf/requests/issues/7308))
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTUuMTIiLCJ1cGRhdGVkSW5WZXIiOiI0My4xOTUuMTIiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbXX0=-->
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
This PR contains the following updates:
==2.33.0→==2.34.2Release Notes
psf/requests (requests)
v2.34.2Compare Source
headersinput type back toMappingto avoid invariance issueswith
MutableMappingand inferred dict types. Users callingRequest.headers.update()may need to narrow typing in their code. (#7441)v2.34.1Compare Source
Bugfixes
jsoninput type fromdictandlisttoMappingand
Sequence. (#7436)headersinput type to MutableMapping and removedNonefromRequest.headerstyping to improve handling for users. (#7431)Response.reasonmoved fromstr | Nonetostrto improve handlingfor users. (#7437)
__getattr__implementationsweren't being properly detected as Iterables. (#7433)
v2.34.0Compare Source
Announcements
Requests 2.34.0 introduces inline types, replacing those provided by
typeshed. Public API types should be fully compatible with mypy, pyright,
and ty. We believe types are comprehensive but if you find issues, please
report them to the pinned tracking issue.
Special thanks to @bastimeyer, @cthoyt, @edgarrmondragon, and @srittau for
helping review and test the types ahead of the release. (#7272)
Improvements
usedforsecurity=Falseto clarifysecurity considerations. (#7310)
should be able to start testing prior to its release in October. (#7422)
Bugfixes
Response.historyno longer contains a reference to itself, preventingaccidental looping when traversing the history list. (#7328)
proxy_bypass implementation has been updated with CPython's fix from
bpo-39057. (#7427)
URI paths. This should address user issues with specific presigned
URLs. Note the full fix requires urllib3 2.7.0+. (#7315)
v2.33.1Compare Source
Bugfixes
files in the tmp directory. (#7305)
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate.