Skip to content

Drop support for Python 3.8 & upgrade urllib3 to 2.5.0 #1574

@WilliamCollishaw

Description

@WilliamCollishaw

Summary

Drop support for Python 3.8 & upgrade urllib3 to 2.5.0. The version of urllib3 currently in use contains some security findings and we're at a stage where this can be upgraded. See additional context.

If there is already a timeline planned for this release, would love to know what that is.

Desired Behavior

Should be no change in behavior minus no support for Python 3.8

Possible Solution

Self explanitory

Additional context

The version of urllib3 being used currently is triggering security findings in our scanners. New relic have stated a version dropping support for Python 3.8 should be released and in November 2025 (source) and urllib3 is only being held back at an old version because they have already dropped python 3.8 support (as of 2.2.0). There should no longer be any reason to accept the risk of CVE-2025-50181 as is being done here.

Metadata

Metadata

Assignees

No one assigned

    Labels

    needs-triageRequires initial review by maintainers.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions