You can use boolean logic (e.g. AND/OR/NOT) for complex search queries. For more help and examples, see the search documentation.
Search by package name:
my-package (implicit)
name:my-package (explicit)
Search by package filename:
filename:my-package.ext
Search by package tag:
tag:latest
Search by package version:
version:1.0.0
prerelease:true (prereleases)
prerelease:false (no prereleases)
Search by package architecture:
architecture:x86_64
Search by package distribution:
distribution:el
Search by package license:
license:MIT
Search by package format:
format:deb
Search by package status:
status:in_progress
Search by package file checksum:
checksum:5afba
Search by package security status:
severity:critical
Search by package vulnerabilities:
vulnerabilities:>1
vulnerabilities:<1000
Search by # of package downloads:
downloads:>8
downloads:<100
Search by package type:
type:binary
type:source
Search by package size (bytes):
size:>50000
size:<10000
Search by dependency name/version:
dependency:log4j
dependency:log4j=1.0.0
dependency:log4j>1.0.0
Search by uploaded date:
uploaded:>"1 day ago"
uploaded:<"August 14, 2022 EST"
Search by entitlement token (identifier):
entitlement:3lKPVJPosCsY
Search by policy violation:
policy_violated:true
deny_policy_violated:true
license_policy_violated:true
vulnerability_policy_violated:true
Search by repository:
repository:repo-name
Search by last download date:
last_downloaded:<"30 days ago"
last_downloaded:>"August 14, 2022 EST"
Search queries for all Debian-specific (and related) package types
Search by component:
deb_component:unstable
Search queries for all Maven-specific (and related) package types
Search by group ID:
maven_group_id:org.apache
Search queries for all Docker-specific (and related) package types
Search by image digest:
docker_image_digest:sha256:7c5..6d4
(full hashref only)
Search by layer digest:
docker_layer_digest:sha256:4c4..ae4
(full hashref only)
Search queries for all Generic-specific package types
Search by file path:
generic_filepath:path/to/file.txt
Search by directory:
generic_directory:path/to
Field type modifiers (depending on the type, you can influence behaviour)
For all queries, you can use:
~foo for negation
For string queries, you can use:
^foo to anchor to start of term
foo$ to anchor to end of term
foo*bar for fuzzy matching
For number/date or version queries, you can use:
>foo for values greater than
>=foo for values greater / equal
<foo for values less than
<=foo for values less / equal
Need a secure and centralised artifact repository to deliver Alpine,
Cargo,
CocoaPods,
Composer,
Conan,
Conda,
CRAN,
Dart,
Debian,
Docker,
Generic,
Go,
Helm,
Hex,
HuggingFace,
LuaRocks,
Maven,
MCP,
npm,
NuGet,
P2,
Python,
RedHat,
Ruby,
Swift,
Terraform,
Vagrant,
VSX,
Raw & More packages?
Cloudsmith is the new standard in Package / Artifact Management and Software Distribution.
With support for all major package formats, you can trust us to manage your software supply chain.
This package is in violation of the following policy.
Medium severity CVEs:
- A security scan detected a vulnerability with a severity which is not permitted by this policy.
requests
1.2.0
One-liner (summary)
Description
License
Size
333.5 KB
Downloads
0
Tags
sdist gz noarch upstream python-upstream-pro… high_sev_less_than_… high-sev
| Status | Quarantined |
|---|---|
| Checksum (MD5) | 22af2682233770e5468a986f451c51c0 |
| Checksum (SHA-1) | 2e310dfc886a696c776b859a347b4edc5515c103 |
| Checksum (SHA-256) | cfa615644ae38efe8423ce9edb23470a4615a9147fa3cea5026afb47c9bb3913 |
| Checksum (SHA-512) | b23447d49a09f8b6ed3e718afd46e95deb6de97f0a263e41ead7cce155c9950e14… |
| GPG Signature | |
| GPG Fingerprint | 6811684bac0b8895434e97bdd4391b8fb999e537 |
| Storage Region | Dublin, Ireland |
| Type | Source (contains source code or documentation) |
| Uploaded At | 9 months, 2 weeks ago |
| Uploaded By |
|
| Slug Id | requests-120targz-ybwj |
| Unique Id | NlNfigAgB5Wqc5WK |
| Version (Raw) | 1.2.0 |
| Version (Parsed) |
|
| extended metadata | |
| Author | Kenneth Reitz <me@kennethreitz.com> |
| Homepage URL | http://python-requests.org |
| Metadata Version | 1.1 |
| Py Filetype | sdist |
| pkg | requests-1.2.0.tar.gz |
0
333.5 KB |
md5 | sha1 | sha256 | sha512 |
This package has 90 files/directories.
Last scanned
9 months, 2 weeks ago
Scan result
Vulnerable
Vulnerability count
5
Max. severity
High| Target: | requirements.txt | |
| HIGH |
CVE-2018-18074: python-requests: Redirect from HTTPS to HTTP does not remove Authorization headerThe Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.Package Name: requests Installed Version: 1.2.0 Fixed Version: 2.20.0 References: docs.python-requests.org lists.opensuse.org access.redhat.com access.redhat.com bugs.debian.org errata.almalinux.org github.com github.com github.com github.com github.com linux.oracle.com linux.oracle.com nvd.nist.gov ubuntu.com ubuntu.com usn.ubuntu.com usn.ubuntu.com usn.ubuntu.com usn.ubuntu.com www.cve.org www.oracle.com |
|
| MEDIUM |
CVE-2014-1829: python-requests: redirect can expose netrc passwordRequests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request.Package Name: requests Installed Version: 1.2.0 Fixed Version: 2.3.0 References: advisories.mageia.org www.debian.org www.mandriva.com www.openwall.com www.ubuntu.com access.redhat.com bugs.debian.org github.com github.com github.com github.com github.com github.com nvd.nist.gov ubuntu.com web.archive.org www.cve.org |
|
| MEDIUM |
CVE-2014-1830: python-requests: Proxy-Authorization header leakRequests (aka python-requests) before 2.3.0 allows remote servers to obtain sensitive information by reading the Proxy-Authorization header in a redirected request.Package Name: requests Installed Version: 1.2.0 Fixed Version: 2.3.0 References: advisories.mageia.org lists.opensuse.org www.debian.org www.mandriva.com www.openwall.com access.redhat.com bugs.debian.org github.com github.com github.com github.com github.com nvd.nist.gov ubuntu.com web.archive.org www.cve.org |
|
| MEDIUM |
CVE-2024-35195: requests: subsequent requests to the same host ignore cert verificationRequests is a HTTP library. Prior to 2.32.0, when making requests through a Requests `Session`, if the first request is made with `verify=False` to disable cert verification, all subsequent requests to the same host will continue to ignore cert verification regardless of changes to the value of `verify`. This behavior will continue for the lifecycle of the connection in the connection pool. This vulnerability is fixed in 2.32.0.Package Name: requests Installed Version: 1.2.0 Fixed Version: 2.32.0 References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com github.com github.com github.com linux.oracle.com linux.oracle.com lists.fedoraproject.org lists.fedoraproject.org lists.fedoraproject.org lists.fedoraproject.org nvd.nist.gov www.cve.org |
|
| MEDIUM |
CVE-2024-47081: requests: Requests vulnerable to .netrc credentials leak via malicious URLsRequests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. Users should upgrade to version 2.32.4 to receive a fix. For older versions of Requests, use of the .netrc file can be disabled with `trust_env=False` on one's Requests Session.Package Name: requests Installed Version: 1.2.0 Fixed Version: 2.32.4 References: seclists.org www.openwall.com www.openwall.com www.openwall.com www.openwall.com access.redhat.com github.com github.com github.com github.com nvd.nist.gov requests.readthedocs.io seclists.org ubuntu.com www.cve.org www.openwall.com |
|
Package statistics are no longer available on cloudsmith.io. Please visit our new web app to access this feature.
You can embed a badge in another website that shows this or the latest version of this package.
To embed the badge for this specific package version, use the following:
[](https://cloudsmith.io/~demo-docs/repos/awesome-repo/packages/detail/python/requests/1.2.0/a=noarch;xf=sdist;xn=requests/)
|This version of 'requests' @ Cloudsmith|
.. |This version of 'requests' @ Cloudsmith| image:: https://api.cloudsmith.com/v1/badges/version/demo-docs/awesome-repo/python/requests/1.2.0/a=noarch;xf=sdist;xn=requests/?render=true
:target: https://cloudsmith.io/~demo-docs/repos/awesome-repo/packages/detail/python/requests/1.2.0/a=noarch;xf=sdist;xn=requests/
image::https://api.cloudsmith.com/v1/badges/version/demo-docs/awesome-repo/python/requests/1.2.0/a=noarch;xf=sdist;xn=requests/?render=true[link="https://cloudsmith.io/~demo-docs/repos/awesome-repo/packages/detail/python/requests/1.2.0/a=noarch;xf=sdist;xn=requests/",title="This version of 'requests' @ Cloudsmith"]
<a href="https://cloudsmith.io/~demo-docs/repos/awesome-repo/packages/detail/python/requests/1.2.0/a=noarch;xf=sdist;xn=requests/"><img src="https://api.cloudsmith.com/v1/badges/version/demo-docs/awesome-repo/python/requests/1.2.0/a=noarch;xf=sdist;xn=requests/?render=true" alt="This version of 'requests' @ Cloudsmith" /></a>
rendered as:
To embed the badge for the latest package version, use the following:
[](https://cloudsmith.io/~demo-docs/repos/awesome-repo/packages/detail/python/requests/latest/a=noarch;xf=sdist;xn=requests/)
|Latest version of 'requests' @ Cloudsmith|
.. |Latest version of 'requests' @ Cloudsmith| image:: https://api.cloudsmith.com/v1/badges/version/demo-docs/awesome-repo/python/requests/latest/a=noarch;xf=sdist;xn=requests/?render=true&show_latest=true
:target: https://cloudsmith.io/~demo-docs/repos/awesome-repo/packages/detail/python/requests/latest/a=noarch;xf=sdist;xn=requests/
image::https://api.cloudsmith.com/v1/badges/version/demo-docs/awesome-repo/python/requests/latest/a=noarch;xf=sdist;xn=requests/?render=true&show_latest=true[link="https://cloudsmith.io/~demo-docs/repos/awesome-repo/packages/detail/python/requests/latest/a=noarch;xf=sdist;xn=requests/",title="Latest version of 'requests' @ Cloudsmith"]
<a href="https://cloudsmith.io/~demo-docs/repos/awesome-repo/packages/detail/python/requests/latest/a=noarch;xf=sdist;xn=requests/"><img src="https://api.cloudsmith.com/v1/badges/version/demo-docs/awesome-repo/python/requests/latest/a=noarch;xf=sdist;xn=requests/?render=true&show_latest=true" alt="Latest version of 'requests' @ Cloudsmith" /></a>
rendered as: