[openstack-dev] Please do *NOT* use "vendorized" versions of anything (here: glanceclient using requests.packages.urllib3)

Jeremy Stanley fungi at yuggoth.org
Fri Sep 19 14:01:09 UTC 2014


On 2014-09-18 14:35:10 +0000 (+0000), Ian Cordasco wrote:
> Except that even OpenStack doesn’t pin requests because of how
> extraordinarily stable our API is.
[...]

FWIW, I nearly capped it a few weeks ago with
https://review.openstack.org/117848 but since the affected projects
were able to rush in changes to their use of the library to work
around the ways it was breaking I ended up abandoning that. Also for
some months we capped requests in our global requirements because of
https://launchpad.net/bugs/1182271 but that was finally lifted about
a year ago with https://review.openstack.org/37461 (so I don't think
it's entirely fair to assert that "OpenStack doesn’t pin requests
because...extraordinarily stable").
-- 
Jeremy Stanley



More information about the OpenStack-dev mailing list