Skip to content

[flake8-bandit] fix S113 false positive for httpx without timeout argument - #12213

Merged
charliermarsh merged 3 commits into
astral-sh:mainfrom
trim21:fix-s113-httpx
Jul 6, 2024
Merged

charliermarsh merged 3 commits into
astral-sh:mainfrom
trim21:fix-s113-httpx

Conversation

@trim21

@trim21 trim21 commented Jul 6, 2024

Copy link
Copy Markdown
Contributor

Summary

S113 exists because requests doesn't have a default timeout, so request without timeout may hang indefinitely

B113: Test for missing requests timeout
This plugin test checks for requests or httpx calls without a timeout specified.

Nearly all production code should use this parameter in nearly all requests, Failure to do so can cause your program to hang indefinitely.

But httpx has default timeout 5s, so S113 for httpx request without timeout argument is a false positive, only valid case would be timeout=None.

https://www.python-httpx.org/advanced/timeouts/

HTTPX is careful to enforce timeouts everywhere by default.

The default behavior is to raise a TimeoutException after 5 seconds of network inactivity.

Test Plan

snap updated

@mkniewallner

Copy link
Copy Markdown
Contributor

We should also probably update the fixture to move the calls that don't pass timeout to the "OK" section.

@trim21

trim21 commented Jul 6, 2024

Copy link
Copy Markdown
Contributor Author

We should also probably update the fixture to move the calls that don't pass timeout to the "OK" section.

make sense

@charliermarsh charliermarsh added the bug An issue describing something that isn't working, or a PR that fixes a bug label Jul 6, 2024
@charliermarsh charliermarsh changed the title [flake8-bandit] fix S113 false positive for httpx without timeout argument [flake8-bandit] fix S113 false positive for httpx without timeout argument Jul 6, 2024
@charliermarsh

Copy link
Copy Markdown
Member

Thank you! Sorry that we missed this initially.

@charliermarsh
charliermarsh merged commit 757c757 into astral-sh:main Jul 6, 2024
@trim21
trim21 deleted the fix-s113-httpx branch July 6, 2024 19:56
ayaangazali added a commit to ayaangazali/ruff that referenced this pull request Aug 19, 2026
…al-sh#27868)

The docs say the rule checks `requests` or `httpx` calls that omit the
`timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which
stopped reporting on it because `httpx` already applies a five second timeout
by default, so omitting the parameter is not a hang risk there.

The description also never mentioned the case the rule does still check for
both modules, an explicit `timeout=None`, even though the violation message
has a separate wording for it.

Describe what the rule actually does: `requests` calls that omit `timeout`,
and `requests` or `httpx` calls that pass `timeout=None`. Say why the two
modules differ, so it is clear this is a deliberate distinction rather than a
gap.
ayaangazali added a commit to ayaangazali/ruff that referenced this pull request Aug 19, 2026
…al-sh#27868)

The docs say the rule checks `requests` or `httpx` calls that omit the
`timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which
stopped reporting on it because `httpx` already applies a five second timeout
by default, so omitting the parameter is not a hang risk there.

The description also never mentioned the case the rule does still check for
both modules, an explicit `timeout=None`, even though the violation message
has a separate wording for it.

Describe what the rule actually does: `requests` calls that omit `timeout`,
and `requests` or `httpx` calls that pass `timeout=None`. Say why the two
modules differ, so it is clear this is a deliberate distinction rather than a
gap.
ayaangazali added a commit to ayaangazali/ruff that referenced this pull request Aug 19, 2026
…al-sh#27868)

The docs say the rule checks `requests` or `httpx` calls that omit the
`timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which
stopped reporting on it because `httpx` already applies a five second timeout
by default, so omitting the parameter is not a hang risk there.

The description also never mentioned the case the rule does still check for
both modules, an explicit `timeout=None`, even though the violation message
has a separate wording for it.

Describe what the rule actually does: `requests` calls that omit `timeout`,
and `requests` or `httpx` calls that pass `timeout=None`. Say why the two
modules differ, so it is clear this is a deliberate distinction rather than a
gap.
ayaangazali added a commit to ayaangazali/ruff that referenced this pull request Aug 19, 2026
…al-sh#27868)

The docs say the rule checks `requests` or `httpx` calls that omit the
`timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which
stopped reporting on it because `httpx` already applies a five second timeout
by default, so omitting the parameter is not a hang risk there.

The description also never mentioned the case the rule does still check for
both modules, an explicit `timeout=None`, even though the violation message
has a separate wording for it.

Describe what the rule actually does: `requests` calls that omit `timeout`,
and `requests` or `httpx` calls that pass `timeout=None`. Say why the two
modules differ, so it is clear this is a deliberate distinction rather than a
gap.
ayaangazali added a commit to ayaangazali/ruff that referenced this pull request Aug 20, 2026
…al-sh#27868)

The docs say the rule checks `requests` or `httpx` calls that omit the
`timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which
stopped reporting on it because `httpx` already applies a five second timeout
by default, so omitting the parameter is not a hang risk there.

The description also never mentioned the case the rule does still check for
both modules, an explicit `timeout=None`, even though the violation message
has a separate wording for it.

Describe what the rule actually does: `requests` calls that omit `timeout`,
and `requests` or `httpx` calls that pass `timeout=None`. Say why the two
modules differ, so it is clear this is a deliberate distinction rather than a
gap.
ayaangazali added a commit to ayaangazali/ruff that referenced this pull request Aug 20, 2026
…al-sh#27868)

The docs say the rule checks `requests` or `httpx` calls that omit the
`timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which
stopped reporting on it because `httpx` already applies a five second timeout
by default, so omitting the parameter is not a hang risk there.

The description also never mentioned the case the rule does still check for
both modules, an explicit `timeout=None`, even though the violation message
has a separate wording for it.

Describe what the rule actually does: `requests` calls that omit `timeout`,
and `requests` or `httpx` calls that pass `timeout=None`. Say why the two
modules differ, so it is clear this is a deliberate distinction rather than a
gap.
itsvedantkumar added a commit to itsvedantkumar/ruff that referenced this pull request Aug 20, 2026
The rule's docs said it checks `requests` or `httpx` calls that omit
`timeout`. That has not been true for httpx since astral-sh#12213: omitting the
argument is fine there, and only an explicit `timeout=None` is reported.
The implementation only reports the implicit case when the module is
`requests`.

Assisted-by: Claude (Anthropic)
ayaangazali added a commit to ayaangazali/ruff that referenced this pull request Aug 20, 2026
…al-sh#27868)

The docs say the rule checks `requests` or `httpx` calls that omit the
`timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which
stopped reporting on it because `httpx` already applies a five second timeout
by default, so omitting the parameter is not a hang risk there.

The description also never mentioned the case the rule does still check for
both modules, an explicit `timeout=None`, even though the violation message
has a separate wording for it.

Describe what the rule actually does: `requests` calls that omit `timeout`,
and `requests` or `httpx` calls that pass `timeout=None`. Say why the two
modules differ, so it is clear this is a deliberate distinction rather than a
gap.
ayaangazali added a commit to ayaangazali/ruff that referenced this pull request Aug 20, 2026
…al-sh#27868)

The docs say the rule checks `requests` or `httpx` calls that omit the
`timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which
stopped reporting on it because `httpx` already applies a five second timeout
by default, so omitting the parameter is not a hang risk there.

The description also never mentioned the case the rule does still check for
both modules, an explicit `timeout=None`, even though the violation message
has a separate wording for it.

Describe what the rule actually does: `requests` calls that omit `timeout`,
and `requests` or `httpx` calls that pass `timeout=None`. Say why the two
modules differ, so it is clear this is a deliberate distinction rather than a
gap.
ayaangazali added a commit to ayaangazali/ruff that referenced this pull request Aug 20, 2026
…al-sh#27868)

The docs say the rule checks `requests` or `httpx` calls that omit the
`timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which
stopped reporting on it because `httpx` already applies a five second timeout
by default, so omitting the parameter is not a hang risk there.

The description also never mentioned the case the rule does still check for
both modules, an explicit `timeout=None`, even though the violation message
has a separate wording for it.

Describe what the rule actually does: `requests` calls that omit `timeout`,
and `requests` or `httpx` calls that pass `timeout=None`. Say why the two
modules differ, so it is clear this is a deliberate distinction rather than a
gap.
ayaangazali added a commit to ayaangazali/ruff that referenced this pull request Aug 21, 2026
…al-sh#27868)

The docs say the rule checks `requests` or `httpx` calls that omit the
`timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which
stopped reporting on it because `httpx` already applies a five second timeout
by default, so omitting the parameter is not a hang risk there.

The description also never mentioned the case the rule does still check for
both modules, an explicit `timeout=None`, even though the violation message
has a separate wording for it.

Describe what the rule actually does: `requests` calls that omit `timeout`,
and `requests` or `httpx` calls that pass `timeout=None`. Say why the two
modules differ, so it is clear this is a deliberate distinction rather than a
gap.
ayaangazali added a commit to ayaangazali/ruff that referenced this pull request Aug 21, 2026
…al-sh#27868)

The docs say the rule checks `requests` or `httpx` calls that omit the
`timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which
stopped reporting on it because `httpx` already applies a five second timeout
by default, so omitting the parameter is not a hang risk there.

The description also never mentioned the case the rule does still check for
both modules, an explicit `timeout=None`, even though the violation message
has a separate wording for it.

Describe what the rule actually does: `requests` calls that omit `timeout`,
and `requests` or `httpx` calls that pass `timeout=None`. Say why the two
modules differ, so it is clear this is a deliberate distinction rather than a
gap.
ayaangazali added a commit to ayaangazali/ruff that referenced this pull request Aug 21, 2026
…al-sh#27868)

The docs say the rule checks `requests` or `httpx` calls that omit the
`timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which
stopped reporting on it because `httpx` already applies a five second timeout
by default, so omitting the parameter is not a hang risk there.

The description also never mentioned the case the rule does still check for
both modules, an explicit `timeout=None`, even though the violation message
has a separate wording for it.

Describe what the rule actually does: `requests` calls that omit `timeout`,
and `requests` or `httpx` calls that pass `timeout=None`. Say why the two
modules differ, so it is clear this is a deliberate distinction rather than a
gap.
ayaangazali added a commit to ayaangazali/ruff that referenced this pull request Aug 21, 2026
…al-sh#27868)

The docs say the rule checks `requests` or `httpx` calls that omit the
`timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which
stopped reporting on it because `httpx` already applies a five second timeout
by default, so omitting the parameter is not a hang risk there.

The description also never mentioned the case the rule does still check for
both modules, an explicit `timeout=None`, even though the violation message
has a separate wording for it.

Describe what the rule actually does: `requests` calls that omit `timeout`,
and `requests` or `httpx` calls that pass `timeout=None`. Say why the two
modules differ, so it is clear this is a deliberate distinction rather than a
gap.
ayaangazali added a commit to ayaangazali/ruff that referenced this pull request Aug 21, 2026
…al-sh#27868)

The docs say the rule checks `requests` or `httpx` calls that omit the
`timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which
stopped reporting on it because `httpx` already applies a five second timeout
by default, so omitting the parameter is not a hang risk there.

The description also never mentioned the case the rule does still check for
both modules, an explicit `timeout=None`, even though the violation message
has a separate wording for it.

Describe what the rule actually does: `requests` calls that omit `timeout`,
and `requests` or `httpx` calls that pass `timeout=None`. Say why the two
modules differ, so it is clear this is a deliberate distinction rather than a
gap.
ayaangazali added a commit to ayaangazali/ruff that referenced this pull request Aug 22, 2026
…al-sh#27868)

The docs say the rule checks `requests` or `httpx` calls that omit the
`timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which
stopped reporting on it because `httpx` already applies a five second timeout
by default, so omitting the parameter is not a hang risk there.

The description also never mentioned the case the rule does still check for
both modules, an explicit `timeout=None`, even though the violation message
has a separate wording for it.

Describe what the rule actually does: `requests` calls that omit `timeout`,
and `requests` or `httpx` calls that pass `timeout=None`. Say why the two
modules differ, so it is clear this is a deliberate distinction rather than a
gap.
ayaangazali added a commit to ayaangazali/ruff that referenced this pull request Aug 23, 2026
…al-sh#27868)

The docs say the rule checks `requests` or `httpx` calls that omit the
`timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which
stopped reporting on it because `httpx` already applies a five second timeout
by default, so omitting the parameter is not a hang risk there.

The description also never mentioned the case the rule does still check for
both modules, an explicit `timeout=None`, even though the violation message
has a separate wording for it.

Describe what the rule actually does: `requests` calls that omit `timeout`,
and `requests` or `httpx` calls that pass `timeout=None`. Say why the two
modules differ, so it is clear this is a deliberate distinction rather than a
gap.
ayaangazali added a commit to ayaangazali/ruff that referenced this pull request Aug 23, 2026
…al-sh#27868)

The docs say the rule checks `requests` or `httpx` calls that omit the
`timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which
stopped reporting on it because `httpx` already applies a five second timeout
by default, so omitting the parameter is not a hang risk there.

The description also never mentioned the case the rule does still check for
both modules, an explicit `timeout=None`, even though the violation message
has a separate wording for it.

Describe what the rule actually does: `requests` calls that omit `timeout`,
and `requests` or `httpx` calls that pass `timeout=None`. Say why the two
modules differ, so it is clear this is a deliberate distinction rather than a
gap.
ayaangazali added a commit to ayaangazali/ruff that referenced this pull request Aug 24, 2026
…al-sh#27868)

The docs say the rule checks `requests` or `httpx` calls that omit the
`timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which
stopped reporting on it because `httpx` already applies a five second timeout
by default, so omitting the parameter is not a hang risk there.

The description also never mentioned the case the rule does still check for
both modules, an explicit `timeout=None`, even though the violation message
has a separate wording for it.

Describe what the rule actually does: `requests` calls that omit `timeout`,
and `requests` or `httpx` calls that pass `timeout=None`. Say why the two
modules differ, so it is clear this is a deliberate distinction rather than a
gap.
ayaangazali added a commit to ayaangazali/ruff that referenced this pull request Aug 25, 2026
…al-sh#27868)

The docs say the rule checks `requests` or `httpx` calls that omit the
`timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which
stopped reporting on it because `httpx` already applies a five second timeout
by default, so omitting the parameter is not a hang risk there.

The description also never mentioned the case the rule does still check for
both modules, an explicit `timeout=None`, even though the violation message
has a separate wording for it.

Describe what the rule actually does: `requests` calls that omit `timeout`,
and `requests` or `httpx` calls that pass `timeout=None`. Say why the two
modules differ, so it is clear this is a deliberate distinction rather than a
gap.
ayaangazali added a commit to ayaangazali/ruff that referenced this pull request Aug 25, 2026
…al-sh#27868)

The docs say the rule checks `requests` or `httpx` calls that omit the
`timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which
stopped reporting on it because `httpx` already applies a five second timeout
by default, so omitting the parameter is not a hang risk there.

The description also never mentioned the case the rule does still check for
both modules, an explicit `timeout=None`, even though the violation message
has a separate wording for it.

Describe what the rule actually does: `requests` calls that omit `timeout`,
and `requests` or `httpx` calls that pass `timeout=None`. Say why the two
modules differ, so it is clear this is a deliberate distinction rather than a
gap.
ayaangazali added a commit to ayaangazali/ruff that referenced this pull request Aug 26, 2026
…al-sh#27868)

The docs say the rule checks `requests` or `httpx` calls that omit the
`timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which
stopped reporting on it because `httpx` already applies a five second timeout
by default, so omitting the parameter is not a hang risk there.

The description also never mentioned the case the rule does still check for
both modules, an explicit `timeout=None`, even though the violation message
has a separate wording for it.

Describe what the rule actually does: `requests` calls that omit `timeout`,
and `requests` or `httpx` calls that pass `timeout=None`. Say why the two
modules differ, so it is clear this is a deliberate distinction rather than a
gap.
ayaangazali added a commit to ayaangazali/ruff that referenced this pull request Aug 26, 2026
…al-sh#27868)

The docs say the rule checks `requests` or `httpx` calls that omit the
`timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which
stopped reporting on it because `httpx` already applies a five second timeout
by default, so omitting the parameter is not a hang risk there.

The description also never mentioned the case the rule does still check for
both modules, an explicit `timeout=None`, even though the violation message
has a separate wording for it.

Describe what the rule actually does: `requests` calls that omit `timeout`,
and `requests` or `httpx` calls that pass `timeout=None`. Say why the two
modules differ, so it is clear this is a deliberate distinction rather than a
gap.
ayaangazali added a commit to ayaangazali/ruff that referenced this pull request Aug 27, 2026
…al-sh#27868)

The docs say the rule checks `requests` or `httpx` calls that omit the
`timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which
stopped reporting on it because `httpx` already applies a five second timeout
by default, so omitting the parameter is not a hang risk there.

The description also never mentioned the case the rule does still check for
both modules, an explicit `timeout=None`, even though the violation message
has a separate wording for it.

Describe what the rule actually does: `requests` calls that omit `timeout`,
and `requests` or `httpx` calls that pass `timeout=None`. Say why the two
modules differ, so it is clear this is a deliberate distinction rather than a
gap.
ayaangazali added a commit to ayaangazali/ruff that referenced this pull request Aug 27, 2026
…al-sh#27868)

The docs say the rule checks `requests` or `httpx` calls that omit the
`timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which
stopped reporting on it because `httpx` already applies a five second timeout
by default, so omitting the parameter is not a hang risk there.

The description also never mentioned the case the rule does still check for
both modules, an explicit `timeout=None`, even though the violation message
has a separate wording for it.

Describe what the rule actually does: `requests` calls that omit `timeout`,
and `requests` or `httpx` calls that pass `timeout=None`. Say why the two
modules differ, so it is clear this is a deliberate distinction rather than a
gap.
ayaangazali added a commit to ayaangazali/ruff that referenced this pull request Aug 28, 2026
…al-sh#27868)

The docs say the rule checks `requests` or `httpx` calls that omit the
`timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which
stopped reporting on it because `httpx` already applies a five second timeout
by default, so omitting the parameter is not a hang risk there.

The description also never mentioned the case the rule does still check for
both modules, an explicit `timeout=None`, even though the violation message
has a separate wording for it.

Describe what the rule actually does: `requests` calls that omit `timeout`,
and `requests` or `httpx` calls that pass `timeout=None`. Say why the two
modules differ, so it is clear this is a deliberate distinction rather than a
gap.
ayaangazali added a commit to ayaangazali/ruff that referenced this pull request Aug 28, 2026
…al-sh#27868)

The docs say the rule checks `requests` or `httpx` calls that omit the
`timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which
stopped reporting on it because `httpx` already applies a five second timeout
by default, so omitting the parameter is not a hang risk there.

The description also never mentioned the case the rule does still check for
both modules, an explicit `timeout=None`, even though the violation message
has a separate wording for it.

Describe what the rule actually does: `requests` calls that omit `timeout`,
and `requests` or `httpx` calls that pass `timeout=None`. Say why the two
modules differ, so it is clear this is a deliberate distinction rather than a
gap.
ayaangazali added a commit to ayaangazali/ruff that referenced this pull request Aug 29, 2026
…al-sh#27868)

The docs say the rule checks `requests` or `httpx` calls that omit the
`timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which
stopped reporting on it because `httpx` already applies a five second timeout
by default, so omitting the parameter is not a hang risk there.

The description also never mentioned the case the rule does still check for
both modules, an explicit `timeout=None`, even though the violation message
has a separate wording for it.

Describe what the rule actually does: `requests` calls that omit `timeout`,
and `requests` or `httpx` calls that pass `timeout=None`. Say why the two
modules differ, so it is clear this is a deliberate distinction rather than a
gap.
ayaangazali added a commit to ayaangazali/ruff that referenced this pull request Aug 29, 2026
…al-sh#27868)

The docs say the rule checks `requests` or `httpx` calls that omit the
`timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which
stopped reporting on it because `httpx` already applies a five second timeout
by default, so omitting the parameter is not a hang risk there.

The description also never mentioned the case the rule does still check for
both modules, an explicit `timeout=None`, even though the violation message
has a separate wording for it.

Describe what the rule actually does: `requests` calls that omit `timeout`,
and `requests` or `httpx` calls that pass `timeout=None`. Say why the two
modules differ, so it is clear this is a deliberate distinction rather than a
gap.
ayaangazali added a commit to ayaangazali/ruff that referenced this pull request Aug 30, 2026
…al-sh#27868)

The docs say the rule checks `requests` or `httpx` calls that omit the
`timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which
stopped reporting on it because `httpx` already applies a five second timeout
by default, so omitting the parameter is not a hang risk there.

The description also never mentioned the case the rule does still check for
both modules, an explicit `timeout=None`, even though the violation message
has a separate wording for it.

Describe what the rule actually does: `requests` calls that omit `timeout`,
and `requests` or `httpx` calls that pass `timeout=None`. Say why the two
modules differ, so it is clear this is a deliberate distinction rather than a
gap.
ayaangazali added a commit to ayaangazali/ruff that referenced this pull request Aug 31, 2026
…al-sh#27868)

The docs say the rule checks `requests` or `httpx` calls that omit the
`timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which
stopped reporting on it because `httpx` already applies a five second timeout
by default, so omitting the parameter is not a hang risk there.

The description also never mentioned the case the rule does still check for
both modules, an explicit `timeout=None`, even though the violation message
has a separate wording for it.

Describe what the rule actually does: `requests` calls that omit `timeout`,
and `requests` or `httpx` calls that pass `timeout=None`. Say why the two
modules differ, so it is clear this is a deliberate distinction rather than a
gap.
vitorantoniazzi added a commit to vitorantoniazzi/ruff that referenced this pull request Sep 2, 2026
The rule stopped flagging `httpx` calls that omit `timeout` in astral-sh#12213,
since httpx applies a default timeout. Update the documentation to
describe what the rule actually checks.
ayaangazali added a commit to ayaangazali/ruff that referenced this pull request Sep 5, 2026
…al-sh#27868)

The docs say the rule checks `requests` or `httpx` calls that omit the
`timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which
stopped reporting on it because `httpx` already applies a five second timeout
by default, so omitting the parameter is not a hang risk there.

The description also never mentioned the case the rule does still check for
both modules, an explicit `timeout=None`, even though the violation message
has a separate wording for it.

Describe what the rule actually does: `requests` calls that omit `timeout`,
and `requests` or `httpx` calls that pass `timeout=None`. Say why the two
modules differ, so it is clear this is a deliberate distinction rather than a
gap.
ayaangazali added a commit to ayaangazali/ruff that referenced this pull request Sep 6, 2026
…al-sh#27868)

The docs say the rule checks `requests` or `httpx` calls that omit the
`timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which
stopped reporting on it because `httpx` already applies a five second timeout
by default, so omitting the parameter is not a hang risk there.

The description also never mentioned the case the rule does still check for
both modules, an explicit `timeout=None`, even though the violation message
has a separate wording for it.

Describe what the rule actually does: `requests` calls that omit `timeout`,
and `requests` or `httpx` calls that pass `timeout=None`. Say why the two
modules differ, so it is clear this is a deliberate distinction rather than a
gap.
ayaangazali added a commit to ayaangazali/ruff that referenced this pull request Sep 6, 2026
…al-sh#27868)

The docs say the rule checks `requests` or `httpx` calls that omit the
`timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which
stopped reporting on it because `httpx` already applies a five second timeout
by default, so omitting the parameter is not a hang risk there.

The description also never mentioned the case the rule does still check for
both modules, an explicit `timeout=None`, even though the violation message
has a separate wording for it.

Describe what the rule actually does: `requests` calls that omit `timeout`,
and `requests` or `httpx` calls that pass `timeout=None`. Say why the two
modules differ, so it is clear this is a deliberate distinction rather than a
gap.
ayaangazali added a commit to ayaangazali/ruff that referenced this pull request Sep 12, 2026
…al-sh#27868)

The docs say the rule checks `requests` or `httpx` calls that omit the
`timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which
stopped reporting on it because `httpx` already applies a five second timeout
by default, so omitting the parameter is not a hang risk there.

The description also never mentioned the case the rule does still check for
both modules, an explicit `timeout=None`, even though the violation message
has a separate wording for it.

Describe what the rule actually does: `requests` calls that omit `timeout`,
and `requests` or `httpx` calls that pass `timeout=None`. Say why the two
modules differ, so it is clear this is a deliberate distinction rather than a
gap.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug An issue describing something that isn't working, or a PR that fixes a bug

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants