Requests
PyPIrequestsRequests is the most-downloaded Python package, used for making HTTP calls from essentially every Python application that interacts with external APIs. It is present in scripts, services, CLI tools, and notebooks. Many packages use Requests internally as their HTTP transport.
Checking Requests
requests 2.32.0 is a clean, monitored version with no known supply chain compromise. The example response returns supply_chain_monitored: true and compromised: false with an empty sources array.
curl "https://api.attestd.io/v1/check?product=requests&version=2.32.0" \
-H "Authorization: Bearer YOUR_API_KEY"{
"product": "requests",
"version": "2.32.0",
"supported": true,
"risk_state": "none",
"risk_factors": [],
"actively_exploited": false,
"remote_exploitable": false,
"authentication_required": false,
"patch_available": false,
"fixed_version": null,
"confidence": 0.9,
"cve_ids": [],
"cves": null,
"max_epss": null,
"typosquat": null,
"supply_chain_monitored": true,
"supply_chain": {
"compromised": false,
"sources": [],
"malware_type": null,
"description": null,
"advisory_url": null,
"compromised_at": null,
"removed_at": null
},
"last_updated": "2026-05-01T00:00:00Z"
}Why this package is monitored
Requests is the outbound HTTP path for a large share of Python services and transitive dependencies. Malicious code can copy Authorization headers and request bodies on every call that uses the library.
Attestd monitors requests using the following detection sources:
registryManually curated advisories in the Attestd registry, verified by a human analyst. Confidence 1.0.
osvOSV.dev malicious-package advisories with IDs prefixed MAL-. Confidence 0.95.
pypi_yankVersions yanked on PyPI with a security-related yanked_reason annotation. Confidence 0.80.