chore(deps): update dependency certifi to v2023.7.22 [security] - autoclosed
Metadata
Current evaluation
Renovate bot PR updating certifi to v2023.7.22 for CVE-2023-37920 was autoclosed due to inactivity. Automerge was disabled by configuration, and the request received no reviews or CI checks before automatic closure.
Suggested action: —
No scores available.
Issue body
[](https://renovatebot.com)
This PR contains the following updates:
| Package | Change | Age | Adoption | Passing | Confidence |
|---|---|---|---|---|---|
| [certifi](https://togithub.com/certifi/python-certifi) | `==2023.5.7` -> `==2023.7.22` | [](https://docs.renovatebot.com/merge-confidence/) | [](https://docs.renovatebot.com/merge-confidence/) | [](https://docs.renovatebot.com/merge-confidence/) | [](https://docs.renovatebot.com/merge-confidence/) |
### GitHub Vulnerability Alerts
#### [CVE-2023-37920](https://togithub.com/certifi/python-certifi/security/advisories/GHSA-xqr8-7jwr-rhp7)
Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store. These are in the process of being removed from Mozilla's trust store.
e-Tugra's root certificates are being removed pursuant to an investigation prompted by reporting of security issues in their systems. Conclusions of Mozilla's investigation can be found [here](https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/C-HrP1SEq1A).
---
### Release Notes
<details>
<summary>certifi/python-certifi (certifi)</summary>
### [`v2023.7.22`](https://togithub.com/certifi/python-certifi/compare/2023.05.07...2023.07.22)
[Compare Source](https://togithub.com/certifi/python-certifi/compare/2023.05.07...2023.07.22)
</details>
---
### Configuration
📅 **Schedule**: Branch creation - "" in timezone Etc/UTC, Automerge - "before 07:00" in timezone Etc/UTC.
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://www.mend.io/free-developer-tools/renovate/). View repository job log [here](https://developer.mend.io/github/canonical/charmcraft).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNi4xMS4wIiwidXBkYXRlZEluVmVyIjoiMzYuMTEuMCIsInRhcmdldEJyYW5jaCI6Im1haW4ifQ==-->
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Renovate bot PR updating certifi to v2023.7.22 for CVE-2023-37920 was autoclosed due to inactivity. Automerge was disabled by configuration, and the request received no reviews or CI checks before automatic closure. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Renovate bot PR updating certifi to v2023.7.22 for CVE-2023-37920 was autoclosed without merging. The security dependency update was abandoned and never applied. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Renovate bot PR to update certifi to v2023.7.22 for CVE-2023-37920 was autoclosed due to inactivity. The security dependency update was never merged. |
Update history
No update history recorded yet.
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #4897 chore(deps): update dependency certifi to v2024 [security] - autoclosed | snapcraft | closed | The certifi v2024.7.4 security update was automatically closed without merging. Renovate bot generated the dependency change, but it was abandoned due to inactivity, leaving the repository on the previous version. | |
| #1720 chore(deps): update dependency certifi to v2024.7.4 [security] | charmcraft | merged | Merged a security update upgrading certifi from v2024.6.2 to v2024.7.4 to address CVE-2024-39689. Approved by two reviewers, passed CI checks, and merged into main. | |
| #4856 chore(deps): update dependency requests to v2.32.2 [security] - autoclosed | snapcraft | closed | Renovate's dependency update PR for requests to v2.32.2 was autoclosed without merging. The bot automatically closed the stale pull request, leaving the CVE-2024-35195 security fix unapplied. | |
| #1695 chore(deps): update dependency certifi to v2024.6.2 | charmcraft | merged | Merged automated dependency update for certifi from v2024.2.2 to v2024.6.2. Approved by two reviewers with passing CI checks. Modified two files. | |
| #1689 chore(deps): update dependency requests to v2.32.0 [security] - autoclosed | charmcraft | closed | Renovate bot dependency update to requests v2.32.0 for CVE-2024-35195 was autoclosed. The branch was abandoned without review or merge, as the update was likely already applied or superseded. | |
| #4773 chore(deps): update dependency pip to v23 [security] - autoclosed | snapcraft | closed | Automatically closed without merging. The Renovate bot dependency update upgrading pip to v23.3 to address CVE-2023-5752 was abandoned, likely due to staleness or repository configuration. | |
| #15 Update dependency certifi to v2023 [SECURITY] - autoclosed | imagecraft | closed | Security update PR for certifi to v2023.7.22 was autoclosed without merging. Renovate automatically closed the pull request due to expiration or branch updates, leaving the dependency unupdated. | |
| #4812 chore(deps): update dependency requests to v2.32.0 [security] - autoclosed | snapcraft | closed | Renovate pull request updating requests to v2.32.0 to address CVE-2024-35195 was autoclosed without merging. The dependency update was likely handled separately or the branch expired. | |
| #1111 chore(deps): update dependency requests to v2.31.0 [security] - abandoned | charmcraft | closed | Renovate-generated dependency update to requests v2.31.0 for CVE-2023-32681 was closed and abandoned. Autoclosing was skipped due to branch modifications, leading to manual closure. | |
| #45 Update dependency certifi to v2024.7.4 [SECURITY] - autoclosed | imagecraft | closed | Renovate dependency update for certifi to v2024.7.4 was autoclosed due to inactivity. Automerge was disabled, and the branch was never merged. |