← Back to issue list

build(deps-dev): bump h11 from 0.14.0 to 0.16.0

View original Github issue

Metadata

Project
charmcraft
Number
#2267
Type
pull request
State
closed
Author
dependabot[bot]
Labels
Created
Updated
Closed

Current evaluation

Dependabot PR to bump h11 from 0.14.0 to 0.16.0 was closed as superseded. The bot confirmed the dependency is already up-to-date, making the update redundant.

Suggested action:

No scores available.

Issue body

Bumps [h11](https://github.com/python-hyper/h11) from 0.14.0 to 0.16.0. <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/python-hyper/h11/commit/1c5b07581f058886c8bdd87adababd7d959dc7ca"><code>1c5b075</code></a> this time for surer</li> <li><a href="https://github.com/python-hyper/h11/commit/d9c369935e853a7ee1aeb7e481f6dddf9b9c9b8a"><code>d9c3699</code></a> this time for sure...</li> <li><a href="https://github.com/python-hyper/h11/commit/d91b9dd2290a25c8c3f5ec15feb57de5873e6e39"><code>d91b9dd</code></a> blacken</li> <li><a href="https://github.com/python-hyper/h11/commit/5a4683ca466b59bbab9b19cfea20ee157b31cee0"><code>5a4683c</code></a> Soothe mypy</li> <li><a href="https://github.com/python-hyper/h11/commit/9c9567f0a92d13a83a8d8ebdbc757c8c2d384536"><code>9c9567f</code></a> Bump version to 0.16.0</li> <li><a href="https://github.com/python-hyper/h11/commit/114803a29ce50116dc47951c690ad4892b1a36ed"><code>114803a</code></a> Merge commit from fork</li> <li><a href="https://github.com/python-hyper/h11/commit/9462006f6ce4941661888228cbd4ac1ea80689b0"><code>9462006</code></a> Bump version to 0.15.0</li> <li><a href="https://github.com/python-hyper/h11/commit/70a96bea8e55403e5d92db14c111432c6d7a8685"><code>70a96be</code></a> Merge pull request <a href="https://redirect.github.com/python-hyper/h11/issues/181">#181</a> from Julien00859/Julien00859/get_int_max_str_digits</li> <li><a href="https://github.com/python-hyper/h11/commit/60782ad107e538b9312aac7e1c119c8358bf797c"><code>60782ad</code></a> Reject Content-Length longer 1 billion TB</li> <li><a href="https://github.com/python-hyper/h11/commit/dff7cc397a26ed4acdedd92d1bda6c8f18a6ed9f"><code>dff7cc3</code></a> Validate Chunked-Encoding chunk footer</li> <li>Additional commits viewable in <a href="https://github.com/python-hyper/h11/compare/v0.14.0...v0.16.0">compare view</a></li> </ul> </details> <br /> [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=h11&package-manager=pip&previous-version=0.14.0&new-version=0.16.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/canonical/charmcraft/network/alerts). </details>

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.6-35b-a3b Dependabot PR to bump h11 from 0.14.0 to 0.16.0 was closed as superseded. The bot confirmed the dependency is already up-to-date, making the update redundant.
qwen3.6-35b-a3b-mtp-q6 Dependabot PR to update h11 from 0.14.0 to 0.16.0 was closed and abandoned. The bot confirmed the dependency is already at the target version, rendering the update redundant.
qwen3.6-35b-a3b-mtp-q6 Automated update to h11 0.16.0 was closed as superseded. Dependabot confirmed the dependency is already current, rendering the change redundant.

Update history

No update history recorded yet.

Related issues

Issue Project State Summary Similarity
#1078 build(deps): update dependency h11 to v0.16.0 [security] (main) - autoclosed craft-parts closed Dependency update for h11 to v0.16.0 to fix CVE-2025-43859 was autoclosed, indicating it was superseded by a newer update or merged automatically.
79%
#1080 build(deps): update dependency h11 to v0.16.0 [security] (hotfix/2.4) craft-parts closed Closed without merge. The security update for CVE-2025-43859 by upgrading h11 to v0.16.0 was abandoned after mixed CI results.
76%
#1079 build(deps): update dependency h11 to v0.16.0 [security] (hotfix/2.3) craft-parts closed Abandoned without merging. The h11 v0.16.0 security update for CVE-2025-43859 was closed after 453 days due to inactivity and failing CI checks. It was superseded by a newer Renovate update, leaving the branch unpatched.
76%
#2269 build(deps): update dependency h11 to v0.16.0 [security] (hotfix/3.3) charmcraft closed The dependency update to h11 v0.16.0 was closed without merging. Multiple CI checks, including security scans and snap builds, failed, preventing the security patch from being applied.
75%
#2270 build(deps): update dependency h11 to v0.16.0 [security] (hotfix/3.4) - autoclosed charmcraft closed Autoclosed and abandoned. The h11 security update to v0.16.0 addressing CVE-2025-43859 was not merged because httpcore also requires an update, necessitating a broader dependency refresh.
75%
#2268 build(deps): update dependency h11 to v0.16.0 [security] (main) charmcraft merged Merged automated dependency update raising h11 from 0.14.0 to 0.16.0 to resolve CVE-2025-43859, a chunked encoding vulnerability enabling HTTP request smuggling. Approved by reviewers and merged to main.
75%
#1083 build(deps): update dependency h11 to v0.16.0 [security] craft-parts merged Merged automated dependency update upgrading h11 from v0.14.0 to v0.16.0 to resolve CVE-2025-43859, a request smuggling vulnerability in chunked-coding parsing. Approved by two reviewers and passed all CI checks.
74%
#1081 build(deps): update dependency h11 to v0.16.0 [security] (hotfix/2.4.3) craft-parts closed Merged to update h11 from v0.14.0 to v0.16.0, addressing CVE-2025-43859 request smuggling vulnerability in chunked-encoding parsing.
74%