chore(autogen): bump jinja2
Metadata
Current evaluation
Merged a dependency update bumping jinja2 to resolve an OSV. Approved by two reviewers, passed CI, and modified two files with a ten-line change.
Suggested action: —
No scores available.
Issue body
- [ ] Have you followed the guidelines for contributing?
- [ ] Have you signed the [CLA](http://www.ubuntu.com/legal/contributors/)?
- [ ] Have you successfully run `make lint && make test`?
- [ ] Have you added an entry to the changelog (`docs/reference/changelog.rst`)?
---
Resolves an OSV.
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Merged a dependency update bumping jinja2 to resolve an OSV. Approved by two reviewers, passed CI, and modified two files with a ten-line change. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Merged to bump jinja2, resolving an OSV. The maintainer acknowledged a minor oversight during the update before finalizing the merge. |
Update history
No update history recorded yet.
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #275 chore(autogen): bump jinja2 | craft-store | merged | Merged a jinja2 dependency bump to resolve an OSV security vulnerability. Approved by two reviewers, passed CI checks, and modified one file. Related test failures were addressed separately. | |
| #155 chore: bump jinja2 | craft-archives | merged | Merged a jinja2 dependency bump to resolve an OSV security vulnerability. The update passed all lint and test checks, received approval from two reviewers, and modified a single file with minimal changes. | |
| #1034 chore: bump jinja2 | craft-parts | merged | Merged a dependency update to bump jinja2, resolving an OSV CI error. The change was generated via uv lock --upgrade-package jinja2, approved by two reviewers, passed all CI checks, and modified two files. | |
| #897 chore: bump gevent dependency | rockcraft | merged | Merged a single-line update to the gevent dependency to resolve an OSV security error. The change was approved by two reviewers, passed all CI checks, and successfully integrated. | |
| #4789 chore(deps): update dependency jinja2 to v3.1.4 [security] | snapcraft | merged | Merged automated dependency update upgrading Jinja2 from 3.1.3 to 3.1.4 to patch CVE-2024-34064, addressing an XSS vulnerability in the xmlattr filter. Approved and auto-merged by Renovate. | |
| #987 chore(deps): bump distro-support version | craft-application | merged | Merged to bump the distro-support dependency version, resolving issue #986. Approved by two reviewers and passed CI checks except OSV-scanner. Changes update two files with minimal modifications. | |
| #1670 chore(deps): update dependency jinja2 to v3.1.4 [security] - autoclosed | charmcraft | closed | Renovate autoclosed the Jinja2 v3.1.4 security update without merging. The branch became obsolete and was likely superseded by another dependency update or abandoned. | |
| #4351 chore(docs): bump requirements and build environment | snapcraft | merged | Merged after reviewer approval and passing CI. Updated the build environment to Ubuntu 22.04 and Python 3.10, bumped documentation requirements, and removed boilerplate comments. The commit adds 13 lines and removes 24 across two files. | |
| #1355 chore(deps): update internal dependencies | charmcraft | merged | Merged pull request updating internal dependencies. Approved by four reviewers with passing CI checks. The change modified two files, adding and removing four lines each. | |
| #4448 chore(deps): update dependencies | snapcraft | merged | Merged PR updating project dependencies across 8 files. Approved by two reviewers, passed CI checks, and maintained test coverage. Changes involve standard dependency version bumps and minor configuration adjustments. |