← Back to issue list

chore: bump jinja2

View original Github issue

Metadata

Project
craft-archives
Number
#155
Type
pull request
State
merged
Author
bepri
Labels
Created
Updated
Closed

Current evaluation

Merged a jinja2 dependency bump to resolve an OSV security vulnerability. The update passed all lint and test checks, received approval from two reviewers, and modified a single file with minimal changes.

Suggested action:

No scores available.

Issue body

- [x] Have you followed the guidelines for contributing? - [x] Have you signed the [CLA](http://www.ubuntu.com/legal/contributors/)? - [x] Have you successfully run `make lint && make test`? --- Resolves an OSV.

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.6-35b-a3b Merged a jinja2 dependency bump to resolve an OSV security vulnerability. The update passed all lint and test checks, received approval from two reviewers, and modified a single file with minimal changes.
qwen3.6-35b-a3b-mtp-q6 Merged a dependency update to bump jinja2, resolving an Open Source Vulnerability. The change passed linting, testing, and compliance checks before integration.

Update history

No update history recorded yet.

Related issues

Issue Project State Summary Similarity
#275 chore(autogen): bump jinja2 craft-store merged Merged a jinja2 dependency bump to resolve an OSV security vulnerability. Approved by two reviewers, passed CI checks, and modified one file. Related test failures were addressed separately.
94%
#1034 chore: bump jinja2 craft-parts merged Merged a dependency update to bump jinja2, resolving an OSV CI error. The change was generated via uv lock --upgrade-package jinja2, approved by two reviewers, passed all CI checks, and modified two files.
93%
#678 chore(autogen): bump jinja2 craft-application merged Merged a dependency update bumping jinja2 to resolve an OSV. Approved by two reviewers, passed CI, and modified two files with a ten-line change.
92%
#4789 chore(deps): update dependency jinja2 to v3.1.4 [security] snapcraft merged Merged automated dependency update upgrading Jinja2 from 3.1.3 to 3.1.4 to patch CVE-2024-34064, addressing an XSS vulnerability in the xmlattr filter. Approved and auto-merged by Renovate.
78%
#1670 chore(deps): update dependency jinja2 to v3.1.4 [security] - autoclosed charmcraft closed Renovate autoclosed the Jinja2 v3.1.4 security update without merging. The branch became obsolete and was likely superseded by another dependency update or abandoned.
77%
#106 build(deps): bump jinja2 from 3.1.5 to 3.1.6 imagecraft merged Merged a dependency update bumping jinja2 from 3.1.5 to 3.1.6 to patch security vulnerability GHSA-cpwx-vrp4-4pq7. Approved by two reviewers, passed CI, and merged after coordinating with a related pull request.
75%
#897 chore: bump gevent dependency rockcraft merged Merged a single-line update to the gevent dependency to resolve an OSV security error. The change was approved by two reviewers, passed all CI checks, and successfully integrated.
74%
#274 Bump jinja2 from 2.11.2 to 2.11.3 charmcraft merged Merged an automated Dependabot update bumping jinja2 from 2.11.2 to 2.11.3. The release fixes a regex backtracking performance issue in the urlize filter. Approved by two reviewers and passed CI checks prior to merge.
72%
#1038 build(deps): update jinja2 to 3.1.6 craft-parts merged Merged to update jinja2 to 3.1.6, resolving CVE-2025-27516 sandbox breakout vulnerability. Approved by two reviewers, passed CI, and applied with a minimal five-line change across two files.
71%
#383 chore: fix OSV scanner vulnerabilities craft-store merged Upgrades idna and urllib3 to patched versions, resolving OSV scanner vulnerabilities. Merged following approval from two reviewers and successful CI checks.
70%