← Back to issue list

build(autogen): bump dependencies

View original Github issue

Metadata

Project
craft-cli
Number
#457
Type
pull request
State
merged
Author
bepri
Labels
Created
Updated
Closed

Current evaluation

Merged after reviewer approval and passing all CI checks. Bumped dependencies across two files to resolve multiple OSV security vulnerabilities. All tests, linting, and security scans passed successfully.

Suggested action:

No scores available.

Issue body

- [ ] Have you followed the guidelines for contributing? - [ ] Have you signed the [CLA](http://www.ubuntu.com/legal/contributors/)? - [ ] Have you successfully run `make lint && make test`? --- Resolves a bunch of OSVs. Note: although almost all of these are docs dependencies, this repository doesn't use Sphinx Stack yet and so I'm not going to treat them any differently here.

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.6-35b-a3b Merged after reviewer approval and passing all CI checks. Bumped dependencies across two files to resolve multiple OSV security vulnerabilities. All tests, linting, and security scans passed successfully.
qwen3.6-35b-a3b-mtp-q6
Staleness: 5
Complexity: 20
Confidence: 85
needs review Updates and bumps various project dependencies to resolve multiple OSV security vulnerabilities. Currently awaiting maintainer review and CI checks.

Update history

No update history recorded yet.

Related issues

Issue Project State Summary Similarity
#342 build(autogen): bump libraries to fix OSVs craft-store merged Merged dependency updates for cffi, filelock, jaraco-context, protobuf, pynacl, urllib3, and wheel to resolve OSV security vulnerabilities. Approved by two reviewers and passed all CI checks.
85%
#247 build(autogen): bump dependencies to resolve OSVs imagecraft merged Merged after passing CI and receiving two approvals. Updated filelock, fonttools, and urllib3 to resolve OSV security warnings. An unrelated Spread test failure was noted but did not block the merge.
84%
#1121 build: bump requests to avoid OSV craft-parts merged Merged after bumping the requests dependency to resolve an OSV vulnerability. Approved by two reviewers with all CI checks passing. The update modifies three files with 136 additions and 10 deletions.
79%
#1000 build: update dependencies to resolve OSVs craft-providers closed Merged and closed to resolve OSVs by updating dependencies and security scan calling conventions. Passed CI checks with no comments or reviewer feedback.
78%
#5871 build(autogen): bump pip for OSV snapcraft merged Merged after three approvals. Bumps pip to 25.3 to resolve OSV vulnerability GHSA-4xh5-x5gv-qwph. All required CI checks passed prior to merge.
77%
#230 build(autogen): bump starlette for OSV imagecraft merged Merged to bump the Starlette dependency, resolving an OSV security warning. Approved by two reviewers, passed all CI checks, and updated the lock file with a minimal version change.
75%
#1055 build(deps): bump cryptography craft-application merged Merged after bumping the cryptography dependency to resolve an OSV security vulnerability. Approved by two reviewers and passed all CI checks, including security scans and multi-platform tests.
75%
#321 build(deps): bump pytest imagecraft merged Merged a dependency update bumping pytest to resolve an OSV vulnerability. Approved by two reviewers with all CI checks passing. The change modified a single file with minimal adjustments.
74%
#1003 build(auto): bump cryptography craft-providers merged Merged to bump the cryptography dependency and resolve an OSV security vulnerability. Approved by two reviewers with all CI checks passing.
74%
#2223 build(dep): update dependencies charmcraft merged Merged dependency updates to resolve OSV scanner failures. Approved by two reviewers, the change modifies two files with 900 additions and 756 deletions.
74%