chore: bump jinja2
Metadata
Current evaluation
Merged a dependency update to bump jinja2, resolving an OSV CI error. The change was generated via uv lock --upgrade-package jinja2, approved by two reviewers, passed all CI checks, and modified two files.
Suggested action: —
No scores available.
Issue body
- [x] Have you signed the [CLA](http://www.ubuntu.com/legal/contributors/)?
- [x] Have you added an entry to the changelog (`docs/reference/changelog.rst`)?
-----
This PR is just the result of `uv lock --upgrade-package jinja2`. Resolves an OSV CI error.
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Merged a dependency update to bump jinja2, resolving an OSV CI error. The change was generated via uv lock --upgrade-package jinja2, approved by two reviewers, passed all CI checks, and modified two files. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Merged a dependency update that bumps jinja2 to resolve an OSV CI error. The change was generated via uv lock --upgrade-package jinja2 and includes required changelog and CLA acknowledgments. |
Update history
No update history recorded yet.
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #155 chore: bump jinja2 | craft-archives | merged | Merged a jinja2 dependency bump to resolve an OSV security vulnerability. The update passed all lint and test checks, received approval from two reviewers, and modified a single file with minimal changes. | |
| #678 chore(autogen): bump jinja2 | craft-application | merged | Merged a dependency update bumping jinja2 to resolve an OSV. Approved by two reviewers, passed CI, and modified two files with a ten-line change. | |
| #275 chore(autogen): bump jinja2 | craft-store | merged | Merged a jinja2 dependency bump to resolve an OSV security vulnerability. Approved by two reviewers, passed CI checks, and modified one file. Related test failures were addressed separately. | |
| #4789 chore(deps): update dependency jinja2 to v3.1.4 [security] | snapcraft | merged | Merged automated dependency update upgrading Jinja2 from 3.1.3 to 3.1.4 to patch CVE-2024-34064, addressing an XSS vulnerability in the xmlattr filter. Approved and auto-merged by Renovate. | |
| #1670 chore(deps): update dependency jinja2 to v3.1.4 [security] - autoclosed | charmcraft | closed | Renovate autoclosed the Jinja2 v3.1.4 security update without merging. The branch became obsolete and was likely superseded by another dependency update or abandoned. | |
| #106 build(deps): bump jinja2 from 3.1.5 to 3.1.6 | imagecraft | merged | Merged a dependency update bumping jinja2 from 3.1.5 to 3.1.6 to patch security vulnerability GHSA-cpwx-vrp4-4pq7. Approved by two reviewers, passed CI, and merged after coordinating with a related pull request. | |
| #274 Bump jinja2 from 2.11.2 to 2.11.3 | charmcraft | merged | Merged an automated Dependabot update bumping jinja2 from 2.11.2 to 2.11.3. The release fixes a regex backtracking performance issue in the urlize filter. Approved by two reviewers and passed CI checks prior to merge. |