build: bump requests to avoid OSV
Metadata
Current evaluation
Merged after bumping the requests dependency to resolve an OSV vulnerability. Approved by two reviewers with all CI checks passing. The update modifies three files with 136 additions and 10 deletions.
Suggested action: —
No scores available.
Issue body
- [x] Have you signed the [CLA](http://www.ubuntu.com/legal/contributors/)?
- [ ] Have you added an entry to the changelog (`docs/reference/changelog.rst`)?
-----
Fixes [an OSV error](https://github.com/canonical/craft-parts/actions/runs/15544456986/job/43762765631?pr=1120)
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Merged after bumping the requests dependency to resolve an OSV vulnerability. Approved by two reviewers with all CI checks passing. The update modifies three files with 136 additions and 10 deletions. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Merged to bump the requests dependency, resolving an OSV security vulnerability. Maintainer bepri applied the change directly without comments or changelog updates. |
Update history
No update history recorded yet.
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #308 build: update requests to 2.33.0 | imagecraft | merged | Merged a dependency update bumping requests to 2.33.0 to resolve an OSV. Approved by two reviewers and passed CI, the single-file change addresses the security vulnerability. | |
| #418 build: bump cryptography for OSV | craft-store | merged | Merged to bump the cryptography dependency and resolve an OSV vulnerability. Approved by a reviewer, passed CI checks, and modified two files. | |
| #321 build(deps): bump pytest | imagecraft | merged | Merged a dependency update bumping pytest to resolve an OSV vulnerability. Approved by two reviewers with all CI checks passing. The change modified a single file with minimal adjustments. | |
| #2223 build(dep): update dependencies | charmcraft | merged | Merged dependency updates to resolve OSV scanner failures. Approved by two reviewers, the change modifies two files with 900 additions and 756 deletions. | |
| #457 build(autogen): bump dependencies | craft-cli | merged | Merged after reviewer approval and passing all CI checks. Bumped dependencies across two files to resolve multiple OSV security vulnerabilities. All tests, linting, and security scans passed successfully. | |
| #1000 build: update dependencies to resolve OSVs | craft-providers | closed | Merged and closed to resolve OSVs by updating dependencies and security scan calling conventions. Passed CI checks with no comments or reviewer feedback. | |
| #131 build(deps): resolve OSVs | debcraft | merged | Merged dependency updates to resolve OSV vulnerabilities. Updated cryptography, pygments, pytest, requests, and craft-parts via uv lock. Approved by two reviewers with all CI checks passing. Changes accepted despite minor pinning discussions. | |
| #353 build(deps): bump libraries for OSVs | craft-store | merged | Merged after updating cryptography, markdown, and pygments to patch OSV vulnerabilities. Approved by two reviewers and passed all CI checks. | |
| #5553 build(deps): bump requests to 2.32.4 | snapcraft | merged | Merged a dependency update bumping requests to 2.32.4 to patch a security vulnerability. Approved by two reviewers and passed core CI checks before integration. | |
| #524 build(deps): bump pytest | starbase | merged | Merged a dependency update bumping pytest to resolve an OSV. Approved by two reviewers with all CI checks passing. The change updates a single file. |