build: bump starlette
Metadata
Current evaluation
Merged to bump starlette and resolve an OSV security advisory. Approved by two reviewers and passed CI after confirming python-apt warnings were false positives.
Suggested action: —
No scores available.
Issue body
- [ ] Have you followed the guidelines for contributing?
- [ ] Have you signed the [CLA](http://www.ubuntu.com/legal/contributors/)?
- [ ] Have you successfully run `make lint && make test`?
- [ ] Have you added an entry to the changelog (`docs/reference/changelog.rst`)?
---
Bumps starlette to resolve an OSV. The python-apt failures all seem to be false positives, we are using a newer version of python-apt than what is being recommended by the scanner.
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Merged to bump starlette and resolve an OSV security advisory. Approved by two reviewers and passed CI after confirming python-apt warnings were false positives. | |
| qwen3.6-35b-a3b-mtp-q6 |
Staleness:
0
Complexity:
10
Confidence:
90
|
needs review | Bumps starlette dependency to address a reported OSV security vulnerability. Author notes CI failures for python-apt are false positives due to version mismatch. PR is fresh and awaiting review. |
Update history
No update history recorded yet.
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #230 build(autogen): bump starlette for OSV | imagecraft | merged | Merged to bump the Starlette dependency, resolving an OSV security warning. Approved by two reviewers, passed all CI checks, and updated the lock file with a minimal version change. | |
| #350 build(deps): bump starlette | imagecraft | merged | Merged dependency update bumping starlette from v0.52.1 to v1.2.0 to resolve an OSV vulnerability. Approved by two reviewers and passed all CI checks prior to integration. | |
| #333 build: bump urllib3 and starlette | craft-store | merged | Merged update bumping urllib3 and starlette to resolve OSV security vulnerabilities. Approved by two reviewers with all CI checks passing. Changes modified a single file with minimal version adjustments. | |
| #84 build(deps): bump starlette from 0.48.0 to 0.49.1 | debcraft | merged | Merged dependabot update to bump starlette from 0.48.0 to 0.49.1. The upgrade patches a FileResponse Range header security vulnerability and adds minor features. CI checks passed and reviewers approved the merge. | |
| #357 build(deps): bump cryptography and starlette | imagecraft | merged | Merged dependency update bumping cryptography to 49.0.0 and adding starlette>=1.3.1 to resolve OSV security vulnerabilities. Approved by one reviewer and merged after passing required CI checks. | |
| #228 build(deps): add constraint for Starlette | craft-platforms | merged | Merged to pin the Starlette indirect dependency, mitigating the BadHost CVE. Approved by two reviewers and integrated after passing the majority of CI checks. | |
| #190 build(deps): add constraint for Starlette | craft-grammar | merged | Merged to pin the Starlette dependency to a secure version, mitigating the BadHost CVE. Approved by two reviewers and passed CI checks. The update applied minor constraint changes across two files. | |
| #376 build(deps): add constraint for Starlette | craft-store | merged | Merged to pin Starlette and mitigate the BadHost CVE. Approved by two reviewers and passed CI checks. The change adds a version constraint to the indirect dependency, resolving the security vulnerability. | |
| #164 build(deps): add constraint for Starlette | debcraft | merged | Merged to pin the Starlette indirect dependency to a version unaffected by the BadHost CVE. Approved by two reviewers and passed CI checks. | |
| #972 build(deps): add constraint for Starlette | craft-providers | merged | Merged to pin the Starlette indirect dependency, mitigating the BadHost CVE. Approved by two reviewers and validated by CI before integration. |