build: update dependencies to resolve OSVs
Metadata
Current evaluation
Merged and closed to resolve OSVs by updating dependencies and security scan calling conventions. Passed CI checks with no comments or reviewer feedback.
Suggested action: —
No scores available.
Issue body
Also updates the calling conventions for the security scan.
---
- [ ] I've followed the [contribution guidelines](https://github.com/canonical/starbase/blob/main/CONTRIBUTING.md).
- [ ] I've signed the [CLA](http://www.ubuntu.com/legal/contributors/).
- [ ] I've successfully run `make lint && make test`.
- [ ] I've added or updated any relevant documentation.
- [ ] In documents I changed, I [added a meta description](https://canonical-starflow.readthedocs-hosted.com/how-to/add-a-page-meta-description/) if one was missing.
- [ ] I've updated the relevant release notes.
---
<sub>Stack created with <a href="https://github.com/github/gh-stack">GitHub Stacks CLI</a> • <a href="https://gh.io/stacks-feedback">Give Feedback 💬</a></sub>
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Merged and closed to resolve OSVs by updating dependencies and security scan calling conventions. Passed CI checks with no comments or reviewer feedback. |
Update history
| Date | Change |
|---|---|
| updated | |
| created |
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #180 build(deps): resolve OSVs | craft-grammar | merged | Merged following two approvals and successful CI checks. Updated pytest from v9.0.2 to v9.0.3 to resolve OSV security vulnerabilities across one dependency file. | |
| #131 build(deps): resolve OSVs | debcraft | merged | Merged dependency updates to resolve OSV vulnerabilities. Updated cryptography, pygments, pytest, requests, and craft-parts via uv lock. Approved by two reviewers with all CI checks passing. Changes accepted despite minor pinning discussions. | |
| #1121 build: bump requests to avoid OSV | craft-parts | merged | Merged after bumping the requests dependency to resolve an OSV vulnerability. Approved by two reviewers with all CI checks passing. The update modifies three files with 136 additions and 10 deletions. | |
| #247 build(autogen): bump dependencies to resolve OSVs | imagecraft | merged | Merged after passing CI and receiving two approvals. Updated filelock, fonttools, and urllib3 to resolve OSV security warnings. An unrelated Spread test failure was noted but did not block the merge. | |
| #2223 build(dep): update dependencies | charmcraft | merged | Merged dependency updates to resolve OSV scanner failures. Approved by two reviewers, the change modifies two files with 900 additions and 756 deletions. | |
| #457 build(autogen): bump dependencies | craft-cli | merged | Merged after reviewer approval and passing all CI checks. Bumped dependencies across two files to resolve multiple OSV security vulnerabilities. All tests, linting, and security scans passed successfully. | |
| #401 fix: update docs dependencies to resolve OSV vulnerabilities | craft-store | closed | Closed without merging. The pull request updated documentation dependencies to resolve OSV vulnerabilities, passing all CI checks but receiving no reviews or comments. | |
| #143 build(deps): resolve OSVs | debcraft | merged | Resolved OSV security vulnerabilities by updating idna to v3.18 and urllib3 to v2.7.0. Approved by a reviewer, passed all CI checks, and merged. | |
| #81 build(deps): resolve OSVs | craft-artifacts | merged | Merged after two approvals. Updates pygments to 2.20.0 and pytest to 9.0.3 to resolve OSV security vulnerabilities. CI checks passed, and the six-line dependency lock update was successfully integrated. | |
| #353 build(deps): bump libraries for OSVs | craft-store | merged | Merged after updating cryptography, markdown, and pygments to patch OSV vulnerabilities. Approved by two reviewers and passed all CI checks. |