← Back to issue list

build: update dependencies to resolve OSVs

View original Github issue

Metadata

Project
craft-providers
Number
#1000
Type
pull request
State
closed
Author
bepri
Labels
Created
Updated
Closed

Current evaluation

Merged and closed to resolve OSVs by updating dependencies and security scan calling conventions. Passed CI checks with no comments or reviewer feedback.

Suggested action:

No scores available.

Issue body

Also updates the calling conventions for the security scan. --- - [ ] I've followed the [contribution guidelines](https://github.com/canonical/starbase/blob/main/CONTRIBUTING.md). - [ ] I've signed the [CLA](http://www.ubuntu.com/legal/contributors/). - [ ] I've successfully run `make lint && make test`. - [ ] I've added or updated any relevant documentation. - [ ] In documents I changed, I [added a meta description](https://canonical-starflow.readthedocs-hosted.com/how-to/add-a-page-meta-description/) if one was missing. - [ ] I've updated the relevant release notes. --- <sub>Stack created with <a href="https://github.com/github/gh-stack">GitHub Stacks CLI</a> • <a href="https://gh.io/stacks-feedback">Give Feedback 💬</a></sub>

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.6-35b-a3b Merged and closed to resolve OSVs by updating dependencies and security scan calling conventions. Passed CI checks with no comments or reviewer feedback.

Update history

Date Change
updated
created

Related issues

Issue Project State Summary Similarity
#180 build(deps): resolve OSVs craft-grammar merged Merged following two approvals and successful CI checks. Updated pytest from v9.0.2 to v9.0.3 to resolve OSV security vulnerabilities across one dependency file.
80%
#131 build(deps): resolve OSVs debcraft merged Merged dependency updates to resolve OSV vulnerabilities. Updated cryptography, pygments, pytest, requests, and craft-parts via uv lock. Approved by two reviewers with all CI checks passing. Changes accepted despite minor pinning discussions.
79%
#1121 build: bump requests to avoid OSV craft-parts merged Merged after bumping the requests dependency to resolve an OSV vulnerability. Approved by two reviewers with all CI checks passing. The update modifies three files with 136 additions and 10 deletions.
78%
#247 build(autogen): bump dependencies to resolve OSVs imagecraft merged Merged after passing CI and receiving two approvals. Updated filelock, fonttools, and urllib3 to resolve OSV security warnings. An unrelated Spread test failure was noted but did not block the merge.
78%
#2223 build(dep): update dependencies charmcraft merged Merged dependency updates to resolve OSV scanner failures. Approved by two reviewers, the change modifies two files with 900 additions and 756 deletions.
78%
#457 build(autogen): bump dependencies craft-cli merged Merged after reviewer approval and passing all CI checks. Bumped dependencies across two files to resolve multiple OSV security vulnerabilities. All tests, linting, and security scans passed successfully.
78%
#401 fix: update docs dependencies to resolve OSV vulnerabilities craft-store closed Closed without merging. The pull request updated documentation dependencies to resolve OSV vulnerabilities, passing all CI checks but receiving no reviews or comments.
78%
#143 build(deps): resolve OSVs debcraft merged Resolved OSV security vulnerabilities by updating idna to v3.18 and urllib3 to v2.7.0. Approved by a reviewer, passed all CI checks, and merged.
78%
#81 build(deps): resolve OSVs craft-artifacts merged Merged after two approvals. Updates pygments to 2.20.0 and pytest to 9.0.3 to resolve OSV security vulnerabilities. CI checks passed, and the six-line dependency lock update was successfully integrated.
75%
#353 build(deps): bump libraries for OSVs craft-store merged Merged after updating cryptography, markdown, and pygments to patch OSV vulnerabilities. Approved by two reviewers and passed all CI checks.
75%