← Back to issue list

chore: fix OSV scanner vulnerabilities

View original Github issue

Metadata

Project
craft-store
Number
#383
Type
pull request
State
merged
Author
lengau
Labels
Created
Updated
Closed

Current evaluation

Upgrades idna and urllib3 to patched versions, resolving OSV scanner vulnerabilities. Merged following approval from two reviewers and successful CI checks.

Suggested action:

No scores available.

Issue body

Upgrades idna and urllib3 to their patched versions to resolve OSV scanner failures.

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.6-35b-a3b Upgrades idna and urllib3 to patched versions, resolving OSV scanner vulnerabilities. Merged following approval from two reviewers and successful CI checks.
qwen3.6-35b-a3b-mtp-q6 Merged an update upgrading idna and urllib3 to patched versions, resolving OSV scanner vulnerabilities.

Update history

No update history recorded yet.

Related issues

Issue Project State Summary Similarity
#143 build(deps): resolve OSVs debcraft merged Resolved OSV security vulnerabilities by updating idna to v3.18 and urllib3 to v2.7.0. Approved by a reviewer, passed all CI checks, and merged.
79%
#6265 build(deps): bump idna, urllib3 snapcraft merged Merged a dependency update bumping idna and urllib3 to resolve OSV security vulnerabilities. Approved by two reviewers and successfully passed CI checks.
76%
#1076 build(deps): bump idna, urllib3 craft-application merged Merged dependency update bumping idna and urllib3 to resolve OSV security vulnerabilities. Approved by one reviewer with all CI checks passing. The change modifies a single file with minimal adjustments.
74%
#275 chore(autogen): bump jinja2 craft-store merged Merged a jinja2 dependency bump to resolve an OSV security vulnerability. Approved by two reviewers, passed CI checks, and modified one file. Related test failures were addressed separately.
74%
#1644 chore(deps): update dependency idna to v3.7 [security] charmcraft merged Merged automated dependency update upgrading idna from v3.6 to v3.7 to resolve CVE-2024-3651, a denial-of-service vulnerability in the encode function. Approved by reviewers and passed CI checks.
74%
#388 chore(deps): update bugfixes rockcraft merged Merged automated dependency updates via Renovate bot. Updated codespell, coverage, dotnet runtime-deps, pylint, and urllib3 to latest patch versions. Approved by two reviewers, passed CI, and merged with minimal changes.
73%
#4726 chore(deps): update dependency idna to v3.7 [security] snapcraft merged Merged automated dependency update upgrading idna to v3.7 from v3.6 and v3.4. Resolves CVE-2024-3651 denial-of-service vulnerability in idna.encode(). Approved by reviewers, passed CI, and merged to main.
73%
#1278 build(deps): update deps to resolve OSV vulnerabilities rockcraft merged Merged dependency updates for cryptography, dulwich, idna, lxml, poetry, pytest, urllib3, and msgpack to resolve OSV vulnerabilities. Added osv-scanner exceptions for python-apt and cryptography. Approved and passed CI.
73%
#102 build: fix urllib3 osv craft-grammar merged Merged after two approvals and passing CI. Fixes an OSV workflow error for urllib3 with a three-line change to one file.
72%
#63 build: bump urllib3 debcraft merged Merged to bump urllib3 and resolve an OSV vulnerability. Approved by two reviewers with all CI checks passing. The update modified a single file.
72%