chore: fix OSV scanner vulnerabilities
Metadata
Current evaluation
Upgrades idna and urllib3 to patched versions, resolving OSV scanner vulnerabilities. Merged following approval from two reviewers and successful CI checks.
Suggested action: —
No scores available.
Issue body
Upgrades idna and urllib3 to their patched versions to resolve OSV scanner failures.
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Upgrades idna and urllib3 to patched versions, resolving OSV scanner vulnerabilities. Merged following approval from two reviewers and successful CI checks. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Merged an update upgrading idna and urllib3 to patched versions, resolving OSV scanner vulnerabilities. |
Update history
No update history recorded yet.
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #143 build(deps): resolve OSVs | debcraft | merged | Resolved OSV security vulnerabilities by updating idna to v3.18 and urllib3 to v2.7.0. Approved by a reviewer, passed all CI checks, and merged. | |
| #6265 build(deps): bump idna, urllib3 | snapcraft | merged | Merged a dependency update bumping idna and urllib3 to resolve OSV security vulnerabilities. Approved by two reviewers and successfully passed CI checks. | |
| #1076 build(deps): bump idna, urllib3 | craft-application | merged | Merged dependency update bumping idna and urllib3 to resolve OSV security vulnerabilities. Approved by one reviewer with all CI checks passing. The change modifies a single file with minimal adjustments. | |
| #275 chore(autogen): bump jinja2 | craft-store | merged | Merged a jinja2 dependency bump to resolve an OSV security vulnerability. Approved by two reviewers, passed CI checks, and modified one file. Related test failures were addressed separately. | |
| #1644 chore(deps): update dependency idna to v3.7 [security] | charmcraft | merged | Merged automated dependency update upgrading idna from v3.6 to v3.7 to resolve CVE-2024-3651, a denial-of-service vulnerability in the encode function. Approved by reviewers and passed CI checks. | |
| #388 chore(deps): update bugfixes | rockcraft | merged | Merged automated dependency updates via Renovate bot. Updated codespell, coverage, dotnet runtime-deps, pylint, and urllib3 to latest patch versions. Approved by two reviewers, passed CI, and merged with minimal changes. | |
| #4726 chore(deps): update dependency idna to v3.7 [security] | snapcraft | merged | Merged automated dependency update upgrading idna to v3.7 from v3.6 and v3.4. Resolves CVE-2024-3651 denial-of-service vulnerability in idna.encode(). Approved by reviewers, passed CI, and merged to main. | |
| #1278 build(deps): update deps to resolve OSV vulnerabilities | rockcraft | merged | Merged dependency updates for cryptography, dulwich, idna, lxml, poetry, pytest, urllib3, and msgpack to resolve OSV vulnerabilities. Added osv-scanner exceptions for python-apt and cryptography. Approved and passed CI. | |
| #102 build: fix urllib3 osv | craft-grammar | merged | Merged after two approvals and passing CI. Fixes an OSV workflow error for urllib3 with a three-line change to one file. | |
| #63 build: bump urllib3 | debcraft | merged | Merged to bump urllib3 and resolve an OSV vulnerability. Approved by two reviewers with all CI checks passing. The update modified a single file. |