← Back to issue list

fix: update docs dependencies to resolve OSV vulnerabilities

View original Github issue

Metadata

Project
craft-store
Number
#401
Type
pull request
State
closed
Author
lengau
Labels
Created
Updated
Closed

Current evaluation

Closed without merging. The pull request updated documentation dependencies to resolve OSV vulnerabilities, passing all CI checks but receiving no reviews or comments.

Suggested action:

No scores available.

Issue body

--- - [ ] I've followed the [contribution guidelines](https://github.com/canonical/craft-store/blob/main/CONTRIBUTING.md). - [ ] I've signed the [CLA](http://www.ubuntu.com/legal/contributors/). - [ ] I've successfully run `make lint && make test`. - [ ] I've added or updated any relevant documentation. - [ ] In documents I changed, I [added a meta description](https://canonical-starflow.readthedocs-hosted.com/how-to/add-a-page-meta-description/) if one was missing. - [ ] I've updated the relevant release notes.

Evaluation history

Date Model Scores Action Summary
qwen3.6-35b-a3b-mtp-q6 Closed without merging. The pull request updated documentation dependencies to resolve OSV vulnerabilities, passing all CI checks but receiving no reviews or comments.
qwen/qwen3.6-35b-a3b
Staleness: 10
Complexity: 10
Confidence: 85
needs review Updates documentation dependencies to resolve OSV security vulnerabilities. Currently pending maintainer review with 7 unresolved comments and all CI checks passing.
qwen3.6-35b-a3b-mtp-q6
Staleness: 5
Complexity: 10
Confidence: 90
needs review Updates documentation dependencies to resolve OSV security vulnerabilities. The PR is open, recently created by a maintainer, and currently awaiting initial review.
qwen3.6-35b-a3b-mtp-q6
Staleness: 5
Complexity: 15
Confidence: 90
needs review Updates documentation dependencies to resolve reported OSV security vulnerabilities. Currently awaiting initial maintainer review and CI checks.

Update history

Date Change
closed

Related issues

Issue Project State Summary Similarity
#1000 build: update dependencies to resolve OSVs craft-providers closed Merged and closed to resolve OSVs by updating dependencies and security scan calling conventions. Passed CI checks with no comments or reviewer feedback.
78%
#1121 build: bump requests to avoid OSV craft-parts merged Merged after bumping the requests dependency to resolve an OSV vulnerability. Approved by two reviewers with all CI checks passing. The update modifies three files with 136 additions and 10 deletions.
74%
#72 docs: update documentation dependencies craft-archives merged Documentation dependency updates were approved, passed CI checks, and successfully merged. The change modified a single file with minor adjustments.
71%
#308 build: update requests to 2.33.0 imagecraft merged Merged a dependency update bumping requests to 2.33.0 to resolve an OSV. Approved by two reviewers and passed CI, the single-file change addresses the security vulnerability.
71%
#131 build(deps): resolve OSVs debcraft merged Merged dependency updates to resolve OSV vulnerabilities. Updated cryptography, pygments, pytest, requests, and craft-parts via uv lock. Approved by two reviewers with all CI checks passing. Changes accepted despite minor pinning discussions.
70%