← Back to issue list

build: bump cryptography for OSV

View original Github issue

Metadata

Project
craft-store
Number
#418
Type
pull request
State
merged
Author
bepri
Labels
Created
Updated
Closed

Current evaluation

Merged to bump the cryptography dependency and resolve an OSV vulnerability. Approved by a reviewer, passed CI checks, and modified two files.

Suggested action:

No scores available.

Issue body

Resolves an OSV. --- - [ ] I've followed the [contribution guidelines](https://github.com/canonical/craft-store/blob/main/CONTRIBUTING.md). - [ ] I've signed the [CLA](http://www.ubuntu.com/legal/contributors/). - [ ] I've successfully run `make lint && make test`. - [ ] I've added or updated any relevant documentation. - [ ] In documents I changed, I [added a meta description](https://canonical-starflow.readthedocs-hosted.com/how-to/add-a-page-meta-description/) if one was missing. - [ ] I've updated the relevant release notes.

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.6-35b-a3b Merged to bump the cryptography dependency and resolve an OSV vulnerability. Approved by a reviewer, passed CI checks, and modified two files.
qwen/qwen3.6-35b-a3b
Staleness: 0
Complexity: 10
Confidence: 90
needs review Bumps the cryptography dependency to resolve an OSV security advisory. The PR is newly opened, CI checks are passing or pending, and requires maintainer review.

Update history

Date Change
updated
created

Related issues

Issue Project State Summary Similarity
#1003 build(auto): bump cryptography craft-providers merged Merged to bump the cryptography dependency and resolve an OSV security vulnerability. Approved by two reviewers with all CI checks passing.
94%
#1055 build(deps): bump cryptography craft-application merged Merged after bumping the cryptography dependency to resolve an OSV security vulnerability. Approved by two reviewers and passed all CI checks, including security scans and multi-platform tests.
91%
#1151 build(auto): bump cryptography craft-application merged Merged a PR by bepri that bumps the cryptography dependency to resolve an OSV. Approved by two reviewers and passing CI, the update addresses a security vulnerability.
90%
#1061 build(deps): bump cryptography craft-application merged Merged a dependency update to bump cryptography, resolving an OSV security vulnerability. Approved by two reviewers and passing all CI checks, the change modified one file with 51 additions and 51 deletions.
90%
#356 build(deps): bump cryptography craft-store merged Merged to bump the cryptography dependency and resolve OSV vulnerability GHSA-p423-j2cm-9vmq. Approved by two reviewers and passed CI checks, with one Windows test failure noted.
90%
#353 build(deps): bump libraries for OSVs craft-store merged Merged after updating cryptography, markdown, and pygments to patch OSV vulnerabilities. Approved by two reviewers and passed all CI checks.
84%
#1098 build(deps): bump cryptography craft-application merged Bumps cryptography from v48.0.0 to v49.0.0 to resolve OSV vulnerability GHSA-537c-gmf6-5ccf. Approved by two reviewers, passed CI checks, and successfully merged.
84%
#6307 build(deps): bump cryptography snapcraft merged Merged after approval. Bumps the cryptography dependency to address a CVE. Core CI checks passed despite some integration and publish job failures.
83%
#318 build: bump cryptography to 46.0.7 imagecraft merged Merged a dependency update bumping cryptography to 46.0.7 to resolve an OSV security advisory. Approved by two reviewers, the change was merged despite failing spread tests on older Ubuntu releases.
82%
#421 build: bump dependencies for OSVs imagecraft merged Merged after two approvals. Updated cryptography to 50.0.0 and httplib2 to 0.32.0 via uv lock to address OSV vulnerabilities. Test and lint checks passed; snap build failures were bypassed to proceed with the dependency update.
81%