← Back to issue list

build(deps): resolve OSVs

View original Github issue

Metadata

Project
debcraft
Number
#143
Type
pull request
State
merged
Author
smethnani
Labels
Created
Updated
Closed

Current evaluation

Resolved OSV security vulnerabilities by updating idna to v3.18 and urllib3 to v2.7.0. Approved by a reviewer, passed all CI checks, and merged.

Suggested action:

No scores available.

Issue body

Bumps idna + urllib3 to resolve OSVs Updated idna v3.10 -> v3.18 Updated urllib3 v2.6.3 -> v2.7.0 - [ ] Have you followed the guidelines for contributing? - [ ] Have you signed the [CLA](http://www.ubuntu.com/legal/contributors/)? - [ ] Have you successfully run `make lint && make test`? ---

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.6-35b-a3b Resolved OSV security vulnerabilities by updating idna to v3.18 and urllib3 to v2.7.0. Approved by a reviewer, passed all CI checks, and merged.
qwen3.6-35b-a3b-mtp-q6 Merged dependency updates bumping idna to v3.18 and urllib3 to v2.7.0 to resolve open source vulnerabilities. Integrated by maintainer smethnani.
qwen3.6-35b-a3b-mtp-q6
Staleness: 45
Complexity: 10
Confidence: 85
needs review Updates lxml from 6.0.2 to 6.1.0 to resolve an OSV vulnerability. Open for 50 days with no comments and an unchecked checklist. Currently inactive, awaiting review or author updates to move forward.

Update history

No update history recorded yet.

Related issues

Issue Project State Summary Similarity
#6265 build(deps): bump idna, urllib3 snapcraft merged Merged a dependency update bumping idna and urllib3 to resolve OSV security vulnerabilities. Approved by two reviewers and successfully passed CI checks.
87%
#1076 build(deps): bump idna, urllib3 craft-application merged Merged dependency update bumping idna and urllib3 to resolve OSV security vulnerabilities. Approved by one reviewer with all CI checks passing. The change modifies a single file with minimal adjustments.
85%
#131 build(deps): resolve OSVs debcraft merged Merged dependency updates to resolve OSV vulnerabilities. Updated cryptography, pygments, pytest, requests, and craft-parts via uv lock. Approved by two reviewers with all CI checks passing. Changes accepted despite minor pinning discussions.
83%
#1278 build(deps): update deps to resolve OSV vulnerabilities rockcraft merged Merged dependency updates for cryptography, dulwich, idna, lxml, poetry, pytest, urllib3, and msgpack to resolve OSV vulnerabilities. Added osv-scanner exceptions for python-apt and cryptography. Approved and passed CI.
83%
#180 build(deps): resolve OSVs craft-grammar merged Merged following two approvals and successful CI checks. Updated pytest from v9.0.2 to v9.0.3 to resolve OSV security vulnerabilities across one dependency file.
82%
#344 build(deps): bump urllib3 imagecraft merged Merged to bump urllib3 and resolve an OSV. Approved by two reviewers with all CI checks passing. The update modifies a single file with three additions and three deletions.
80%
#383 chore: fix OSV scanner vulnerabilities craft-store merged Upgrades idna and urllib3 to patched versions, resolving OSV scanner vulnerabilities. Merged following approval from two reviewers and successful CI checks.
79%
#81 build(deps): resolve OSVs craft-artifacts merged Merged after two approvals. Updates pygments to 2.20.0 and pytest to 9.0.3 to resolve OSV security vulnerabilities. CI checks passed, and the six-line dependency lock update was successfully integrated.
79%
#963 build(deps): update lockfile for OSVs craft-providers merged Merged after two approvals. Updated lockfile via uv lock on cryptography, idna, pytest, and urllib3 to fix OSV CI. Approved and passed checks.
78%
#1615 build(deps): bump idna + urllib3 craft-parts merged Merged dependency update bumping idna to v3.18 and urllib3 to v2.7.0 to resolve open source vulnerabilities. Approved by two reviewers and passed CI checks.
78%