build(deps): resolve OSVs
Metadata
Current evaluation
Resolved OSV security vulnerabilities by updating idna to v3.18 and urllib3 to v2.7.0. Approved by a reviewer, passed all CI checks, and merged.
Suggested action: —
No scores available.
Issue body
Bumps idna + urllib3 to resolve OSVs
Updated idna v3.10 -> v3.18
Updated urllib3 v2.6.3 -> v2.7.0
- [ ] Have you followed the guidelines for contributing?
- [ ] Have you signed the [CLA](http://www.ubuntu.com/legal/contributors/)?
- [ ] Have you successfully run `make lint && make test`?
---
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Resolved OSV security vulnerabilities by updating idna to v3.18 and urllib3 to v2.7.0. Approved by a reviewer, passed all CI checks, and merged. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Merged dependency updates bumping idna to v3.18 and urllib3 to v2.7.0 to resolve open source vulnerabilities. Integrated by maintainer smethnani. | |
| qwen3.6-35b-a3b-mtp-q6 |
Staleness:
45
Complexity:
10
Confidence:
85
|
needs review | Updates lxml from 6.0.2 to 6.1.0 to resolve an OSV vulnerability. Open for 50 days with no comments and an unchecked checklist. Currently inactive, awaiting review or author updates to move forward. |
Update history
No update history recorded yet.
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #6265 build(deps): bump idna, urllib3 | snapcraft | merged | Merged a dependency update bumping idna and urllib3 to resolve OSV security vulnerabilities. Approved by two reviewers and successfully passed CI checks. | |
| #1076 build(deps): bump idna, urllib3 | craft-application | merged | Merged dependency update bumping idna and urllib3 to resolve OSV security vulnerabilities. Approved by one reviewer with all CI checks passing. The change modifies a single file with minimal adjustments. | |
| #131 build(deps): resolve OSVs | debcraft | merged | Merged dependency updates to resolve OSV vulnerabilities. Updated cryptography, pygments, pytest, requests, and craft-parts via uv lock. Approved by two reviewers with all CI checks passing. Changes accepted despite minor pinning discussions. | |
| #1278 build(deps): update deps to resolve OSV vulnerabilities | rockcraft | merged | Merged dependency updates for cryptography, dulwich, idna, lxml, poetry, pytest, urllib3, and msgpack to resolve OSV vulnerabilities. Added osv-scanner exceptions for python-apt and cryptography. Approved and passed CI. | |
| #180 build(deps): resolve OSVs | craft-grammar | merged | Merged following two approvals and successful CI checks. Updated pytest from v9.0.2 to v9.0.3 to resolve OSV security vulnerabilities across one dependency file. | |
| #344 build(deps): bump urllib3 | imagecraft | merged | Merged to bump urllib3 and resolve an OSV. Approved by two reviewers with all CI checks passing. The update modifies a single file with three additions and three deletions. | |
| #383 chore: fix OSV scanner vulnerabilities | craft-store | merged | Upgrades idna and urllib3 to patched versions, resolving OSV scanner vulnerabilities. Merged following approval from two reviewers and successful CI checks. | |
| #81 build(deps): resolve OSVs | craft-artifacts | merged | Merged after two approvals. Updates pygments to 2.20.0 and pytest to 9.0.3 to resolve OSV security vulnerabilities. CI checks passed, and the six-line dependency lock update was successfully integrated. | |
| #963 build(deps): update lockfile for OSVs | craft-providers | merged | Merged after two approvals. Updated lockfile via uv lock on cryptography, idna, pytest, and urllib3 to fix OSV CI. Approved and passed checks. | |
| #1615 build(deps): bump idna + urllib3 | craft-parts | merged | Merged dependency update bumping idna to v3.18 and urllib3 to v2.7.0 to resolve open source vulnerabilities. Approved by two reviewers and passed CI checks. |