← Back to issue list

build(deps): bump jinja2 from 3.1.5 to 3.1.6

View original Github issue

Metadata

Project
imagecraft
Number
#106
Type
pull request
State
merged
Author
upils
Labels
Created
Updated
Closed

Current evaluation

Merged a dependency update bumping jinja2 from 3.1.5 to 3.1.6 to patch security vulnerability GHSA-cpwx-vrp4-4pq7. Approved by two reviewers, passed CI, and merged after coordinating with a related pull request.

Suggested action:

No scores available.

Issue body

- [ ] Have you followed the guidelines for contributing? - [ ] Have you signed the [CLA](http://www.ubuntu.com/legal/contributors/)? - [ ] Have you successfully run `make lint && make test`? --- Addresses https://osv.dev/vulnerability/GHSA-cpwx-vrp4-4pq7

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.6-35b-a3b Merged a dependency update bumping jinja2 from 3.1.5 to 3.1.6 to patch security vulnerability GHSA-cpwx-vrp4-4pq7. Approved by two reviewers, passed CI, and merged after coordinating with a related pull request.
qwen3.6-35b-a3b-mtp-q6 Merged dependency update bumping jinja2 from 3.1.5 to 3.1.6 to address security vulnerability GHSA-cpwx-vrp4-4pq7. Initially held pending PR #105, then merged after that dependency was resolved.
qwen3.6-35b-a3b-mtp-q6 Merged dependency update bumping jinja2 from 3.1.5 to 3.1.6 to patch vulnerability GHSA-cpwx-vrp4-4pq7. Initially deferred pending another PR, it was merged after the prerequisite was resolved.

Update history

No update history recorded yet.

Related issues

Issue Project State Summary Similarity
#5305 build(deps): update jinja to 3.1.6 snapcraft merged Merged update to jinja 3.1.6 to resolve security vulnerability GHSA-cpwx-vrp4-4pq7. Approved by two reviewers, passed CI, and integrated without comments.
93%
#5312 build(deps): bump jinja2 from 3.1.5 to 3.1.6 in /docs/.sphinx snapcraft merged Merged Dependabot update bumping jinja2 from 3.1.5 to 3.1.6 in /docs/.sphinx. The security patch fixes a sandbox attribute lookup bypass. Approved by reviewers and passed CI before automatic merge.
88%
#2064 build(deps): update dependency jinja2 to v3.1.5 [security] (main) charmcraft merged Merged an automated dependency update upgrading jinja2 from 3.1.4 to 3.1.5 to patch CVE-2024-56326 and CVE-2024-56201. The change passed CI, received reviewer approval, and was auto-merged to main.
88%
#1038 build(deps): update jinja2 to 3.1.6 craft-parts merged Merged to update jinja2 to 3.1.6, resolving CVE-2025-27516 sandbox breakout vulnerability. Approved by two reviewers, passed CI, and applied with a minimal five-line change across two files.
88%
#4518 build(deps): bump jinja2 from 3.1.2 to 3.1.3 in /docs/.sphinx snapcraft merged Dependabot PR bumping jinja2 from 3.1.2 to 3.1.3 in /docs/.sphinx was approved by two reviewers, passed CI checks, and successfully merged. The update resolves security vulnerabilities and compiler errors in the template engine.
88%
#2206 build(deps-dev): bump jinja2 from 3.1.5 to 3.1.6 charmcraft closed The jinja2 update from 3.1.5 to 3.1.6 was abandoned because the dependency is already up-to-date, making the pull request redundant.
85%
#2210 build(deps): update dependency jinja2 to v3.1.6 [security] (hotfix/3.4) - autoclosed charmcraft closed Dependency update PR for jinja2 v3.1.6 addressing CVE-2025-27516 was autoclosed without merging. No reviews or CI checks ran.
85%
#5190 build(deps): update dependency jinja2 to v3.1.5 [security] (main) snapcraft merged Merged automated dependency update upgrading Jinja2 from 3.1.4 to 3.1.5 to patch CVE-2024-56326 and CVE-2024-56201. The change passed CI, received two approvals, and was auto-merged into main by Renovate bot.
84%
#5189 build(deps): bump jinja2 from 3.1.4 to 3.1.5 snapcraft closed PR closed because jinja2 is already up-to-date. Dependabot noted the update is no longer needed, so the dependency bump was abandoned without merging.
84%
#252 build(deps): update Jinja2 craft-store merged Merged to update the Jinja2 dependency, resolving a failing pipeline and addressing a CVE scan result. The change also disabled a false-positive S105 security check. Approved by two reviewers and passed all CI checks.
83%