← Back to issue list

Update dependency certifi to v2023 [SECURITY] - autoclosed

View original Github issue

Metadata

Project
imagecraft
Number
#15
Type
pull request
State
closed
Author
renovate[bot]
Labels
Created
Updated
Closed

Current evaluation

Security update PR for certifi to v2023.7.22 was autoclosed without merging. Renovate automatically closed the pull request due to expiration or branch updates, leaving the dependency unupdated.

Suggested action:

No scores available.

Issue body

[![Mend Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com) This PR contains the following updates: | Package | Change | Age | Adoption | Passing | Confidence | |---|---|---|---|---|---| | [certifi](https://togithub.com/certifi/python-certifi) | `==2022.9.24` -> `==2023.7.22` | [![age](https://developer.mend.io/api/mc/badges/age/pypi/certifi/2023.7.22?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/pypi/certifi/2023.7.22?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/pypi/certifi/2022.9.24/2023.7.22?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/pypi/certifi/2022.9.24/2023.7.22?slim=true)](https://docs.renovatebot.com/merge-confidence/) | --- > [!WARNING] > Some dependencies could not be looked up. Check the Dependency Dashboard for more information. ### GitHub Vulnerability Alerts #### [CVE-2022-23491](https://togithub.com/certifi/python-certifi/security/advisories/GHSA-43fp-rhv2-5gv8) Certifi 2022.12.07 removes root certificates from "TrustCor" from the root store. These are in the process of being removed from Mozilla's trust store. TrustCor's root certificates are being removed pursuant to an investigation prompted by media reporting that TrustCor's ownership also operated a business that produced spyware. Conclusions of Mozilla's investigation can be found [here](https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/oxX69KFvsm4/m/yLohoVqtCgAJ). #### [CVE-2023-37920](https://togithub.com/certifi/python-certifi/security/advisories/GHSA-xqr8-7jwr-rhp7) Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store. These are in the process of being removed from Mozilla's trust store. e-Tugra's root certificates are being removed pursuant to an investigation prompted by reporting of security issues in their systems. Conclusions of Mozilla's investigation can be found [here](https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/C-HrP1SEq1A). --- ### Release Notes <details> <summary>certifi/python-certifi (certifi)</summary> ### [`v2023.7.22`](https://togithub.com/certifi/python-certifi/compare/2023.05.07...2023.07.22) [Compare Source](https://togithub.com/certifi/python-certifi/compare/2023.05.07...2023.07.22) ### [`v2023.5.7`](https://togithub.com/certifi/python-certifi/compare/2022.12.07...2023.05.07) [Compare Source](https://togithub.com/certifi/python-certifi/compare/2022.12.07...2023.05.07) ### [`v2022.12.7`](https://togithub.com/certifi/python-certifi/compare/2022.09.24...2022.12.07) [Compare Source](https://togithub.com/certifi/python-certifi/compare/2022.09.24...2022.12.07) </details> --- ### Configuration 📅 **Schedule**: Branch creation - "" in timezone Etc/UTC, Automerge - "every weekend" in timezone Etc/UTC. 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://www.mend.io/free-developer-tools/renovate/). View repository job log [here](https://developer.mend.io/github/canonical/imagecraft). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy44Ny4yIiwidXBkYXRlZEluVmVyIjoiMzcuODcuMiIsInRhcmdldEJyYW5jaCI6Im1haW4ifQ==-->

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.6-35b-a3b Security update PR for certifi to v2023.7.22 was autoclosed without merging. Renovate automatically closed the pull request due to expiration or branch updates, leaving the dependency unupdated.
qwen3.6-35b-a3b-mtp-q6 Renovate pull request to update certifi to v2023.7.22 for security patches was autoclosed without merging. Automerge was disabled by configuration, causing the PR to be abandoned due to inactivity.
qwen3.6-35b-a3b-mtp-q6 Renovate dependency update for certifi to v2023.7.22 was abandoned and autoclosed. Automerge was disabled by configuration, preventing integration. The security patch remains unapplied.

Update history

No update history recorded yet.

Related issues

Issue Project State Summary Similarity
#45 Update dependency certifi to v2024.7.4 [SECURITY] - autoclosed imagecraft closed Renovate dependency update for certifi to v2024.7.4 was autoclosed due to inactivity. Automerge was disabled, and the branch was never merged.
89%
#1181 chore(deps): update dependency certifi to v2023.7.22 [security] - autoclosed charmcraft closed Renovate bot PR updating certifi to v2023.7.22 for CVE-2023-37920 was autoclosed due to inactivity. Automerge was disabled by configuration, and the request received no reviews or CI checks before automatic closure.
81%
#4897 chore(deps): update dependency certifi to v2024 [security] - autoclosed snapcraft closed The certifi v2024.7.4 security update was automatically closed without merging. Renovate bot generated the dependency change, but it was abandoned due to inactivity, leaving the repository on the previous version.
80%
#12 Update dependency requests to v2.31.0 [SECURITY] - autoclosed imagecraft closed Renovate autoclosed this pull request to update requests to v2.31.0 for CVE-2023-32681. The PR was abandoned without merging, indicating it was superseded by a newer update or stale configuration.
74%
#4000 build(deps): bump certifi from 2022.9.24 to 2022.12.7 snapcraft closed Closed without merging because the project already adopted a newer certifi version, rendering the update obsolete. Dependabot acknowledged the closure.
72%
#4 Update dependency reportlab to v3.6.13 [SECURITY] - autoclosed imagecraft closed Automated reportlab update to v3.6.13 for CVE-2023-33733 was autoclosed without merging. The bot closed the inactive PR due to zero reviews and no CI checks.
72%
#11 Update dependency furo to v2023 - autoclosed craft-application closed Automerge was disabled in configuration, causing the Renovate bot PR updating furo from 2022.12.07 to 2023.5.20 to be autoclosed without merging. The request received no reviews or CI checks before being abandoned.
71%
#1117 build(deps): update dependency requests to v2.32.4 [security] (main) - autoclosed craft-parts closed Renovate autoclosed the pull request updating requests to v2.32.4 for CVE-2024-47081. The security update was automatically closed and unmerged, likely due to CI failures or being superseded.
71%
#6125 build(deps): update dependency requests to v2.33.0 [security] (main) - autoclosed snapcraft closed Renovate automatically closed the requests v2.33.0 security update without merging. The PR was abandoned due to inactivity and unresolved CI checks, leaving the dependency outdated.
71%
#945 Bump certifi from 2022.6.15 to 2022.12.7 charmcraft closed Closed without merging as the certifi dependency was already updated to the target version. Dependabot automatically resolved the request as it was no longer needed.
71%