← Back to issue list

build(autogen): bump starlette for OSV

View original Github issue

Metadata

Project
imagecraft
Number
#230
Type
pull request
State
merged
Author
bepri
Labels
Created
Updated
Closed

Current evaluation

Merged to bump the Starlette dependency, resolving an OSV security warning. Approved by two reviewers, passed all CI checks, and updated the lock file with a minimal version change.

Suggested action:

No scores available.

Issue body

- [ ] Have you followed the guidelines for contributing? - [ ] Have you signed the [CLA](http://www.ubuntu.com/legal/contributors/)? - [ ] Have you successfully run `make lint && make test`? --- Fixes an OSV warning from Starlette. Just ran `uv lock --upgrade-package starlette`

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.6-35b-a3b Merged to bump the Starlette dependency, resolving an OSV security warning. Approved by two reviewers, passed all CI checks, and updated the lock file with a minimal version change.
qwen3.6-35b-a3b-mtp-q6 Merged an update to upgrade the Starlette dependency, resolving an OSV security warning. The change was applied using uv lock --upgrade-package starlette.
qwen3.6-35b-a3b-mtp-q6 Merged a maintainer pull request upgrading Starlette to resolve an OSV security warning. The package was updated via uv lock and successfully integrated into the repository.

Update history

No update history recorded yet.

Related issues

Issue Project State Summary Similarity
#1629 build: bump starlette craft-parts merged Merged to bump starlette and resolve an OSV security advisory. Approved by two reviewers and passed CI after confirming python-apt warnings were false positives.
86%
#350 build(deps): bump starlette imagecraft merged Merged dependency update bumping starlette from v0.52.1 to v1.2.0 to resolve an OSV vulnerability. Approved by two reviewers and passed all CI checks prior to integration.
86%
#190 build(deps): add constraint for Starlette craft-grammar merged Merged to pin the Starlette dependency to a secure version, mitigating the BadHost CVE. Approved by two reviewers and passed CI checks. The update applied minor constraint changes across two files.
77%
#228 build(deps): add constraint for Starlette craft-platforms merged Merged to pin the Starlette indirect dependency, mitigating the BadHost CVE. Approved by two reviewers and integrated after passing the majority of CI checks.
77%
#357 build(deps): bump cryptography and starlette imagecraft merged Merged dependency update bumping cryptography to 49.0.0 and adding starlette>=1.3.1 to resolve OSV security vulnerabilities. Approved by one reviewer and merged after passing required CI checks.
77%
#333 build: bump urllib3 and starlette craft-store merged Merged update bumping urllib3 and starlette to resolve OSV security vulnerabilities. Approved by two reviewers with all CI checks passing. Changes modified a single file with minimal version adjustments.
77%
#164 build(deps): add constraint for Starlette debcraft merged Merged to pin the Starlette indirect dependency to a version unaffected by the BadHost CVE. Approved by two reviewers and passed CI checks.
76%
#376 build(deps): add constraint for Starlette craft-store merged Merged to pin Starlette and mitigate the BadHost CVE. Approved by two reviewers and passed CI checks. The change adds a version constraint to the indirect dependency, resolving the security vulnerability.
76%
#972 build(deps): add constraint for Starlette craft-providers merged Merged to pin the Starlette indirect dependency, mitigating the BadHost CVE. Approved by two reviewers and validated by CI before integration.
76%
#457 build(autogen): bump dependencies craft-cli merged Merged after reviewer approval and passing all CI checks. Bumped dependencies across two files to resolve multiple OSV security vulnerabilities. All tests, linting, and security scans passed successfully.
75%