← Back to issue list

build: update requests to 2.33.0

View original Github issue

Metadata

Project
imagecraft
Number
#308
Type
pull request
State
merged
Author
smethnani
Labels
Created
Updated
Closed

Current evaluation

Merged a dependency update bumping requests to 2.33.0 to resolve an OSV. Approved by two reviewers and passed CI, the single-file change addresses the security vulnerability.

Suggested action:

No scores available.

Issue body

Bumps requests to 2.33.0 to resolve an osv --- - [x] I've followed the [contribution guidelines](https://github.com/canonical/imagecraft/blob/main/CONTRIBUTING.md). - [x] I've signed the [CLA](http://www.ubuntu.com/legal/contributors/). - [ ] I've successfully run `make lint && make test`. - [ ] I've added or updated any relevant documentation.

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.6-35b-a3b Merged a dependency update bumping requests to 2.33.0 to resolve an OSV. Approved by two reviewers and passed CI, the single-file change addresses the security vulnerability.
qwen3.6-35b-a3b-mtp-q6 Merged dependency update to requests 2.33.0 to resolve an OSV. Authored by maintainer smethnani, the change was successfully integrated into the codebase.
qwen3.6-35b-a3b-mtp-q6 Merged an update upgrading the requests dependency to version 2.33.0 to resolve an open source vulnerability. Authored by maintainer smethnani, the change was integrated without additional comments.

Update history

No update history recorded yet.

Related issues

Issue Project State Summary Similarity
#1121 build: bump requests to avoid OSV craft-parts merged Merged after bumping the requests dependency to resolve an OSV vulnerability. Approved by two reviewers with all CI checks passing. The update modifies three files with 136 additions and 10 deletions.
86%
#1516 build(deps): update dependency requests to v2.33.0 [security] (main) craft-parts merged Merged automated dependency update upgrading requests from 2.32.5 to 2.33.0 to patch CVE-2026-25645. Approved by two reviewers, passed CI validation, and merged into main.
84%
#348 build(deps): update dependency requests to v2.33.0 [security] (main) craft-store merged Merged automated dependency update upgrading requests from 2.32.4 to 2.33.0 to resolve CVE-2026-25645. Approved by reviewers, passed CI checks, and merged into main.
84%
#5553 build(deps): bump requests to 2.32.4 snapcraft merged Merged a dependency update bumping requests to 2.32.4 to patch a security vulnerability. Approved by two reviewers and passed core CI checks before integration.
83%
#5065 build(deps): update dependency requests to v2.32.2 [security] (hotfix/7.5) snapcraft merged Merged an automated security update upgrading the requests dependency from v2.28.1 to v2.32.2 to fix CVE-2024-35195. Approved by two reviewers, passed CI, and merged into the hotfix/7.5 branch.
81%
#1519 build(deps): update dependency requests to v2.33.0 [security] (hotfix/2.7) craft-parts closed Updated requests to v2.33.0 to patch CVE-2026-25645. Closed without merging, likely due to failing CI checks or abandonment. No reviewer comments were recorded.
81%
#122 build(deps): bump requests from 2.32.5 to 2.33.0 starflow merged Merged Dependabot update bumping requests from 2.32.5 to 2.33.0. Includes CVE-2026-25645 security fix and Python 3.9 removal. All CI checks passed and two reviewers approved the change prior to merge.
80%
#5067 build(deps): update dependency requests to v2.32.2 [security] (hotfix/8.4) snapcraft merged Merged security hotfix updating requests from v2.31.0 to v2.32.2 to resolve CVE-2024-35195, fixing SSL verification state leakage in HTTP sessions. Approved by two reviewers and passed CI checks.
78%
#106 build(deps): bump requests from 2.32.5 to 2.33.0 debcraft merged Merged Dependabot update bumping requests from 2.32.5 to 2.33.0. Includes CVE-2026-25645 security fix, PEP 517 migration, and Python 3.9 removal. Approved by two reviewers with all CI checks passing before merge.
77%
#5064 build(deps): update dependency requests to v2.32.2 [security] (main) snapcraft merged Merged to main after approval and CI. Updates requests from v2.31.0 to v2.32.2 to fix CVE-2024-35195, resolving an SSL verification bypass vulnerability in persistent sessions.
77%