build(deps): bump idna
Metadata
Current evaluation
Merged dependency update bumping idna from 3.11 to 3.15 to resolve an OSV vulnerability. Approved by two reviewers with all CI checks passing. Single file change with minimal modifications.
Suggested action: —
No scores available.
Issue body
Bumps `idna` from 3.11 to 3.15 to resolve an osv
---
- [x] I've followed the [contribution guidelines](https://github.com/canonical/imagecraft/blob/main/CONTRIBUTING.md).
- [x] I've signed the [CLA](http://www.ubuntu.com/legal/contributors/).
- [x] I've successfully run `make lint && make test`.
- [ ] I've added or updated any relevant documentation.
- [ ] In documents I changed, I [added a meta description](https://canonical-starflow.readthedocs-hosted.com/how-to/add-a-page-meta-description/) if one was missing.
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Merged dependency update bumping idna from 3.11 to 3.15 to resolve an OSV vulnerability. Approved by two reviewers with all CI checks passing. Single file change with minimal modifications. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Merged dependency update bumping idna from 3.11 to 3.15 to resolve an OSV vulnerability. Changes passed linting and testing before final merge. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Merged a dependency update bumping idna from 3.11 to 3.15 to resolve an OSV. The change passed lint and test checks before integration. |
Update history
No update history recorded yet.
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #1076 build(deps): bump idna, urllib3 | craft-application | merged | Merged dependency update bumping idna and urllib3 to resolve OSV security vulnerabilities. Approved by one reviewer with all CI checks passing. The change modifies a single file with minimal adjustments. | |
| #6265 build(deps): bump idna, urllib3 | snapcraft | merged | Merged a dependency update bumping idna and urllib3 to resolve OSV security vulnerabilities. Approved by two reviewers and successfully passed CI checks. | |
| #5439 build(deps): update dependency idna to v3.10 (main) | snapcraft | merged | Merged automated idna dependency update from v3.7 to v3.10 into main. Approved by two reviewers and passed CI checks before successful integration. | |
| #4727 build(deps): bump idna from 3.6 to 3.7 | snapcraft | closed | Closed and superseded by pull request #4726. Dependabot proposed bumping idna from 3.6 to 3.7 to address CVE-2024-3651. The dependency update was handled through the referenced PR instead. | |
| #1615 build(deps): bump idna + urllib3 | craft-parts | merged | Merged dependency update bumping idna to v3.18 and urllib3 to v2.7.0 to resolve open source vulnerabilities. Approved by two reviewers and passed CI checks. | |
| #1938 build(deps): update dependency idna to v3.10 (main) | charmcraft | merged | Merged automated dependency update upgrading idna from v3.7 to v3.10. The change passed CI checks, received two approvals, and was merged into the main branch. | |
| #4725 build(deps): bump idna from 3.4 to 3.7 in /docs/.sphinx | snapcraft | closed | Dependabot PR to update idna to 3.7 for CVE-2024-3651 was closed and superseded by pull request #4726. The security patch was applied in the alternative branch instead. | |
| #143 build(deps): resolve OSVs | debcraft | merged | Resolved OSV security vulnerabilities by updating idna to v3.18 and urllib3 to v2.7.0. Approved by a reviewer, passed all CI checks, and merged. | |
| #1121 build: bump requests to avoid OSV | craft-parts | merged | Merged after bumping the requests dependency to resolve an OSV vulnerability. Approved by two reviewers with all CI checks passing. The update modifies three files with 136 additions and 10 deletions. | |
| #321 build(deps): bump pytest | imagecraft | merged | Merged a dependency update bumping pytest to resolve an OSV vulnerability. Approved by two reviewers with all CI checks passing. The change modified a single file with minimal adjustments. |