← Back to issue list

build(deps): bump starlette

View original Github issue

Metadata

Project
imagecraft
Number
#350
Type
pull request
State
merged
Author
smethnani
Labels
Created
Updated
Closed

Current evaluation

Merged dependency update bumping starlette from v0.52.1 to v1.2.0 to resolve an OSV vulnerability. Approved by two reviewers and passed all CI checks prior to integration.

Suggested action:

No scores available.

Issue body

Bumps `starlette` from v0.52.1 -> v1.2.0 to resolve an osv --- - [x] I've followed the [contribution guidelines](https://github.com/canonical/imagecraft/blob/main/CONTRIBUTING.md). - [x] I've signed the [CLA](http://www.ubuntu.com/legal/contributors/). - [ ] I've successfully run `make lint && make test`. - [ ] I've added or updated any relevant documentation. - [ ] In documents I changed, I [added a meta description](https://canonical-starflow.readthedocs-hosted.com/how-to/add-a-page-meta-description/) if one was missing.

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.6-35b-a3b Merged dependency update bumping starlette from v0.52.1 to v1.2.0 to resolve an OSV vulnerability. Approved by two reviewers and passed all CI checks prior to integration.
qwen3.6-35b-a3b-mtp-q6 Merged dependency update bumping starlette from v0.52.1 to v1.2.0 to resolve an OSV vulnerability. Authored by maintainer smethnani, the change was successfully integrated into the repository.

Update history

No update history recorded yet.

Related issues

Issue Project State Summary Similarity
#84 build(deps): bump starlette from 0.48.0 to 0.49.1 debcraft merged Merged dependabot update to bump starlette from 0.48.0 to 0.49.1. The upgrade patches a FileResponse Range header security vulnerability and adds minor features. CI checks passed and reviewers approved the merge.
86%
#230 build(autogen): bump starlette for OSV imagecraft merged Merged to bump the Starlette dependency, resolving an OSV security warning. Approved by two reviewers, passed all CI checks, and updated the lock file with a minimal version change.
86%
#5119 build(deps): update dependency starlette to v0.40.0 [security] (main) snapcraft merged Merged dependency update upgrading starlette to v0.40.0 to resolve CVE-2024-47874, a denial-of-service vulnerability in multipart/form-data parsing. Approved by two reviewers with passing CI checks.
85%
#5120 build(deps): update dependency starlette to v0.40.0 [security] (hotfix/8.4) snapcraft merged Merged security hotfix updating starlette from 0.38.4 to 0.40.0 on the hotfix/8.4 branch. Resolves CVE-2024-47874 DoS vulnerability in multipart/form-data parsing. Approved by two reviewers and passed CI.
84%
#1181 build(deps): update dependency starlette to v0.47.2 [security] (hotfix/2.7) craft-parts merged Merged automated upgrade of starlette from v0.45.3 to v0.47.2 to patch CVE-2025-54121, fixing a thread-blocking vulnerability during large uploads. Approved by two reviewers and merged into hotfix/2.7.
84%
#1180 build(deps): update dependency starlette to v0.47.2 [security] (main) craft-parts merged Merged automated update upgrading starlette from 0.45.3 to 0.47.2 to resolve CVE-2025-54121, preventing main thread blocking during large file uploads. Approved by two reviewers and merged to main.
84%
#357 build(deps): bump cryptography and starlette imagecraft merged Merged dependency update bumping cryptography to 49.0.0 and adding starlette>=1.3.1 to resolve OSV security vulnerabilities. Approved by one reviewer and merged after passing required CI checks.
84%
#1629 build: bump starlette craft-parts merged Merged to bump starlette and resolve an OSV security advisory. Approved by two reviewers and passed CI after confirming python-apt warnings were false positives.
83%
#5118 build(deps): bump starlette from 0.38.5 to 0.40.0 snapcraft closed Closed after approval to update starlette to 0.40.0, addressing a multipart/form-data DoS vulnerability.
83%
#228 build(deps): add constraint for Starlette craft-platforms merged Merged to pin the Starlette indirect dependency, mitigating the BadHost CVE. Approved by two reviewers and integrated after passing the majority of CI checks.
82%