Update dependency reportlab to v3.6.13 [SECURITY] - autoclosed
Metadata
Current evaluation
Automated reportlab update to v3.6.13 for CVE-2023-33733 was autoclosed without merging. The bot closed the inactive PR due to zero reviews and no CI checks.
Suggested action: —
No scores available.
Issue body
[](https://renovatebot.com)
This PR contains the following updates:
| Package | Change | Age | Adoption | Passing | Confidence |
|---|---|---|---|---|---|
| [reportlab](https://www.reportlab.com/) | `==3.6.12` -> `==3.6.13` | [](https://docs.renovatebot.com/merge-confidence/) | [](https://docs.renovatebot.com/merge-confidence/) | [](https://docs.renovatebot.com/merge-confidence/) | [](https://docs.renovatebot.com/merge-confidence/) |
---
> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
### GitHub Vulnerability Alerts
#### [CVE-2023-33733](https://nvd.nist.gov/vuln/detail/CVE-2023-33733)
Reportlab up to and including v3.6.12 allows attackers to execute arbitrary code via supplying a crafted PDF file.
---
### Configuration
📅 **Schedule**: Branch creation - "" in timezone Etc/UTC, Automerge - "every weekend" in timezone Etc/UTC.
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://www.mend.io/free-developer-tools/renovate/). View repository job log [here](https://developer.mend.io/github/canonical/imagecraft).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy44Ny4yIiwidXBkYXRlZEluVmVyIjoiMzcuODcuMiIsInRhcmdldEJyYW5jaCI6Im1haW4ifQ==-->
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Automated reportlab update to v3.6.13 for CVE-2023-33733 was autoclosed without merging. The bot closed the inactive PR due to zero reviews and no CI checks. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | The reportlab dependency update to v3.6.13 to address CVE-2023-33733 was autoclosed by Renovate bot. The changes were not merged and the branch was automatically closed, likely superseded by a newer update. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | The reportlab v3.6.13 security update PR was automatically closed by Renovate due to inactivity or being superseded, without being merged. |
Update history
No update history recorded yet.
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #6 Bump reportlab from 3.6.12 to 3.6.13 | imagecraft | closed | Closed as unnecessary. Dependabot's reportlab version bump was abandoned after the bot noted the package is no longer a project dependency. | |
| #12 Update dependency requests to v2.31.0 [SECURITY] - autoclosed | imagecraft | closed | Renovate autoclosed this pull request to update requests to v2.31.0 for CVE-2023-32681. The PR was abandoned without merging, indicating it was superseded by a newer update or stale configuration. | |
| #15 Update dependency certifi to v2023 [SECURITY] - autoclosed | imagecraft | closed | Security update PR for certifi to v2023.7.22 was autoclosed without merging. Renovate automatically closed the pull request due to expiration or branch updates, leaving the dependency unupdated. | |
| #11 Update dependency markdown-it-py to v2.2.0 [SECURITY] - autoclosed | imagecraft | closed | Renovate bot PR updating markdown-it-py to v2.2.0 for security fixes was autoclosed without review or merge. The update was abandoned, likely due to inactivity or configuration. | |
| #20 Update dependency paramiko to v3 [SECURITY] - autoclosed | imagecraft | closed | Renovate pull request to update paramiko to v3.4.0 for CVE-2023-48795 was autoclosed due to inactivity. The security update was abandoned and never merged. | |
| #10 Update dependency Pygments to v2.15.0 [SECURITY] - autoclosed | imagecraft | closed | Renovate bot PR to update Pygments to v2.15.0 for CVE-2022-40896 was autoclosed without merging. No reviews or CI checks were performed. | |
| #1117 build(deps): update dependency requests to v2.32.4 [security] (main) - autoclosed | craft-parts | closed | Renovate autoclosed the pull request updating requests to v2.32.4 for CVE-2024-47081. The security update was automatically closed and unmerged, likely due to CI failures or being superseded. |