← Back to issue list

Update dependency reportlab to v3.6.13 [SECURITY] - autoclosed

View original Github issue

Metadata

Project
imagecraft
Number
#4
Type
pull request
State
closed
Author
renovate[bot]
Labels
Created
Updated
Closed

Current evaluation

Automated reportlab update to v3.6.13 for CVE-2023-33733 was autoclosed without merging. The bot closed the inactive PR due to zero reviews and no CI checks.

Suggested action:

No scores available.

Issue body

[![Mend Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com) This PR contains the following updates: | Package | Change | Age | Adoption | Passing | Confidence | |---|---|---|---|---|---| | [reportlab](https://www.reportlab.com/) | `==3.6.12` -> `==3.6.13` | [![age](https://developer.mend.io/api/mc/badges/age/pypi/reportlab/3.6.13?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/pypi/reportlab/3.6.13?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/pypi/reportlab/3.6.12/3.6.13?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/pypi/reportlab/3.6.12/3.6.13?slim=true)](https://docs.renovatebot.com/merge-confidence/) | --- > [!WARNING] > Some dependencies could not be looked up. Check the Dependency Dashboard for more information. ### GitHub Vulnerability Alerts #### [CVE-2023-33733](https://nvd.nist.gov/vuln/detail/CVE-2023-33733) Reportlab up to and including v3.6.12 allows attackers to execute arbitrary code via supplying a crafted PDF file. --- ### Configuration 📅 **Schedule**: Branch creation - "" in timezone Etc/UTC, Automerge - "every weekend" in timezone Etc/UTC. 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://www.mend.io/free-developer-tools/renovate/). View repository job log [here](https://developer.mend.io/github/canonical/imagecraft). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy44Ny4yIiwidXBkYXRlZEluVmVyIjoiMzcuODcuMiIsInRhcmdldEJyYW5jaCI6Im1haW4ifQ==-->

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.6-35b-a3b Automated reportlab update to v3.6.13 for CVE-2023-33733 was autoclosed without merging. The bot closed the inactive PR due to zero reviews and no CI checks.
qwen3.6-35b-a3b-mtp-q6 The reportlab dependency update to v3.6.13 to address CVE-2023-33733 was autoclosed by Renovate bot. The changes were not merged and the branch was automatically closed, likely superseded by a newer update.
qwen3.6-35b-a3b-mtp-q6 The reportlab v3.6.13 security update PR was automatically closed by Renovate due to inactivity or being superseded, without being merged.

Update history

No update history recorded yet.

Related issues

Issue Project State Summary Similarity
#6 Bump reportlab from 3.6.12 to 3.6.13 imagecraft closed Closed as unnecessary. Dependabot's reportlab version bump was abandoned after the bot noted the package is no longer a project dependency.
73%
#12 Update dependency requests to v2.31.0 [SECURITY] - autoclosed imagecraft closed Renovate autoclosed this pull request to update requests to v2.31.0 for CVE-2023-32681. The PR was abandoned without merging, indicating it was superseded by a newer update or stale configuration.
72%
#15 Update dependency certifi to v2023 [SECURITY] - autoclosed imagecraft closed Security update PR for certifi to v2023.7.22 was autoclosed without merging. Renovate automatically closed the pull request due to expiration or branch updates, leaving the dependency unupdated.
72%
#11 Update dependency markdown-it-py to v2.2.0 [SECURITY] - autoclosed imagecraft closed Renovate bot PR updating markdown-it-py to v2.2.0 for security fixes was autoclosed without review or merge. The update was abandoned, likely due to inactivity or configuration.
71%
#20 Update dependency paramiko to v3 [SECURITY] - autoclosed imagecraft closed Renovate pull request to update paramiko to v3.4.0 for CVE-2023-48795 was autoclosed due to inactivity. The security update was abandoned and never merged.
71%
#10 Update dependency Pygments to v2.15.0 [SECURITY] - autoclosed imagecraft closed Renovate bot PR to update Pygments to v2.15.0 for CVE-2022-40896 was autoclosed without merging. No reviews or CI checks were performed.
71%
#1117 build(deps): update dependency requests to v2.32.4 [security] (main) - autoclosed craft-parts closed Renovate autoclosed the pull request updating requests to v2.32.4 for CVE-2024-47081. The security update was automatically closed and unmerged, likely due to CI failures or being superseded.
70%