← Back to issue list

build: bump dependencies for OSVs

View original Github issue

Metadata

Project
imagecraft
Number
#421
Type
pull request
State
merged
Author
bepri
Labels
Created
Updated
Closed

Current evaluation

Merged after two approvals. Updated cryptography to 50.0.0 and httplib2 to 0.32.0 via uv lock to address OSV vulnerabilities. Test and lint checks passed; snap build failures were bypassed to proceed with the dependency update.

Suggested action:

No scores available.

Issue body

``` ❯ uv lock -P cryptography -P httplib2 -P setuptools Resolved 139 packages in 1.70s Updated cryptography v49.0.0 -> v50.0.0 Updated httplib2 v0.31.2 -> v0.32.0 ``` --- - [ ] I've followed the [contribution guidelines](https://github.com/canonical/imagecraft/blob/main/CONTRIBUTING.md). - [ ] I've signed the [CLA](http://www.ubuntu.com/legal/contributors/). - [ ] I've successfully run `make lint && make test`. - [ ] I've added or updated any relevant documentation. - [ ] In documents I changed, I [added a meta description](https://canonical-starflow.readthedocs-hosted.com/how-to/add-a-page-meta-description/) if one was missing.

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.6-35b-a3b Merged after two approvals. Updated cryptography to 50.0.0 and httplib2 to 0.32.0 via uv lock to address OSV vulnerabilities. Test and lint checks passed; snap build failures were bypassed to proceed with the dependency update.
qwen/qwen3.6-35b-a3b
Staleness: 5
Complexity: 15
Confidence: 85
needs review Bumps cryptography, httplib2, and setuptools to address OSV security advisories. Approved by one reviewer, but CI fails on snap-builds and build steps.
qwen/qwen3.6-35b-a3b
Staleness: 5
Complexity: 15
Confidence: 90
needs review Updates cryptography, httplib2, and setuptools to latest versions to address OSV security advisories. CI is passing, awaiting maintainer review.
qwen/qwen3.6-35b-a3b
Staleness: 5
Complexity: 15
Confidence: 90
needs review Updates cryptography, httplib2, and setuptools to address OSV security vulnerabilities. Currently pending maintainer review with one failing OSV-scanner CI check.
qwen/qwen3.6-35b-a3b
Staleness: 5
Complexity: 15
Confidence: 85
needs review Updates cryptography, httplib2, and setuptools to address OSV security advisories. Currently pending maintainer review with failing snap-build and OSV-scanner CI checks.

Update history

Date Change
updated
updated
updated
updated
created

Related issues

Issue Project State Summary Similarity
#418 build: bump cryptography for OSV craft-store merged Merged to bump the cryptography dependency and resolve an OSV vulnerability. Approved by a reviewer, passed CI checks, and modified two files.
81%
#945 build(deps): resolve OSVs craft-providers merged Merged dependency updates resolving OSV vulnerabilities. Bumps cryptography to 46.0.7 and pytest to 9.0.3 to fix minimum dependency test failures. Conflicts resolved automatically before final merge.
80%
#353 build(deps): bump libraries for OSVs craft-store merged Merged after updating cryptography, markdown, and pygments to patch OSV vulnerabilities. Approved by two reviewers and passed all CI checks.
80%
#131 build(deps): resolve OSVs debcraft merged Merged dependency updates to resolve OSV vulnerabilities. Updated cryptography, pygments, pytest, requests, and craft-parts via uv lock. Approved by two reviewers with all CI checks passing. Changes accepted despite minor pinning discussions.
79%
#1055 build(deps): bump cryptography craft-application merged Merged after bumping the cryptography dependency to resolve an OSV security vulnerability. Approved by two reviewers and passed all CI checks, including security scans and multi-platform tests.
79%
#1278 build(deps): update deps to resolve OSV vulnerabilities rockcraft merged Merged dependency updates for cryptography, dulwich, idna, lxml, poetry, pytest, urllib3, and msgpack to resolve OSV vulnerabilities. Added osv-scanner exceptions for python-apt and cryptography. Approved and passed CI.
78%
#356 build(deps): bump cryptography craft-store merged Merged to bump the cryptography dependency and resolve OSV vulnerability GHSA-p423-j2cm-9vmq. Approved by two reviewers and passed CI checks, with one Windows test failure noted.
77%
#1061 build(deps): bump cryptography craft-application merged Merged a dependency update to bump cryptography, resolving an OSV security vulnerability. Approved by two reviewers and passing all CI checks, the change modified one file with 51 additions and 51 deletions.
77%
#182 build: bump deps, fix security scan debcraft merged Merged following approval and passing CI checks. Bumped cryptography, httplib2, and setuptools to resolve OSV vulnerabilities and corrected the security scan workflow. Closes #181.
76%
#1098 build(deps): bump cryptography craft-application merged Bumps cryptography from v48.0.0 to v49.0.0 to resolve OSV vulnerability GHSA-537c-gmf6-5ccf. Approved by two reviewers, passed CI checks, and successfully merged.
75%