← Back to issue list

Update dependency certifi to v2024.7.4 [SECURITY] - autoclosed

View original Github issue

Metadata

Project
imagecraft
Number
#45
Type
pull request
State
closed
Author
renovate[bot]
Labels
Created
Updated
Closed

Current evaluation

Renovate dependency update for certifi to v2024.7.4 was autoclosed due to inactivity. Automerge was disabled, and the branch was never merged.

Suggested action:

No scores available.

Issue body

[![Mend Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com) This PR contains the following updates: | Package | Change | Age | Adoption | Passing | Confidence | |---|---|---|---|---|---| | [certifi](https://togithub.com/certifi/python-certifi) | `==2024.6.2` -> `==2024.7.4` | [![age](https://developer.mend.io/api/mc/badges/age/pypi/certifi/2024.7.4?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/pypi/certifi/2024.7.4?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/pypi/certifi/2024.6.2/2024.7.4?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/pypi/certifi/2024.6.2/2024.7.4?slim=true)](https://docs.renovatebot.com/merge-confidence/) | ### GitHub Vulnerability Alerts #### [CVE-2024-39689](https://togithub.com/certifi/python-certifi/security/advisories/GHSA-248v-346w-9cwc) Certifi 2024.07.04 removes root certificates from "GLOBALTRUST" from the root store. These are in the process of being removed from Mozilla's trust store. GLOBALTRUST's root certificates are being removed pursuant to an investigation which identified "long-running and unresolved compliance issues". Conclusions of Mozilla's investigation can be found [here]( https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/XpknYMPO8dI). --- ### Release Notes <details> <summary>certifi/python-certifi (certifi)</summary> ### [`v2024.7.4`](https://togithub.com/certifi/python-certifi/compare/2024.06.02...2024.07.04) [Compare Source](https://togithub.com/certifi/python-certifi/compare/2024.06.02...2024.07.04) </details> --- ### Configuration 📅 **Schedule**: Branch creation - "" in timezone Etc/UTC, Automerge - "every weekend" in timezone Etc/UTC. 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://www.mend.io/free-developer-tools/renovate/). View repository job log [here](https://developer.mend.io/github/canonical/imagecraft). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy40MjEuOSIsInVwZGF0ZWRJblZlciI6IjM3LjQyMS45IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=-->

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.6-35b-a3b Renovate dependency update for certifi to v2024.7.4 was autoclosed due to inactivity. Automerge was disabled, and the branch was never merged.
qwen3.6-35b-a3b-mtp-q6 Renovate PR updating certifi to v2024.7.4 for CVE-2024-39689 was autoclosed without merging. Automerge was disabled by config, and the branch was automatically closed due to staleness or being superseded.
qwen3.6-35b-a3b-mtp-q6 Security update for certifi to v2024.7.4 was autoclosed and never merged. Automerge was disabled by configuration, and the branch was abandoned due to prolonged inactivity.

Update history

No update history recorded yet.

Related issues

Issue Project State Summary Similarity
#15 Update dependency certifi to v2023 [SECURITY] - autoclosed imagecraft closed Security update PR for certifi to v2023.7.22 was autoclosed without merging. Renovate automatically closed the pull request due to expiration or branch updates, leaving the dependency unupdated.
89%
#4897 chore(deps): update dependency certifi to v2024 [security] - autoclosed snapcraft closed The certifi v2024.7.4 security update was automatically closed without merging. Renovate bot generated the dependency change, but it was abandoned due to inactivity, leaving the repository on the previous version.
80%
#1181 chore(deps): update dependency certifi to v2023.7.22 [security] - autoclosed charmcraft closed Renovate bot PR updating certifi to v2023.7.22 for CVE-2023-37920 was autoclosed due to inactivity. Automerge was disabled by configuration, and the request received no reviews or CI checks before automatic closure.
78%
#1234 build(deps): update dependency certifi to v2024.12.14 (hotfix/1.5) rockcraft closed Closed without merging. The certifi dependency update to v2024.12.14 was abandoned after 49 days with no reviews, while several CI checks remained failing or pending.
72%
#4000 build(deps): bump certifi from 2022.9.24 to 2022.12.7 snapcraft closed Closed without merging because the project already adopted a newer certifi version, rendering the update obsolete. Dependabot acknowledged the closure.
71%
#945 Bump certifi from 2022.6.15 to 2022.12.7 charmcraft closed Closed without merging as the certifi dependency was already updated to the target version. Dependabot automatically resolved the request as it was no longer needed.
71%