Update dependency certifi to v2024.7.4 [SECURITY] - autoclosed
Metadata
Current evaluation
Renovate dependency update for certifi to v2024.7.4 was autoclosed due to inactivity. Automerge was disabled, and the branch was never merged.
Suggested action: —
No scores available.
Issue body
[](https://renovatebot.com)
This PR contains the following updates:
| Package | Change | Age | Adoption | Passing | Confidence |
|---|---|---|---|---|---|
| [certifi](https://togithub.com/certifi/python-certifi) | `==2024.6.2` -> `==2024.7.4` | [](https://docs.renovatebot.com/merge-confidence/) | [](https://docs.renovatebot.com/merge-confidence/) | [](https://docs.renovatebot.com/merge-confidence/) | [](https://docs.renovatebot.com/merge-confidence/) |
### GitHub Vulnerability Alerts
#### [CVE-2024-39689](https://togithub.com/certifi/python-certifi/security/advisories/GHSA-248v-346w-9cwc)
Certifi 2024.07.04 removes root certificates from "GLOBALTRUST" from the root store. These are in the process of being removed from Mozilla's trust store.
GLOBALTRUST's root certificates are being removed pursuant to an investigation which identified "long-running and unresolved compliance issues". Conclusions of Mozilla's investigation can be found [here]( https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/XpknYMPO8dI).
---
### Release Notes
<details>
<summary>certifi/python-certifi (certifi)</summary>
### [`v2024.7.4`](https://togithub.com/certifi/python-certifi/compare/2024.06.02...2024.07.04)
[Compare Source](https://togithub.com/certifi/python-certifi/compare/2024.06.02...2024.07.04)
</details>
---
### Configuration
📅 **Schedule**: Branch creation - "" in timezone Etc/UTC, Automerge - "every weekend" in timezone Etc/UTC.
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://www.mend.io/free-developer-tools/renovate/). View repository job log [here](https://developer.mend.io/github/canonical/imagecraft).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy40MjEuOSIsInVwZGF0ZWRJblZlciI6IjM3LjQyMS45IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=-->
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Renovate dependency update for certifi to v2024.7.4 was autoclosed due to inactivity. Automerge was disabled, and the branch was never merged. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Renovate PR updating certifi to v2024.7.4 for CVE-2024-39689 was autoclosed without merging. Automerge was disabled by config, and the branch was automatically closed due to staleness or being superseded. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Security update for certifi to v2024.7.4 was autoclosed and never merged. Automerge was disabled by configuration, and the branch was abandoned due to prolonged inactivity. |
Update history
No update history recorded yet.
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #15 Update dependency certifi to v2023 [SECURITY] - autoclosed | imagecraft | closed | Security update PR for certifi to v2023.7.22 was autoclosed without merging. Renovate automatically closed the pull request due to expiration or branch updates, leaving the dependency unupdated. | |
| #4897 chore(deps): update dependency certifi to v2024 [security] - autoclosed | snapcraft | closed | The certifi v2024.7.4 security update was automatically closed without merging. Renovate bot generated the dependency change, but it was abandoned due to inactivity, leaving the repository on the previous version. | |
| #1181 chore(deps): update dependency certifi to v2023.7.22 [security] - autoclosed | charmcraft | closed | Renovate bot PR updating certifi to v2023.7.22 for CVE-2023-37920 was autoclosed due to inactivity. Automerge was disabled by configuration, and the request received no reviews or CI checks before automatic closure. | |
| #1234 build(deps): update dependency certifi to v2024.12.14 (hotfix/1.5) | rockcraft | closed | Closed without merging. The certifi dependency update to v2024.12.14 was abandoned after 49 days with no reviews, while several CI checks remained failing or pending. | |
| #4000 build(deps): bump certifi from 2022.9.24 to 2022.12.7 | snapcraft | closed | Closed without merging because the project already adopted a newer certifi version, rendering the update obsolete. Dependabot acknowledged the closure. | |
| #945 Bump certifi from 2022.6.15 to 2022.12.7 | charmcraft | closed | Closed without merging as the certifi dependency was already updated to the target version. Dependabot automatically resolved the request as it was no longer needed. |