← Back to issue list

build(deps): update deps to resolve OSV vulnerabilities

View original Github issue

Metadata

Project
rockcraft
Number
#1278
Type
pull request
State
merged
Author
tigarmo
Labels
Created
Updated
Closed

Current evaluation

Merged dependency updates for cryptography, dulwich, idna, lxml, poetry, pytest, urllib3, and msgpack to resolve OSV vulnerabilities. Added osv-scanner exceptions for python-apt and cryptography. Approved and passed CI.

Suggested action:

No scores available.

Issue body

Updated cryptography v46.0.6 -> v49.0.0 Updated dulwich v1.1.0 -> v1.2.7 Updated idna v3.11 -> v3.18 Updated lxml v6.0.2 -> v6.1.1 Updated poetry v2.3.3 -> v2.4.1 Updated poetry-core v2.3.2 -> v2.4.0 Updated pytest v9.0.2 -> v9.1.1 Updated urllib3 v2.6.3 -> v2.7.0 Updated msgpack v1.1.2 -> v1.2.1 Also add a python-apt exception on osv-scanner, as the detected CVEs are quite old and not applicable (false-positive?), and an exception for 'cryptography', because we can't update and the CVE affects the pre-built wheel that we don't use. --- - [ ] I've followed the [contribution guidelines](https://github.com/canonical/rockcraft/blob/main/CONTRIBUTING.md). - [ ] I've signed the [CLA](http://www.ubuntu.com/legal/contributors/). - [ ] I've successfully run `make lint && make test`. - [ ] I've added or updated any relevant documentation. - [ ] In documents I changed, I [added a meta description](https://canonical-starflow.readthedocs-hosted.com/how-to/add-a-page-meta-description/) if one was missing. - [ ] I've updated the relevant release notes.

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.6-35b-a3b Merged dependency updates for cryptography, dulwich, idna, lxml, poetry, pytest, urllib3, and msgpack to resolve OSV vulnerabilities. Added osv-scanner exceptions for python-apt and cryptography. Approved and passed CI.
qwen3.6-35b-a3b-mtp-q6
Staleness: 0
Complexity: 10
Confidence: 90
needs review Updates multiple Python dependencies to resolve OSV security vulnerabilities and adds an osv-scanner exception for python-apt. Awaiting maintainer review and CI checks.

Update history

No update history recorded yet.

Related issues

Issue Project State Summary Similarity
#131 build(deps): resolve OSVs debcraft merged Merged dependency updates to resolve OSV vulnerabilities. Updated cryptography, pygments, pytest, requests, and craft-parts via uv lock. Approved by two reviewers with all CI checks passing. Changes accepted despite minor pinning discussions.
86%
#945 build(deps): resolve OSVs craft-providers merged Merged dependency updates resolving OSV vulnerabilities. Bumps cryptography to 46.0.7 and pytest to 9.0.3 to fix minimum dependency test failures. Conflicts resolved automatically before final merge.
85%
#143 build(deps): resolve OSVs debcraft merged Resolved OSV security vulnerabilities by updating idna to v3.18 and urllib3 to v2.7.0. Approved by a reviewer, passed all CI checks, and merged.
83%
#353 build(deps): bump libraries for OSVs craft-store merged Merged after updating cryptography, markdown, and pygments to patch OSV vulnerabilities. Approved by two reviewers and passed all CI checks.
82%
#1055 build(deps): bump cryptography craft-application merged Merged after bumping the cryptography dependency to resolve an OSV security vulnerability. Approved by two reviewers and passed all CI checks, including security scans and multi-platform tests.
79%
#81 build(deps): resolve OSVs craft-artifacts merged Merged after two approvals. Updates pygments to 2.20.0 and pytest to 9.0.3 to resolve OSV security vulnerabilities. CI checks passed, and the six-line dependency lock update was successfully integrated.
79%
#182 build: bump deps, fix security scan debcraft merged Merged following approval and passing CI checks. Bumped cryptography, httplib2, and setuptools to resolve OSV vulnerabilities and corrected the security scan workflow. Closes #181.
79%
#421 build: bump dependencies for OSVs imagecraft merged Merged after two approvals. Updated cryptography to 50.0.0 and httplib2 to 0.32.0 via uv lock to address OSV vulnerabilities. Test and lint checks passed; snap build failures were bypassed to proceed with the dependency update.
78%
#180 build(deps): resolve OSVs craft-grammar merged Merged following two approvals and successful CI checks. Updated pytest from v9.0.2 to v9.0.3 to resolve OSV security vulnerabilities across one dependency file.
78%
#453 build(deps): bump pytest craft-cli merged Merged a dependency update to bump pytest, resolving an OSV scanner vulnerability. Approved by one reviewer and passed all CI checks across multiple platforms and Python versions.
78%