build(deps): bump lxml from 4.5.0 to 4.6.2
Metadata
Current evaluation
Merged a Dependabot update bumping lxml from 4.5.0 to 4.6.2 to resolve security vulnerabilities and bugs. CI checks passed and the dependency upgrade was successfully integrated.
Suggested action: —
No scores available.
Issue body
Bumps [lxml](https://github.com/lxml/lxml) from 4.5.0 to 4.6.2.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/lxml/lxml/blob/master/CHANGES.txt">lxml's changelog</a>.</em></p>
<blockquote>
<h1>4.6.2 (2020-11-26)</h1>
<h2>Bugs fixed</h2>
<ul>
<li>A vulnerability (CVE-2020-27783) was discovered in the HTML Cleaner by Yaniv Nizry,
which allowed JavaScript to pass through. The cleaner now removes more sneaky
"style" content.</li>
</ul>
<h1>4.6.1 (2020-10-18)</h1>
<h2>Bugs fixed</h2>
<ul>
<li>A vulnerability was discovered in the HTML Cleaner by Yaniv Nizry, which allowed
JavaScript to pass through. The cleaner now removes more sneaky "style" content.</li>
</ul>
<h1>4.6.0 (2020-10-17)</h1>
<h2>Features added</h2>
<ul>
<li>
<p>GH#310: <code>lxml.html.InputGetter</code> supports <code>__len__()</code> to count the number of input fields.
Patch by Aidan Woolley.</p>
</li>
<li>
<p><code>lxml.html.InputGetter</code> has a new <code>.items()</code> method to ease processing all input fields.</p>
</li>
<li>
<p><code>lxml.html.InputGetter.keys()</code> now returns the field names in document order.</p>
</li>
<li>
<p><a href="https://github-redirect.dependabot.com/lxml/lxml/issues/309">GH-309</a>: The API documentation is now generated using <code>sphinx-apidoc</code>.
Patch by Chris Mayo.</p>
</li>
</ul>
<h2>Bugs fixed</h2>
<ul>
<li>
<p>LP#1869455: C14N 2.0 serialisation failed for unprefixed attributes
when a default namespace was defined.</p>
</li>
<li>
<p><code>TreeBuilder.close()</code> raised <code>AssertionError</code> in some error cases where it
should have raised <code>XMLSyntaxError</code>. It now raises a combined exception to
keep up backwards compatibility, while switching to <code>XMLSyntaxError</code> as an
interface.</p>
</li>
</ul>
<p>4.5.2 (2020-07-09)</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="https://github.com/lxml/lxml/commit/4cb57362deb23bca0f70f41ab1efa13390fcdbb1"><code>4cb5736</code></a> Work around Py2's lack of "re.ASCII".</li>
<li><a href="https://github.com/lxml/lxml/commit/c30106ff2648cdafe7857654e9606c491b1acf4d"><code>c30106f</code></a> Prepare release of 4.6.2.</li>
<li><a href="https://github.com/lxml/lxml/commit/a105ab8dc262ec6735977c25c13f0bdfcdec72a7"><code>a105ab8</code></a> Prevent combinations of <math/svg> and <style> to sneak JavaScript through th...</li>
<li><a href="https://github.com/lxml/lxml/commit/c053dc159c7f0a6a98922c937a0baede7ce7af9d"><code>c053dc1</code></a> Add a recipe for a look-ahead generator to allow modifications during tree it...</li>
<li><a href="https://github.com/lxml/lxml/commit/b083124281d824eb861ff58e7276a5c1f1d8c18d"><code>b083124</code></a> lxml actually works in Py3.9.</li>
<li><a href="https://github.com/lxml/lxml/commit/0f80590d7ebe62c61d2bdf2a220a093821dcbab8"><code>0f80590</code></a> lxml actually works in Py3.9.</li>
<li><a href="https://github.com/lxml/lxml/commit/fd8893ccb538e95c5acb2a2b47f0e87003de5b0d"><code>fd8893c</code></a> Add a doc note that the .find() methods are usually faster than one might exp...</li>
<li><a href="https://github.com/lxml/lxml/commit/eb6df27fc265cea4462f966282a701acdad5d167"><code>eb6df27</code></a> Update release version on homepage.</li>
<li><a href="https://github.com/lxml/lxml/commit/69b5c9bd575800f80a6515aeef6421f33db0294d"><code>69b5c9b</code></a> Automate the build artefact downloading from github and appveyor.</li>
<li><a href="https://github.com/lxml/lxml/commit/61432a8489657744ed32367ed9fb17fafe405d8e"><code>61432a8</code></a> Prepare release of lxml 4.6.1.</li>
<li>Additional commits viewable in <a href="https://github.com/lxml/lxml/compare/lxml-4.5.0...lxml-4.6.2">compare view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language
- `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language
- `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language
- `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/snapcore/snapcraft/network/alerts).
</details>
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Merged a Dependabot update bumping lxml from 4.5.0 to 4.6.2 to resolve security vulnerabilities and bugs. CI checks passed and the dependency upgrade was successfully integrated. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Merged Dependabot update bumping lxml from 4.5.0 to 4.6.2, resolving CVE-2020-27783 and other bug fixes. Code coverage remained stable at 90.76%. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Merged Dependabot PR updating lxml from 4.5.0 to 4.6.2. The update patches CVE-2020-27783, fixes bugs, and adds features. Code coverage remained unchanged upon merge. |
Update history
No update history recorded yet.
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #3606 build(deps): bump lxml from 4.6.3 to 4.6.5 | snapcraft | merged | Merged Dependabot update bumping lxml from 4.6.3 to 4.6.5. The upgrade patches two HTML cleaner security vulnerabilities enabling script injection. Approved by reviewer and passed CI. | |
| #3485 build(deps): bump lxml from 4.6.2 to 4.6.3 | snapcraft | merged | Merged Dependabot update bumping lxml 4.6.2 to 4.6.3. Resolves CVE-2021-28957, patching an HTML Cleaner vulnerability allowing JavaScript injection. Approved by two reviewers, passed CI, and merged. | |
| #362 build(deps): bump lxml | craft-store | merged | Merged dependency update bumping lxml from 5.4.0 to 6.1.0 to address an OSV security vulnerability. Approved by two reviewers with all CI checks passing. | |
| #86 build(deps): bump lxml | craft-artifacts | merged | Merged a dependency update bumping lxml from v6.0.2 to v6.1.1 to resolve an OSV security advisory. Approved by two reviewers and integrated after passing CI checks. | |
| #1072 build(deps): bump lxml | craft-application | merged | Merged a dependency update bumping lxml from 6.0.2 to 6.1.0 to resolve an OSV vulnerability. Approved by two reviewers and passed all CI checks prior to integration. | |
| #1563 build(deps): bump lxml | craft-parts | merged | Merged dependency update bumping lxml from v6.0.2 to v6.1.0 to resolve an OSV vulnerability. Approved by two reviewers and passed all CI checks. | |
| #3829 build(deps): bump lxml from 4.9.0 to 4.9.1 | snapcraft | merged | Merged Dependabot update bumping lxml from 4.9.0 to 4.9.1, resolving a crash in iterwalk() and canonicalize() with malformed input. Approved by one reviewer, passed CI, and merged with a two-line dependency version change. | |
| #6210 build(deps): bump lxml | snapcraft | merged | Merged a dependency update to bump lxml, resolving an OSV vulnerability. Approved by two reviewers and validated by CI checks before integration. | |
| #141 build(deps): update lxml to 6.1.0 | debcraft | merged | Merged dependency update upgrading lxml to version 6.1.0. Approved by two reviewers and passed all CI checks before integration by maintainer cmatsuoka. | |
| #540 build(deps): bump lxml | starbase | merged | Merged after bumping lxml to resolve an OSV vulnerability. Approved by two reviewers with all CI checks passing. The update modified a single file, adding 114 lines and removing 120. |