build(deps): bump lxml from 4.6.2 to 4.6.3
Metadata
Current evaluation
Merged Dependabot update bumping lxml 4.6.2 to 4.6.3. Resolves CVE-2021-28957, patching an HTML Cleaner vulnerability allowing JavaScript injection. Approved by two reviewers, passed CI, and merged.
Suggested action: —
No scores available.
Issue body
Bumps [lxml](https://github.com/lxml/lxml) from 4.6.2 to 4.6.3.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/lxml/lxml/blob/master/CHANGES.txt">lxml's changelog</a>.</em></p>
<blockquote>
<h1>4.6.3 (2021-03-21)</h1>
<h2>Bugs fixed</h2>
<ul>
<li>A vulnerability (CVE-2021-28957) was discovered in the HTML Cleaner by Kevin Chung,
which allowed JavaScript to pass through. The cleaner now removes the HTML5
<code>formaction</code> attribute.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="https://github.com/lxml/lxml/commit/a5f9cb52079dc57477c460dbe6ba0f775e14a999"><code>a5f9cb5</code></a> Prepare release of lxml 4.6.3.</li>
<li><a href="https://github.com/lxml/lxml/commit/2d01a1ba8984e0483ce6619b972832377f208a0d"><code>2d01a1b</code></a> Add HTML-5 "formaction" attribute to "defs.link_attrs" (<a href="https://github-redirect.dependabot.com/lxml/lxml/issues/316">GH-316</a>)</li>
<li><a href="https://github.com/lxml/lxml/commit/e986a9cb5d54827c59aefa8803bc90954d67221e"><code>e986a9c</code></a> Fix reference in docs.</li>
<li>See full diff in <a href="https://github.com/lxml/lxml/compare/lxml-4.6.2...lxml-4.6.3">compare view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language
- `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language
- `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language
- `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/snapcore/snapcraft/network/alerts).
</details>
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Merged Dependabot update bumping lxml 4.6.2 to 4.6.3. Resolves CVE-2021-28957, patching an HTML Cleaner vulnerability allowing JavaScript injection. Approved by two reviewers, passed CI, and merged. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Merged Dependabot update bumping lxml from 4.6.2 to 4.6.3. The upgrade resolves CVE-2021-28957, a vulnerability in the HTML Cleaner that permitted JavaScript injection. The dependency is now patched and live. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Merged Dependabot update bumping lxml from 4.6.2 to 4.6.3. The upgrade resolves CVE-2021-28957, a vulnerability in the HTML Cleaner that permitted JavaScript injection. Successfully merged. |
Update history
No update history recorded yet.
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #3606 build(deps): bump lxml from 4.6.3 to 4.6.5 | snapcraft | merged | Merged Dependabot update bumping lxml from 4.6.3 to 4.6.5. The upgrade patches two HTML cleaner security vulnerabilities enabling script injection. Approved by reviewer and passed CI. | |
| #3404 build(deps): bump lxml from 4.5.0 to 4.6.2 | snapcraft | merged | Merged a Dependabot update bumping lxml from 4.5.0 to 4.6.2 to resolve security vulnerabilities and bugs. CI checks passed and the dependency upgrade was successfully integrated. | |
| #362 build(deps): bump lxml | craft-store | merged | Merged dependency update bumping lxml from 5.4.0 to 6.1.0 to address an OSV security vulnerability. Approved by two reviewers with all CI checks passing. | |
| #1563 build(deps): bump lxml | craft-parts | merged | Merged dependency update bumping lxml from v6.0.2 to v6.1.0 to resolve an OSV vulnerability. Approved by two reviewers and passed all CI checks. | |
| #1072 build(deps): bump lxml | craft-application | merged | Merged a dependency update bumping lxml from 6.0.2 to 6.1.0 to resolve an OSV vulnerability. Approved by two reviewers and passed all CI checks prior to integration. | |
| #6210 build(deps): bump lxml | snapcraft | merged | Merged a dependency update to bump lxml, resolving an OSV vulnerability. Approved by two reviewers and validated by CI checks before integration. | |
| #86 build(deps): bump lxml | craft-artifacts | merged | Merged a dependency update bumping lxml from v6.0.2 to v6.1.1 to resolve an OSV security advisory. Approved by two reviewers and integrated after passing CI checks. | |
| #3829 build(deps): bump lxml from 4.9.0 to 4.9.1 | snapcraft | merged | Merged Dependabot update bumping lxml from 4.9.0 to 4.9.1, resolving a crash in iterwalk() and canonicalize() with malformed input. Approved by one reviewer, passed CI, and merged with a two-line dependency version change. | |
| #540 build(deps): bump lxml | starbase | merged | Merged after bumping lxml to resolve an OSV vulnerability. Approved by two reviewers with all CI checks passing. The update modified a single file, adding 114 lines and removing 120. | |
| #141 build(deps): update lxml to 6.1.0 | debcraft | merged | Merged dependency update upgrading lxml to version 6.1.0. Approved by two reviewers and passed all CI checks before integration by maintainer cmatsuoka. |