← Back to issue list

chore(deps): update dependency pip to v23 [security] - autoclosed

View original Github issue

Metadata

Project
snapcraft
Number
#4773
Type
pull request
State
closed
Author
renovate[bot]
Labels
Created
Updated
Closed

Current evaluation

Automatically closed without merging. The Renovate bot dependency update upgrading pip to v23.3 to address CVE-2023-5752 was abandoned, likely due to staleness or repository configuration.

Suggested action:

No scores available.

Issue body

[![Mend Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com) This PR contains the following updates: | Package | Change | Age | Adoption | Passing | Confidence | |---|---|---|---|---|---| | [pip](https://togithub.com/pypa/pip) ([changelog](https://pip.pypa.io/en/stable/news/)) | `==22.0.2` -> `==23.3` | [![age](https://developer.mend.io/api/mc/badges/age/pypi/pip/23.3?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/pypi/pip/23.3?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/pypi/pip/22.0.2/23.3?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/pypi/pip/22.0.2/23.3?slim=true)](https://docs.renovatebot.com/merge-confidence/) | ### GitHub Vulnerability Alerts #### [CVE-2023-5752](https://nvd.nist.gov/vuln/detail/CVE-2023-5752) When installing a package from a Mercurial VCS URL, e.g. `pip install hg+...`, with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options to the `hg clone` call (e.g. `--config`). Controlling the Mercurial configuration can modify how and which repository is installed. This vulnerability does not affect users who aren't installing from Mercurial. --- ### Release Notes <details> <summary>pypa/pip (pip)</summary> ### [`v23.3`](https://togithub.com/pypa/pip/compare/23.2.1...23.3) [Compare Source](https://togithub.com/pypa/pip/compare/23.2.1...23.3) ### [`v23.2.1`](https://togithub.com/pypa/pip/compare/23.2...23.2.1) [Compare Source](https://togithub.com/pypa/pip/compare/23.2...23.2.1) ### [`v23.2`](https://togithub.com/pypa/pip/compare/23.1.2...23.2) [Compare Source](https://togithub.com/pypa/pip/compare/23.1.2...23.2) ### [`v23.1.2`](https://togithub.com/pypa/pip/compare/23.1.1...23.1.2) [Compare Source](https://togithub.com/pypa/pip/compare/23.1.1...23.1.2) ### [`v23.1.1`](https://togithub.com/pypa/pip/compare/23.1...23.1.1) [Compare Source](https://togithub.com/pypa/pip/compare/23.1...23.1.1) ### [`v23.1`](https://togithub.com/pypa/pip/compare/23.0.1...23.1) [Compare Source](https://togithub.com/pypa/pip/compare/23.0.1...23.1) ### [`v23.0.1`](https://togithub.com/pypa/pip/compare/23.0...23.0.1) [Compare Source](https://togithub.com/pypa/pip/compare/23.0...23.0.1) ### [`v23.0`](https://togithub.com/pypa/pip/compare/22.3.1...23.0) [Compare Source](https://togithub.com/pypa/pip/compare/22.3.1...23.0) ### [`v22.3.1`](https://togithub.com/pypa/pip/compare/22.3...22.3.1) [Compare Source](https://togithub.com/pypa/pip/compare/22.3...22.3.1) ### [`v22.3`](https://togithub.com/pypa/pip/compare/22.2.2...22.3) [Compare Source](https://togithub.com/pypa/pip/compare/22.2.2...22.3) ### [`v22.2.2`](https://togithub.com/pypa/pip/compare/22.2.1...22.2.2) [Compare Source](https://togithub.com/pypa/pip/compare/22.2.1...22.2.2) ### [`v22.2.1`](https://togithub.com/pypa/pip/compare/22.2...22.2.1) [Compare Source](https://togithub.com/pypa/pip/compare/22.2...22.2.1) ### [`v22.2`](https://togithub.com/pypa/pip/compare/22.1.2...22.2) [Compare Source](https://togithub.com/pypa/pip/compare/22.1.2...22.2) ### [`v22.1.2`](https://togithub.com/pypa/pip/compare/22.1.1...22.1.2) [Compare Source](https://togithub.com/pypa/pip/compare/22.1.1...22.1.2) ### [`v22.1.1`](https://togithub.com/pypa/pip/compare/22.1...22.1.1) [Compare Source](https://togithub.com/pypa/pip/compare/22.1...22.1.1) ### [`v22.1`](https://togithub.com/pypa/pip/compare/22.0.4...22.1) [Compare Source](https://togithub.com/pypa/pip/compare/22.0.4...22.1) ### [`v22.0.4`](https://togithub.com/pypa/pip/compare/22.0.3...22.0.4) [Compare Source](https://togithub.com/pypa/pip/compare/22.0.3...22.0.4) ### [`v22.0.3`](https://togithub.com/pypa/pip/compare/22.0.2...22.0.3) [Compare Source](https://togithub.com/pypa/pip/compare/22.0.2...22.0.3) </details> --- ### Configuration 📅 **Schedule**: Branch creation - "" in timezone Etc/UTC, Automerge - "every weekend" in timezone Etc/UTC. 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://www.mend.io/free-developer-tools/renovate/). View repository job log [here](https://developer.mend.io/github/canonical/snapcraft). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy4zMjEuMiIsInVwZGF0ZWRJblZlciI6IjM3LjMyMS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=-->

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.6-35b-a3b Automatically closed without merging. The Renovate bot dependency update upgrading pip to v23.3 to address CVE-2023-5752 was abandoned, likely due to staleness or repository configuration.
qwen3.6-35b-a3b-mtp-q6 Renovate bot opened a dependency update for pip to v23.3 to address CVE-2023-5752. The pull request was autoclosed due to inactivity without review or merge.
qwen3.6-35b-a3b-mtp-q6 Renovate bot PR updating pip from 22.0.2 to 23.3 for CVE-2023-5752 was automatically closed without merging, likely superseded by a newer update.

Update history

No update history recorded yet.

Related issues

Issue Project State Summary Similarity
#4856 chore(deps): update dependency requests to v2.32.2 [security] - autoclosed snapcraft closed Renovate's dependency update PR for requests to v2.32.2 was autoclosed without merging. The bot automatically closed the stale pull request, leaving the CVE-2024-35195 security fix unapplied.
84%
#4774 chore(deps): update dependency setuptools to v65 [security] - autoclosed snapcraft closed Automatically closed by Renovate due to inactivity. The update to setuptools v65.5.1 to address CVE-2022-40897 was abandoned without review or merge.
83%
#1689 chore(deps): update dependency requests to v2.32.0 [security] - autoclosed charmcraft closed Renovate bot dependency update to requests v2.32.0 for CVE-2024-35195 was autoclosed. The branch was abandoned without review or merge, as the update was likely already applied or superseded.
82%
#1181 chore(deps): update dependency certifi to v2023.7.22 [security] - autoclosed charmcraft closed Renovate bot PR updating certifi to v2023.7.22 for CVE-2023-37920 was autoclosed due to inactivity. Automerge was disabled by configuration, and the request received no reviews or CI checks before automatic closure.
81%
#4897 chore(deps): update dependency certifi to v2024 [security] - autoclosed snapcraft closed The certifi v2024.7.4 security update was automatically closed without merging. Renovate bot generated the dependency change, but it was abandoned due to inactivity, leaving the repository on the previous version.
80%
#4860 chore(deps): update dependency urllib3 to v1.26.19 [security] - autoclosed snapcraft closed The urllib3 security update to v1.26.19 was autoclosed by Renovate due to a branch head mismatch. The dependency change was not merged and the automated pull request was automatically closed.
80%
#4531 chore(deps): update dependency packaging to v23 snapcraft merged Merged automated dependency update for packaging from v21.3 to v23.2 via Renovate bot. Approved by two reviewers, passed CI checks, and successfully integrated.
80%
#4902 chore(deps): update dependency zipp to v3.19.1 [security] - autoclosed snapcraft closed Renovate bot PR updating zipp to v3.19.1 for CVE-2024-5569 was autoclosed without merging. The security update was not applied via this pull request.
80%
#1111 chore(deps): update dependency requests to v2.31.0 [security] - abandoned charmcraft closed Renovate-generated dependency update to requests v2.31.0 for CVE-2023-32681 was closed and abandoned. Autoclosing was skipped due to branch modifications, leading to manual closure.
79%
#4812 chore(deps): update dependency requests to v2.32.0 [security] - autoclosed snapcraft closed Renovate pull request updating requests to v2.32.0 to address CVE-2024-35195 was autoclosed without merging. The dependency update was likely handled separately or the branch expired.
79%