chore(deps): update dependency pip to v23 [security] - autoclosed
Metadata
Current evaluation
Automatically closed without merging. The Renovate bot dependency update upgrading pip to v23.3 to address CVE-2023-5752 was abandoned, likely due to staleness or repository configuration.
Suggested action: —
No scores available.
Issue body
[](https://renovatebot.com)
This PR contains the following updates:
| Package | Change | Age | Adoption | Passing | Confidence |
|---|---|---|---|---|---|
| [pip](https://togithub.com/pypa/pip) ([changelog](https://pip.pypa.io/en/stable/news/)) | `==22.0.2` -> `==23.3` | [](https://docs.renovatebot.com/merge-confidence/) | [](https://docs.renovatebot.com/merge-confidence/) | [](https://docs.renovatebot.com/merge-confidence/) | [](https://docs.renovatebot.com/merge-confidence/) |
### GitHub Vulnerability Alerts
#### [CVE-2023-5752](https://nvd.nist.gov/vuln/detail/CVE-2023-5752)
When installing a package from a Mercurial VCS URL, e.g. `pip install hg+...`, with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options to the `hg clone` call (e.g. `--config`). Controlling the Mercurial configuration can modify how and which repository is installed. This vulnerability does not affect users who aren't installing from Mercurial.
---
### Release Notes
<details>
<summary>pypa/pip (pip)</summary>
### [`v23.3`](https://togithub.com/pypa/pip/compare/23.2.1...23.3)
[Compare Source](https://togithub.com/pypa/pip/compare/23.2.1...23.3)
### [`v23.2.1`](https://togithub.com/pypa/pip/compare/23.2...23.2.1)
[Compare Source](https://togithub.com/pypa/pip/compare/23.2...23.2.1)
### [`v23.2`](https://togithub.com/pypa/pip/compare/23.1.2...23.2)
[Compare Source](https://togithub.com/pypa/pip/compare/23.1.2...23.2)
### [`v23.1.2`](https://togithub.com/pypa/pip/compare/23.1.1...23.1.2)
[Compare Source](https://togithub.com/pypa/pip/compare/23.1.1...23.1.2)
### [`v23.1.1`](https://togithub.com/pypa/pip/compare/23.1...23.1.1)
[Compare Source](https://togithub.com/pypa/pip/compare/23.1...23.1.1)
### [`v23.1`](https://togithub.com/pypa/pip/compare/23.0.1...23.1)
[Compare Source](https://togithub.com/pypa/pip/compare/23.0.1...23.1)
### [`v23.0.1`](https://togithub.com/pypa/pip/compare/23.0...23.0.1)
[Compare Source](https://togithub.com/pypa/pip/compare/23.0...23.0.1)
### [`v23.0`](https://togithub.com/pypa/pip/compare/22.3.1...23.0)
[Compare Source](https://togithub.com/pypa/pip/compare/22.3.1...23.0)
### [`v22.3.1`](https://togithub.com/pypa/pip/compare/22.3...22.3.1)
[Compare Source](https://togithub.com/pypa/pip/compare/22.3...22.3.1)
### [`v22.3`](https://togithub.com/pypa/pip/compare/22.2.2...22.3)
[Compare Source](https://togithub.com/pypa/pip/compare/22.2.2...22.3)
### [`v22.2.2`](https://togithub.com/pypa/pip/compare/22.2.1...22.2.2)
[Compare Source](https://togithub.com/pypa/pip/compare/22.2.1...22.2.2)
### [`v22.2.1`](https://togithub.com/pypa/pip/compare/22.2...22.2.1)
[Compare Source](https://togithub.com/pypa/pip/compare/22.2...22.2.1)
### [`v22.2`](https://togithub.com/pypa/pip/compare/22.1.2...22.2)
[Compare Source](https://togithub.com/pypa/pip/compare/22.1.2...22.2)
### [`v22.1.2`](https://togithub.com/pypa/pip/compare/22.1.1...22.1.2)
[Compare Source](https://togithub.com/pypa/pip/compare/22.1.1...22.1.2)
### [`v22.1.1`](https://togithub.com/pypa/pip/compare/22.1...22.1.1)
[Compare Source](https://togithub.com/pypa/pip/compare/22.1...22.1.1)
### [`v22.1`](https://togithub.com/pypa/pip/compare/22.0.4...22.1)
[Compare Source](https://togithub.com/pypa/pip/compare/22.0.4...22.1)
### [`v22.0.4`](https://togithub.com/pypa/pip/compare/22.0.3...22.0.4)
[Compare Source](https://togithub.com/pypa/pip/compare/22.0.3...22.0.4)
### [`v22.0.3`](https://togithub.com/pypa/pip/compare/22.0.2...22.0.3)
[Compare Source](https://togithub.com/pypa/pip/compare/22.0.2...22.0.3)
</details>
---
### Configuration
📅 **Schedule**: Branch creation - "" in timezone Etc/UTC, Automerge - "every weekend" in timezone Etc/UTC.
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://www.mend.io/free-developer-tools/renovate/). View repository job log [here](https://developer.mend.io/github/canonical/snapcraft).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy4zMjEuMiIsInVwZGF0ZWRJblZlciI6IjM3LjMyMS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=-->
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Automatically closed without merging. The Renovate bot dependency update upgrading pip to v23.3 to address CVE-2023-5752 was abandoned, likely due to staleness or repository configuration. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Renovate bot opened a dependency update for pip to v23.3 to address CVE-2023-5752. The pull request was autoclosed due to inactivity without review or merge. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Renovate bot PR updating pip from 22.0.2 to 23.3 for CVE-2023-5752 was automatically closed without merging, likely superseded by a newer update. |
Update history
No update history recorded yet.
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #4856 chore(deps): update dependency requests to v2.32.2 [security] - autoclosed | snapcraft | closed | Renovate's dependency update PR for requests to v2.32.2 was autoclosed without merging. The bot automatically closed the stale pull request, leaving the CVE-2024-35195 security fix unapplied. | |
| #4774 chore(deps): update dependency setuptools to v65 [security] - autoclosed | snapcraft | closed | Automatically closed by Renovate due to inactivity. The update to setuptools v65.5.1 to address CVE-2022-40897 was abandoned without review or merge. | |
| #1689 chore(deps): update dependency requests to v2.32.0 [security] - autoclosed | charmcraft | closed | Renovate bot dependency update to requests v2.32.0 for CVE-2024-35195 was autoclosed. The branch was abandoned without review or merge, as the update was likely already applied or superseded. | |
| #1181 chore(deps): update dependency certifi to v2023.7.22 [security] - autoclosed | charmcraft | closed | Renovate bot PR updating certifi to v2023.7.22 for CVE-2023-37920 was autoclosed due to inactivity. Automerge was disabled by configuration, and the request received no reviews or CI checks before automatic closure. | |
| #4897 chore(deps): update dependency certifi to v2024 [security] - autoclosed | snapcraft | closed | The certifi v2024.7.4 security update was automatically closed without merging. Renovate bot generated the dependency change, but it was abandoned due to inactivity, leaving the repository on the previous version. | |
| #4860 chore(deps): update dependency urllib3 to v1.26.19 [security] - autoclosed | snapcraft | closed | The urllib3 security update to v1.26.19 was autoclosed by Renovate due to a branch head mismatch. The dependency change was not merged and the automated pull request was automatically closed. | |
| #4531 chore(deps): update dependency packaging to v23 | snapcraft | merged | Merged automated dependency update for packaging from v21.3 to v23.2 via Renovate bot. Approved by two reviewers, passed CI checks, and successfully integrated. | |
| #4902 chore(deps): update dependency zipp to v3.19.1 [security] - autoclosed | snapcraft | closed | Renovate bot PR updating zipp to v3.19.1 for CVE-2024-5569 was autoclosed without merging. The security update was not applied via this pull request. | |
| #1111 chore(deps): update dependency requests to v2.31.0 [security] - abandoned | charmcraft | closed | Renovate-generated dependency update to requests v2.31.0 for CVE-2023-32681 was closed and abandoned. Autoclosing was skipped due to branch modifications, leading to manual closure. | |
| #4812 chore(deps): update dependency requests to v2.32.0 [security] - autoclosed | snapcraft | closed | Renovate pull request updating requests to v2.32.0 to address CVE-2024-35195 was autoclosed without merging. The dependency update was likely handled separately or the branch expired. |