build(deps): bump jinja2 from 3.1.3 to 3.1.4 in /docs
Metadata
Current evaluation
Closed as abandoned. Another PR already updated jinja2 to 3.1.4, rendering this dependency bump redundant. Dependabot commented that the update is no longer needed.
Suggested action: —
No scores available.
Issue body
Bumps [jinja2](https://github.com/pallets/jinja) from 3.1.3 to 3.1.4.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/pallets/jinja/releases">jinja2's releases</a>.</em></p>
<blockquote>
<h2>3.1.4</h2>
<p>This is the Jinja 3.1.4 security release, which fixes security issues and bugs but does not otherwise change behavior and should not result in breaking changes.</p>
<p>PyPI: <a href="https://pypi.org/project/Jinja2/3.1.4/">https://pypi.org/project/Jinja2/3.1.4/</a>
Changes: <a href="https://jinja.palletsprojects.com/en/3.1.x/changes/#version-3-1-4">https://jinja.palletsprojects.com/en/3.1.x/changes/#version-3-1-4</a></p>
<ul>
<li>The <code>xmlattr</code> filter does not allow keys with <code>/</code> solidus, <code>></code> greater-than sign, or <code>=</code> equals sign, in addition to disallowing spaces. Regardless of any validation done by Jinja, user input should never be used as keys to this filter, or must be separately validated first. GHSA-h75v-3vvj-5mfj</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/pallets/jinja/blob/main/CHANGES.rst">jinja2's changelog</a>.</em></p>
<blockquote>
<h2>Version 3.1.4</h2>
<p>Released 2024-05-05</p>
<ul>
<li>The <code>xmlattr</code> filter does not allow keys with <code>/</code> solidus, <code>></code>
greater-than sign, or <code>=</code> equals sign, in addition to disallowing spaces.
Regardless of any validation done by Jinja, user input should never be used
as keys to this filter, or must be separately validated first.
:ghsa:<code>h75v-3vvj-5mfj</code></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="https://github.com/pallets/jinja/commit/dd4a8b5466d8790540c181590b14db4d4d889d57"><code>dd4a8b5</code></a> release version 3.1.4</li>
<li><a href="https://github.com/pallets/jinja/commit/0668239dc6b44ef38e7a6c9f91f312fd4ca581cb"><code>0668239</code></a> Merge pull request from GHSA-h75v-3vvj-5mfj</li>
<li><a href="https://github.com/pallets/jinja/commit/d655030770081e2dfe46f90e27620472a502289d"><code>d655030</code></a> disallow invalid characters in keys to xmlattr filter</li>
<li><a href="https://github.com/pallets/jinja/commit/a7863ba9d3521f1450f821119c50d19d7ecea329"><code>a7863ba</code></a> add ghsa links</li>
<li><a href="https://github.com/pallets/jinja/commit/b5c98e78c2ee7d2bf0aa06d29ed9bf7082de9cf4"><code>b5c98e7</code></a> start version 3.1.4</li>
<li><a href="https://github.com/pallets/jinja/commit/da3a9f0b804199845fcb76f2e08748bdaeba93ee"><code>da3a9f0</code></a> update project files (<a href="https://redirect.github.com/pallets/jinja/issues/1968">#1968</a>)</li>
<li><a href="https://github.com/pallets/jinja/commit/0ee5eb41d1a2d7d9a05a02dc26dd70e63aaaeeb1"><code>0ee5eb4</code></a> satisfy formatter, linter, and strict mypy</li>
<li><a href="https://github.com/pallets/jinja/commit/20477c63575175196bfc8103f223cc9f5642595d"><code>20477c6</code></a> update project files (<a href="https://redirect.github.com/pallets/jinja/issues/5457">#5457</a>)</li>
<li><a href="https://github.com/pallets/jinja/commit/e491223739dedbb1f4fc6a71340c1484e149d947"><code>e491223</code></a> update pyyaml dev dependency</li>
<li><a href="https://github.com/pallets/jinja/commit/36f98854c721f98ba103f97f65a8a098da5af0d7"><code>36f9885</code></a> fix pr link</li>
<li>Additional commits viewable in <a href="https://github.com/pallets/jinja/compare/3.1.3...3.1.4">compare view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/canonical/snapcraft/network/alerts).
</details>
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Closed as abandoned. Another PR already updated jinja2 to 3.1.4, rendering this dependency bump redundant. Dependabot commented that the update is no longer needed. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Update to jinja2 3.1.4 was closed and superseded. The dependency was already updated in the repository, making the change redundant. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Dependabot PR to bump jinja2 to 3.1.4 was closed as no longer needed. The dependency was already updated elsewhere, superseding the proposed change. |
Update history
No update history recorded yet.
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #5189 build(deps): bump jinja2 from 3.1.4 to 3.1.5 | snapcraft | closed | PR closed because jinja2 is already up-to-date. Dependabot noted the update is no longer needed, so the dependency bump was abandoned without merging. | |
| #4788 build(deps): bump jinja2 from 3.1.3 to 3.1.4 in /docs/.sphinx | snapcraft | closed | Closed and superseded because jinja2 is already at version 3.1.4. The dependency update is no longer needed, so the pull request was abandoned without merging. | |
| #2206 build(deps-dev): bump jinja2 from 3.1.5 to 3.1.6 | charmcraft | closed | The jinja2 update from 3.1.5 to 3.1.6 was abandoned because the dependency is already up-to-date, making the pull request redundant. | |
| #2066 build(deps): update dependency jinja2 to v3.1.5 [security] (hotfix/3.2) - autoclosed | charmcraft | closed | Renovate bot pull request updating jinja2 to v3.1.5 for security fixes was automatically closed without review or merge. The update was abandoned by the bot. | |
| #2065 build(deps): update dependency jinja2 to v3.1.5 [security] (hotfix/2.7) - autoclosed | charmcraft | closed | The Renovate-generated pull request updating Jinja2 to v3.1.5 for security patches was automatically closed without merging. The dependency update was abandoned by the system. | |
| #4518 build(deps): bump jinja2 from 3.1.2 to 3.1.3 in /docs/.sphinx | snapcraft | merged | Dependabot PR bumping jinja2 from 3.1.2 to 3.1.3 in /docs/.sphinx was approved by two reviewers, passed CI checks, and successfully merged. The update resolves security vulnerabilities and compiler errors in the template engine. | |
| #2209 build(deps): update dependency jinja2 to v3.1.6 [security] (hotfix/3.3) - autoclosed | charmcraft | closed | Renovate bot dependency update for jinja2 to v3.1.6 was autoclosed without review or merging. The security patch was abandoned. | |
| #106 build(deps): bump jinja2 from 3.1.5 to 3.1.6 | imagecraft | merged | Merged a dependency update bumping jinja2 from 3.1.5 to 3.1.6 to patch security vulnerability GHSA-cpwx-vrp4-4pq7. Approved by two reviewers, passed CI, and merged after coordinating with a related pull request. | |
| #5306 build(deps): update dependency jinja2 to v3.1.6 [security] (main) - autoclosed | snapcraft | closed | Renovate PR updating Jinja2 to v3.1.6 to fix CVE-2025-27516 passed CI and received approval but was autoclosed without merging, likely superseded by a newer dependency update. | |
| #2208 build(deps): update dependency jinja2 to v3.1.6 [security] (hotfix/2.7) - autoclosed | charmcraft | closed | Automatically closed without merging. The dependency update to jinja2 v3.1.6 for CVE-2025-27516 was superseded or abandoned before review. |