build(deps): update dependency setuptools to v70 [security] (hotfix/8.3) - autoclosed
Metadata
Current evaluation
Automatically closed by Renovate due to inactivity. The setuptools update to v70 for CVE-2024-6345 was never reviewed or merged.
Suggested action: —
No scores available.
Issue body
[](https://renovatebot.com)
This PR contains the following updates:
| Package | Change | Age | Adoption | Passing | Confidence |
|---|---|---|---|---|---|
| [setuptools](https://togithub.com/pypa/setuptools) ([changelog](https://setuptools.pypa.io/en/stable/history.html)) | `==65.5.1` -> `==70.0.0` | [](https://docs.renovatebot.com/merge-confidence/) | [](https://docs.renovatebot.com/merge-confidence/) | [](https://docs.renovatebot.com/merge-confidence/) | [](https://docs.renovatebot.com/merge-confidence/) |
### GitHub Vulnerability Alerts
#### [CVE-2024-6345](https://nvd.nist.gov/vuln/detail/CVE-2024-6345)
A vulnerability in the `package_index` module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or retrieved from package index servers, are susceptible to code injection. If these functions are exposed to user-controlled inputs, such as package URLs, they can execute arbitrary commands on the system. The issue is fixed in version 70.0.
---
### Release Notes
<details>
<summary>pypa/setuptools (setuptools)</summary>
### [`v70.0.0`](https://togithub.com/pypa/setuptools/compare/v69.5.1...v70.0.0)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v69.5.1...v70.0.0)
### [`v69.5.1`](https://togithub.com/pypa/setuptools/compare/v69.5.0...v69.5.1)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v69.5.0...v69.5.1)
### [`v69.5.0`](https://togithub.com/pypa/setuptools/compare/v69.4.2...v69.5.0)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v69.4.2...v69.5.0)
### [`v69.4.2`](https://togithub.com/pypa/setuptools/compare/v69.4.1...v69.4.2)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v69.4.1...v69.4.2)
### [`v69.4.1`](https://togithub.com/pypa/setuptools/compare/v69.4.0...v69.4.1)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v69.4.0...v69.4.1)
### [`v69.4.0`](https://togithub.com/pypa/setuptools/compare/v69.3.1...v69.4.0)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v69.3.1...v69.4.0)
### [`v69.3.1`](https://togithub.com/pypa/setuptools/compare/v69.3.0...v69.3.1)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v69.3.0...v69.3.1)
### [`v69.3.0`](https://togithub.com/pypa/setuptools/compare/v69.2.0...v69.3.0)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v69.2.0...v69.3.0)
### [`v69.2.0`](https://togithub.com/pypa/setuptools/compare/v69.1.1...v69.2.0)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v69.1.1...v69.2.0)
### [`v69.1.1`](https://togithub.com/pypa/setuptools/compare/v69.1.0...v69.1.1)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v69.1.0...v69.1.1)
### [`v69.1.0`](https://togithub.com/pypa/setuptools/compare/v69.0.3...v69.1.0)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v69.0.3...v69.1.0)
### [`v69.0.3`](https://togithub.com/pypa/setuptools/compare/v69.0.2...v69.0.3)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v69.0.2...v69.0.3)
### [`v69.0.2`](https://togithub.com/pypa/setuptools/compare/v69.0.1...v69.0.2)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v69.0.1...v69.0.2)
### [`v69.0.1`](https://togithub.com/pypa/setuptools/compare/v69.0.0...v69.0.1)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v69.0.0...v69.0.1)
### [`v69.0.0`](https://togithub.com/pypa/setuptools/compare/v68.2.2...v69.0.0)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v68.2.2...v69.0.0)
### [`v68.2.2`](https://togithub.com/pypa/setuptools/compare/v68.2.1...v68.2.2)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v68.2.1...v68.2.2)
### [`v68.2.1`](https://togithub.com/pypa/setuptools/compare/v68.2.0...v68.2.1)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v68.2.0...v68.2.1)
### [`v68.2.0`](https://togithub.com/pypa/setuptools/compare/v68.1.2...v68.2.0)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v68.1.2...v68.2.0)
### [`v68.1.2`](https://togithub.com/pypa/setuptools/compare/v68.1.0...v68.1.2)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v68.1.0...v68.1.2)
### [`v68.1.0`](https://togithub.com/pypa/setuptools/compare/v68.0.0...v68.1.0)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v68.0.0...v68.1.0)
### [`v68.0.0`](https://togithub.com/pypa/setuptools/compare/v67.8.0...v68.0.0)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v67.8.0...v68.0.0)
### [`v67.8.0`](https://togithub.com/pypa/setuptools/compare/v67.7.2...v67.8.0)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v67.7.2...v67.8.0)
### [`v67.7.2`](https://togithub.com/pypa/setuptools/compare/v67.7.1...v67.7.2)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v67.7.1...v67.7.2)
### [`v67.7.1`](https://togithub.com/pypa/setuptools/compare/v67.7.0...v67.7.1)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v67.7.0...v67.7.1)
### [`v67.7.0`](https://togithub.com/pypa/setuptools/compare/v67.6.1...v67.7.0)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v67.6.1...v67.7.0)
### [`v67.6.1`](https://togithub.com/pypa/setuptools/compare/v67.6.0...v67.6.1)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v67.6.0...v67.6.1)
### [`v67.6.0`](https://togithub.com/pypa/setuptools/compare/v67.5.1...v67.6.0)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v67.5.1...v67.6.0)
### [`v67.5.1`](https://togithub.com/pypa/setuptools/compare/v67.5.0...v67.5.1)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v67.5.0...v67.5.1)
### [`v67.5.0`](https://togithub.com/pypa/setuptools/compare/v67.4.0...v67.5.0)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v67.4.0...v67.5.0)
### [`v67.4.0`](https://togithub.com/pypa/setuptools/compare/v67.3.3...v67.4.0)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v67.3.3...v67.4.0)
### [`v67.3.3`](https://togithub.com/pypa/setuptools/compare/v67.3.2...v67.3.3)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v67.3.2...v67.3.3)
### [`v67.3.2`](https://togithub.com/pypa/setuptools/compare/v67.3.1...v67.3.2)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v67.3.1...v67.3.2)
### [`v67.3.1`](https://togithub.com/pypa/setuptools/compare/v67.2.0...v67.3.1)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v67.2.0...v67.3.1)
### [`v67.2.0`](https://togithub.com/pypa/setuptools/compare/v67.1.0...v67.2.0)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v67.1.0...v67.2.0)
### [`v67.1.0`](https://togithub.com/pypa/setuptools/compare/v67.0.0...v67.1.0)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v67.0.0...v67.1.0)
### [`v67.0.0`](https://togithub.com/pypa/setuptools/compare/v66.1.1...v67.0.0)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v66.1.1...v67.0.0)
### [`v66.1.1`](https://togithub.com/pypa/setuptools/compare/v66.1.0...v66.1.1)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v66.1.0...v66.1.1)
### [`v66.1.0`](https://togithub.com/pypa/setuptools/compare/v66.0.0...v66.1.0)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v66.0.0...v66.1.0)
### [`v66.0.0`](https://togithub.com/pypa/setuptools/compare/v65.7.0...v66.0.0)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v65.7.0...v66.0.0)
### [`v65.7.0`](https://togithub.com/pypa/setuptools/compare/v65.6.3...v65.7.0)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v65.6.3...v65.7.0)
### [`v65.6.3`](https://togithub.com/pypa/setuptools/compare/v65.6.2...v65.6.3)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v65.6.2...v65.6.3)
### [`v65.6.2`](https://togithub.com/pypa/setuptools/compare/v65.6.1...v65.6.2)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v65.6.1...v65.6.2)
### [`v65.6.1`](https://togithub.com/pypa/setuptools/compare/v65.6.0...v65.6.1)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v65.6.0...v65.6.1)
### [`v65.6.0`](https://togithub.com/pypa/setuptools/compare/v65.5.1...v65.6.0)
[Compare Source](https://togithub.com/pypa/setuptools/compare/v65.5.1...v65.6.0)
</details>
---
### Configuration
📅 **Schedule**: Branch creation - "" in timezone Etc/UTC, Automerge - At any time (no schedule defined).
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR was generated by [Mend Renovate](https://www.mend.io/free-developer-tools/renovate/). View the [repository job log](https://developer.mend.io/github/canonical/snapcraft).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC4yNi4xIiwidXBkYXRlZEluVmVyIjoiMzguMjYuMSIsInRhcmdldEJyYW5jaCI6ImhvdGZpeC84LjMiLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19-->
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Automatically closed by Renovate due to inactivity. The setuptools update to v70 for CVE-2024-6345 was never reviewed or merged. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Automatically closed by Renovate without merging. The setuptools security update to v70.0.0 was abandoned, likely due to branch expiration or configuration overrides. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Autoclosed without merging. The setuptools update to v70.0.0 addressing CVE-2024-6345 was abandoned, likely due to branch deletion or the security fix being applied via an alternative workflow. |
Update history
No update history recorded yet.
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #4920 build(deps): update dependency setuptools to v70 [security] (hotfix/8.3) - autoclosed | snapcraft | closed | Closed without merging. Renovate proposed updating setuptools to v70.0.0 to fix CVE-2024-6345. The branch was manually modified, causing the bot to skip autoclosing. The update was ultimately abandoned. | |
| #4986 build(deps): update dependency setuptools to v70 [security] (main) - autoclosed | snapcraft | closed | Dependency update to setuptools v70.0.0 for CVE-2024-6345 was autoclosed without merging. Renovate automatically closed the branch, likely superseded by another update or applied separately. | |
| #2292 build(deps): update dependency setuptools to v78 [security] (hotfix/2.7) - autoclosed | charmcraft | closed | Autoclosed and abandoned without merging. Renovate proposed updating setuptools to v78.1.1 to address CVE-2025-47273, but multiple CI checks failed and the branch was automatically closed. | |
| #2293 build(deps): update dependency setuptools to v78 [security] (hotfix/3.4) - autoclosed | charmcraft | closed | A security update to setuptools v78.1.1 addressing CVE-2025-47273 was autoclosed by the bot without merging. The dependency patch was abandoned and not applied. | |
| #1097 build(deps): update dependency setuptools to v78 [security] (hotfix/2.4) - autoclosed | craft-parts | closed | Renovate PR updating setuptools to v78.1.1 for CVE-2025-47273 was autoclosed without merging. Minor CI failures on older Ubuntu versions prevented progress. The security update was abandoned and never applied. | |
| #2291 build(deps): update dependency setuptools to v78 [security] (main) - autoclosed | charmcraft | closed | Renovate bot PR updating setuptools to v78.1.1 to patch CVE-2025-47273 was autoclosed and abandoned. The security update was not merged. | |
| #1098 build(deps): update dependency setuptools to v78 [security] (hotfix/2.7) - autoclosed | craft-parts | closed | Security update for setuptools to v78.1.1 addressing CVE-2025-47273 was autoclosed without merging. CI checks failed on Ubuntu 20.04 and linters. The bot-generated PR was abandoned due to inactivity and configuration constraints. | |
| #4774 chore(deps): update dependency setuptools to v65 [security] - autoclosed | snapcraft | closed | Automatically closed by Renovate due to inactivity. The update to setuptools v65.5.1 to address CVE-2022-40897 was abandoned without review or merge. | |
| #1283 build(deps): update dependency setuptools to v82 (main) - autoclosed | rockcraft | closed | The setuptools dependency update PR was autoclosed without merging. Renovate bot automatically closed the request after it received no reviews or comments. | |
| #294 build(deps): update dependency setuptools to v75.2.0 | craft-cli | merged | Merged automated dependency update upgrading setuptools from v75.1.0 to v75.2.0. Generated by Renovate, the change passed all CI checks and received approval from two reviewers before being merged. |