build(deps): update jinja to 3.1.6
Metadata
Current evaluation
Merged update to jinja 3.1.6 to resolve security vulnerability GHSA-cpwx-vrp4-4pq7. Approved by two reviewers, passed CI, and integrated without comments.
Suggested action: —
No scores available.
Issue body
- [x] Have you followed the [guidelines for contributing](https://github.com/canonical/snapcraft/blob/main/CONTRIBUTING.md)?
- [x] Have you signed the [CLA](http://www.ubuntu.com/legal/contributors/)?
- [x] Have you successfully run `make lint`?
- [x] Have you successfully run `make test`?
---
Addresses https://osv.dev/vulnerability/GHSA-cpwx-vrp4-4pq7
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Merged update to jinja 3.1.6 to resolve security vulnerability GHSA-cpwx-vrp4-4pq7. Approved by two reviewers, passed CI, and integrated without comments. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Merged dependency update upgrading Jinja2 to 3.1.6 to patch security vulnerability GHSA-cpwx-vrp4-4pq7. Code passed lint and test checks prior to integration. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Merged update to Jinja2 3.1.6 addressing security vulnerability GHSA-cpwx-vrp4-4pq7. Changes passed lint and test checks before integration. |
Update history
No update history recorded yet.
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #106 build(deps): bump jinja2 from 3.1.5 to 3.1.6 | imagecraft | merged | Merged a dependency update bumping jinja2 from 3.1.5 to 3.1.6 to patch security vulnerability GHSA-cpwx-vrp4-4pq7. Approved by two reviewers, passed CI, and merged after coordinating with a related pull request. | |
| #1038 build(deps): update jinja2 to 3.1.6 | craft-parts | merged | Merged to update jinja2 to 3.1.6, resolving CVE-2025-27516 sandbox breakout vulnerability. Approved by two reviewers, passed CI, and applied with a minimal five-line change across two files. | |
| #2064 build(deps): update dependency jinja2 to v3.1.5 [security] (main) | charmcraft | merged | Merged an automated dependency update upgrading jinja2 from 3.1.4 to 3.1.5 to patch CVE-2024-56326 and CVE-2024-56201. The change passed CI, received reviewer approval, and was auto-merged to main. | |
| #5190 build(deps): update dependency jinja2 to v3.1.5 [security] (main) | snapcraft | merged | Merged automated dependency update upgrading Jinja2 from 3.1.4 to 3.1.5 to patch CVE-2024-56326 and CVE-2024-56201. The change passed CI, received two approvals, and was auto-merged into main by Renovate bot. | |
| #4518 build(deps): bump jinja2 from 3.1.2 to 3.1.3 in /docs/.sphinx | snapcraft | merged | Dependabot PR bumping jinja2 from 3.1.2 to 3.1.3 in /docs/.sphinx was approved by two reviewers, passed CI checks, and successfully merged. The update resolves security vulnerabilities and compiler errors in the template engine. | |
| #2210 build(deps): update dependency jinja2 to v3.1.6 [security] (hotfix/3.4) - autoclosed | charmcraft | closed | Dependency update PR for jinja2 v3.1.6 addressing CVE-2025-27516 was autoclosed without merging. No reviews or CI checks ran. | |
| #5312 build(deps): bump jinja2 from 3.1.5 to 3.1.6 in /docs/.sphinx | snapcraft | merged | Merged Dependabot update bumping jinja2 from 3.1.5 to 3.1.6 in /docs/.sphinx. The security patch fixes a sandbox attribute lookup bypass. Approved by reviewers and passed CI before automatic merge. | |
| #252 build(deps): update Jinja2 | craft-store | merged | Merged to update the Jinja2 dependency, resolving a failing pipeline and addressing a CVE scan result. The change also disabled a false-positive S105 security check. Approved by two reviewers and passed all CI checks. | |
| #5306 build(deps): update dependency jinja2 to v3.1.6 [security] (main) - autoclosed | snapcraft | closed | Renovate PR updating Jinja2 to v3.1.6 to fix CVE-2025-27516 passed CI and received approval but was autoclosed without merging, likely superseded by a newer dependency update. | |
| #5308 build(deps): update dependency jinja2 to v3.1.6 [security] (hotfix/8.6) | snapcraft | closed | Automatically merged via Renovate to update Jinja2 to v3.1.6, resolving CVE-2025-27516. Applied to hotfix/8.6 without manual review. |