build(deps): bump requests to 2.32.4
Metadata
Current evaluation
Merged a dependency update bumping requests to 2.32.4 to patch a security vulnerability. Approved by two reviewers and passed core CI checks before integration.
Suggested action: —
No scores available.
Issue body
- [x] Have you followed the [guidelines for contributing](https://github.com/canonical/snapcraft/blob/main/CONTRIBUTING.md)?
- [x] Have you signed the [CLA](http://www.ubuntu.com/legal/contributors/)?
- [ ] Have you successfully run `make lint`?
- [ ] Have you successfully run `make test`?
---
Bump and set a minimum version of requests for a CVE.
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Merged a dependency update bumping requests to 2.32.4 to patch a security vulnerability. Approved by two reviewers and passed core CI checks before integration. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Merged to address a CVE by updating the requests dependency to version 2.32.4 and setting it as the minimum required version. The change was successfully integrated into the main branch. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Merged dependency update bumping requests to 2.32.4 to patch a security vulnerability. Approved and integrated by maintainer mr-cal without additional review comments or required test runs. |
Update history
No update history recorded yet.
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #122 build(deps): bump requests from 2.32.5 to 2.33.0 | starflow | merged | Merged Dependabot update bumping requests from 2.32.5 to 2.33.0. Includes CVE-2026-25645 security fix and Python 3.9 removal. All CI checks passed and two reviewers approved the change prior to merge. | |
| #1516 build(deps): update dependency requests to v2.33.0 [security] (main) | craft-parts | merged | Merged automated dependency update upgrading requests from 2.32.5 to 2.33.0 to patch CVE-2026-25645. Approved by two reviewers, passed CI validation, and merged into main. | |
| #5065 build(deps): update dependency requests to v2.32.2 [security] (hotfix/7.5) | snapcraft | merged | Merged an automated security update upgrading the requests dependency from v2.28.1 to v2.32.2 to fix CVE-2024-35195. Approved by two reviewers, passed CI, and merged into the hotfix/7.5 branch. | |
| #106 build(deps): bump requests from 2.32.5 to 2.33.0 | debcraft | merged | Merged Dependabot update bumping requests from 2.32.5 to 2.33.0. Includes CVE-2026-25645 security fix, PEP 517 migration, and Python 3.9 removal. Approved by two reviewers with all CI checks passing before merge. | |
| #348 build(deps): update dependency requests to v2.33.0 [security] (main) | craft-store | merged | Merged automated dependency update upgrading requests from 2.32.4 to 2.33.0 to resolve CVE-2026-25645. Approved by reviewers, passed CI checks, and merged into main. | |
| #5067 build(deps): update dependency requests to v2.32.2 [security] (hotfix/8.4) | snapcraft | merged | Merged security hotfix updating requests from v2.31.0 to v2.32.2 to resolve CVE-2024-35195, fixing SSL verification state leakage in HTTP sessions. Approved by two reviewers and passed CI checks. | |
| #308 build: update requests to 2.33.0 | imagecraft | merged | Merged a dependency update bumping requests to 2.33.0 to resolve an OSV. Approved by two reviewers and passed CI, the single-file change addresses the security vulnerability. | |
| #6127 build(deps): bump requests from 2.32.5 to 2.33.0 | snapcraft | merged | Merged Dependabot PR bumping requests from 2.32.5 to 2.33.0. The update addresses CVE-2026-25645, migrates to PEP 517, and drops Python 3.9 support. Approved by reviewers and merged after CI checks. | |
| #5064 build(deps): update dependency requests to v2.32.2 [security] (main) | snapcraft | merged | Merged to main after approval and CI. Updates requests from v2.31.0 to v2.32.2 to fix CVE-2024-35195, resolving an SSL verification bypass vulnerability in persistent sessions. | |
| #2612 build(deps): bump requests from 2.32.5 to 2.33.0 | charmcraft | merged | Merged Dependabot PR bumping requests from 2.32.5 to 2.33.0. Update includes CVE-2026-25645 fix, authentication bug fixes, and Python 3.9 removal. Merged despite minor CI failures and non-blocking type warnings. |