← Back to issue list

build(deps): bump requests to 2.32.4

View original Github issue

Metadata

Project
snapcraft
Number
#5553
Type
pull request
State
merged
Author
mr-cal
Labels
Created
Updated
Closed

Current evaluation

Merged a dependency update bumping requests to 2.32.4 to patch a security vulnerability. Approved by two reviewers and passed core CI checks before integration.

Suggested action:

No scores available.

Issue body

- [x] Have you followed the [guidelines for contributing](https://github.com/canonical/snapcraft/blob/main/CONTRIBUTING.md)? - [x] Have you signed the [CLA](http://www.ubuntu.com/legal/contributors/)? - [ ] Have you successfully run `make lint`? - [ ] Have you successfully run `make test`? --- Bump and set a minimum version of requests for a CVE.

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.6-35b-a3b Merged a dependency update bumping requests to 2.32.4 to patch a security vulnerability. Approved by two reviewers and passed core CI checks before integration.
qwen3.6-35b-a3b-mtp-q6 Merged to address a CVE by updating the requests dependency to version 2.32.4 and setting it as the minimum required version. The change was successfully integrated into the main branch.
qwen3.6-35b-a3b-mtp-q6 Merged dependency update bumping requests to 2.32.4 to patch a security vulnerability. Approved and integrated by maintainer mr-cal without additional review comments or required test runs.

Update history

No update history recorded yet.

Related issues

Issue Project State Summary Similarity
#122 build(deps): bump requests from 2.32.5 to 2.33.0 starflow merged Merged Dependabot update bumping requests from 2.32.5 to 2.33.0. Includes CVE-2026-25645 security fix and Python 3.9 removal. All CI checks passed and two reviewers approved the change prior to merge.
86%
#1516 build(deps): update dependency requests to v2.33.0 [security] (main) craft-parts merged Merged automated dependency update upgrading requests from 2.32.5 to 2.33.0 to patch CVE-2026-25645. Approved by two reviewers, passed CI validation, and merged into main.
85%
#5065 build(deps): update dependency requests to v2.32.2 [security] (hotfix/7.5) snapcraft merged Merged an automated security update upgrading the requests dependency from v2.28.1 to v2.32.2 to fix CVE-2024-35195. Approved by two reviewers, passed CI, and merged into the hotfix/7.5 branch.
85%
#106 build(deps): bump requests from 2.32.5 to 2.33.0 debcraft merged Merged Dependabot update bumping requests from 2.32.5 to 2.33.0. Includes CVE-2026-25645 security fix, PEP 517 migration, and Python 3.9 removal. Approved by two reviewers with all CI checks passing before merge.
85%
#348 build(deps): update dependency requests to v2.33.0 [security] (main) craft-store merged Merged automated dependency update upgrading requests from 2.32.4 to 2.33.0 to resolve CVE-2026-25645. Approved by reviewers, passed CI checks, and merged into main.
85%
#5067 build(deps): update dependency requests to v2.32.2 [security] (hotfix/8.4) snapcraft merged Merged security hotfix updating requests from v2.31.0 to v2.32.2 to resolve CVE-2024-35195, fixing SSL verification state leakage in HTTP sessions. Approved by two reviewers and passed CI checks.
84%
#308 build: update requests to 2.33.0 imagecraft merged Merged a dependency update bumping requests to 2.33.0 to resolve an OSV. Approved by two reviewers and passed CI, the single-file change addresses the security vulnerability.
83%
#6127 build(deps): bump requests from 2.32.5 to 2.33.0 snapcraft merged Merged Dependabot PR bumping requests from 2.32.5 to 2.33.0. The update addresses CVE-2026-25645, migrates to PEP 517, and drops Python 3.9 support. Approved by reviewers and merged after CI checks.
83%
#5064 build(deps): update dependency requests to v2.32.2 [security] (main) snapcraft merged Merged to main after approval and CI. Updates requests from v2.31.0 to v2.32.2 to fix CVE-2024-35195, resolving an SSL verification bypass vulnerability in persistent sessions.
83%
#2612 build(deps): bump requests from 2.32.5 to 2.33.0 charmcraft merged Merged Dependabot PR bumping requests from 2.32.5 to 2.33.0. Update includes CVE-2026-25645 fix, authentication bug fixes, and Python 3.9 removal. Merged despite minor CI failures and non-blocking type warnings.
82%