build(deps): add constraint for Starlette
Metadata
Current evaluation
Merged to pin Starlette to a secure version, mitigating the BadHost CVE. Approved by two reviewers and passed CI checks, updating constraints in two files.
Suggested action: —
No scores available.
Issue body
Pin the indirect dependency to a version not affected by BadHost CVE.
---
- [ ] I've followed the [contribution guidelines](https://github.com/canonical/snapcraft/blob/main/CONTRIBUTING.md).
- [ ] I've signed the [CLA](http://www.ubuntu.com/legal/contributors/).
- [ ] I've successfully run `make lint && make test`.
- [ ] I've added or updated any relevant documentation.
- [ ] In documents I changed, I [added a meta description](https://canonical-starflow.readthedocs-hosted.com/how-to/add-a-page-meta-description/) if one was missing.
- [ ] I've updated the relevant release notes.
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Merged to pin Starlette to a secure version, mitigating the BadHost CVE. Approved by two reviewers and passed CI checks, updating constraints in two files. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Merged a dependency constraint update for Starlette to pin it to a version unaffected by the BadHost CVE. The security fix for the indirect dependency was successfully integrated. |
Update history
No update history recorded yet.
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #190 build(deps): add constraint for Starlette | craft-grammar | merged | Merged to pin the Starlette dependency to a secure version, mitigating the BadHost CVE. Approved by two reviewers and passed CI checks. The update applied minor constraint changes across two files. | |
| #1241 build(deps): add constraint for Starlette | rockcraft | merged | Merged change pins Starlette to a version unaffected by the BadHost CVE. Approved by two reviewers with all CI checks passing, the update enforces the secure dependency constraint across two files. | |
| #376 build(deps): add constraint for Starlette | craft-store | merged | Merged to pin Starlette and mitigate the BadHost CVE. Approved by two reviewers and passed CI checks. The change adds a version constraint to the indirect dependency, resolving the security vulnerability. | |
| #164 build(deps): add constraint for Starlette | debcraft | merged | Merged to pin the Starlette indirect dependency to a version unaffected by the BadHost CVE. Approved by two reviewers and passed CI checks. | |
| #2716 build(deps): add constraint for Starlette | charmcraft | merged | Merged dependency constraint pinning Starlette to a version unaffected by the BadHost CVE. Approved by a reviewer, passed CI checks, and successfully integrated. | |
| #228 build(deps): add constraint for Starlette | craft-platforms | merged | Merged to pin the Starlette indirect dependency, mitigating the BadHost CVE. Approved by two reviewers and integrated after passing the majority of CI checks. | |
| #972 build(deps): add constraint for Starlette | craft-providers | merged | Merged to pin the Starlette indirect dependency, mitigating the BadHost CVE. Approved by two reviewers and validated by CI before integration. | |
| #547 build(deps): add constraint for Starlette | starbase | merged | Merged a dependency update pinning Starlette to a version unaffected by the BadHost CVE. Approved by two reviewers and passing all CI checks, the change adds a version constraint to mitigate the vulnerability. | |
| #91 build(deps): add constraint for Starlette | craft-artifacts | merged | Merged a pull request adding a version constraint for the Starlette dependency to mitigate the BadHost CVE. Approved by two reviewers, passed CI checks, and was merged 48 days ago. | |
| #350 build(deps): bump starlette | imagecraft | merged | Merged dependency update bumping starlette from v0.52.1 to v1.2.0 to resolve an OSV vulnerability. Approved by two reviewers and passed all CI checks prior to integration. |