build(deps): bump pip
Metadata
Current evaluation
Merged a dependency update bumping pip from v26.1 to v26.1.2 to resolve an OSV security vulnerability. Approved by reviewers and integrated after passing CI checks.
Suggested action: —
No scores available.
Issue body
Updates pip v26.1 -> v26.1.2 to resolve an OSV
---
- [x] I've followed the [contribution guidelines](https://github.com/canonical/snapcraft/blob/main/CONTRIBUTING.md).
- [x] I've signed the [CLA](http://www.ubuntu.com/legal/contributors/).
- [ ] I've successfully run `make lint && make test`.
- [ ] I've added or updated any relevant documentation.
- [ ] In documents I changed, I [added a meta description](https://canonical-starflow.readthedocs-hosted.com/how-to/add-a-page-meta-description/) if one was missing.
- [ ] I've updated the relevant release notes.
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Merged a dependency update bumping pip from v26.1 to v26.1.2 to resolve an OSV security vulnerability. Approved by reviewers and integrated after passing CI checks. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Merged a dependency update bumping pip from v26.1 to v26.1.2 to resolve an OSV vulnerability. The change was integrated by maintainer smethnani without additional review comments or documentation updates. |
Update history
No update history recorded yet.
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #6221 build(deps): bump pip | snapcraft | merged | Merged a dependency update to bump pip, resolving an OSV security vulnerability. Approved by two reviewers, the change was accepted after passing CI checks and involved a minor version bump in one file. | |
| #4776 build(deps): bump pip from 22.0.2 to 23.3 in /docs | snapcraft | merged | Dependabot merged an automated dependency update bumping pip from 22.0.2 to 23.3 in /docs. Approved by two reviewers, passed CI checks, and applied cleanly without conflicts or review comments. | |
| #1550 build(deps): bump pytest | craft-parts | merged | Merged to bump pytest, resolving an OSV security vulnerability. Approved by two reviewers with all CI checks passing. The update required a minimal three-line configuration change. | |
| #5871 build(autogen): bump pip for OSV | snapcraft | merged | Merged after three approvals. Bumps pip to 25.3 to resolve OSV vulnerability GHSA-4xh5-x5gv-qwph. All required CI checks passed prior to merge. | |
| #321 build(deps): bump pytest | imagecraft | merged | Merged a dependency update bumping pytest to resolve an OSV vulnerability. Approved by two reviewers with all CI checks passing. The change modified a single file with minimal adjustments. | |
| #453 build(deps): bump pytest | craft-cli | merged | Merged a dependency update to bump pytest, resolving an OSV scanner vulnerability. Approved by one reviewer and passed all CI checks across multiple platforms and Python versions. | |
| #6008 build(deps-dev): bump pip from 25.3 to 26.0 | snapcraft | closed | Superseded by PR #6011. Dependabot closed this pip version bump after the update was resolved in another pull request. | |
| #1336 build(deps): update dependency pip to v25 [security] (hotfix/2.20) - autoclosed | craft-parts | closed | Renovate autoclosed this dependency update after CI checks passed. The PR proposed upgrading pip to v25.2 to patch CVE-2025-8869. Automatic closure indicates the change was merged, superseded, or the target branch was deleted. | |
| #5553 build(deps): bump requests to 2.32.4 | snapcraft | merged | Merged a dependency update bumping requests to 2.32.4 to patch a security vulnerability. Approved by two reviewers and passed core CI checks before integration. | |
| #524 build(deps): bump pytest | starbase | merged | Merged a dependency update bumping pytest to resolve an OSV. Approved by two reviewers with all CI checks passing. The change updates a single file. |