Skip to content

chore(deps): bump cryptography from 46.0.7 to 50.0.0 in /envs/agent_world_model_env - #1059

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/envs/agent_world_model_env/cryptography-50.0.0
Closed

chore(deps): bump cryptography from 46.0.7 to 50.0.0 in /envs/agent_world_model_env#1059
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/envs/agent_world_model_env/cryptography-50.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 5, 2026

Copy link
Copy Markdown
Contributor

Bumps cryptography from 46.0.7 to 50.0.0.

Changelog

Sourced from cryptography's changelog.

50.0.0 - 2026-07-31


* **SECURITY ISSUE**:
  :func:`~cryptography.hazmat.primitives.serialization.pkcs7.pkcs7_decrypt_der`
  and its PEM and S/MIME variants no longer expose distinguishable errors or
  timing when unwrapping a ``RecipientInfo``'s ``encryptedKey``, which could
  act as a Bleichenbacher oracle for callers that decrypt untrusted messages.
  A random key is now substituted on failure, as described in :rfc:`3218`.
  Credit to **@X1AOxiang** for reporting the issue. **CVE-2026-69247**
* Deprecated Diffie-Hellman key exchange over finite fields (FFDH).
  Everything FFDH is deprecated, including the types in
  ``cryptography.hazmat.primitives.asymmetric.dh`` and loading FFDH keys or
  parameters with the key loading APIs. Users should migrate to a more
  modern key exchange algorithm.
* Added ``xof()`` class methods to
  :class:`~cryptography.hazmat.primitives.hashes.SHAKE128` and
  :class:`~cryptography.hazmat.primitives.hashes.SHAKE256` for constructing
  algorithm instances configured for use with
  :class:`~cryptography.hazmat.primitives.hashes.XOFHash`.
* The :mod:`X.509 verification <cryptography.x509.verification>` APIs are now
  considered stable and are subject to our API stability policy.
* Added the :doc:`/cobblestone` recipe, an implementation of the
  Cobblestone-128 and Cobblestone-256 instantiations of the `C2SP
  chunked-encryption specification
  <https://c2sp.org/chunked-encryption>`_ for streaming authenticated
  encryption of large messages.
* Parsing a Signed Certificate Timestamp list now rejects encodings that
  carry trailing bytes after the list or after an individual SCT, instead of
  silently ignoring them.
* Added support for using :class:`~cryptography.x509.Name` as a field type in
  the :doc:`/hazmat/asn1/index` module.
* Loading a public key or an EC private key now rejects DER where the
  ``subjectPublicKey`` (or EC ``publicKey``) ``BIT STRING`` declares a non-zero
  number of unused bits, instead of silently ignoring it.
* Parsing a CRL entry's ``InvalidityDate`` extension now rejects a
  ``GeneralizedTime`` that carries fractional seconds or another non-DER form,
  matching the strict encoding already required for every other X.509 time
  field.
* :func:`~cryptography.x509.ocsp.load_der_ocsp_request` and
  :func:`~cryptography.x509.ocsp.load_der_ocsp_response` now reject a request
  or response whose ``version`` field is not ``v1``, the only version defined
  by RFC 6960, matching the version validation already performed when loading
  certificates, CSRs and CRLs.
* :class:`~cryptography.hazmat.primitives.hashes.XOFHash` is now supported
  when building against AWS-LC.
* HMAC (and therefore PBKDF2-HMAC) with SHA-3 hashes is now supported when
  building against AWS-LC.
* Diffie-Hellman (:doc:`/hazmat/primitives/asymmetric/dh`) is now supported
  when building against AWS-LC.
</tr></table> 

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Note

Medium Risk
Major transitive crypto upgrade can change TLS/JWT/key behavior for Authlib consumers; the release tightens parsing and deprecates FFDH, so regression risk is moderate despite no app code edits.

Overview
Updates envs/agent_world_model_env/uv.lock so the resolved cryptography package moves from 46.0.7 to 50.0.0 (still pulled in transitively, e.g. via Authlib and SecretStorage). No Python or config files outside the lockfile change.

The lock refresh also drops several Python-version markers on transitive deps for pandas, scikit-learn, scipy, and secretstorage—resolver/metadata churn from the same uv update, not separate feature work.

50.0.0 includes a security fix (CVE-2026-69247) for PKCS#7 encryptedKey decryption oracles and stricter X.509/OCSP parsing; finite-field DH APIs are deprecated in this release.

Reviewed by Cursor Bugbot for commit b1c29f0. Bugbot is set up for automated code reviews on this repo. Configure here.

Bumps [cryptography](https://github.com/pyca/cryptography) from 46.0.7 to 50.0.0.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@46.0.7...50.0.0)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 50.0.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added Dependencies python:uv Pull requests that update python:uv code labels Aug 5, 2026
@bot-ci-comment

bot-ci-comment Bot commented Aug 5, 2026

Copy link
Copy Markdown

The docs for this PR live here. All of your documentation changes will be reflected on that endpoint. The docs are available until 30 days after the last update.

@burtenshaw burtenshaw added environment size: small Small pull request labels Aug 5, 2026 — with Cursor

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Alignment Review Report

chore(deps): bump cryptography 46.0.7 → 50.0.0 in /envs/agent_world_model_env — dependabot, lock-only (envs/agent_world_model_env/uv.lock, +67/−70, no .py/source changes).

Automated Checks

  • Lint: N/A / no new issues — the PR touches only uv.lock (TOML/lock is not linted). The repo lint hook exit-1's on ~25 pre-existing ruff format drifts in unrelated envs (chat_env, coding_tools_env, opencode_env, pi_env, repl_env, terminus_env, textarena_env, …); none are in this diff, and GitHub CI lint is green.
  • Debug code: CLEANcheck-debug.sh scans src/ only; this PR changes no source.

Lockfile verification (dependency-bump playbook)

  • Transitive dep: cryptography is pulled in via authlib and secretstorage (both declare it unconstrained); the env's pyproject.toml doesn't pin it, so a lock-only bump is the correct shape.
  • Consistency: uv lock --check passes (159 packages, lock up-to-date with pyproject.toml).
  • Hashes real: lock sdist sha256 eeac2acb…a6c9 (size 880201) matches PyPI exactly; not yanked.
  • Python constraint OK: env requires-python >=3.10 ⊆ cryptography 50.0.0 >=3.9.
  • Security-positive: 46.0.7 carries 7 advisories; 50.0.0 clears all of them and has 0 known advisories. The jump to exactly 50.0.0 is warranted — CVE-2026-69247 (GHSA-g6cj-pr64-35w5 / PYSEC-2026-3552) is fixed_in: 50.0.0 (49.x would not clear it).
  • No index-flip / no revision bump: this env's lock is "born-clean" (0 HF-mirror refs, revision = 3 on both sides). The only incidental churn is benign resolution-marker simplification on numpy/scipy/pandas/scikit-learn/secretstorage entries (redundant python_full_version markers dropped — these entries are already partitioned by section-level resolution-markers). uv lock --check confirms the resolution is unchanged.

Open RFCs Context

Open RFCs: 000/001/002/003/005 (In Review), 010 (Draft), 004 Rubrics (no status header). None govern dependency management / packaging / PyPI, and no RFC-covered surface is touched.

Tier 1: Fixes Required

  • None.

Tier 2: Alignment Discussion

Principle / Invariant Conflicts — None identified. A transitive dependency version bump doesn't touch the Gym API signatures, client/server separation, rewards-in-environment, MCP boundary, agents-cannot-reset, or Pydantic wire types.

RFC Conflicts — None identified.

Process note (non-blocking, FYI) — This is a native dependabot/uv/envs/agent_world_model_env/... PR, yet .github/dependabot.yml declares exclude-paths: ["envs/**"] for the uv updater (the intended lane for env bumps is the aggregate codex/dependabot-envs-* roll-ups). The uv ecosystem not honoring exclude-paths is a known platform limitation, so native env-lock PRs keep appearing — purely a tooling/process observation. cc @burtenshaw (owns .github/dependabot.yml).

Summary

  • 0 mechanical issues to fix
  • 0 principle/invariant conflicts
  • 0 RFC conflicts
  • 1 non-blocking process FYI. Security-positive bump; lock verified consistent and hashes authentic — looks good to merge once CI is green.
Open in Web View Automation 

Sent by Cursor Automation: Pre-review

[[package]]
name = "cryptography"
version = "46.0.7"
version = "50.0.0"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security-positive bump — verified. The sdist sha256 eeac2acb…a6c9 (size 880201) matches PyPI and is not yanked, and uv lock --check passes.

Bumping to exactly 50.0.0 is required: the prior 46.0.7 has 7 advisories, and CVE-2026-69247 (GHSA-g6cj-pr64-35w5 / PYSEC-2026-3552) is fixed_in: 50.0.0 — 49.x would not clear it. 50.0.0 itself has 0 known advisories.

cryptography is transitive here (via authlib/secretstorage, both unconstrained), so the lock-only change is the correct shape and the env requires-python >=3.10 satisfies cryptography's >=3.9.

{ name = "python-dateutil", marker = "python_full_version < '3.11'" },
{ name = "pytz", marker = "python_full_version < '3.11'" },
{ name = "tzdata", marker = "python_full_version < '3.11'" },
{ name = "numpy", version = "2.2.6", source = { registry = "https://pypi.org/simple" } },

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Incidental (benign) re-resolution churn, not part of the named bump: redundant marker = "python_full_version < '3.11'" suffixes were dropped from several transitive entries (numpy/scipy/pandas/scikit-learn/secretstorage) because those package versions are already gated by the section-level resolution-markers. Semantically equivalent — uv lock --check confirms the resolution is unchanged. No action needed.

@burtenshaw

Copy link
Copy Markdown
Collaborator

Closing in favor of aggregate env Dependabot PR #1015.

@burtenshaw burtenshaw closed this Aug 6, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 6, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/uv/envs/agent_world_model_env/cryptography-50.0.0 branch August 6, 2026 09:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Dependencies environment python:uv Pull requests that update python:uv code size: small Small pull request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant