chore(deps): bump cryptography from 46.0.7 to 50.0.0 in /envs/agent_world_model_env - #1059
Conversation
Bumps [cryptography](https://github.com/pyca/cryptography) from 46.0.7 to 50.0.0. - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@46.0.7...50.0.0) --- updated-dependencies: - dependency-name: cryptography dependency-version: 50.0.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
|
The docs for this PR live here. All of your documentation changes will be reflected on that endpoint. The docs are available until 30 days after the last update. |
There was a problem hiding this comment.
Alignment Review Report
chore(deps): bump cryptography 46.0.7 → 50.0.0 in /envs/agent_world_model_env — dependabot, lock-only (envs/agent_world_model_env/uv.lock, +67/−70, no .py/source changes).
Automated Checks
- Lint: N/A / no new issues — the PR touches only
uv.lock(TOML/lock is not linted). The repo lint hook exit-1's on ~25 pre-existingruff formatdrifts in unrelated envs (chat_env,coding_tools_env,opencode_env,pi_env,repl_env,terminus_env,textarena_env, …); none are in this diff, and GitHub CIlintis green. - Debug code: CLEAN —
check-debug.shscanssrc/only; this PR changes no source.
Lockfile verification (dependency-bump playbook)
- Transitive dep:
cryptographyis pulled in viaauthlibandsecretstorage(both declare it unconstrained); the env'spyproject.tomldoesn't pin it, so a lock-only bump is the correct shape. - Consistency:
uv lock --checkpasses (159 packages, lock up-to-date withpyproject.toml). - Hashes real: lock sdist
sha256 eeac2acb…a6c9(size 880201) matches PyPI exactly; not yanked. - Python constraint OK: env
requires-python >=3.10⊆ cryptography 50.0.0>=3.9. - Security-positive: 46.0.7 carries 7 advisories; 50.0.0 clears all of them and has 0 known advisories. The jump to exactly 50.0.0 is warranted — CVE-2026-69247 (GHSA-g6cj-pr64-35w5 / PYSEC-2026-3552) is
fixed_in: 50.0.0(49.x would not clear it). - No index-flip / no revision bump: this env's lock is "born-clean" (0 HF-mirror refs,
revision = 3on both sides). The only incidental churn is benign resolution-marker simplification onnumpy/scipy/pandas/scikit-learn/secretstorageentries (redundantpython_full_versionmarkers dropped — these entries are already partitioned by section-levelresolution-markers).uv lock --checkconfirms the resolution is unchanged.
Open RFCs Context
Open RFCs: 000/001/002/003/005 (In Review), 010 (Draft), 004 Rubrics (no status header). None govern dependency management / packaging / PyPI, and no RFC-covered surface is touched.
Tier 1: Fixes Required
- None.
Tier 2: Alignment Discussion
Principle / Invariant Conflicts — None identified. A transitive dependency version bump doesn't touch the Gym API signatures, client/server separation, rewards-in-environment, MCP boundary, agents-cannot-reset, or Pydantic wire types.
RFC Conflicts — None identified.
Process note (non-blocking, FYI) — This is a native dependabot/uv/envs/agent_world_model_env/... PR, yet .github/dependabot.yml declares exclude-paths: ["envs/**"] for the uv updater (the intended lane for env bumps is the aggregate codex/dependabot-envs-* roll-ups). The uv ecosystem not honoring exclude-paths is a known platform limitation, so native env-lock PRs keep appearing — purely a tooling/process observation. cc @burtenshaw (owns .github/dependabot.yml).
Summary
- 0 mechanical issues to fix
- 0 principle/invariant conflicts
- 0 RFC conflicts
- 1 non-blocking process FYI. Security-positive bump; lock verified consistent and hashes authentic — looks good to merge once CI is green.
Sent by Cursor Automation: Pre-review
| [[package]] | ||
| name = "cryptography" | ||
| version = "46.0.7" | ||
| version = "50.0.0" |
There was a problem hiding this comment.
Security-positive bump — verified. The sdist sha256 eeac2acb…a6c9 (size 880201) matches PyPI and is not yanked, and uv lock --check passes.
Bumping to exactly 50.0.0 is required: the prior 46.0.7 has 7 advisories, and CVE-2026-69247 (GHSA-g6cj-pr64-35w5 / PYSEC-2026-3552) is fixed_in: 50.0.0 — 49.x would not clear it. 50.0.0 itself has 0 known advisories.
cryptography is transitive here (via authlib/secretstorage, both unconstrained), so the lock-only change is the correct shape and the env requires-python >=3.10 satisfies cryptography's >=3.9.
| { name = "python-dateutil", marker = "python_full_version < '3.11'" }, | ||
| { name = "pytz", marker = "python_full_version < '3.11'" }, | ||
| { name = "tzdata", marker = "python_full_version < '3.11'" }, | ||
| { name = "numpy", version = "2.2.6", source = { registry = "https://pypi.org/simple" } }, |
There was a problem hiding this comment.
Incidental (benign) re-resolution churn, not part of the named bump: redundant marker = "python_full_version < '3.11'" suffixes were dropped from several transitive entries (numpy/scipy/pandas/scikit-learn/secretstorage) because those package versions are already gated by the section-level resolution-markers. Semantically equivalent — uv lock --check confirms the resolution is unchanged. No action needed.
|
Closing in favor of aggregate env Dependabot PR #1015. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |


Bumps cryptography from 46.0.7 to 50.0.0.
Changelog
Sourced from cryptography's changelog.
... (truncated)
Commits
dcb7050Prepare for 50.0.0 release (#15372)53fccd9Don't leak how PKCS#7 encryptedKey decryption failed (#15369)d472f97Addfrom __future__ import annotationsto all src/ Python files (#15371)908773dBump downstream dependencies in CI (#15368)2cc07ccBump BoringSSL, OpenSSL, AWS-LC in CI (#15367)c94ede9chore(deps): bump ruff from 0.16.0 to 0.16.1 (#15366)67a8308chore(deps): bump virtualenv from 21.7.0 to 21.7.1 (#15365)95018ffRelease the GIL in one-shot AEAD encrypt/decrypt (#15361)6954733Release the GIL during DH and DSA parameter generation (#15364)6893b94Import _serialization instead of serialization in x509/extensions (#15363)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.
Note
Medium Risk
Major transitive crypto upgrade can change TLS/JWT/key behavior for Authlib consumers; the release tightens parsing and deprecates FFDH, so regression risk is moderate despite no app code edits.
Overview
Updates
envs/agent_world_model_env/uv.lockso the resolvedcryptographypackage moves from 46.0.7 to 50.0.0 (still pulled in transitively, e.g. via Authlib and SecretStorage). No Python or config files outside the lockfile change.The lock refresh also drops several Python-version markers on transitive deps for pandas, scikit-learn, scipy, and secretstorage—resolver/metadata churn from the same
uvupdate, not separate feature work.50.0.0 includes a security fix (CVE-2026-69247) for PKCS#7
encryptedKeydecryption oracles and stricter X.509/OCSP parsing; finite-field DH APIs are deprecated in this release.Reviewed by Cursor Bugbot for commit b1c29f0. Bugbot is set up for automated code reviews on this repo. Configure here.