chore(deps): bump cryptography from 47.0.0 to 50.0.0 in /envs/opencode_env - #1061
chore(deps): bump cryptography from 47.0.0 to 50.0.0 in /envs/opencode_env#1061dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [cryptography](https://github.com/pyca/cryptography) from 47.0.0 to 50.0.0. - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@47.0.0...50.0.0) --- updated-dependencies: - dependency-name: cryptography dependency-version: 50.0.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
|
The docs for this PR live here. All of your documentation changes will be reflected on that endpoint. The docs are available until 30 days after the last update. |
There was a problem hiding this comment.
Alignment Review Report
PR #1061 — chore(deps): bump cryptography 47.0.0 → 50.0.0 in /envs/opencode_env (dependabot[bot], native dependabot/uv/envs/opencode_env/cryptography-50.0.0). Scope: 1 file, envs/opencode_env/uv.lock (+191/−194). Lock-only transitive bump. Security-positive.
Automated Checks
- Lint: PASS (for this PR).
.claude/hooks/lint.shexits 1 only on ~26 pre-existingenvs/**/*.pyreformat candidates (the long-standingopencode_envx8 +pi_envx5 from #999). This PR changes onlyuv.lock(TOML — not linted by the hook or CI; CI's lint job scopes tosrc/ tests/), so none of the flagged files are yours. - Debug code: CLEAN.
check-debug.shscanssrc/only; every hit is pre-existing (containers/*,generic_client.pydoc-examples,serve.pyTODO). Nothing in this diff.
Open RFCs Context
Active RFCs on this branch: 000/001/002/003/004 (Rubrics)/005 (Agentic Harnesses, In Review)/010 (Token World Model, Draft). None govern packaging / dependency management / PyPI index selection. opencode_env is RFC-005 territory, but this is a lock-only bump that touches no harness code → no RFC conflict.
Tier 1: Fixes Required
None. Verification performed:
-
uv lock --check(opencode_env) → PASS ("Resolved 130 packages"). - Hash integrity: all 46 locked
cryptography-50.0.0artifacts (1 sdist + 45 wheels) match PyPIsha256+ size + filename exactly; none yanked; no PyPI artifact missing from the lock; no non-cryptographyfiles.pythonhosted.orgline changed. - Correct as lock-only: cryptography is transitive (
openenv → fastmcp → authlib → cryptography, also viajoserfc,pyjwt[crypto],secretstorage); pyproject untouched; norequires-distre-sync; no editable-openenv refresh. - Blast radius: no
opencode_envsource importscryptography/authlib/jwt/secretstorage/keyring→ zero env-code impact. - Stale check:
origin/main== PR base (024eedc);git merge-treeclean; 1 commit ahead, no rebase needed.
Tier 2: Alignment Discussion
Principle Conflicts
ALIGNMENT FLAG: Lock index-source flip from the HF PyPI mirror to public PyPI
- Principle at stake: PRINCIPLES.md L15/L22 — "Container isolation for reproducibility"; artifact provenance
- The concern: this re-lock flips all 135 index sources from
pypi.registries.huggingface.tech→pypi.org/simple(0 mirror refs remain; 0 → 135). Artifact URLs stayfiles.pythonhosted.organd all hashes are unchanged, so it is almost certainly benign — but it changes the declared provenance of every dependency, which is a team/reproducibility decision rather than something to silently accept in a bot bump. Do not self-revert — registry choice is a team call. - Suggested reviewer: @Darktex (reproducibility principle author) + @burtenshaw (dependabot config owner)
RFC Conflicts
None identified.
Process / heads-up notes (non-blocking)
- exclude-paths bypass:
.github/dependabot.ymlconfigures theuvupdater withdirectory: "/"+exclude-paths: ["envs/**"](authored by @burtenshaw, 5f499da), yet this native PR modifiesenvs/opencode_env/uv.lock. Two compounding reasons it still fires: (1) the uv ecosystem doesn't honorexclude-paths(dependabot-core#15102), and (2) CVE-driven security updates can't be suppressed byexclude-pathsat all (dependabot-core#14408). Thecodex/dependabot-envs-*aggregate roll-ups are the intended path for env bumps. cc @burtenshaw. - Lock
revision = 2 → 3: latent-only.openenv-base:latestships uv 0.5.27 (too old for rev-3) and this env'sserver/Dockerfileusesuv sync --frozen(only installs fresh uvif ! command -v uv, which won't trigger). Not exercised here —docker-build.ymltriggers onenvs/**/Dockerfile/*.py, notuv.lock— and several already-rev-3 envs (openapp/jupyter/…) deploy fine. Worth confirming the base image's uv can parse rev-3 eventually.
Summary
- 0 mechanical issues to fix
- 1 alignment point for human review (index-source provenance flip)
- 0 RFC conflicts
- Verdict: security-positive transitive bump (clears 4 distinct advisories, incl. one fixed only in 50.0.0); safe to proceed after a nod on the index-flip provenance.
Sent by Cursor Automation: Pre-review
| @@ -605,68 +605,65 @@ toml = [ | |||
|
|
|||
| [[package]] | |||
| name = "cryptography" | |||
| version = "47.0.0" | |||
| source = { registry = "https://pypi.registries.huggingface.tech/" } | |||
| version = "50.0.0" | |||
There was a problem hiding this comment.
Security bump (positive). cryptography 47.0.0 → 50.0.0 clears all 4 distinct advisories outstanding at 47.0.0 (7 PyPI records incl. GHSA/PYSEC aliases):
- GHSA-537c-gmf6-5ccf → fixed 48.0.1
- CVE-2026-69248 / GHSA-m2h6-j472-rp4c → 49.0.0
- CVE-2026-69249 / GHSA-jwv3-5hgf-82ww → 49.0.0
- CVE-2026-69247 / GHSA-g6cj-pr64-35w5 → 50.0.0 only — this is why the target is exactly 50.0.0, not 49.x.
Verified: all 46 locked 50.0.0 artifacts (1 sdist + 45 wheels) match PyPI sha256+size exactly, none yanked; 50.0.0 itself reports 0 advisories; requires_python >=3.9 satisfied by opencode_env >=3.10. Transitive via authlib/joserfc/pyjwt[crypto]/secretstorage — no opencode_env code imports it.
| @@ -17,7 +17,7 @@ resolution-markers = [ | |||
| [[package]] | |||
| name = "aiofile" | |||
| version = "3.9.0" | |||
| source = { registry = "https://pypi.registries.huggingface.tech/" } | |||
| source = { registry = "https://pypi.org/simple" } | |||
There was a problem hiding this comment.
Tier 2 (reproducibility / provenance). This re-lock flips all 135 index sources from the HF mirror (pypi.registries.huggingface.tech) to public PyPI (pypi.org/simple) — 0 mirror refs remain. Artifact URLs stay files.pythonhosted.org and every hash is unchanged, so it's almost certainly benign, but it changes the declared provenance of the whole lock. Registry choice is a team decision → flagging for @Darktex + @burtenshaw; please don't self-revert in this PR.
| @@ -1,5 +1,5 @@ | |||
| version = 1 | |||
| revision = 2 | |||
| revision = 3 | |||
There was a problem hiding this comment.
Heads-up (non-blocking). Lock revision bumps 2 → 3, which needs uv ≥ ~0.8. openenv-base:latest ships uv 0.5.27 and this env's server/Dockerfile uses uv sync --frozen (only installs fresh uv if ! command -v uv, which won't trigger since the base has it). Not exercised by this PR (docker-build.yml triggers on Dockerfile/*.py, not uv.lock), and other rev-3 envs already deploy — but worth confirming the base image's uv can parse rev-3.
|
Closing in favor of aggregate env Dependabot PR #1015. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |


Bumps cryptography from 47.0.0 to 50.0.0.
Changelog
Sourced from cryptography's changelog.
... (truncated)
Commits
dcb7050Prepare for 50.0.0 release (#15372)53fccd9Don't leak how PKCS#7 encryptedKey decryption failed (#15369)d472f97Addfrom __future__ import annotationsto all src/ Python files (#15371)908773dBump downstream dependencies in CI (#15368)2cc07ccBump BoringSSL, OpenSSL, AWS-LC in CI (#15367)c94ede9chore(deps): bump ruff from 0.16.0 to 0.16.1 (#15366)67a8308chore(deps): bump virtualenv from 21.7.0 to 21.7.1 (#15365)95018ffRelease the GIL in one-shot AEAD encrypt/decrypt (#15361)6954733Release the GIL during DH and DSA parameter generation (#15364)6893b94Import _serialization instead of serialization in x509/extensions (#15363)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.
Note
Medium Risk
Major bump of a security-critical transitive library may change crypto/X.509 behavior at runtime; impact is limited to lockfile resolution unless PKCS#7 or deprecated FFDH APIs are used directly.
Overview
Updates the
envs/opencode_envlockfile so the transitivecryptographydependency moves from 47.0.0 to 50.0.0 (pulled in viaauthlib; not a directpyproject.tomldependency).This is a major release that includes a security fix for PKCS#7
encryptedKeydecryption (CVE-2026-69247, Bleichenbacher-style oracle mitigation) plus stricter X.509/OCSP parsing and deprecation of finite-field Diffie-Hellman. No application source in this PR—only resolved package versions inuv.lock.Reviewed by Cursor Bugbot for commit 6cb3cf5. Bugbot is set up for automated code reviews on this repo. Configure here.